
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@galaxy-stack/orbit-mcp
Advanced tools
Model Context Protocol server for Orbit framework — AI coding agents get framework knowledge, scaffolding, and security review tools
Model Context Protocol server for the Orbit framework
Give AI coding agents first-class knowledge of Orbit: framework patterns, code scaffolding, and security review — through the Model Context Protocol.
Orbit MCP turns any AI coding agent (Claude, Cursor, Codex, …) into an Orbit-aware collaborator. It exposes:
| Capability | Tools / Resources | Purpose |
|---|---|---|
| Knowledge | orbit_knowledge_topics, orbit_knowledge_read, orbit://knowledge/* | Module/controller/DI/GraphQL/microservices patterns, package map, security checklist |
| Scaffolding | orbit_scaffold_module, orbit_scaffold_graphql | Generate complete feature modules with validation, guards, and tests |
| Security review | orbit_security_review | Static checklist against pasted code — missing validation, guards, rate limits, GraphQL limits, hardcoded secrets, unsanitized HTML |
| Prompts | build_orbit_feature, harden_graphql_api, migrate_from_nestjs | Ready-made task prompts for agents |
Add to your agent's MCP config:
{
"mcpServers": {
"orbit": {
"command": "bunx",
"args": ["@galaxy-stack/orbit-mcp"]
}
}
}
Or run directly from a checkout:
bun run src/server.ts
Agent: List what you know about Orbit.
orbit_knowledge_topics→- module-pattern — Module pattern: Organize features into @Module classes…- security-checklist — Security checklist: Helmet headers, CSRF, rate limiting……
Agent: Review this controller for security issues.
orbit_security_reviewwith the pasted code →1. [HIGH] Mutation endpoints lack input validation. Add ValidationPipe with a Zod schema…2. [HIGH] State-changing endpoint without an auth guard…
The skills/orbit-framework/SKILL.md file is a
portable skill definition covering the same guidance for agents that prefer
skills over MCP. Copy it into your agent's skills directory or reference it in
your prompt.
Implements MCP 2025-03-26 over stdio (newline-delimited JSON-RPC 2.0):
initialize, ping, tools/list, tools/call, resources/list,
resources/read, prompts/list, prompts/get. Zero runtime dependencies —
runs under Bun or Node >= 18.
MIT
FAQs
Model Context Protocol server for Orbit framework — AI coding agents get framework knowledge, scaffolding, and security review tools
The npm package @galaxy-stack/orbit-mcp receives a total of 1,601 weekly downloads. As such, @galaxy-stack/orbit-mcp popularity was classified as popular.
We found that @galaxy-stack/orbit-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.