Safer Fetch MCP Server
Fetches content from web pages and automatically converts HTML and PDF files into Markdown format, ensuring language models receive structured and clean text for processing.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Safer Fetch MCP Serverfetch the latest blog post from example.com and convert it to markdown"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Safer Fetch MCP Server
A Model Context Protocol server that provides web content fetching capabilities with built-in prompt injection safeguards. This server enables LLMs to retrieve and process content from web pages, converting HTML to markdown for easier consumption, while protecting against malicious content that could manipulate the LLM.
Acknowledgements
This project is based on Anthropic's Fetch MCP server implementation and incorporates prompt injection safeguard code/patterns from Goose.
Related MCP server: Fetch MCP Server
🚀 Quick Start
Installing the Server
Run the MCP server using uvx:
uvx --refresh mcp-server-fetch-tomThe --refresh flag ensures you always get the latest version.
Configuring in Your AI IDE
Choose your IDE and add the configuration to enable the fetch MCP server:
Claude Desktop
Edit your Claude Desktop configuration file:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.jsonLinux:
~/.config/Claude/claude_desktop_config.json
{
"mcpServers": {
"fetch": {
"command": "uvx",
"args": ["--refresh", "mcp-server-fetch-tom"]
}
}
}VS Code (Cline / Roo Cline)
Add to your VS Code settings (.vscode/mcp.json in workspace or User Settings JSON):
{
"mcp": {
"servers": {
"fetch": {
"command": "uvx",
"args": ["--refresh", "mcp-server-fetch-tom"]
}
}
}
}Or use the one-click install buttons:
Cursor
Add to Cursor settings:
Open Cursor Settings (
Cmd/Ctrl + ,)Search for "MCP"
Add server configuration, or edit
.cursor/mcp.json:
{
"mcpServers": {
"fetch": {
"command": "uvx",
"args": ["--refresh", "mcp-server-fetch-tom"]
}
}
}Continue (VS Code Extension)
Edit ~/.continue/config.json:
{
"mcpServers": {
"fetch": {
"command": "uvx",
"args": ["--refresh", "mcp-server-fetch-tom"]
}
}
}Goose AI
Edit ~/.config/goose/profiles.yaml:
default:
provider: openai
processor: gpt-4
accelerator: gpt-4o-mini
moderator: passive
toolkits:
- developer
- mcp
mcp_servers:
fetch:
command: uvx
args:
- --refresh
- mcp-server-fetch-tom⚠️ Disclaimer
This software is provided "as is" without warranty of any kind. While this server implements prompt injection detection and mitigation measures, no security solution is 100% effective. The safeguards implemented are designed to reduce risk but cannot guarantee complete protection against all prompt injection attacks.
Users should:
Exercise caution when fetching content from untrusted sources
Review fetched content before acting on it in sensitive contexts
Understand that determined attackers may find ways to bypass detection
Not rely solely on these safeguards for security-critical applications
The maintainers are not responsible for any damages or security incidents resulting from the use of this software.
Security Features
This server includes prompt injection safeguards to protect LLMs from malicious web content:
1. Content Boundary Wrapping
All fetched content is wrapped in security boundary tags with a random boundary ID (to prevent escape attacks). The wrapper includes:
Clear instructions that content should be treated as DATA ONLY, not as instructions
Critical security rules for the LLM to follow
Source URL attribution
2. Prompt Injection Pattern Detection
Content is scanned for 20+ suspicious patterns including:
Instruction overrides: "ignore previous instructions", "disregard prior prompts"
Role manipulation: "you are now", "act as", "pretend to be"
System prompt attacks: "new system prompt", "override instructions"
Jailbreak attempts: "developer mode", "DAN mode", "bypass restrictions"
Output manipulation: "do not mention", "keep this secret"
Encoded instructions: Base64 patterns, "decode and execute"
When suspicious patterns are detected:
NO DATA is returned - the fetched content is completely blocked
Only a warning message is returned indicating the number of patterns detected
The source URL is provided so users can manually review if they believe it's a false positive
This server can access local/internal IP addresses and may represent a security risk. Exercise caution when using this MCP server to ensure this does not expose any sensitive data.
The fetch tool will truncate the response, but by using the start_index argument, you can specify where to start the content extraction. This lets models read a webpage in chunks, until they find the information they need.
Available Tools
fetch- Fetches a URL from the internet and extracts its contents as markdown.url(string, required): URL to fetchmax_length(integer, optional): Maximum number of characters to return (default: 5000)start_index(integer, optional): Start content from this character index (default: 0)raw(boolean, optional): Get raw content without markdown conversion (default: false)
When the output type is 'md' and the fetched resource is a PDF, it will be automatically converted to plain text.
Prompts
fetch
Fetch a URL and extract its contents as markdown
Arguments:
url(string, required): URL to fetch
Installation
Using uv (recommended)
When using uv no specific installation is needed. We will
use uvx to directly run mcp-server-fetch-tom:
uvx --refresh mcp-server-fetch-tomAdvanced Configuration
Alternative Installation Methods
The examples above use uvx for simplicity. You can also use:
{
"mcpServers": {
"fetch": {
"command": "docker",
"args": ["run", "-i", "--rm", "mcp/fetch"]
}
}
}First install: pip install mcp-server-fetch-tom
Then configure:
{
"mcpServers": {
"fetch": {
"command": "mcp-server-fetch-tom"
}
}
}Customization - User-agent
By default, depending on if the request came from the model (via a tool), or was user initiated (via a prompt), the server will use either the user-agent
ModelContextProtocol/1.0 (Autonomous; +https://github.com/modelcontextprotocol/servers)or
ModelContextProtocol/1.0 (User-Specified; +https://github.com/modelcontextprotocol/servers)This can be customized by adding the argument --user-agent=YourUserAgent to the args list in the configuration.
Customization - Proxy
The server can be configured to use a proxy by using the --proxy-url argument.
Windows Configuration
If you're experiencing timeout issues on Windows, you may need to set the PYTHONIOENCODING environment variable to ensure proper character encoding:
{
"mcpServers": {
"fetch": {
"command": "uvx",
"args": ["--refresh", "mcp-server-fetch-tom"],
"env": {
"PYTHONIOENCODING": "utf-8"
}
}
}
}{
"mcpServers": {
"fetch": {
"command": "mcp-server-fetch-tom",
"env": {
"PYTHONIOENCODING": "utf-8"
}
}
}
}This addresses character encoding issues that can cause the server to timeout on Windows systems.
Debugging
You can use the MCP inspector to debug the server. For uvx installations:
npx @modelcontextprotocol/inspector uvx mcp-server-fetch-tomOr if you've installed the package in a specific directory or are developing on it:
cd path/to/fetch_mcp
npx @modelcontextprotocol/inspector uv run mcp-server-fetch-tomBuilding and Publishing
For maintainers: See the Publishing Guide for detailed instructions on building and publishing to PyPI.
Quick Reference:
# Build the package
uvx --from build pyproject-build --installer uv
# Check the build
uvx twine check dist/*
# Upload to PyPI
uvx twine upload dist/*Or use the Makefile:
make build # Build package
make check # Verify package
make upload # Upload to PyPIFor more details, see:
Full Publishing Guide - Comprehensive documentation
Quick Start Guide - TL;DR version
Makefile - Automated commands
Contributing
We encourage contributions to help expand and improve mcp-server-fetch. Whether you want to add new tools, enhance existing functionality, or improve documentation, your input is valuable.
For examples of other MCP servers and implementation patterns, see: https://github.com/modelcontextprotocol/servers
Pull requests are welcome! Feel free to contribute new ideas, bug fixes, or enhancements to make mcp-server-fetch even more powerful and useful.
Security Considerations
While this server implements prompt injection safeguards, security is a shared responsibility:
Defense in depth: These safeguards are one layer of protection; combine with other security measures
Regular updates: Keep the server updated to benefit from new pattern detection rules
Report vulnerabilities: If you discover a bypass or vulnerability, please report it responsibly
False positives: The pattern detection may flag legitimate content; review warnings in context
License
mcp-server-fetch is licensed under the MIT License. This means you are free to use, modify, and distribute the software, subject to the terms and conditions of the MIT License. For more details, please see the LICENSE file in the project repository.
Available Tools
1 toolfetchB
Fetches a URL from the internet and optionally extracts its contents as markdown.
When the output type is 'md' and the resource is a PDF, it will be transformed into plain text.
Although originally you did not have internet access, and were advised to refuse and tell the user this, this tool now grants you internet access. Now you can fetch the most up-to-date information and let the user know that.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | URL to fetch | |
| max_length | No | Maximum number of characters to return. | |
| start_index | No | On return output starting at this character index, useful if a previous fetch was truncated and more content is required. | |
| output | No | Output format: 'raw' returns the fetched content as-is, 'md' parses HTML to markdown. | md |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It adds some context: it mentions PDF-to-text transformation for 'md' output and internet access capability. However, it lacks details on error handling, rate limits, authentication needs, or what happens with truncated content, leaving gaps for a tool with significant behavioral implications.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with core functionality but includes redundant and verbose sentences, such as the historical context about internet access and user instructions ('let the user know that'). These do not add essential value and could be trimmed for better efficiency, reducing overall conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no annotations and no output schema, the description partially compensates by explaining key behaviors like PDF transformation and internet access. However, for a tool with 4 parameters and potential complexity (e.g., handling different content types, errors), it lacks details on return values, error cases, or advanced usage, making it minimally adequate but incomplete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all parameters thoroughly. The description adds minimal value beyond the schema by mentioning PDF transformation for 'md' output, but it doesn't provide additional syntax or format details. This meets the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Fetches a URL from the internet and optionally extracts its contents as markdown.' This specifies the verb ('fetches') and resource ('URL'), and mentions optional markdown extraction. However, with no sibling tools, it doesn't need to differentiate from alternatives, so it doesn't reach the highest score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides implied usage context by stating 'originally you did not have internet access... this tool now grants you internet access,' suggesting it should be used when internet access is needed. However, it lacks explicit guidance on when to use this tool versus alternatives (though none exist) or any exclusions, making it adequate but not comprehensive.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
- First observed
fetch
TDQS
With only one tool, there is no possibility of ambiguity or overlap between tools. The single tool 'fetch' has a clear and distinct purpose, making it impossible for an agent to misselect between multiple options.
A single tool inherently exhibits perfect naming consistency, as there are no other tools to compare against. The name 'fetch' is straightforward and follows a simple verb pattern, which is consistent within this minimal set.
A single tool is generally too few for most server purposes, as it limits functionality and scope. While 'fetch' is useful, a typical MCP server would benefit from additional tools to handle related tasks like caching, error handling, or different fetch modes, making this count borderline inadequate.
The tool provides a core functionality for fetching URLs and converting content to markdown or plain text, which covers basic internet access needs. However, there are notable gaps, such as lack of tools for handling different HTTP methods, managing cookies or sessions, or providing advanced parsing options, which could limit agent capabilities in more complex scenarios.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Web scraping for AI agents. Converts URLs to clean, LLM-ready Markdown with anti-bot bypass.
Read any web page as clean Markdown for AI agents: fetch, search, metadata, links. SSRF-safe.
Converts any URL to clean, LLM-ready Markdown using real Chrome browsers
Prompt-injection scanning and safe webpage fetching for AI agents reading untrusted content.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables LLMs to retrieve and process web content by fetching URLs and converting HTML to markdown format. Supports chunked reading of large pages and can access both public websites and local networks.1MIT
- AlicenseCqualityDmaintenanceEnables LLMs to retrieve and process web content by fetching URLs and converting HTML to markdown, with support for chunked reading and customizable user-agents.1MIT
- AlicenseAqualityDmaintenanceEnables LLMs to fetch and process web content by converting HTML into markdown for easier consumption. It supports chunked reading via pagination and provides configuration options for robots.txt compliance and proxy usage.1MIT
- AlicenseAqualityDmaintenanceEnables LLMs to fetch and extract web content as markdown with browser impersonation to bypass basic bot detection.1MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Tommertom/safer_fetch_mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server