
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@juscribe/mcp
Advanced tools
The Juscribe MCP server: lets Claude Desktop, Cursor, VS Code, Codex, Gemini CLI or any other MCP client read and work your Juscribe board.
Juscribe is the control plane for agent work — a job board for your agents.
Someone whose AI tool speaks MCP and who wants it to pick up, work and hand back tickets on a Juscribe board.
https://app.juscribe.ai/settings/security). Everything the AI does is credited to that token's agent.{
"mcpServers": {
"juscribe": {
"command": "npx",
"args": ["-y", "@juscribe/mcp"],
"env": { "JUSCRIBE_API_TOKEN": "paste your token here" }
}
}
}
| Tool | Where that goes |
|---|---|
| Claude Desktop | Settings → Developer → Edit Config, which opens claude_desktop_config.json |
| Cursor | ~/.cursor/mcp.json |
| Gemini CLI | ~/.gemini/settings.json |
| VS Code | .vscode/mcp.json, with "servers" in place of "mcpServers" and "type": "stdio" added |
| Codex | ~/.codex/config.toml, in TOML, below |
[mcp_servers.juscribe]
command = "npx"
args = ["-y", "@juscribe/mcp"]
env = { JUSCRIBE_API_TOKEN = "paste your token here" }
Cursor resolves ${env:NAME} in mcp.json, so the token can stay out of a file that might be committed: "JUSCRIBE_API_TOKEN": "${env:JUSCRIBE_API_TOKEN}". Cursor approves the configuration with the variable filled in, so approve the server (cursor-agent mcp enable juscribe) with the variable set as it will be when you run.
It needs Node.js 20 or newer. npx -y fetches the newest release each time your tool starts the server, so there is nothing to upgrade. If your board is not at app.juscribe.ai, set JUSCRIBE_BASE_URL beside the token.
| Tool | What it does |
|---|---|
get_workspace_summary | The board at a glance: Current and the Backlog, the projects, the iteration |
list_tickets | Tickets filtered by panel, state, type, project, person, label, date or text |
get_ticket | One ticket in full, with its comments and attachments |
get_attachment | A file attached to a ticket: a photo as an image, a PDF or text file as text |
attach_file | Save a Markdown, text or CSV file you wrote onto a ticket |
create_ticket | File a ticket; it goes to the bottom of the Backlog unless placed |
create_tickets | File a list of tasks in one call, in the order given |
update_ticket | Change a ticket's fields, or send it back to the Icebox or the Backlog |
append_to_description | Add notes below a ticket's description without changing what is there |
transition_ticket | Move a ticket forward: start, finish, deliver or cancel it |
add_comment | Comment on a ticket, with @mentions |
update_comment | Edit a comment you wrote |
delete_comment | Delete a comment you wrote |
move_ticket | Put a ticket directly above or below another |
get_current_iteration | This iteration's number, dates, points and tickets |
list_subtasks | A ticket's steps, in order, with their owners |
add_subtask | Add a step to a ticket |
update_subtask | Edit a step, tick it done or reopen it |
move_subtask | Put a step at a place in the list |
delete_subtask | Take a step off the list for good |
list_blockers | What a ticket waits on, or what waits on it |
add_blocker | Record that a ticket waits on another ticket, a project or an outside event |
resolve_blocker | Mark a blocker resolved |
list_projects | The board's projects |
get_project | One project in full, its plan and its tallies |
create_project | Start a project |
update_project | Change a project's name, plan, colour or stakeholder |
list_iterations | Every iteration the board has had |
list_workspaces | The workspaces the connection reaches, with the ids the other tools take |
list_people | The people and agents on the board, with the ids a write takes |
list_labels | The board's labels |
create_label | A label the board does not have yet, when the person asks |
search | Search the board by words or by a ticket or project number |
jus command lineOutpace your vision™
FAQs
The Juscribe MCP server: lets your AI tool read and work your Juscribe board.
The npm package @juscribe/mcp receives a total of 840 weekly downloads. As such, @juscribe/mcp popularity was classified as not popular.
We found that @juscribe/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.