Developer Tools
sighttrue.com
Provides developers with package health, security advisories, model pricing, and end-of-life information for their dependencies.
ENDPOINT 1
https://sighttrue.com/api/mcp
MCP server metadata
- Name
- sighttrue
- Version
- 1.0.0
Readings about open-source dependencies, taken every four hours and published as static files. Every figure is measured rather than estimated, and every tool result carries the limits of what it can support. The watchlist is curated and partial: an uncovered package is untracked, not judged.
Known tools 31
check_packageRead the current standing of one open-source package: downloads with the window they cover, OpenSSF scorecard, advisory count, licence, whether the repository is archived, and when it was last pushed to.
Inferred read-onlycheck_stackRead a whole dependency list at once and report what is archived, what carries advisories, what has a source-available licence, and what has not been pushed to in a year.
Inferred read-onlysearch_repositoriesFind watched repositories whose name contains a string, with their current readings.
Inferred read-onlycompare_repositoriesHold two watched repositories against each other across downloads, OpenSSF scorecard, advisories, forks, stars and findings on record.
Inferred read-onlyfind_modelFind language models by price and context window, from a catalogue read daily across sixty providers.
Inferred read-onlycheck_eolCheck whether a runtime, database or framework release is still receiving security fixes, and what to move to.
Inferred read-onlycheck_providerRecorded incidents for a hosting or API provider over a window, kept after the provider’s own status page dropped them.
Inferred read-onlylist_readingsList every reading this server can return, what each one measures, and which require a key.
Inferred read-onlywho_can_publishHow many accounts hold publish rights on a package, as the registry lists them.
Potential side effectswithdrawn_but_installedPackages whose own publisher has withdrawn them and which are still being installed heavily, with the download figure and the publisher’s notice.
Inferred read-onlytyposquat_checkWhether a name is one edit away from a more widely installed package.
Potential side effectsfunding_gapPackages that ask for funding, beside how heavily they are installed and how many people write them.
Potential side effectstime_to_fixDays between an advisory being published and a release appearing that postdates it, per package and as a distribution.
Inferred read-onlyadvisory_severityAdvisories broken down by severity rather than counted, with identifiers and dates.
Inferred read-onlyruntime_deadlinesSupport end dates for the runtimes a dependency set requires, including any already past.
Inferred read-onlybase_image_checkFor a container base image: its size, when it was last rebuilt, and whether the OS underneath it is still supported.
Inferred read-onlyregistry_healthRecorded outages of the package registries themselves, kept after their status pages drop them.
Potential side effectsprovider_incidentsA provider’s recorded incidents, grouped by the component that failed, over the whole archive rather than the window its status page shows.
Inferred read-onlyprovider_transparencyHow long a provider takes to acknowledge an incident: the interval between an incident starting and its first public update.
Potential side effectsprovider_terms_changedWhen a provider last changed its terms or pricing page, from a stored fingerprint of the page.
Inferred read-onlymodel_withdrawnModels that were in the catalogue and no longer are, with the date last seen.
Inferred read-onlyhelp_availabilityFor a technology tag: questions asked against questions answered, over time.
Inferred read-onlyaudit_manifestRead a whole manifest and return every reading on record for it, ordered by how much a reviewer would want to know.
Inferred read-onlydiff_sinceWhat changed for a set of packages since a given date, read from the daily archive.
Inferred read-onlywatch_addAdd a package to the caller’s own private watchlist, so later readings are about their stack rather than the public one.
Inferred read-onlywatch_changesEverything that has changed across the caller’s private watchlist since a given date: withdrawals, licence changes, advisories, archived repositories and runtimes going out of support.
Inferred read-onlyexplain_findingGiven a finding id, return what was measured, when, by whom, and the address it can be checked at.
Inferred read-onlydomain_riskWhether the domains a package points at — homepage, funding, documentation — still resolve to a registered owner.
Inferred read-onlyCONNECT WITH APPROVAL
Client installation
Review this server and its permissions before adding it. Secret placeholders must be set locally.
Codex
~/.codex/config.toml
[mcp_servers.sighttrue]
url = "https://sighttrue.com/api/mcp"
enabled = true
Claude Code
.mcp.json
{
"mcpServers": {
"sighttrue": {
"type": "http",
"url": "https://sighttrue.com/api/mcp"
}
}
}
Claude Desktop
Settings → Connectors → Add custom connector
Name: sighttrue
Remote MCP URL: https://sighttrue.com/api/mcp
Add this remote URL as a custom connector in Claude Desktop. Availability depends on the user plan and workspace policy.
Cursor
.cursor/mcp.json
{
"mcpServers": {
"sighttrue": {
"url": "https://sighttrue.com/api/mcp"
}
}
}
Visual Studio Code
.vscode/mcp.json
Add to Visual Studio Code{
"servers": {
"sighttrue": {
"type": "http",
"url": "https://sighttrue.com/api/mcp"
}
}
}
Generic MCP
Client-specific MCP configuration
{
"name": "sighttrue",
"transport": "streamable-http",
"url": "https://sighttrue.com/api/mcp"
}
MCP Inspector
Run the official MCP Inspector locally and enter the indexed Streamable HTTP endpoint.
TRUST AND VERIFICATION EVIDENCE
Loading Trust v2 evidence…
Checking the associated registrable domain. The BuiltWith key remains server-side.
Evidence is source-attributed and does not guarantee that a third-party server is safe. Risk labels are conservative metadata heuristics.