
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@matrajs/mcp
Advanced tools
The Matra documentation as a Model Context Protocol server, so any AI tool can read it. Zero dependencies.
The Matra documentation as a Model Context Protocol server, so any AI tool can read it. Zero dependencies, like every other Matra package.
npx -y @matrajs/mcp # stdio · what a desktop client spawns
npx -y @matrajs/mcp --http # http://localhost:3333/mcp
Claude Code
claude mcp add matra -- npx -y @matrajs/mcp
Claude Desktop — in claude_desktop_config.json:
{
"mcpServers": {
"matra": { "command": "npx", "args": ["-y", "@matrajs/mcp"] }
}
}
Cursor — in .cursor/mcp.json, the same object under "mcpServers".
Codex — in ~/.codex/config.toml:
[mcp_servers.matra]
command = "npx"
args = ["-y", "@matrajs/mcp"]
Anything that speaks HTTP — run npx -y @matrajs/mcp --http 3333 and
point the client at http://localhost:3333/mcp.
Then ask the tool something about Matra. It will call search_docs, read
the page it needs, and answer from the documentation rather than from
memory.
| Tool | Does |
|---|---|
list_docs | Every page, with its slug and a one-line description. |
read_doc { slug } | One page, as Markdown. |
search_docs { query, limit? } | Ranked pages with a snippet each. |
Every page is also a resource at matra://docs/<slug>.
The pages are the repository's Markdown — README, the engine notes, benchmarks, security, the changelog — and every page of matrajs.com/docs, converted to Markdown at build time and shipped inside the package. Nothing is fetched at runtime.
import { createServer } from '@matrajs/mcp'
const server = createServer(docs)
server.handle({ jsonrpc: '2.0', id: 1, method: 'tools/list' })
createServer is the protocol without a transport: one message in, one
reply out. Put it behind whatever transport you already have.
FAQs
The Matra documentation as a Model Context Protocol server, so any AI tool can read it. Zero dependencies.
The npm package @matrajs/mcp receives a total of 59 weekly downloads. As such, @matrajs/mcp popularity was classified as not popular.
We found that @matrajs/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.