
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@complyedge/mcp
Advanced tools
Offline MCP server for EU AI Act compliance checks. Three read-only tools over a bundled 64-rule corpus — Art. 5 prohibited practices, Art. 50 transparency, GDPR, HIPAA, SOX, PCI DSS, COPPA. Runs with npx: no Python, no API key, no network call.
EU AI Act Article 5 and Article 50 runtime deny via TrustLint, offline. Classifiers (eu-ai-act-*) score the system; this server denies this prompt or output. Article 50 here is unlabeled or deceptive use, not C2PA.
npx -y @complyedge/mcp
pip install 'complyedge[mcp]'
pip install complyedge
pip install trustlint
claude mcp add complyedge -- npx -y @complyedge/mcp
Run offline TrustLint checks from any MCP host with Node.js:
{
"complyedge": {
"command": "npx",
"args": ["-y", "@complyedge/mcp"]
}
}
The server exposes three read-only tools.
| Tool | Returns | Notes |
|---|---|---|
check_compliance | PASS / FAIL with cited findings | Checks already-produced text. Optional jurisdiction: EU, US, GLOBAL |
scan_prompt | SAFE / RISK_DETECTED | Checks a candidate prompt before it is sent to a model |
list_rules | Rule inventory | Discovery only — does not evaluate text |
@complyedge/sdk for
POST /v1/check and the Article 12 audit trail.@complyedge/sdk — hosted runtime enforcement and the Article 12 audit trailtrustlint — the same offline engine as a CLIcomplyedge on PyPI — Python MCP server, published under this same registry entryuses: complyedge/trustlint-action@v1trustlint on PyPI — Python linterFAQs
Offline MCP server for EU AI Act compliance checks. Three read-only tools over a bundled 64-rule corpus — Art. 5 prohibited practices, Art. 50 transparency, GDPR, HIPAA, SOX, PCI DSS, COPPA. Runs with npx: no Python, no API key, no network call.
The npm package @complyedge/mcp receives a total of 191 weekly downloads. As such, @complyedge/mcp popularity was classified as not popular.
We found that @complyedge/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.