
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@edititall/mcp
Advanced tools
MCP server that drives EditItAll's in-browser editors locally (photo, vector, PDF, sheet, Word, slides, image convert). Files never leave the machine.
mcp-name: io.github.Subcue/edititall-mcp
EditItAll is a free, local-first suite of in-browser editors (photo, vector, PDF, spreadsheet, Word, slides, image convert/compress) built by Subcue AI LLC. This repository is the Model Context Protocol server that lets Claude Code, Claude Desktop, Cursor, and any MCP client operate those editors on your machine.
Your files never leave the device. The server launches a local headless Chrome, loads the editors from edititall.com (or a local wrangler dev URL), and drives their official automation hooks. The AI client only sees tool results (cell values, file sizes, screenshots you request).
Public docs: https://edititall.com/ai
WebSocket)From npm:
npx -y @edititall/mcp
# or
npm i -g @edititall/mcp
claude mcp add edititall -- edititall-mcp
From crates.io (Rust wrapper):
cargo install edititall-mcp
claude mcp add edititall -- edititall-mcp
The Rust binary embeds edititall-mcp.mjs and execs node. Set NODE if node is not on PATH.
Claude Desktop (one click). Download edititall-mcp.mcpb and drag it into Claude Desktop → Settings → Extensions. Claude Desktop ships its own Node runtime.
Claude Code (Node, no Rust):
curl -fsSL https://edititall.com/edititall-mcp.mjs -o ~/edititall-mcp.mjs
claude mcp add edititall -- node ~/edititall-mcp.mjs
Or clone this repo:
git clone https://github.com/Subcue/edititall-mcp.git
claude mcp add edititall -- node /path/to/edititall-mcp/edititall-mcp.mjs
Cursor / other stdio clients (mcp.json):
{
"mcpServers": {
"edititall": {
"command": "edititall-mcp"
}
}
}
Node-only equivalent: "command": "node", "args": ["/path/to/edititall-mcp.mjs"].
Env:
| Variable | Default | Meaning |
|---|---|---|
EDITITALL_URL | https://edititall.com | Editor origin (point at wrangler dev while developing) |
CHROME_PATH | auto-detect Chrome/Edge/Chromium/Brave | Browser binary |
| Tool | What it does |
|---|---|
sheet_set_cells / sheet_load_csv / sheet_export_csv | Write cells/formulas, bulk-load CSV, export computed values |
sheet_read_range | Read computed values of "A1:D10" as a 2D array |
pdf_open / pdf_page_text / pdf_rotate_page / pdf_delete_page / pdf_merge / pdf_export | Open, read, reorganize and export PDFs locally |
word_write / word_get_text | Draft and read documents |
slides_from_outline | Build a deck from a title + bullet outline |
vector_import_svg | Import SVG markup as a new vector document |
photo_open_image / photo_export | Open a local image in the photo editor and export flattened |
images_process | Compress/convert local images through the real codec pipeline; reports before/after sizes |
editor_screenshot | Screenshot sheet | vector | photo | tools | pdf | word | slides |
Example prompts: compress every PNG on the desktop to WebP at quality 80 · build a Q3 budget sheet and total the column · draw a rocket in SVG and import it into the vector editor.
The same promise as the website: processing is on-device. Headless Chrome talks to the editors in a local profile under $TMPDIR. Nothing is uploaded to Subcue AI LLC or to a third-party API by this server.
| Endpoint | What it is |
|---|---|
https://edititall.com/ai | Human + agent install docs |
https://edititall.com/llms.txt | Plain-text product summary |
https://edititall.com/edititall-mcp.mjs | Same server file, served from the product origin |
https://edititall.com/edititall-mcp.mcpb | Claude Desktop extension bundle |
The product suite itself is closed-source. This repository is the MCP client/server that talks to it.
MIT © 2026 Subcue AI LLC. EditItAll is a brand of Subcue AI LLC.
FAQs
MCP server that drives EditItAll's in-browser editors locally (photo, vector, PDF, sheet, Word, slides, image convert). Files never leave the machine.
The npm package @edititall/mcp receives a total of 22 weekly downloads. As such, @edititall/mcp popularity was classified as not popular.
We found that @edititall/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.