
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@domscout/mcp
Advanced tools
domscout browser API as MCP tools: screenshots, Markdown extraction, structured data, DOM snapshots, page automation, and crawls.
Use domscout as MCP tools to read pages as Markdown, capture screenshots, extract structured data, inspect interactive structure, automate browser flows, and crawl allowlisted sites.
{
"mcpServers": {
"domscout": {
"command": "npx",
"args": ["-y", "@domscout/mcp"],
"env": {
"DOMSCOUT_API_KEY": "ds_your_key_here"
}
}
}
}
| Variable | Required | Purpose |
|---|---|---|
DOMSCOUT_API_KEY | Yes | Your API key. |
DOMSCOUT_BASE_URL | No | Overrides the current production gateway for an intentionally separate deployment. |
The default targets https://api.domscout.io.
Verify the key in the dashboard before connecting a client; never commit or
paste the key into prompts.
| Tool | Cost | What it does |
|---|---|---|
domscout_check_credits | free | Balance, quota, rate limit, and price list |
domscout_extract_markdown | 1 | Read a page as clean Markdown (fast:true skips the browser) |
domscout_capture_screenshot | 1–3 | Capture PNG/JPEG/WebP/PDF |
domscout_extract_data | 2 | Extract named fields as typed JSON |
domscout_inspect_page | 2 | Read the accessibility tree and interactive elements |
domscout_automate_page | 1–2 | Run allowed actions and capture the result |
domscout_crawl_site | 1/page | Run a bounded, allowlisted, robots-respecting crawl |
domscout_get_job | free | Poll a durable job, batch, or crawl |
domscout_cancel_job | free | Cancel one durable job |
domscout_send_feedback | free | Send product feedback |
A request never costs more than 10 credits. Tool results include the request cost and remaining balance.
| URI | Contents |
|---|---|
domscout://docs | API reference |
domscout://openapi | OpenAPI 3.1 contract |
The MCP server sends an x-api-key to the configured API host and reads the
response. It has no browser, database, or billing credential. Keep the key in
the MCP client environment block; do not commit it or paste it into prompts.
npm --prefix mcp ci # this package ships its own dependency tree
npm --prefix mcp run check # parse
npm --prefix mcp test # boot the server and complete a real handshake
npm run test:unit:hermetic # the tool table and HTTP client, from the root suite
npm run check is node --check, which resolves no imports — it cannot tell
you the server still talks to @modelcontextprotocol/sdk. npm test spawns
src/index.js exactly as a client would and drives it over stdio. Run both.
The published package is what npx -y @domscout/mcp resolves, so the release is
gated and tagged rather than hand-run:
version in mcp/package.json.mcp-v<version>..github/workflows/publish-mcp.yml checks the tag against the
manifest, refuses to reuse a published version, re-runs the gates, and
publishes.The workflow needs an NPM_TOKEN repository secret, and specifically a
classic Automation token for an account with write access to the
@domscout scope. An ordinary npm login session token is not enough: the
account has 2FA on writes, so the registry answers EOTP and asks for a
one-time password, which no CI job can supply. That is what the Automation
token type exists to bypass.
There is no --provenance on the publish, because npm publishes the
attestation to a public transparency log and refuses it for a private
repository. See the comment on that step before adding it back.
To publish by hand instead, run npm publish --otp=<code> from mcp/. Plain
npm publish fails with EOTP for the reason above. publishConfig.access is
already public, which a scoped package requires or it fails E402.
FAQs
domscout browser API as MCP tools: screenshots, Markdown, structured data, page automation, crawls.
The npm package @domscout/mcp receives a total of 423 weekly downloads. As such, @domscout/mcp popularity was classified as not popular.
We found that @domscout/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.