
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@indiebob/mcp
Advanced tools
MCP server for IndieBob — read metrics, publish posts, run cold outreach and ask what to do next, from any MCP client.
IndieBob as MCP tools. Read your metrics, draft and publish posts, list prospects, enrol them in an outreach sequence, read the review queue, approve a first touch, and ask what to do next — from any MCP client.
Nothing to install. Add this to your MCP client config:
{
"mcpServers": {
"indiebob": {
"command": "npx",
"args": ["-y", "@indiebob/mcp"],
"env": {
"INDIEBOB_API_KEY": "ib_sk_…",
"INDIEBOB_BASE_URL": "https://www.indiebob.com"
}
}
}
}
INDIEBOB_BASE_URL is optional and defaults to https://www.indiebob.com.
Claude Code: claude mcp add indiebob --env INDIEBOB_API_KEY=ib_sk_… -- npx -y @indiebob/mcp
Service keys are minted by the account owner and carry explicit scopes. A key for every tool here needs:
read:projects, read:metrics, read:actions, read:content,
write:content, read:outreach, write:outreach.
Grant less and the rest still works — a tool that needs a scope you did not grant answers with the scope's name so you can ask for exactly that one.
See https://www.indiebob.com/docs/agents to mint one, and https://www.indiebob.com/agents.md for the full capability document (this server's tools are generated from it).
| Tool | Does |
|---|---|
whoami | Check the key and list its scopes |
list_projects | Every project, with health and stage |
read_metrics | Daily MRR / visitors / signups snapshots |
next_actions | The ranked "what should I do next" feed |
list_posts / get_post | Blog posts and one post's markdown |
create_post / publish_post | Draft and publish |
list_prospects | Cold-outreach prospects for a project |
list_sequences | Sequences, with whether each is personalised |
enroll_prospects | Enrol prospects into a sequence |
list_review_queue | First touches waiting for a human yes |
approve_message | Approve one first touch |
Billing, key minting, project creation and settings stay in the browser. Approving a first touch does not send it — the sequence's send window, daily cap and sending account still apply.
MIT.
Download indiebob.mcpb and open it; Claude Desktop asks for your IndieBob API key and stores it in the system keychain. The same server, bundled as a Desktop Extension.
FAQs
MCP server for IndieBob — read metrics, publish posts, run cold outreach and ask what to do next, from any MCP client.
The npm package @indiebob/mcp receives a total of 25 weekly downloads. As such, @indiebob/mcp popularity was classified as not popular.
We found that @indiebob/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.