
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@page2ai/mcp
Advanced tools
MCP server that converts any web page URL to clean Markdown for LLM context. Zero external API calls, SSRF-guarded, 100% local.
Turn any web page into clean Markdown for Claude, ChatGPT, or your own LLM.
Companion to the Page2AI Chrome extension. Shares the same @page2ai/core extraction library. Zero external API calls — runs entirely on your machine using linkedom.
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%/Claude/claude_desktop_config.json (Windows):
{
"mcpServers": {
"page2ai": {
"command": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
Restart Claude Desktop.
Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project):
{
"mcpServers": {
"page2ai": {
"command": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
Add to ~/.windsurf/mcp.json:
{
"mcpServers": {
"page2ai": {
"command": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
Add to settings.json:
{
"context_servers": {
"page2ai": {
"command": {
"path": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
}
Refer to your MCP-compatible extension's documentation. The command is npx -y @page2ai/mcp.
| Tool | Description | Read-only | Example |
|---|---|---|---|
page_to_markdown | Fetch a web page URL and convert to clean Markdown | ✅ | page_to_markdown(url="https://docs.anthropic.com/en/api/messages") |
1. Fetch documentation and answer questions:
"Use page_to_markdown to fetch https://docs.anthropic.com/en/docs/build-with-claude/extended-thinking and summarize the three main use cases for extended thinking."
2. Extract API reference into a code snippet:
"Fetch https://ai.google.dev/gemini-api/docs/thinking with page_to_markdown, then generate a Python code sample using the thinking budget parameter."
3. Compare two documentation pages:
"Fetch both https://docs.anthropic.com/en/docs/prompt-engineering and https://platform.openai.com/docs/guides/prompt-engineering with page_to_markdown, then summarize the differences in approach."
None required in v0.1. All extraction options use sensible defaults.
Future versions will support options via tool arguments:
include_images (boolean, default false)include_frontmatter (boolean, default true)profile (string, one of auto | docs | marketing | research | dashboard | wordpress-marketing, default auto)@page2ai/mcp collects no data, sends no telemetry, and makes no external network calls beyond the URLs you explicitly provide. See PRIVACY.md for details.
Since 0.2.0 this server answers both MCP protocol revisions on the same stdio connection:
| Revision | How a client opens the connection | Served |
|---|---|---|
2026-07-28 | server/discover, carrying io.modelcontextprotocol/protocolVersion in _meta | yes |
2025-11-25 and earlier | the initialize handshake | yes |
serveStdio picks the era from the opening message and pins one server instance for
the life of the connection, so clients on older SDKs are unaffected. Note that a
message carrying no version claim is treated by the specification as a 2025-era
opening; server/discover without that _meta field is therefore answered with
-32601 rather than being upgraded.
Verify against a build with the raw JSON-RPC frames, without a client library:
printf '%s\n' '{"jsonrpc":"2.0","id":1,"method":"server/discover","params":{"_meta":{"io.modelcontextprotocol/protocolVersion":"2026-07-28"}}}' | node dist/index.js
None. Moving to the v2 SDK removed 90 transitive packages (117 production
dependencies down to 26) and with them the @hono/node-server advisory that
0.1.x carried through the monolithic @modelcontextprotocol/sdk; that package
pulled the HTTP and OAuth server stack even for a stdio-only server. npm audit
is clean as of 0.2.0.
git clone https://github.com/igorsaevets/page2ai-mcp
cd page2ai-mcp
npm install
npm run build
node dist/index.js # runs stdio MCP server
Test with MCP Inspector:
npx @modelcontextprotocol/inspector node dist/index.js
Pick the channel by what you have, not by what is quickest to type:
| You have | Use |
|---|---|
| A bug, a page that extracts badly, a feature idea | GitHub issues — public and searchable, so the fix helps the next person too |
| A security vulnerability | Private vulnerability reporting, see SECURITY.md. Do not open a public issue |
| A usage question | Docs first, then an issue |
Written and maintained by Igor Saevets — AI expert and founder of Page2AI. Full bio: igorsaevets.github.io/page2ai-docs/about/.
These are identity and collaboration links, not the support queue. A bug reported in a DM is a bug nobody else can find later, so anything you want fixed belongs in the table above.
An MCP server runs with the privileges of whatever launched it, so where the tarball came from is a security question, not a formality. Releases from v0.1.2 onward are published from GitHub Actions with npm provenance: each version carries a Sigstore attestation naming the commit and workflow run that produced it, recorded in the public Rekor transparency ledger and shown as a badge on npmjs.com.
Check it before you trust it:
npm audit signatures
npm view @page2ai/mcp --json | jq '.dist.attestations'
MIT — see LICENSE. Copyright © 2026 Igor Saevets.
npx -y page2ai-mcp works without a scope prefix)swh:1:snp:05123c51ef9e7c0aeb06f42b1263c07a8d26999aFAQs
MCP server that converts any web page URL to clean Markdown for LLM context. Zero external API calls, SSRF-guarded, 100% local.
The npm package @page2ai/mcp receives a total of 333 weekly downloads. As such, @page2ai/mcp popularity was classified as not popular.
We found that @page2ai/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.