Fitter
OCI · GHCR.IO/PXYUP/FITTER-MCP:V1.8.3-PLAYWRIGHT · 7 COMPONENTS · SCANNED SEP 20
Turn any website or API into structured JSON with LLM-authored declarative scraping configs.
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security0
- Malware scan not yet available for this package.Unverified
- Known CVEs could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.Unverified
- Install-script risk not yet assessed.Unverified
- Dependency health could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.Unverified
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 24 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability87
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 857 tokens (~122/item across 7 items; 6 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the Fitter MCP server?
Fitter runs locally as a container image, launched with docker run --rm -i ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.
oci · ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright
claude mcp add pxyup-fitter -- docker run --rm -i ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright
{
"mcpServers": {
"pxyup-fitter": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright"
]
}
}
} {
"servers": {
"pxyup-fitter": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright"
]
}
}
} codex mcp add pxyup-fitter -- docker run --rm -i ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"pxyup-fitter": {
"type": "local",
"command": [
"docker",
"run",
"--rm",
"-i",
"ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright"
],
"enabled": true
}
}
} mcp_servers:
pxyup-fitter:
command: "docker"
args: ["run", "--rm", "-i", "ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright"] {
"McpServers": {
"pxyup-fitter": {
"Transport": "stdio",
"Command": "docker",
"Arguments": [
"run",
"--rm",
"-i",
"ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright"
]
}
}
} {
"mcpServers": {
"pxyup-fitter": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 5 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed oci/ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | oci |
| Reason | No attestation published |
Background: How many MCP packages publish verified provenance →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
fitter_config_reference ~55
Return a condensed reference of the Fitter config format (connectors, parsers, model/field schema, placeholders, notifiers, references, limits) with working examples. Use it before authoring a config for fitter_run.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
fitter_inspect_url ~278
Fetch a URL and return a compact structure outline plus candidate selectors/paths, so you can author a fitter config that matches on the first try instead of guessing selectors and getting nulls. For JSON it lists gjson paths with types and sample values; for HTML it lists repeated elements (candidate array_config root_path / list rows) and link/heading selectors. For client-rendered SPAs (content built by JavaScript), a plain fetch sees only an empty shell — the output warns when it detects one; pass render:true to render it in a headless browser first (mirrors what a browser_config scrape would see). Read-only helper that does NOT extract data — use it before fitter_run, then fitter_run to actually extract.
| Name | Type | Req | Description |
|---|---|---|---|
| render | boolean | – | Render the page in a headless browser (Playwright/Chromium) before inspecting — needed for client-rendered SPAs whose content is built by JavaScript and is absent from the raw HTML. Requires browser… |
| response_type | string | – | Optional hint for how to read the response: json, HTML, xpath or XML. Empty auto-detects from the Content-Type/body. |
| url | string | yes | HTTP(S) URL to fetch and inspect for its structure and candidate selectors. |
No output schema declared.
No examples provided.
fitter_run ~152
Run a Fitter scraping/parsing config passed inline (JSON or YAML) and return the extracted data as JSON. Fitter fetches data via a connector (HTTP request, headless browser, static value, file, ...) and extracts structured data using json/HTML/XML/xpath selectors described by a declarative model. Call fitter_config_reference first if you are unsure about the config format.
| Name | Type | Req | Description |
|---|---|---|---|
| config | string | yes | Fitter CliItem config as a JSON or YAML string. Top-level keys: item (required), limits, references. |
| input | string | – | Optional input value (plain string or JSON), available in the config via {{{FromInput=.}}} or {{{FromInput=json.path}}} placeholders. |
No output schema declared.
No examples provided.
fitter_run_file ~116
Run a Fitter scraping/parsing config from a local JSON or YAML file and return the extracted data as JSON. Same as fitter_run but reads the config from disk.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | – | Optional input value (plain string or JSON), available in the config via {{{FromInput=.}}} or {{{FromInput=json.path}}} placeholders. |
| path | string | yes | Absolute path to a Fitter config file (.json, .yaml or .yml) with top-level keys: item (required), limits, references. |
No output schema declared.
No examples provided.
fitter_run_url ~129
Run a Fitter scraping/parsing config downloaded from an HTTP(S) URL (JSON or YAML) and return the extracted data as JSON. Same as fitter_run but fetches the config from a remote location, e.g. a raw GitHub link.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | – | Optional input value (plain string or JSON), available in the config via {{{FromInput=.}}} or {{{FromInput=json.path}}} placeholders. |
| url | string | yes | HTTP(S) URL of a Fitter config (JSON or YAML) with top-level keys: item (required), limits, references. |
No output schema declared.
No examples provided.
fitter_validate_config ~108
Validate a Fitter config (JSON or YAML) without executing it. Checks the structural rules: item/connector_config/model presence, valid response_type, that the connector has a data source, and compiles every condition/item_condition expression in the model. Returns "valid" or the validation error. Cheap and safe — use it while iterating on a config before calling fitter_run.
| Name | Type | Req | Description |
|---|---|---|---|
| config | string | yes | Fitter CliItem config as a JSON or YAML string to validate without executing it. |
No output schema declared.
No examples provided.
What is the Fitter MCP server?
Fitter is an MCP server listed in the public MCP registry as io.github.PxyUp/fitter. Turn any website or API into structured JSON with LLM-authored declarative scraping configs. This page covers its container image (ghcr.io/pxyup/fitter-mcp:v1.8.3-playwright).
Is the Fitter MCP server safe to use?
Fitter scores 54 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Fitter MCP server expose?
Fitter exposes 6 tools: fitter_config_reference, fitter_inspect_url, fitter_run, fitter_run_file, fitter_run_url, fitter_validate_config. Their descriptions and schemas cost roughly 838 tokens of context every time the server is loaded.
Is the Fitter MCP server still maintained?
Fitter is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Fitter MCP server under?
Fitter declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.