@infoinlet/mcp-fetch
v0.1.1
Published
SSRF-safe URL fetch for AI agents — returns clean markdown/text/HTML/JSON, plus guarded REST calls. MCP server.
Readme
@infoinlet/mcp-fetch
SSRF-safe web fetch for AI agents, as an MCP server.
fetch_url— page → clean markdown (default) / text / html / jsonfetch_json— guarded REST call (GET/POST/…) → parsed JSON
Security: every request blocks private/loopback/link-local/cloud-metadata (169.254.169.254) IPs and non-http(s) schemes, validating the resolved IP on every redirect hop (defeats DNS-rebinding). 38 SSRF unit tests.
{ "mcpServers": { "fetch": { "command": "npx", "args": ["-y", "@infoinlet/mcp-fetch"] } } }