
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@merchinary/docs-mcp
Advanced tools
MCP server exposing Merchinary's product knowledge (Bulk Product Editor + Image Editor for Shopify) — search docs, read how-to guides, and discover capabilities.
An MCP server that exposes Merchinary's product knowledge — what the Shopify apps Bulk Product Editor and Image Editor can do, and how to do it. Point any MCP-capable AI client at it to answer "how do I…" and feature-discovery questions, grounded in the public docs at https://docs.merchinary.com.
The knowledge is the curated documentation itself (54 pages), baked into a static index at build time — no database, no auth (the docs are public).
| Tool | Purpose |
|---|---|
search_docs | Fuzzy/keyword search across the docs. { query, product?, limit? } → ranked pages with snippet + URL. |
read_doc | Full plain-text of one page. { id } (from a search hit) or { url }. |
list_capabilities | Structured map of products → categories → pages. { product? }. Use for feature discovery. |
Products: bulk-product-editor, image-editor.
Connect your client to the hosted Streamable HTTP endpoint:
https://mcp.merchinary.com/mcp
Claude Desktop / clients that support remote MCP servers:
{
"mcpServers": {
"merchinary-docs": {
"type": "streamable-http",
"url": "https://mcp.merchinary.com/mcp"
}
}
}
{
"mcpServers": {
"merchinary-docs": {
"command": "npx",
"args": ["-y", "@merchinary/docs-mcp"]
}
}
}
npm install
npm run build:knowledge # generate data/knowledge.json from ../web-docs docs
npm run build # build:knowledge + tsc -> dist/
npm test # vitest unit tests over the knowledge layer
# Run locally
npm run dev:stdio # stdio transport (tsx)
npm run dev:http # Streamable HTTP on :8080 (POST /mcp, GET /healthz)
# Inspect interactively
npm run inspector # MCP Inspector against the stdio server
The index is generated from the curated docs in
web-docs/sites/docs-site/docs/ (single source, shared with the in-app Help search). Rebuild
(npm run build:knowledge) and redeploy whenever the docs change.
Dockerfile builds a stateless image with the index baked in — suitable for Cloud Run, Firebase,
or any container host. Listens on $PORT (default 8080), serving POST /mcp and GET /healthz.
server.json is the MCP registry manifest,
listing both the npm (stdio) package and the remote (streamable-http) endpoint.
FAQs
MCP server exposing Merchinary's product knowledge (Bulk Product Editor + Image Editor for Shopify) — search docs, read how-to guides, and discover capabilities.
The npm package @merchinary/docs-mcp receives a total of 28 weekly downloads. As such, @merchinary/docs-mcp popularity was classified as not popular.
We found that @merchinary/docs-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.