since-cutoff
PYPI · SINCE-CUTOFF · SCANNED OCT 2
Which Python library APIs changed after your model's training cutoff (static diff, no model calls)
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
- 5 of 40 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to MohammadHijjawi97/since-cutoff). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 3 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability61
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2097 tokens (~699/item across 3 items; 3 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 3 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 4 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the since-cutoff MCP server?
since-cutoff runs locally as a PyPI package, launched with uvx since-cutoff. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · since-cutoff
claude mcp add mohammadhijjawi97-since-cutoff -- uvx since-cutoff
{
"mcpServers": {
"mohammadhijjawi97-since-cutoff": {
"command": "uvx",
"args": [
"since-cutoff"
]
}
}
} {
"servers": {
"mohammadhijjawi97-since-cutoff": {
"command": "uvx",
"args": [
"since-cutoff"
]
}
}
} codex mcp add mohammadhijjawi97-since-cutoff -- uvx since-cutoff
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"mohammadhijjawi97-since-cutoff": {
"type": "local",
"command": [
"uvx",
"since-cutoff"
],
"enabled": true
}
}
} openclaw mcp add mohammadhijjawi97-since-cutoff --command uvx --arg since-cutoff
mcp_servers:
mohammadhijjawi97-since-cutoff:
command: "uvx"
args: ["since-cutoff"] {
"McpServers": {
"mohammadhijjawi97-since-cutoff": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"since-cutoff"
]
}
}
} assistant mcp add mohammadhijjawi97-since-cutoff -t stdio -c uvx -a since-cutoff
{
"mcpServers": {
"mohammadhijjawi97-since-cutoff": {
"command": "uvx",
"args": [
"since-cutoff"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 29 Sept 26 +16
- Malware scan: unverified → pass ▲ security
- 28 Sept 26 −5
- Malware scan: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Provenance: fail → pass ▲ security
- Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
- The attested source repository moved: MohammadHijjawi97/since-cutoff security
- Schema quality: 609 → 699 ▼ functional
- Schema quality: 609 → 676 ▼ functional
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Stability: unverified → 0.03 ▲ functional
- First check of Schema quality: unverified functional
- Package version: 0.3.2 → 0.5.0 functional
- Package version: 0.3.2 → 0.4.1 functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 69
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Analysed pypi/since-cutoff@0.5.0
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | pypi |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | MohammadHijjawi97/since-cutoff |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/MohammadHijjawi97/since-cutoff/.github/workflows/release.yml@refs/tags/v0.5.0 |
| Rekor log index | 2983290992 |
| Predicate type | PyPI publish attestation https://docs.pypi.org/attestations/publish/v1 |
| Subject digest | sha256:2fc0fd0c6862dcb19fbe873f22eadf95263c13a2db0f795abc243576f3bd7e06 |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 40 packages
| Packages resolved | 40 |
|---|---|
| Stale | 2 |
| No linked repository | 3 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
api_changes Library API changes since the cutoff ~727
List the public API changes of one PyPI package since a model's training cutoff. Use it before writing code against a library version that may have been released after your training cutoff (check the lockfile or requirements for the version), or when code fails on a name, import or parameter of that library. Pass `symbol` to see only the functions or classes you are about to use. For all dependencies of a project in one call, use project_changes. Compares the newest final release on or before the cutoff (or `from_version`) with `to_version` (default: the latest final release on PyPI). Read-only: downloads the two releases' wheels from PyPI (80 MB at most each, by default) and reads their sources statically. No package code runs and no model is called. The first call for a package takes a few seconds, up to a minute or two for very large packages; the result is cached, and later calls take about a second. One of `model`, `cutoff` or `from_version` is required. Returns Markdown: a "# <package> <old> -> <new>" heading; bullets with both versions and their release dates and the number of breaking changes and new deprecations by kind; then sections "Dependencies switched" (the package requires another library instead of one it required, such as `httpx2` instead of `httpx`, and its signatures take that library's objects), "Removed or moved", "Parameters removed", "Parameters now required", "Changed kind", "Now keyword-only or positional-only" and "Deprecated", one line per change with what to use instead when the diff knows it (the new import, the new signature, a parameter probably renamed in place, what the old version's deprecation text said), and names that merely look similar, labelled as not confirmed. A change reachable under several import paths is listed once. If the package had no release by the cutoff, a short note says its whole API was released after your reported training cutoff.
| Name | Type | Req | Description |
|---|---|---|---|
| cutoff | – | – | your training cutoff instead of `model`, as "YYYY-MM" or "YYYY-MM-DD", e.g. "2025-02". |
| from_version | – | – | compare from this version instead of the one at the cutoff, e.g. "0.29.1". |
| limit | integer | – | the most changes to list, e.g. 100 (default 40), shared between the kinds of change. |
| model | – | – | your model id, e.g. "claude-haiku-4-5" or "gpt-5.4"; its training cutoff is looked up. |
| package | string | yes | the PyPI name, e.g. "huggingface-hub" or "openai", optionally pinned: "anthropic==1.8.0" (the pin is used as `to_version`). |
| symbol | – | – | only changes to what this names, e.g. "hf_hub_download", "Messages.create", "client.messages.create" or "client.chat.completions.create". Call syntax and variable names are ignored: the last one or t… |
| to_version | – | – | the version the project uses, e.g. "2.0.0" (default: the latest release on PyPI). |
No output schema declared.
No examples provided.
model_cutoff Model training cutoff ~284
Look up a model's training cutoff: library releases after it may be missing from its training data. Use it to find or confirm your own cutoff. The other two tools do not need it first: they take `model` and look the cutoff up themselves. Read-only and quick (about a second): no model is called. The cutoffs come from the models.dev catalogue, fetched at most once a day and cached; without network access a cached or bundled copy is used. Returns one short paragraph of plain text: "<id> (<provider>, <name>): training cutoff YYYY-MM-DD. Released YYYY-MM-DD. Source: models.dev", then the api_changes and project_changes calls to make with that id. An unknown id is a tool error that lists close matches.
| Name | Type | Req | Description |
|---|---|---|---|
| model | string | yes | a model id, e.g. "claude-haiku-4-5", "claude-sonnet-4-5", "claude-opus-4-6[1m]", "gpt-5.4", "gemini-2.5-pro", "anthropic/claude-haiku-4.5" or "openai:gpt-5.4". Pass your own id. The aliases "sonnet",… |
No output schema declared.
No examples provided.
project_changes Project dependency changes since the cutoff ~752
Check every dependency of a Python project for API changes since a training cutoff. Use it at the start of work on a project, or before adding code that uses its dependencies: one call covers every direct dependency at the version the project pins. For a single package, a single symbol, or a version the project does not pin, api_changes is faster. Reads the project's lockfile (uv.lock, poetry.lock, pdm.lock, pylock.toml, Pipfile.lock), requirements*.txt, pyproject.toml or .venv, and for each direct dependency compares the release that existed at the cutoff with the pinned one. Changes to names the project's code uses, in packages it imports, come first. Read-only: nothing in the project is written. Reads PyPI metadata, downloads the wheels of the dependencies that changed and reads them statically; no package code runs and no model is called. The first call on a project with many dependencies can take several minutes (large packages such as transformers take longest); results are cached, so later calls take seconds. Running `since-cutoff scan` in the project once fills the same cache. Reports progress while it works if the client asks for it. One of `model` or `cutoff` is required. Returns Markdown: a heading with the number of dependencies checked and where their versions came from; bullets with the cutoff, how many of the changed APIs the project's code uses, and how many dependencies changed, were first released after the cutoff, are unchanged, or could not be checked; then "## Your code uses these changed APIs": each changed API the code uses, with what changed, "old form" (the code uses it as the release at the cutoff allowed) or "uses this API", the files that use it (at most 3), the note to follow with its tag ([diff]: from the static diff; [library]: the replacement is named in the library's own deprecation text), the runtime caveat when the pinned source still accepts a removed name, and similar names, not confirmed as replacements; then one "## <pack…
| Name | Type | Req | Description |
|---|---|---|---|
| cutoff | – | – | your training cutoff instead of `model`, as "YYYY-MM" or "YYYY-MM-DD", e.g. "2025-02". |
| limit_per_package | integer | – | changes listed per dependency, e.g. 20 (default 10); api_changes lists the rest. |
| model | – | – | your model id, e.g. "claude-haiku-4-5" or "gpt-5.4"; its training cutoff is looked up. |
| only | – | – | check only these dependencies (PyPI names), e.g. ["openai", "pydantic"]. |
| project_dir | string | – | the project root, e.g. "/home/me/app" or ".". A relative path resolves against the project the client started the server for (or the server's working directory); pass an absolute path when unsure. |
No output schema declared.
No examples provided.
What is the since-cutoff MCP server?
since-cutoff is an MCP server listed in the public MCP registry as io.github.MohammadHijjawi97/since-cutoff. Which Python library APIs changed after your model's training cutoff (static diff, no model calls). This page covers its PyPI package (since-cutoff).
Is the since-cutoff MCP server safe to use?
since-cutoff scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 2 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the since-cutoff MCP server expose?
since-cutoff exposes 3 tools: model_cutoff, api_changes, project_changes. Their descriptions and schemas cost roughly 1,763 tokens of context every time the server is loaded.
Is the since-cutoff MCP server still maintained?
since-cutoff is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the since-cutoff MCP server under?
since-cutoff declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.