
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@galaxy-stack/nebula-mcp
Advanced tools
Nebula MCP Server — exposes Galaxy UI components to AI assistants through the Model Context Protocol. Works with Claude Desktop, Cursor, Windsurf, Cline, and any MCP-compatible client.
| Tool | Description |
|---|---|
list_components | All components with per-framework availability (React, Vue, Angular, React Native, Flutter) |
get_component | Detailed manifest — props, files, dependencies, framework status |
get_component_source | Actual source code for a specific component file |
get_coverage | Coverage matrix across all 5 frameworks (67 components) |
search_components | Search by name or description |
All component data + 700 source files are bundled inside the package — zero setup, works offline.
npx -y @smithery/cli@latest install galaxy-stack/design-mcp --client claude
Add to your MCP client config:
{
"mcpServers": {
"galaxy-ui": {
"command": "npx",
"args": ["-y", "@galaxy-stack/nebula-mcp"]
}
}
}
~/Library/Application Support/Claude/claude_desktop_config.json~/.cursor/mcp.jsonPaste into clients that support remote MCP (Claude web Custom Connectors):
https://nebula-mcp--galaxy-stack.run.tools
"List Galaxy UI components for React"
"Show me the source code of the Vue Select component"
"Which components are missing in Flutter?"
Bump version in package.json
Push to main — GitHub Actions workflow publish-mcp.yml builds contracts artifacts, bundles data, verifies the version is new, and publishes via npm Trusted Publishing (OIDC) — no NPM_TOKEN required
Rebuild the MCPB bundle and run smithery mcp publish for Smithery
Publish to the Official MCP Registry (org namespace requires a PAT — device-flow login cannot read org roles, see registry#1468):
# PAT needs read:org scope (classic) or Organization → Members → Read-only (fine-grained)
mcp-publisher login github --token <YOUR_PAT> # requires mcp-publisher >= 1.8.1
mcp-publisher validate
mcp-publisher publish # → io.github.galaxy-nebula/nebula-mcp
FAQs
MCP server exposing Galaxy Nebula components for AI assistants.
The npm package @galaxy-stack/nebula-mcp receives a total of 452 weekly downloads. As such, @galaxy-stack/nebula-mcp popularity was classified as not popular.
We found that @galaxy-stack/nebula-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.