
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@init-computer/mcp
Advanced tools
Init is a programmable backend platform available through MCP for generating and running backend APIs.
Use Init from any MCP-compatible assistant or development tool. Init turns a natural-language request into a deployed backend endpoint or project and returns structured JSON with routes, schemas, versions, and results.
Documentation: Init.computer
npm install -g @init-computer/mcp
Requires Node.js 18 or later.
The MCP server is stateless and reads the API key from its process environment. It never stores the key itself:
export INIT_API_KEY=init_sk_...
export INIT_API_BASE_URL=https://api.init.computer
Keep the key in the MCP client's secret/environment configuration, not in a prompt or checked-in file.
{
"mcpServers": {
"init": {
"command": "init-mcp",
"env": {
"INIT_API_KEY": "init_sk_...",
"INIT_API_BASE_URL": "https://api.init.computer"
}
}
}
}
Run the server directly for a stdio client:
init-mcp
init_generateCreate an endpoint, or create a new version of an existing endpoint with resource_id.
{
"prompt": "Create an API that reviews source code for security issues.",
"resource_id": "optional-resource-id",
"projects": ["Security"]
}
init_generate_projectCreate a project and a cohesive endpoint suite.
{
"name": "Customer Support",
"prompt": "Build ticket intake and status lookup."
}
init_edit_projectAdd endpoints or create new endpoint versions in an existing project.
{
"project_id": "project_uuid",
"prompt": "Add ticket assignment."
}
init_runCall a generated endpoint by route, /vN/... path, or full URL.
{
"route": "abc123",
"version": 1,
"input": { "topic": "sports players" },
"requestFormat": "json"
}
init_list_resourcesList the authenticated user's generated resources. Optional filters such as q and status are passed through.
{ "q": "sales", "status": "enabled" }
init_get_resourceFetch one resource by id:
{ "id": "resource_uuid" }
init_list_packagesInspect available runtime packages and enabled connections. Filter by category, for example Database or Storage.
{ "category": "Database" }
The server uses MCP stdio transport and returns JSON text content for every tool call. It does not upload repository secrets; its file tool reads and writes only the explicit init.json path supplied to it.
Use init_apply_project_file with an explicit local init.json path and an edit request. The MCP server reads that one file, finds project.id, applies the edit to the matching Init project, and writes the canonical contract back to the same path. For agents that already have a parsed document, use init_apply_project_manifest; it returns the updated initJson without touching the filesystem.
FAQs
Init is a programmable backend platform available through MCP for generating and running backend APIs.
We found that @init-computer/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.