
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
@page2ai/mcp
Advanced tools
MCP server that converts any web page URL to clean Markdown for LLM context. Zero external API calls, SSRF-guarded, 100% local.
Turn any web page into clean Markdown for Claude, ChatGPT, or your own LLM.
Companion to the Page2AI Chrome extension. Shares the same @page2ai/core extraction library. Zero external API calls — runs entirely on your machine using linkedom.
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%/Claude/claude_desktop_config.json (Windows):
{
"mcpServers": {
"page2ai": {
"command": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
Restart Claude Desktop.
Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project):
{
"mcpServers": {
"page2ai": {
"command": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
Add to ~/.windsurf/mcp.json:
{
"mcpServers": {
"page2ai": {
"command": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
Add to settings.json:
{
"context_servers": {
"page2ai": {
"command": {
"path": "npx",
"args": ["-y", "@page2ai/mcp"]
}
}
}
}
Refer to your MCP-compatible extension's documentation. The command is npx -y @page2ai/mcp.
| Tool | Description | Read-only | Example |
|---|---|---|---|
page_to_markdown | Fetch a web page URL and convert to clean Markdown | ✅ | page_to_markdown(url="https://docs.anthropic.com/en/api/messages") |
1. Fetch documentation and answer questions:
"Use page_to_markdown to fetch https://docs.anthropic.com/en/docs/build-with-claude/extended-thinking and summarize the three main use cases for extended thinking."
2. Extract API reference into a code snippet:
"Fetch https://ai.google.dev/gemini-api/docs/thinking with page_to_markdown, then generate a Python code sample using the thinking budget parameter."
3. Compare two documentation pages:
"Fetch both https://docs.anthropic.com/en/docs/prompt-engineering and https://platform.openai.com/docs/guides/prompt-engineering with page_to_markdown, then summarize the differences in approach."
None required in v0.1. All extraction options use sensible defaults.
Future versions will support options via tool arguments:
include_images (boolean, default false)include_frontmatter (boolean, default true)profile (string, one of auto | docs | marketing | research | dashboard | wordpress-marketing, default auto)@page2ai/mcp collects no data, sends no telemetry, and makes no external network calls beyond the URLs you explicitly provide. See PRIVACY.md for details.
npm audit will surface a moderate finding in @hono/node-server (a transitive dependency of @modelcontextprotocol/sdk). That vulnerability lives in the SDK's HTTP/OAuth server path; @page2ai/mcp uses only the stdio transport and never loads that code path, so it is not exploitable through this package. The audit line will clear once the SDK bumps its Hono constraint to >=2.0.5.
git clone https://github.com/igorsaevets/page2ai-mcp
cd page2ai-mcp
npm install
npm run build
node dist/index.js # runs stdio MCP server
Test with MCP Inspector:
npx @modelcontextprotocol/inspector node dist/index.js
Written and maintained by Igor Saevets — AI expert and founder of Page2AI. Full bio and social links: igorsaevets.github.io/page2ai-docs/about/.
An MCP server runs with the privileges of whatever launched it, so where the tarball came from is a security question, not a formality. Releases from v0.1.2 onward are published from GitHub Actions with npm provenance: each version carries a Sigstore attestation naming the commit and workflow run that produced it, recorded in the public Rekor transparency ledger and shown as a badge on npmjs.com.
Check it before you trust it:
npm audit signatures
npm view @page2ai/mcp --json | jq '.dist.attestations'
MIT — see LICENSE. Copyright © 2026 Igor Saevets.
npx -y page2ai-mcp works without a scope prefix)swh:1:snp:05123c51ef9e7c0aeb06f42b1263c07a8d26999aFAQs
MCP server that converts any web page URL to clean Markdown for LLM context. Processing is local and SSRF-guarded; no external APIs, no telemetry.
The npm package @page2ai/mcp receives a total of 38 weekly downloads. As such, @page2ai/mcp popularity was classified as not popular.
We found that @page2ai/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.