← Registry

Developer Tools

sighttrue.com

Provides developers with package health, security advisories, model pricing, and end-of-life information for their dependencies.

1 endpoint31 known toolsFirst detected August 7, 2026Last detected September 19, 2026

ENDPOINT 1

https://sighttrue.com/api/mcp

No auth detected

MCP server metadata

Name
sighttrue
Version
1.0.0
Capabilities
tools
Server instructions

Readings about open-source dependencies, taken every four hours and published as static files. Every figure is measured rather than estimated, and every tool result carries the limits of what it can support. The watchlist is curated and partial: an uncovered package is untracked, not judged.

Known tools 31

check_before_install

Call this before adding a dependency.

Inferred read-only
check_package

Read the current standing of one open-source package: downloads with the window they cover, OpenSSF scorecard, advisory count, licence, whether the repository is archived, and when it was last pushed to.

Inferred read-only
check_stack

Read a whole dependency list at once and report what is archived, what carries advisories, what has a source-available licence, and what has not been pushed to in a year.

Inferred read-only
search_repositories

Find watched repositories whose name contains a string, with their current readings.

Inferred read-only
compare_repositories

Hold two watched repositories against each other across downloads, OpenSSF scorecard, advisories, forks, stars and findings on record.

Inferred read-only
find_model

Find language models by price and context window, from a catalogue read daily across sixty providers.

Inferred read-only
check_eol

Check whether a runtime, database or framework release is still receiving security fixes, and what to move to.

Inferred read-only
check_provider

Recorded incidents for a hosting or API provider over a window, kept after the provider’s own status page dropped them.

Inferred read-only
list_readings

List every reading this server can return, what each one measures, and which require a key.

Inferred read-only
who_can_publish

How many accounts hold publish rights on a package, as the registry lists them.

Potential side effects
package_weight_history

How the published artefact size has moved over time.

Inferred read-only
withdrawn_but_installed

Packages whose own publisher has withdrawn them and which are still being installed heavily, with the download figure and the publisher’s notice.

Inferred read-only
typosquat_check

Whether a name is one edit away from a more widely installed package.

Potential side effects
funding_gap

Packages that ask for funding, beside how heavily they are installed and how many people write them.

Potential side effects
time_to_fix

Days between an advisory being published and a release appearing that postdates it, per package and as a distribution.

Inferred read-only
advisory_severity

Advisories broken down by severity rather than counted, with identifiers and dates.

Inferred read-only
runtime_deadlines

Support end dates for the runtimes a dependency set requires, including any already past.

Inferred read-only
base_image_check

For a container base image: its size, when it was last rebuilt, and whether the OS underneath it is still supported.

Inferred read-only
registry_health

Recorded outages of the package registries themselves, kept after their status pages drop them.

Potential side effects
provider_incidents

A provider’s recorded incidents, grouped by the component that failed, over the whole archive rather than the window its status page shows.

Inferred read-only
provider_transparency

How long a provider takes to acknowledge an incident: the interval between an incident starting and its first public update.

Potential side effects
provider_terms_changed

When a provider last changed its terms or pricing page, from a stored fingerprint of the page.

Inferred read-only
model_price_history

Every recorded price for a model, with the date each was read.

Inferred read-only
model_withdrawn

Models that were in the catalogue and no longer are, with the date last seen.

Inferred read-only
help_availability

For a technology tag: questions asked against questions answered, over time.

Inferred read-only
audit_manifest

Read a whole manifest and return every reading on record for it, ordered by how much a reviewer would want to know.

Inferred read-only
diff_since

What changed for a set of packages since a given date, read from the daily archive.

Inferred read-only
watch_add

Add a package to the caller’s own private watchlist, so later readings are about their stack rather than the public one.

Inferred read-only
watch_changes

Everything that has changed across the caller’s private watchlist since a given date: withdrawals, licence changes, advisories, archived repositories and runtimes going out of support.

Inferred read-only
explain_finding

Given a finding id, return what was measured, when, by whom, and the address it can be checked at.

Inferred read-only
domain_risk

Whether the domains a package points at — homepage, funding, documentation — still resolve to a registered owner.

Inferred read-only

CONNECT WITH APPROVAL

Client installation

Review this server and its permissions before adding it. Secret placeholders must be set locally.

Codex

~/.codex/config.toml

[mcp_servers.sighttrue]
url = "https://sighttrue.com/api/mcp"
enabled = true
Claude Code

.mcp.json

{
  "mcpServers": {
    "sighttrue": {
      "type": "http",
      "url": "https://sighttrue.com/api/mcp"
    }
  }
}
Claude Desktop

Settings → Connectors → Add custom connector

Name: sighttrue
Remote MCP URL: https://sighttrue.com/api/mcp

Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.

Cursor

.cursor/mcp.json

{
  "mcpServers": {
    "sighttrue": {
      "url": "https://sighttrue.com/api/mcp"
    }
  }
}
Visual Studio Code

.vscode/mcp.json

Add to Visual Studio Code
{
  "servers": {
    "sighttrue": {
      "type": "http",
      "url": "https://sighttrue.com/api/mcp"
    }
  }
}
Generic MCP

Client-specific MCP configuration

{
  "name": "sighttrue",
  "transport": "streamable-http",
  "url": "https://sighttrue.com/api/mcp"
}
MCP Inspector

Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.

TRUST AND VERIFICATION EVIDENCE

Loading Trust v2 evidence…

Checking the associated registrable domain. The BuiltWith key remains server-side.

Indexed

Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.