
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@openplan/mcp
Advanced tools
Waze for AI agents — plan, track, and learn from software projects.
An MCP server that helps AI agents decompose goals into costed execution plans, checkpoint progress with deviation tracking, and learn from past project data.
npx @openplan/mcp
The server auto-creates its config and SQLite database on first run — no setup needed.
Add it to your MCP client:
opencode.json:
{
"mcp": {
"openplan": {
"type": "local",
"command": ["npx", "-y", "@openplan/mcp"]
}
}
}
claude_desktop_config.json:
{
"mcpServers": {
"openplan": {
"command": "npx",
"args": ["-y", "@openplan/mcp"]
}
}
}
Or run openplan install to auto-detect and configure both.
| Tool | Description |
|---|---|
plan(goal, context?, replan?, project?) | Decompose a goal into costed phases with estimates |
checkpoint(phase?, actual_cost?, correct?, route_id?, project?) | Record phase cost, correct data, or check status |
review(route_id?, project?) | Session retrospective with deviations, accuracy, learning |
| URI | Description |
|---|---|
openplan://{project}/route | Current route state and phase progress |
openplan://profiles | Personal bias and accuracy by action |
openplan://sync-status | Mesh sync health and pending checkpoints |
openplan # Start MCP server (stdio mode)
openplan install # Auto-detect and install in MCP clients
openplan auth # Authenticate with Mesh via GitHub OAuth
openplan subscribe # Subscribe to Pro (Stripe Checkout)
openplan portal # Manage subscription (Stripe Customer Portal)
openplan account # Show identity, API key, subscription
openplan config # View current configuration
openplan mesh [on|off] # Show or toggle Mesh sync
openplan status # List routes for a project
openplan log # Show checkpoint trail
openplan export # Export calibration data (Pro)
openplan completion # Generate shell completion script
openplan doctor # Check system health and diagnose issues
Use --json on account, config, status, log, mesh for structured output. Auth supports --no-browser, --clipboard, --with-token <key>, and --debug.
core/ Domain types, pure logic, typed ports
handlers/ MCP tool handlers — validation, wiring
adapters/ Mesh sync, cost probes, config loaders
db/ Drizzle schema, SQLite, DataStore implementation
One rule: Core never imports adapters or handlers. The DataStore port insulates core from Drizzle.
npm install
npm run dev # tsx watch
npm test # vitest (config at vitest.config.ts)
npm run test:e2e # end-to-end against compiled dist/
npm run build # tsc
npm run lint # biome check
GitHub Actions runs lint, test, build on every push/PR. Publish to npm happens automatically on version tags (v*).
better-sqlite3 / Drizzle ORM — 7 tables, local-firstgithub.com/vncsleal/openplan-api) — cross-session cost learningcreateLogger(module) with [openplan:module] prefixLicense: MIT
FAQs
Waze for AI agents — plan, track, and learn from software projects.
The npm package @openplan/mcp receives a total of 60 weekly downloads. As such, @openplan/mcp popularity was classified as not popular.
We found that @openplan/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.