
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@dexun/adwhiz-mcp
Advanced tools
MCP server that lets Claude Desktop / Cursor talk to your DEXUN AdWhiz account. Lists ad accounts, surfaces AI recommendations, reports savings — all through your existing API key.
Let Claude Desktop / Cursor / any MCP-aware client talk to your DEXUN AdWhiz account. Ask Claude things like:
"List my connected ad accounts." "What's the AI recommending I do right now?" "Have there been any sign-ins from new IPs this week?" "How close am I to my API rate limit?"
Read-only for now (v0.1) — Claude can see your AdWhiz state but can't apply changes or pause campaigns. Mutation tools land in a later version once the optimizer exits shadow mode.
node --version)No npm install required. The server is a single Node script with zero runtime dependencies.
Clone or download this repo somewhere stable on your machine:
git clone https://github.com/dexun-inc/adwhiz-mcp.git ~/.adwhiz-mcp
Open Claude Desktop's MCP config file. On macOS:
~/Library/Application Support/Claude/claude_desktop_config.json
On Windows:
%APPDATA%\Claude\claude_desktop_config.json
Add the adwhiz entry to mcpServers:
{
"mcpServers": {
"adwhiz": {
"command": "node",
"args": ["/absolute/path/to/.adwhiz-mcp/src/index.mjs"],
"env": {
"ADWHIZ_API_KEY": "dxk_live_PUT_YOUR_KEY_HERE"
}
}
}
}
Replace the path with where you cloned the repo, and the API key with one from /settings#api-keys.
Quit Claude Desktop completely and reopen. The 5 AdWhiz tools should now show up when you start a new conversation.
git clone step.command + args + env shape as Claude Desktop.Any client that follows the MCP spec can use this. The server speaks plain JSON-RPC 2.0 over stdio. Tell the client to run node /path/to/src/index.mjs and set ADWHIZ_API_KEY in the spawn environment.
| Tool | Use when the user asks |
|---|---|
list_ad_accounts | "What accounts do I have connected?" / "Show me my Meta accounts" |
list_recommendations | "What does the AI recommend right now?" / "Anything to do today?" |
get_savings_summary | "How much has AdWhiz saved me?" / "Is the AI actually working?" |
get_recent_activity | "What happened this week?" / "Any sign-ins I didn't make?" |
get_quota | "Am I close to my rate limit?" / "How much API quota do I have?" |
All five are read-only. They never apply budget changes, pause campaigns, or revoke keys. To do those things use the dashboard.
| Variable | Default | Notes |
|---|---|---|
ADWHIZ_API_KEY | (required) | dxk_live_* or dxk_test_*. Generate at /settings#api-keys. |
ADWHIZ_BASE_URL | https://app.7275.com | Override for self-hosted / staging environments. |
Claude says "Server adwhiz is not responding" or the tools don't appear. Run the script manually to see stderr output:
ADWHIZ_API_KEY=dxk_live_... node /path/to/src/index.mjs
It should sit idle waiting for stdin. If it errors immediately, the message tells you what's wrong (most commonly: API key missing or node is too old).
Tools error with "Unauthorized". Your API key was revoked or you copied it wrong. Generate a fresh one at https://app.7275.com/settings#api-keys.
Rate limited.
You're hitting your plan's per-key RPM cap (60/120/600/3000 RPM by tier). Either wait for the window to reset (get_quota tells you when) or upgrade.
app.7275.com over HTTPS.apply_recommendation once auto-apply is calibration-gated.pause_campaign + change_budget direct mutations.MIT — see LICENSE.
Bug reports + feature requests: open an issue on the main repo or email service@7275.com.
FAQs
MCP server that lets Claude Desktop / Cursor talk to your DEXUN AdWhiz account. Lists ad accounts, surfaces AI recommendations, reports savings — all through your existing API key.
We found that @dexun/adwhiz-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.