
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@dpf-it/mcp-server
Advanced tools
RETIRED — DPF now runs a remote MCP server at https://api.dpf-it.com/mcp. Installing this package prints setup instructions and exits.
This package is retired. DPF now runs a remote MCP server — no install, no npm package, no local Node.js required.
Point your MCP client at:
https://api.dpf-it.com/mcp
VS Code, Cursor, Claude Desktop/Claude.ai, Kiro IDE, and ChatGPT Developer Mode all support this directly: connecting opens a browser login (OAuth 2.1) — your password is typed on DPF's own page, never inside a chat — and the client stores its own session from then on, including for brand-new accounts (the same login page handles sign-up).
Full setup instructions per client: https://dpf-it.com/integration-guide.html#mcp
Tools exposed by the remote server (https://api.dpf-it.com/mcp), authenticated via OAuth 2.1:
list_my_workspaces — List my workspacescreate_workspace — Create a workspaceonboard_data_source — Onboard a new data source, step 1: create a data spec and get upload URL(s)finish_data_source_onboarding — Onboard a new data source, step 2: run analysis after uploadingupdate_data_spec — Update an existing data specfinish_data_spec_update — Update an existing data spec, step 2: run analysis after uploadingrun_data_job — Run a data processing job, step 1: create job and get upload URL(s)finish_data_job — Run a data processing job, step 2: start processing after uploadingsetup_scheduled_pull — Set up a scheduled SFTP or S3 pull into an existing data specmanage_connection — Manage an external data-source connection (SFTP, AWS S3)manage_trigger — Manage a workspace trigger (SFTP/AWS S3 pull, spec chaining, or schedule)list_data — List data specs or jobsget_status — Get spec or job statusdelete_data_spec — Delete a data specsubmit_query — Query workspace datacall_dpf_api — Call any DPF API action (fallback for requests with no dedicated tool)A small number of clients (Codex CLI, Kiro CLI) don't yet support the OAuth browser flow that the remote server requires, and this package no longer provides a working local alternative. Check the integration guide for updates once those clients add OAuth support.
The remote server give every client a consistent, install-free setup, real per-user attribution (not a shared workspace credential), and is the only way for hosted clients like ChatGPT — which can't spawn a local process at all — to use DPF's MCP server.
FAQs
RETIRED — DPF now runs a remote MCP server at https://api.dpf-it.com/mcp. Installing this package prints setup instructions and exits.
The npm package @dpf-it/mcp-server receives a total of 89 weekly downloads. As such, @dpf-it/mcp-server popularity was classified as not popular.
We found that @dpf-it/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.