Drop-in fetch MCP: clean Markdown from any URL, with JS rendering and anti-bot.
MCPpedia last refreshed this data
io.github.labtools-studio/fetchmcp is an MCP server that drop-in fetch MCP: clean Markdown from any URL, with JS rendering and anti-bot. Its tool list has not been published yet over stdio, sse and http, requires no API key, and scores 57/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"io-github-labtools-studio-fetchmcp": {
"args": [
"-y",
"@labtoolsstudio/fetchmcp"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
A drop-in replacement for the official fetch MCP that actually works on modern web pages.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y '@labtoolsstudio/fetchmcp' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
Checked @labtoolsstudio/fetchmcp against OSV.dev.
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in writing
MCP server for document format conversion using pandoc.
This is an MCP server that allows you to directly download transcripts of YouTube videos.
Scrape, crawl, and map websites to Markdown or JSON via local CLI.
Any URL to clean, LLM-ready Markdown for RAG. Strips ads, nav, and boilerplate.
MCP Security Weekly
Get CVE alerts and security updates for io.github.labtools-studio/fetchmcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
A drop-in replacement for the official fetch MCP that actually works on modern web pages.
The official fetch MCP is broken on JavaScript-heavy pages, truncates output at 5,000 characters, and ships an unpatched SSRF vulnerability. fetchmcp returns clean, LLM-ready Markdown from any URL — rendering JavaScript when needed, passing basic bot protection without paid proxies, and telling you honestly when a page is blocked instead of hallucinating content. npx and go.

// Replace the official fetch server with this — one line in your MCP config:
"fetchmcp": { "command": "npx", "args": ["-y", "@labtoolsstudio/fetchmcp"] }
official fetch | fetchmcp | |
|---|---|---|
| JavaScript pages | ❌ empty / broken | ✅ auto-renders in a real browser |
| Output length | ✂️ truncated at 5,000 chars | ✅ full page, with paging |
| Bot protection (403 / Cloudflare) | ❌ fails silently | ✅ passes mid-tier walls, no paid proxy |
| Blocked page | ❌ returns the CAPTCHA as "content" | ✅ honest typed error, never fakes it |
| SSRF safety | ❌ CVE-2025-65513 (CVSS 9.3) | ✅ private/metadata IPs refused by default |
| Cost | free | free, self-hosted, $0 |
Add to your MCP client config (claude_desktop_config.json, Cursor mcp.json, Cline, etc.):
{
"mcpServers": {
"fetchmcp": {
"command": "npx",
"args": ["-y", "@labtoolsstudio/fetchmcp"]
}
}
}
The install is light — no browser is downloaded up front, and static reading (fetch → Readability → Markdown) works immediately. The first time a page actually needs JavaScript, fetchmcp downloads a stealth Chromium once (~150 MB) automatically, then renders it — still zero-config. To pre-download it at install time, set FETCHMCP_PREINSTALL_BROWSER=1. To stay static-only and never download it, set FETCHMCP_SKIP_BROWSER_DOWNLOAD=1 (JS pages then return an honest needs_js).
read_urlFetch any web page as clean Markdown.
| arg | type | description |
|---|---|---|
url | string | the URL to fetch (http/https) |
render | boolean | JS rendering: true = always, false = never, omitted = automatic (only for empty SPA shells) |
raw | boolean | return raw HTML instead of Markdown |
headers | object | extra request headers, e.g. {"Authorization": "Bearer …", "Cookie": "…"} |
max_length | integer | cap characters returned (0 = unlimited, the default) |
start_index | integer | offset for paging through a long page |
read_docsSame engine, tuned for documentation: strips navigation sidebars, headers, and footers so API docs and guides come back as clean reference text. Takes url, render, headers, max_length, start_index.
fetchmcp never returns a bot wall, an error page, or a truncated shell dressed up as real content. When it can't read a page it says why, with a t