npm
PulseAugur coverage of npm — every cluster mentioning npm across labs, papers, and developer communities, ranked by signal.
- subsidiary of GitHub 100%
- used by GrahamduesCN/mcp-platform 90%
- instance of @modelcontextprotocol/server-postgres 90%
- used by @modelcontextprotocol/server-postgres 70%
- used by server-postgres 70%
- used by ModelContextProtocol 70%
- uses ModelContextProtocol 70%
- uses server-github 70%
- used by Olud Pulse 70%
- instance of server-postgres 70%
- used by server-github 70%
- instance of MarketNow 70%
- 2026-05-29 product_launch Malicious npm packages mimicking popular libraries were discovered and removed. source
22 day(s) with sentiment data
-
Agent-usage tool v0.10.0 released for macOS developers
The `agent-usage` tool has released version 0.10.0 on npm, offering a local dashboard for visualizing multi-agent system performance. This update includes charts that break down usage by individual agents, providing dev…
-
ComfyUI leads open-source AI image generation adoption
Olud Pulse, a daily adoption score for open-source AI tools, has identified ComfyUI as the leading tool in AI image generation. The score is calculated using data from GitHub, Docker, Python Package Index, and Node Pack…
-
Claude Code hooks fail on Windows, exposing users to risks
A technical post details how Claude Code's safety hooks can fail on Windows, potentially allowing unintended actions. The author outlines nine specific ways these hooks can malfunction, often due to differences in shell…
-
Claude Code automates npm dependency license audit in two days
A developer utilized Claude Code to efficiently audit over 1,400 npm dependencies for license compliance, a task that would typically take weeks. The process involved using Claude Code to classify licenses, identify ris…
-
Fission AI launches OpenSpec for streamlined AI code development
OpenSpec, an open-source CLI tool from Fission AI, aims to streamline Spec-Driven Development for AI coding agents. It allows developers and agents to agree on code changes using plain Markdown specifications before any…
-
AI's Impact on Library Development Explored by Experienced Developer
A developer with five years of experience creating libraries, including their first published on npm seven years ago, reflects on the impact of AI in their field. They note that despite initial doubts, AI has indeed cha…
-
DeepDeck adds WebMCP benchmark, ChatGPT tested, and ChainDrop npm worm identified
A new benchmark called WebMCP has been integrated into DeepDeck, an MIT-licensed macOS desktop project that utilizes DeepSeek. Separately, a consumer version of ChatGPT was tested with an agency-selection question on Se…
-
Developer's laptop scan reveals AI agent security risks
A developer's scan of their own laptop revealed significant security vulnerabilities related to AI agents and their configurations. The scan identified that many AI agents use unpinned package versions, posing a supply …
-
AI agent tool failures linked to npx startup delays
A common issue where AI agents fail to recognize tools from an MCP server is attributed to the startup overhead of the `npx` command. The `npx` tool, used to launch servers as subprocesses, introduces significant delays…
-
AI-generated PhantomRaven malware distributed via malicious npm packages
CrowdStrike has identified AI-generated malware, dubbed PhantomRaven, which was distributed through malicious Node Package Manager (npm) packages. This malware is reportedly linked to a bug bounty hunter who allegedly u…
-
Model Context Protocol registries split into discovery and gateway architectures
The Model Context Protocol (MCP) ecosystem has evolved with registries diverging into two main architectures: static metadata catalogs for public tool discovery and gateway-backed registries that enforce runtime authent…
-
CodeScope tool lets users query local codebases with ChatGPT
A new open-source tool called CodeScope has been developed to allow users to query their local code repositories using existing ChatGPT quotas. This read-only bridge connects to MCP-compatible clients, enabling users to…
-
Security flaws in MCP stdio launch boundary enable unauthorized server execution
A security analysis highlights critical authorization flaws in the MCP stdio launch boundary, arguing that current security practices focus on tool call authorization rather than the initial server launch. The author po…
-
Mastodon crawler warns of malicious npm packages and bounty risks
A security crawler on Mastodon has highlighted the risks associated with open-source npm dependencies, warning users to audit their packages for malicious content. The crawler also advised cross-referencing suspicious b…
-
Model Context Protocol (MCP) sees explosive ecosystem growth with 97M monthly SDK downloads
The Model Context Protocol (MCP) ecosystem has experienced significant growth, with over 13,000 MCP servers registered on npm and GitHub as of May 2026. Monthly SDK downloads have tripled in six months to 97 million, an…
-
Google launches Chrome DevTools MCP for agent-based browser debugging
Google has released Chrome DevTools MCP, a project from the Chrome DevTools and Puppeteer teams that bridges the gap between shipping code and observing its execution. This tool exposes a live Chrome instance to various…
-
AI agents' tool manifests audited for prompt injection risks · 2 sources tracked
Two articles discuss methods for auditing AI agent tool manifests to prevent prompt injection and other security vulnerabilities. The first article details how to build a Python-based static scanner to identify maliciou…
-
Tencent open-sources WeKnora, integrating DeepSeek Harness for RAG-to-agent workflows
Tencent has open-sourced WeKnora, a knowledge platform for retrieval-augmented generation (RAG) to agentic workflows, which has garnered over 25,000 GitHub stars. The release includes an official DeepSeek Harness plugin…
-
APX Community launches Discord for AI agent development and orchestration
The APX Community, focused on building and orchestrating AI agents, has launched an official Discord server. This platform aims to foster collaboration and provide support for users of the Agent Project eXecutable (APX)…
-
Developer finds internal tests fail to catch inaccurate documentation
A developer encountered an issue where documentation and internal tests for their MCP server incorrectly stated the number of keyless tools available. The problem stemmed from tests comparing documentation against a con…