
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@opsmaxx/mcp
Advanced tools
Connect any stdio MCP client to a running OpsMaxx desktop app.
npx -y @opsmaxx/mcp
OpsMaxx already exposes an MCP server over Streamable HTTP on 127.0.0.1, and
clients that can express an HTTP server with an Authorization header — Claude
Code, Codex — should use that directly. It is one command:
opsmaxx claude
Some clients cannot. Claude Desktop, notably, does not read url or headers
from claude_desktop_config.json at all, so an HTTP MCP server is simply not
expressible there. This package is the adapter for those: stdio in, authenticated
HTTP out.
It is a protocol relay. Every message is forwarded unmodified in both directions. No tool, session or policy logic lives here — access groups, approvals, secret redaction and the audit log all stay in the app, so a stdio client gets exactly the same treatment an HTTP client would.
It talks only to 127.0.0.1. It is not a server, it holds no state, and it
cannot reach anything OpsMaxx would not already allow.
OpsMaxx must be running, with the bridge enabled under AI & MCP.
Environment first, then the session the opsmaxx CLI has already cached:
| Variable | Meaning |
|---|---|
OPSMAXX_MCP_TOKEN | Session token from AI & MCP → AI Agents → New AI agent session |
OPSMAXX_MCP_PORT | Bridge port, shown under AI & MCP → Security |
OPSMAXX_MCP_URL | Full endpoint instead of the port, e.g. http://127.0.0.1:5177/mcp |
If none are set it reads the session cached by the CLI, so running
opsmaxx claude once is enough and there is no token to paste.
{
"mcpServers": {
"opsmaxx": {
"command": "npx",
"args": ["-y", "@opsmaxx/mcp"],
"env": {
"OPSMAXX_MCP_TOKEN": "your-session-token",
"OPSMAXX_MCP_PORT": "5177"
}
}
}
}
Restart Claude Desktop afterwards.
The token is scoped to one workspace and one access group, and it is the same secret you would otherwise paste into a client's config by hand. It is not an SSH key and it is not a vault password: an agent holding it still never receives an SSH password, a private key, a database credential, a hostname or an interactive root shell. See the threat model.
MIT. Source: https://github.com/OpsMaxx/OpsMaxx
FAQs
Connect any stdio MCP client to a running OpsMaxx desktop app.
The npm package @opsmaxx/mcp receives a total of 82 weekly downloads. As such, @opsmaxx/mcp popularity was classified as not popular.
We found that @opsmaxx/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.