
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@patentprecheck/mcp
Advanced tools
Patent PreCheck CLI + MCP server — run a patentability pre-check on your code from inside Cursor, Claude Code, Codex, and other AI coding agents.
Run a patentability pre-check on your code from inside your terminal or your AI coding agent (Cursor, Claude Code, Codex, Antigravity). It wraps the hosted Patent PreCheck engine, so no API keys are required — the scoring engine and prior-art corpus stay server-side.
Informational only — not legal advice and not a substitute for a licensed patent attorney.
# Run directly (no install)
npx -y @patentprecheck/mcp score ./src/widget.ts
# Or install globally
npm i -g @patentprecheck/mcp
precheck score ./src/widget.ts
precheck score ./path/to/file.ts # human-readable report
precheck score ./file.ts --format json # raw JSON
cat invention.md | precheck score - # read from stdin
precheck score ./file.ts --min-score 60 # exit 4 if below threshold (CI gate)
precheck pillars # scoring reference (no network)
precheck review # Interactive Code Review signup URL
precheck mcp # run as an MCP server over stdio
Exit codes: 0 ok · 1 usage · 2 request error · 3 §101 gate not passed ·
4 below --min-score. stdout is clean data; progress/errors go to stderr.
See config-examples/. Quickest paths:
# Claude Code
claude mcp add patent-precheck -- npx -y @patentprecheck/mcp mcp
// Cursor — .cursor/mcp.json
{ "mcpServers": { "patent-precheck": { "command": "npx", "args": ["-y", "@patentprecheck/mcp", "mcp"] } } }
MCP tools: precheck_score, precheck_prior_art, precheck_rejection_patterns, precheck_legal_context, precheck_pillars, precheck_start_review, precheck_search_corpus, precheck_cpc_suggest, precheck_session_status, precheck_deliverables.
Cursor users can skip the JSON and use the Add to Cursor button at the top.
The server is published to the official MCP Registry
(io.github.Patent-PreCheck/patent-precheck), so MCP-aware clients can discover it directly.
There's also a hosted, keyless Streamable HTTP MCP server, so remote-capable
clients can connect without npx or a local Node install:
https://patentprecheck.com/mcp
// Cursor — remote server, no command needed
{ "mcpServers": { "patent-precheck": { "url": "https://patentprecheck.com/mcp" } } }
Same three tools and the same scoring engine. The hosted variant takes invention
text inline via code (it never reads files from your machine — use the local
npx server above if you want the path argument).
cd tools/precheck-mcp
npm install
node bin/precheck.js pillars
echo "a novel rate limiter that ..." | node bin/precheck.js score - --format text
node bin/precheck.js mcp # stdio server; blocks waiting for an MCP client
FAQs
Score code for patentability inside Cursor, Claude, and Codex — keyless MCP with prior-art search, USPTO pillar scores, and patent lookup. Hosted at patentprecheck.com/mcp.
The npm package @patentprecheck/mcp receives a total of 96 weekly downloads. As such, @patentprecheck/mcp popularity was classified as not popular.
We found that @patentprecheck/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.