
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@handset/mcp
Advanced tools
MCP server for the Handset API — give any AI agent a business phone system: send texts, place calls, read transcripts, buy numbers. Safe by default with test-mode keys.
The Handset API as an MCP server: give any AI agent a business phone system — send texts, place calls, read live transcripts and AI summaries, buy numbers, provision tenants.
# Claude Code
claude mcp add handset -e HANDSET_API_KEY=hs_test_... -- npx -y @handset/mcp
// Claude Desktop / Cursor (mcpServers config)
{
"handset": {
"command": "npx",
"args": ["-y", "@handset/mcp"],
"env": { "HANDSET_API_KEY": "hs_test_..." }
}
}
Use your test-mode key: it runs Handset's simulated carrier — numbers
are free and instant, calls answer in a second, nothing touches a real
phone. The server refuses hs_live_ keys unless HANDSET_ALLOW_LIVE=1
is set, because a live key lets the agent text and call real people.
Tenants & numbers: list_tenants, create_tenant, search_numbers,
buy_number, list_numbers · Messaging: send_message,
list_conversations, get_thread · Voice: make_call, get_call,
list_calls, get_transcript, start_transcription, list_voicemails ·
get_usage.
npx -y @handset/mcp --skill prints an agent skill (SKILL.md) that teaches
coding agents the Handset integration patterns — pipe it into
.claude/skills/handset/SKILL.md.
Docs: https://docs.handset.dev · Get a key: https://handset.dev/early-access
FAQs
MCP server for the Handset API — give any AI agent a business phone system: send texts, place calls, read transcripts, buy numbers. Safe by default with test-mode keys.
The npm package @handset/mcp receives a total of 50 weekly downloads. As such, @handset/mcp popularity was classified as not popular.
We found that @handset/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.