
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@marketmaster/mcp
Advanced tools
MCP server for the MarketMaster prediction-market data API — use live edges, arbitrage, and whale data inside Claude and Cursor.
MCP server for the MarketMaster prediction-market data API. Pull live edges, arbitrage spreads, market snapshots, and the whale feed (Kalshi and Polymarket) straight into Claude or Cursor.
mm_edges — mispriced edges, rankedmm_markets — latest market snapshotsmm_market — one market + its edgesmm_arbitrage — cross-platform spreadsmm_whales — large real-money tradesmm_status — your tier, limits, usageGet an API key at https://marketmaster.live/dashboard (looks like mmk_live_...).
Add to claude_desktop_config.json:
{
"mcpServers": {
"marketmaster": {
"command": "npx",
"args": ["-y", "@marketmaster/mcp"],
"env": { "MARKETMASTER_API_KEY": "mmk_live_your_key" }
}
}
}
Add to ~/.cursor/mcp.json (same shape as above), then enable it in Settings → MCP.
"Use MarketMaster to find the 5 biggest Kalshi edges right now." "Any cross-platform arbitrage over 3%?" "Show recent whale trades over $25k."
Read-only — never places trades or touches funds. Full API docs: https://marketmaster.live/developers
FAQs
MCP server for the MarketMaster prediction-market data API — use live edges, arbitrage, and whale data inside Claude and Cursor.
The npm package @marketmaster/mcp receives a total of 0 weekly downloads. As such, @marketmaster/mcp popularity was classified as not popular.
We found that @marketmaster/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.