
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@aioproductoscom/mcp-studio
Advanced tools
AIOProductOS Studio — an MCP server that turns your AI host into a product videographer: scripted screen recordings of YOUR web app with a smooth on-screen cursor, camera zooms, highlight callouts, caption cards, branded transitions, and marketing-grade s
Your AI teammate becomes your product videographer. Studio is an MCP server that records scripted walkthroughs of your own web app — a visible cursor that glides to every click, camera punch-ins, highlight callouts, storyline captions, designed scene transitions — and takes marketing-grade screenshots. Tell your AI host what story to shoot; get back a share-ready MP4.
The videos PMs hate making — demo clips, explainers, changelog GIFs, launch screenshots — become one prompt.
Free · MIT · runs 100% locally (your browser, your URLs, your logged-in session — nothing is uploaded anywhere). By AIOProductOS, built from the same pipeline we use for our own launch videos.
# Claude Code
claude mcp add studio -- npx -y @aioproductoscom/mcp-studio
# Cursor / Codex — .mcp.json
{ "mcpServers": { "studio": { "command": "npx", "args": ["-y", "@aioproductoscom/mcp-studio"] } } }
Requirements: Node 18+, Playwright Chromium (npx playwright install chromium,
one-time), and ffmpeg on PATH for MP4/GIF export (brew install ffmpeg — without
it you still get the raw WebM).
Then just direct the film:
"Record a 30-second walkthrough of https://app.example.com — theme it to our brand (#0d1117 bg, #f97316 accent), open on the dashboard with the title 'Meet Example', caption the three key features, zoom in on the analytics chart, and end with 'Start free · example.com'. Also grab a hero screenshot."
Your host runs the shoot tool by tool; files land in ./studio-output/.
| Tool | What it does |
|---|---|
studio_start | open a themed recording browser (viewport, brand colors, logged-in state) |
studio_goto | navigate behind a designed title card — no loading flashes on tape |
studio_click / studio_type | cursor glides to the target; typing is human-paced |
studio_scroll | cubic-eased scroll, never a jump cut |
studio_caption | bottom-left storyline caption (the "voiceover" in text) |
studio_highlight | accent ring + label callout around any element or visible text |
studio_zoom | smooth camera punch-in on a metric, button, or result |
studio_hold | hold the shot (micro-drift keeps frames flowing) |
studio_end_card | closing glass card: title, subtitle, CTA URL |
studio_screenshot | high-DPI PNG of the frame, an element, or the full page |
studio_finish | stop, auto-remove dark frames, export MP4 (+ optional GIF) |
studio_cancel | abandon the take |
Studio never sees your credentials. Save a Playwright storageState
once (npx playwright codegen --save-storage=auth.json https://app.example.com),
then pass storage_state_path: "auth.json" to studio_start.
cookies so it never mounts.hide_selectors — hidden from frame 1.theme.bg to your app's real background.No white flash on page commits (the theme background paints before any page CSS), no black frames (navigations hide behind designed title cards, and residual dark frames are detected and cut deterministically with ffmpeg), no stutter (every camera move is compositor-friendly easing), and action that reads on camera (a visible cursor glides to every target before it acts).
@aioproductoscom/mcp (the workspace connector) · @aioproductoscom/mcp-agent (assignable coding teammate)MIT © AIOProductOS Inc.
FAQs
AIOProductOS Studio — an MCP server that turns your AI host into a product videographer: scripted screen recordings of YOUR web app with a smooth on-screen cursor, camera zooms, highlight callouts, caption cards, branded transitions, and marketing-grade s
The npm package @aioproductoscom/mcp-studio receives a total of 35 weekly downloads. As such, @aioproductoscom/mcp-studio popularity was classified as not popular.
We found that @aioproductoscom/mcp-studio demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.