
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@fileseal/send
Advanced tools
MCP server that delivers a file to a person as a one-time, AES-256 encrypted, auto-deleting download link via the FileSeal Secure Send API.
A standalone Model Context Protocol stdio
server that wraps the FileSeal Secure Send API (/v1/sends). It encrypts
files client-side (AES-GCM-256) before they ever reach FileSeal and exposes
three tools to an MCP client (e.g. Claude).
This package is self-contained: it does not import from the FileSeal Next
app. Its crypto (crypto.mjs) mirrors src/lib/attachments.ts byte-for-byte so
that ciphertext it produces decrypts on the FileSeal /receive/[id] page.
secure_send — encrypt a file and create a send.
filePath or (fileBase64 + filename + mimeType),
recipientEmail?, deliveryMode ('link' default | 'email'),
expiryHours? (1-168, default 48), message?.#k=
fragment.recipientEmail.send_status — { id } → status, expiry, download count, audit events.revoke_send — { id } → revoke the send and delete its blobs.| Variable | Required | Default | Purpose |
|---|---|---|---|
FILESEAL_API_KEY | yes | — | Bearer token sent as Authorization: Bearer <key> on every call. The server exits at startup if unset. |
FILESEAL_API_BASE_URL | no | http://localhost:3000 | API origin. Routes are <base>/v1/sends. |
No install needed — npx fetches and runs the latest published version:
FILESEAL_API_KEY=fsk_... \
FILESEAL_API_BASE_URL=https://fileseal.uk \
npx -y @fileseal/send
The server speaks MCP over stdio, so it's normally launched by an MCP client rather than run by hand.
# from the repo root
npm install --prefix mcp/fileseal-send
FILESEAL_API_KEY=fsk_... \
FILESEAL_API_BASE_URL=https://fileseal.uk \
node mcp/fileseal-send/index.mjs
.mcp.json){
"mcpServers": {
"fileseal-send": {
"command": "npx",
"args": ["-y", "@fileseal/send"],
"env": {
"FILESEAL_API_KEY": "fsk_your_api_key_here",
"FILESEAL_API_BASE_URL": "https://fileseal.uk"
}
}
}
}
The "fileseal-send" key is just the local server label; the npm package is
@fileseal/send. To run the in-repo copy instead, use
"command": "node", "args": ["mcp/fileseal-send/index.mjs"].
Copy for MCP registries and marketplaces. The literal name fileseal-send and the
one-line description are what assistants match against user intent, so keep them
stable and verb-first.
fileseal-send@fileseal/send (npx -y @fileseal/send)file-sharing, secure, encryption, one-time, gdpr, file-delivery, emailsecure_send, send_status, revoke_sendFAQs
MCP server that delivers a file to a person as a one-time, AES-256 encrypted, auto-deleting download link via the FileSeal Secure Send API.
The npm package @fileseal/send receives a total of 649 weekly downloads. As such, @fileseal/send popularity was classified as not popular.
We found that @fileseal/send demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.