
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@evan-moon/skope
Advanced tools
Local-first, AI-native personalized news intelligence — a lens + watcher on the world. Built-in MCP server for Claude Desktop.
Your feed shows you everything.
skope shows you what reaches you.
Stop hunting the news. Let Claude scan the world, keep only what has a path to your
life (your money, your work, your country) and watch you against your own bubble.
You: Catch me up on today's news.
Claude: Reading your world, assets (TSLA, NVDA), work (Toss), stack (React),
Seoul. Searched the literal names AND what *reaches* them (Fed, USD/KRW,
chip controls). 12 stories reached you. Your brief:
🎯 Reaches you, narrow & deep
· US tightens Nvidia chip-export ban (asset · keyword)
· Fed holds; sticky CPI keeps rates high (asset · reach: Fed → growth-stock valuations)
· 금융위 DSR tightening hits household loans (career · reach → Toss)
🌏 Could affect you, broad & thin
· M7.8 quake off the Philippines (situational · your region)
· Strait of Hormuz oil shock (situational · energy)
⚠ Attention check: effective N = 3.1 across 5 axes, lens is wide today.
You: Go deeper on the chip story.
Claude: [digs 3 passes] One export rule reaches you twice: it caps Nvidia's
China revenue (your holding) and, via the Nasdaq-100 reshuffle, forces
index funds to trim your Apple and Microsoft. Same week, two mechanical
hits on the same book. Here's the chain, step by step…
A "Rio street festival" headline? Zero path. You'll never see it.
Brazil rate hike → dollar → your TSLA reaches you, while a stranger's daily life abroad doesn't. Searching only the literal names is what makes feeds feel repetitive; the upstream anchors are the lens.~/.skope/skope.db. No server, no account, no cloud. The only thing that ever leaves your machine is a search query.# 1. Install
npm install -g @evan-moon/skope
# 2. Seed a profile (works with zero integrations)
skope init --location "Seoul, Korea" --languages ko,en
# 3. Connect Claude Desktop, then restart it
skope mcp install
Then just talk to Claude: "set up my interests" (it fills your axes), then "what's my news today?" Claude searches the web itself, hands the results to skope, and reads you back a brief, broad enough to break your bubble, narrow enough to skip a festival on the other side of the planet.
If skope helps you see the news that actually reaches you, ⭐ star the repo, it's the cheapest way to help others find it.
skope is MCP-first. Searching, scoring, briefing, explaining, all of it happens in conversation with Claude. The CLI exists for the things a chat can't safely own: setup and inspection.
# Setup
skope init --location "City, Country" # seed a cold-start profile
skope config set tavily-key <key> # optional, only for the scan_news fallback
skope mcp install # register with Claude Desktop
# Inspect (read-only)
skope profile # show your axes and weights
Everything else is a conversation. The MCP tools Claude drives:
| Tool | What it does |
|---|---|
show_profile | read your axes, weights, location, plus a gaps report (what onboarding/refresh still needs to fill) |
update_profile | set axes with their reachAnchors (causal-upstream topics), weights, and current location, the federation entry point |
ingest_news | primary, key-less, Claude searches across keywords and reachAnchors, hands results here; skope dedups, tier-tags, and reachability-scores them. Pass current_location while traveling |
scan_news | fallback, skope fetches via Tavily when a client has no web search of its own |
get_brief | assemble the two-band brief ([reaches you] + [could affect you] + the world layer + the effective-N meter) re-scored against your current profile, for Claude to render as a research note |
reading_signal | the living-profile signal, what you keep reading (promote to a keyword), axes you've drifted from (downweight), and reads with no path yet (new-interest candidates), all gated on your concentration |
mark_read | drop seen stories from future briefs (deterministically) |
The boundary is the whole point: collection is active and lives with the LLM; the ledger is deterministic and lives with skope (URL/content dedup, rule-based reachability, trust-tiered ranking, effective-N, never LLM guesswork).
A Yarn Berry monorepo with a strict port-and-adapter layout. Business logic never imports an external API directly, it talks to domain interfaces, and adapters implement them.
packages/
domain/ ports + types (Profile, Article, ReachabilitySeed, SearchProvider), zero external-API knowledge
external-api/ raw clients (tavily) + trust-tier seed data (source-trust), zero domain knowledge
adapter/ the only layer that imports both sides
use-case/ business logic (profile, discovery, brief, watch)
shared/ db + utils
apps/
cli/ mcp/ docs/
The rule: use-case reaches the web only through the domain's SearchProvider port, never the concrete Tavily client. Trust tiering and reachability are pure, deterministic rules. Reachability stores only the rule-match seed; Claude renders the causal-chain narrative statelessly at brief time.
Verified end-to-end by 48 MCP scenarios across 5 adversarial test rounds (test/mcp-tests-*.mjs), plus a unit suite (vitest) covering reachability scoring, the situational band, brief assembly + freshness rotation, the living-profile signal, and a 5-persona validation matrix that proves the same article reaches different users via different paths, and drops for the wrong ones.
Requires Node.js 22+ and Yarn Berry.
corepack enable
yarn install
yarn build
yarn typecheck
yarn dev:mcp # run the MCP server over stdio
yarn test # unit suite (vitest)
node test/mcp-tests.mjs # end-to-end MCP regression suite
skope is one of three local-first tools that share one principle, your data stays on your machine, and the AI comes to it. They interoperate through any MCP client, and none depends on the others.
flowchart TB
U([You])
subgraph I["Interfaces, talk to your tools"]
direction LR
CD[Claude Desktop]
CC[Claude Code]
H["Herald · voice"]
end
subgraph T["Local-first tools, each owns its data, on your machine"]
direction LR
F["firma · money<br/>~/.firma"]
M["memex · memory<br/>~/.memex"]
S["skope · news<br/>~/.skope"]
end
U --> I
I -- MCP --> F & M & S
F <-. never call each other .-> M
M <-.-> S
You reach them through Claude Desktop, Claude Code, Cursor, or Herald, a voice interface. The tools compose through the model, never by calling each other.
MIT © Evan Moon
FAQs
Local-first, AI-native personalized news intelligence — a lens + watcher on the world. Built-in MCP server for Claude Desktop.
The npm package @evan-moon/skope receives a total of 5 weekly downloads. As such, @evan-moon/skope popularity was classified as not popular.
We found that @evan-moon/skope demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.