
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@image-mcp/cli
Advanced tools
Agent-first CLI for Image MCP image generation, editing, jobs, and skill install flows
@image-mcp/cliAgent-first CLI for Image MCP.
This package gives agents and humans a direct workflow surface for:
npm install -g @image-mcp/cli
Or run it directly:
npx --yes --package=@image-mcp/cli image-mcp --help
image-mcp login
image-mcp models --limit 5
image-mcp create "studio product shot" --model nano-banana-2
image-mcp skill install --agent all
Use provider-neutral public ids:
nano-banananano-banana/editnano-banana-2nano-banana-2/editSlash-style edit ids are canonical.
loginlogoutwhoamimodelsactivityuploadcreateeditjob get|list|wait|canceldoctorskill installThe default flow opens the browser for OAuth and stores a local session. You can also point the CLI at another deployment with:
image-mcp whoami --base-url https://image-mcp.com
If you are using npx without a global install, use the explicit package form because the published package name and executable name differ:
npx --yes --package=@image-mcp/cli image-mcp --help
npx --yes --package=@image-mcp/cli image-mcp whoami
Image MCP ships four product surfaces:
For most agent workflows, the CLI + skill path is the best default.
FAQs
Agent-first CLI for Image MCP image generation, editing, jobs, and skill install flows
The npm package @image-mcp/cli receives a total of 6 weekly downloads. As such, @image-mcp/cli popularity was classified as not popular.
We found that @image-mcp/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.