Skip to main content

lastseen-mcp

mcp-name: dev.lastseen/mortality

last seen data: CC-BY-4.0 code: MIT

Is this dependency dead? Dated observations of whether an npm package, GitHub Action, MCP server, or Docker image is alive, dormant, abandoned, archived, or deleted — published by lastseen.dev. Free, no API key, zero telemetry.

There are two ways in, and they answer the same question from the same dated data:

  1. Call the free HTTP API directly — the durable, machine-native path (below). An agent that keeps a dependency list can re-check it on every build.
  2. Run it as an MCP server — a thin stdio wrapper over that same API, for MCP clients.

1. The free API (call it directly)

No key. No signup. 60 requests/minute, anonymous GET. Every response is a dated observation with its source — not a score, not advice. Base URL https://lastseen.dev.

# one component (owner/repo)
curl https://lastseen.dev/api/v1/entity/actions/checkout

# everything held under a GitHub owner/org
curl https://lastseen.dev/api/v1/org/actions

# a whole manifest at once (names-only body)
curl -X POST https://lastseen.dev/api/v1/manifest \
  -H 'content-type: application/json' \
  -d '{"channel":"api","components":[{"name":"actions/checkout","kind":"github-action"}]}'

# self-describing API docs (JSON)
curl https://lastseen.dev/api/v1/docs

A single-component response carries the latest_state, the dated series behind it, the source_of_record, and interval-censoring notes — enough to re-check any verdict against GitHub yourself. This is the recurring path: wire GET /api/v1/entity/{owner}/{repo} into CI and a dead dependency shows up on the build that introduces it, not months later.

Contract

  • Lookups, not advice. Every answer is a dated observation with its source. Never "use X instead", never a composite score, never a ranking by preference, never urgency language.
  • Fails closed. An unknown or fabricated subject returns a clean not_observed — never a fabricated result. A network/store error degrades (try later); it is never read as "dead".
  • Absence ≠ gone. No record means "not checked", never "deleted". Only an authoritative HTTP 404 is a deletion.

States

alive (≤180d since last commit) · dormant (180–365d) · abandoned (>365d) · archived (repo archived) · deleted (authoritative HTTP 404) · eol (declared end-of-life) · unknown-stale (the observation the verdict rests on is older than the 180-day threshold and was not re-verified — no state asserted; not a death) · not_observed (403 / 429 / timeout / not held — not dead).


2. Run it as an MCP server

A pure-standard-library stdio wrapper over the API above — no mcp package, no requests, no FastAPI/Starlette, nothing that can conflict with a host app. It speaks JSON-RPC 2.0 over stdio and calls the free API over urllib.

Install

pipx install lastseen-mcp
# or run without installing:
uvx lastseen-mcp

Requires Python ≥ 3.10. No dependencies.

Add to an MCP client

{
  "mcpServers": {
    "lastseen": { "command": "lastseen-mcp" }
  }
}

(If you use uvx, set "command": "uvx", "args": ["lastseen-mcp"].)

Tools

Tool What it does
check_entity(slug, live?) Dated survival series for one owner/repo (e.g. actions/checkout). live=true attaches a live GitHub read (absence ≠ gone).
check_org(name) Dated states for every held component under a GitHub owner/org.
check_manifest(paste) Paste a GitHub Actions workflow (uses: refs) or owner/repo lines; get the dated state per component. Unheld components are not_observed.
survival_profile(category) Category ranking — not available over the free API; returns an honest not-supported result pointing to the per-entity/org/manifest lookups and the CC-BY dumps.

check_manifest looks up at most 30 parsed components per call (free-tier rate bound); any remainder is reported as n_truncated.


Privacy

Zero telemetry. The client and the API store nothing and transmit no identifier about you, your org, or the subjects you look up — anonymous GETs only.

Licensing

  • Code: MIT (see LICENSE).
  • Data: the mortality/survival observations are published by lastseen.dev under CC-BY-4.0 (attribution required). The two licenses are independent.

Links

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

lastseen_mcp-0.1.2.tar.gz (17.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

lastseen_mcp-0.1.2-py3-none-any.whl (16.5 kB view details)

Uploaded Python 3

File details

Details for the file lastseen_mcp-0.1.2.tar.gz.

File metadata

  • Download URL: lastseen_mcp-0.1.2.tar.gz
  • Upload date:
  • Size: 17.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.3

File hashes

Hashes for lastseen_mcp-0.1.2.tar.gz
Algorithm Hash digest
SHA256 56f380e78737b7a69cc6f48fc91392b254c419ece356bd577b21d139cca39bef
MD5 713e652b6c33cee2fa496b3a737765e4
BLAKE2b-256 c36b408ae6137c8cdcef66521343f7c915d61e67b34ff2e53015e95cdc772326

See more details on using hashes here.

File details

Details for the file lastseen_mcp-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: lastseen_mcp-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 16.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.3

File hashes

Hashes for lastseen_mcp-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 76c0a3cb511dd2328108076ba6a760543e68fd3f1b505f56bb3710a28f2ef299
MD5 bff01e86d415cdc193acc6241c190e50
BLAKE2b-256 5caa60cfd86154a8fa13d2510d7b7db3198232cb76dcf00c77d3adc7dbeda389

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 files

0.1.1

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page