
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@galaxy-stack/orbit-mcp
Advanced tools
Model Context Protocol server for Orbit framework — AI coding agents get framework knowledge, scaffolding, and security review tools
Model Context Protocol server for the Orbit framework
Give AI coding agents first-class knowledge of Orbit: framework patterns, code scaffolding, and security review — through the Model Context Protocol.
Orbit MCP turns any AI coding agent (Claude, Cursor, Codex, …) into an Orbit-aware collaborator. It exposes:
| Capability | Tools / Resources | Purpose |
|---|---|---|
| Knowledge | orbit_knowledge_topics, orbit_knowledge_read, orbit://knowledge/* | Module/controller/DI/GraphQL/microservices patterns, package map, security checklist |
| Scaffolding | orbit_scaffold_module, orbit_scaffold_graphql | Generate complete feature modules with validation, guards, and tests |
| Security review | orbit_security_review | Static checklist against pasted code — missing validation, guards, rate limits, GraphQL limits, hardcoded secrets, unsanitized HTML |
| Prompts | build_orbit_feature, harden_graphql_api, migrate_from_nestjs | Ready-made task prompts for agents |
Add to your agent's MCP config:
{
"mcpServers": {
"orbit": {
"command": "bunx",
"args": ["@galaxy-stack/orbit-mcp"]
}
}
}
Or run directly from a checkout:
bun run src/server.ts
Agent: List what you know about Orbit.
orbit_knowledge_topics→- module-pattern — Module pattern: Organize features into @Module classes…- security-checklist — Security checklist: Helmet headers, CSRF, rate limiting……
Agent: Review this controller for security issues.
orbit_security_reviewwith the pasted code →1. [HIGH] Mutation endpoints lack input validation. Add ValidationPipe with a Zod schema…2. [HIGH] State-changing endpoint without an auth guard…
The skills/orbit-framework/SKILL.md file is a
portable skill definition covering the same guidance for agents that prefer
skills over MCP. Copy it into your agent's skills directory or reference it in
your prompt.
Implements MCP 2025-03-26 over stdio (newline-delimited JSON-RPC 2.0):
initialize, ping, tools/list, tools/call, resources/list,
resources/read, prompts/list, prompts/get. Zero runtime dependencies —
runs under Bun or Node >= 18.
MIT
FAQs
Model Context Protocol server for Orbit framework — AI coding agents get framework knowledge, scaffolding, and security review tools
We found that @galaxy-stack/orbit-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.