
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@first-ch/tools-mcp
Advanced tools
First CH Tools の計算ロジック(WCAGコントラスト比・文字数/Xウェイト・WebP変換・JSON-LD生成・llms.txt生成)をMCPツールとして提供するサーバー
MCP server exposing First CH Tools' free web-tool logic (WCAG contrast, JP character/X-weight counting, WebP conversion, JSON-LD, and llms.txt generation) to AI agents such as Claude Code.
日本語版は 後半セクション を参照してください。
| Tool | What it does | Main input |
|---|---|---|
contrast_check | Computes the WCAG 2.1 contrast ratio between a foreground and background color and returns AA/AAA pass/fail (normal text, large text, UI components) | fg, bg (hex, e.g. #333333 / 333 / fff) |
count_chars | Counts Japanese text by grapheme, breaks it down into zenkaku/hankaku, counts lines, and computes the X (Twitter) post weight (zenkaku=2, hankaku=1, URL=23 flat, limit 280) | text |
webp_convert | Converts PNG/JPEG files to WebP using the same libwebp WASM encoder (default quality 80) as the browser tool at tools.first-ch.com/webp/ | paths[] (absolute paths), quality? (1-100), outputDir? |
jsonld_generate | Generates schema.org JSON-LD for organization / faqpage / service / breadcrumb. Empty fields are omitted automatically | type, plus the matching organization / faq / service / breadcrumb object |
llmstxt_generate | Generates an llms.txt file (per the llmstxt.org proposed format) summarizing a site for AI crawlers/agents | siteName, summary?, notes?, sections? |
See server.mjs for the exact Zod input schemas.
With Claude Code:
claude mcp add firstch-tools -- npx -y @first-ch/tools-mcp
With any other MCP client, add to its server config (e.g. mcp.json / claude_desktop_config.json):
{
"mcpServers": {
"firstch-tools": {
"command": "npx",
"args": ["-y", "@first-ch/tools-mcp"]
}
}
}
Requires Node.js >=18.14.1.
Nothing is logged by default. Usage is recorded only when you set the FIRSTCH_TOOLS_USAGE_LOG environment variable to a file path — each tool call then appends one JSON line ({ ts, tool, source }) to that local file. There is no network transmission of any kind; if the variable is unset, no file is written and no data leaves your machine.
The same algorithms are also available as a free, no-install browser tool at tools.first-ch.com — useful when you want a UI instead of an MCP call, or want to hand a link to someone without an MCP client.
The package itself is licensed under MIT.
It bundles a subset of jSquash's WebP codec under vendor/jsquash-webp/ to power webp_convert, which carries its own licenses:
vendor/jsquash-webp/LICENSE.vendor/jsquash-webp/codec/LICENSE.codec.md.Both license files are included verbatim in the published npm package, as required by their respective terms (BSD-3-Clause in particular requires the copyright notice, condition list, and disclaimer to be reproduced in binary redistributions).
@first-ch/tools-mcp は、First CH Tools(無料Webツール集)の計算ロジック — WCAGコントラスト比・日本語文字数/Xウェイト計測・WebP変換・JSON-LD生成・llms.txt生成 — をAIエージェント(Claude Code等)向けMCPツールとして提供するサーバーです。
| ツール | 何をするか | 主な入力 |
|---|---|---|
contrast_check | 文字色と背景色のWCAG 2.1コントラスト比を計算し、AA/AAA基準(通常テキスト・大テキスト・UI部品)の合否を返す | fg・bg(hex。例: #333333 / 333 / fff) |
count_chars | 日本語テキストを書記素単位で数え、全角/半角内訳・行数・X(Twitter)投稿ウェイト(全角=2・半角=1・URL=一律23・上限280)を返す | text |
webp_convert | PNG/JPEG画像をWebPへ変換する。tools.first-ch.com/webp/ と同一のlibwebp WASMエンコーダ(品質既定80) | paths[](絶対パス)・quality?(1-100)・outputDir? |
jsonld_generate | schema.org準拠のJSON-LDを生成する(organization / faqpage / service / breadcrumb)。空項目は自動で省略 | type と対応する organization / faq / service / breadcrumb オブジェクト |
llmstxt_generate | AI検索・生成AI向けにサイト概要を伝える llms.txt(llmstxt.org提案フォーマット準拠)を生成する | siteName・summary?・notes?・sections? |
正確な入力スキーマ(Zod定義)は server.mjs を参照してください。
Claude Codeの場合:
claude mcp add firstch-tools -- npx -y @first-ch/tools-mcp
他のMCPクライアントの場合は設定ファイル(mcp.json / claude_desktop_config.json 等)に以下を追加します。
{
"mcpServers": {
"firstch-tools": {
"command": "npx",
"args": ["-y", "@first-ch/tools-mcp"]
}
}
}
Node.js >=18.14.1 が必要です。
既定では何も記録しません。環境変数 FIRSTCH_TOOLS_USAGE_LOG にファイルパスを設定したときのみ、各ツール呼び出しごとに1行のJSON({ ts, tool, source })をそのローカルファイルへ追記します。ネットワーク送信は一切ありません(未設定であればファイルへの書き込み自体が発生せず、データが端末外に出ることはありません)。
同一アルゴリズムを、インストール不要の無料ブラウザツールとしても公開しています: tools.first-ch.com。UIで使いたいとき・MCPクライアントを持たない相手にリンクを共有したいときはこちらをどうぞ。
本パッケージ自体は MIT です。
webp_convert のために jSquash のWebPコーデックの一部を vendor/jsquash-webp/ 配下に同梱しており、それぞれ別のライセンスが適用されます。
vendor/jsquash-webp/LICENSE を参照vendor/jsquash-webp/codec/LICENSE.codec.md を参照いずれのライセンスファイルも公開npmパッケージに原文のまま同梱しています(BSD-3-Clauseはバイナリ再配布時にも著作権表示・条件・免責事項の再掲を求めるため)。
FAQs
First CH Tools の計算ロジック(WCAGコントラスト比・文字数/Xウェイト・WebP変換・JSON-LD生成・llms.txt生成・文字コード/改行コード変換・Marp Markdown→スライド レンダリング・テストデータ生成・テキスト/コード差分・Cron式の解説・Base64/Data URI変換・URLパラメータの分解/再構築・HTML特殊文字のエスケープ/エンティティのデコード・JSON⇄YAMLの相互変換・px⇄rem/emの単位換算とCSSの一括変換・カラーコードの相互変換とア
The npm package @first-ch/tools-mcp receives a total of 715 weekly downloads. As such, @first-ch/tools-mcp popularity was classified as not popular.
We found that @first-ch/tools-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.