
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@nats-trail/mcp
Advanced tools
Read-only MCP tool contracts and stdio server for [NATS Trail](https://github.com/solsolettidev/nats-trail).
Read-only MCP tool contracts and stdio server for NATS Trail.
claude mcp add nats-trail -- npx -y @nats-trail/mcp
Twenty-five natstrail.* tools with explicit JSON input and output schemas, required result
limits capped at 200, cursors, scan budgets with truncation warnings, per-tool timeouts, and
structured error envelopes.
Start here when the topology is unknown:
discover_subjects — which subjects carry traffic, and the payload shape inferred from real messagesreconstruct_flow — the causal chain behind one request_id, ending at the step that failedget_health_summary — what is broken right now, ranked worst firstenrich_incident — flat incident context for Sentry, Grafana or DatadogThe runtime cannot write. It receives an interface exposing only read functions, so publish, purge and delete are absent rather than disabled.
Set NATS_TRAIL_API to forward tool calls to a running bridge, and NATS_TRAIL_TOKEN when the
bridge has bearer auth enabled.
Apache-2.0
FAQs
Read-only MCP tool contracts and stdio server for [NATS Trail](https://github.com/solsolettidev/nats-trail).
The npm package @nats-trail/mcp receives a total of 58 weekly downloads. As such, @nats-trail/mcp popularity was classified as not popular.
We found that @nats-trail/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.