
Security News
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
@airtable/cli
Advanced tools
A command-line interface for Airtable that auto-discovers available operations from the Airtable MCP server.
npm install -g @airtable/cli
curl -fsSL https://raw.githubusercontent.com/Airtable/airtable-cli/main/install.sh | sh
npx @airtable/cli --help
Note: Node.js 18+ is required for all install methods.
Configure with a personal access token:
airtable configure
List available tools:
airtable tools
Run a tool:
airtable <tool-name> --flag value
airtable configure Set up endpoint and personal access token
airtable tools List available tools
airtable <tool> [--flags] Run a tool
airtable <tool> --help Show help for a tool
airtable <tool> --input - Pass arguments as JSON via stdin
airtable --version Print version
You can manage multiple accounts using profiles:
airtable configure --profile work
airtable configure --profile personal
airtable tools --profile work
For complex arguments, pipe JSON via stdin:
echo '{"baseId": "appXXX", "tableIdOrName": "Tasks"}' | airtable list-records --input -
airtable <tool> --output raw # Raw text output from the server
Config is stored in ~/.airtable/cli.json. Tool definitions are cached in ~/.airtable/cache-{profile}.json (5-minute TTL).
Build:
npm install
npm run build
Install locally as the airtable command:
npm run build
npm link
After npm link, the airtable binary points directly to dist/cli.js, so you only need to re-run npm run build to pick up changes — no need to re-link.
Unlink when done:
npm unlink -g @airtable/cli
Type-check:
npm run typecheck
Version is tracked in package.json. To cut a release:
npm version patch # or minor / major
git push -u origin chore/bump-version-x.y.z
gh pr create
git checkout main && git pull
git tag v0.1.1
git push origin v0.1.1
The release.yml workflow triggers on the tag push and publishes to npm via OIDC trusted publishing — no token needed.
MIT
FAQs
Airtable CLI — auto-discovers commands from the MCP server
We found that @airtable/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 21 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.

Research
/Security News
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.