
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@itechsoftsolutions/social-mcp-server
Advanced tools
MCP server exposing Feedlio (Social AI) posting/scheduling tools to MCP clients (Claude Desktop, Claude Code, etc.) via a Feedlio personal access token.
MCP server exposing Feedlio's posting/scheduling API as tools for MCP clients
(Claude Desktop, Claude Code, ChatGPT connectors, etc). Every tool is a thin
wrapper around the social-auth-api-gateway GraphQL API (q_mcp_* /
m_mcp_* operations) — no business logic lives here, so scheduling, plan
limits, and validation stay exactly as they are for the dashboard.
Everything is authenticated with a Feedlio personal access token (fdl_...),
created by the user in the dashboard under Settings → MCP, with the scopes
the tools need: workspaces:read, workspaces:write, accounts:read,
posts:read, posts:write.
src/http.tsOne shared process serving many users. Each MCP client authenticates itself, either:
/.well-known/oauth-authorization-server, registers itself
(/register), and sends the user to /authorize, which shows a Feedlio
login page asking them to paste their token. The issued access token is
that token; /revoke really revokes it in Feedlio. Implemented in
src/oauth.ts on top of the SDK's mcpAuthRouter.Authorization: Bearer fdl_... on
each request — claude mcp add --transport http feedlio <url>/mcp --header "Authorization: Bearer fdl_...".Env: PORT (3210), HOST, FEEDLIO_API_URL (gateway GraphQL URL),
MCP_PUBLIC_URL (the externally reachable base URL — advertised as the OAuth
issuer, must be HTTPS unless localhost), FEEDLIO_DASHBOARD_URL. Runs as the
mcp-server service in backend/docker-compose*.yml.
src/index.tsOne process per user, token in the environment
(FEEDLIO_API_TOKEN, FEEDLIO_API_URL). Handy for local development;
not needed once the HTTP server is deployed.
list_workspaces, create_workspace, set_default_workspace, delete_workspace.list_social_accounts — connected accounts in a workspace, each with
platform_slug and can_post (whether create_post will accept it).create_post — schedule (scheduled_at) or publish immediately
(publish_now: true); exactly one is required so nothing goes live by
accident.list_posts, reschedule_post, cancel_post, delete_post.list_media, add_media_from_url, delete_media — media library; files
can't be uploaded from chat, but a public URL can be imported.get_connect_platform_link — connecting a platform needs an OAuth popup,
so this just returns the dashboard link where the user does it.Status integers from the backend are translated to labels here; the accepted
platform_slug list mirrors the gateway's SOCIAL_PLATFORM_ARRAY and must be
kept in sync with it.
yarn dev # stdio server from src (tsx)
yarn dev:http # HTTP server from src, watch mode
yarn build # compile to dist/
yarn start # node dist/index.js (stdio)
yarn start:http # node dist/http.js (HTTP)
FAQs

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.