
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@pulse-circle/mcp
Advanced tools
MCP server for Pulse growth analytics: install the SDK and connect RevenueCat, App Store and Google Play from an AI coding agent. Runs offline over stdio.
Local (stdio) MCP server for Pulse: gives AI coding agents the Pulse SDK setup and store-connection guides — fully offline. Everything it serves is baked in at build time, so it works in hardened sandboxes where Pulse domains are blocked but npm is allowed.
claude mcp add pulse -- npx -y @pulse-circle/mcp
Or in any MCP client config:
{
"mcpServers": {
"pulse": { "command": "npx", "args": ["-y", "@pulse-circle/mcp"] }
}
}
| Tool | Input | Returns |
|---|---|---|
pulse_setup_guide | platform: web | react-native | swift | kotlin | Step-by-step SDK install for that platform |
pulse_connect | source: revenuecat | app_store | google_play | How to connect the revenue source for MRR / LTV / revenue |
Things the guides insist on:
track(). Purchase
events never become revenue — connect the store/billing source instead.{ signedPayload } body to the Pulse hook instead of replacing
your URL. Pulse re-verifies Apple's signature itself.pulse_verify and pulse_ask need access to the Pulse API and database, so
they stay on the remote MCP server and in the web dashboard. The value of this
package is offline delivery of the install/connect guides.
npm run build -w @pulse-circle/mcp # tsup → dist/index.js (the pulse-mcp bin)
npm test # includes the stdio smoke test
Release: tag mcp-v<version> — see RELEASING.md.
FAQs
MCP server for Pulse growth analytics: install the SDK and connect RevenueCat, App Store and Google Play from an AI coding agent. Runs offline over stdio.
The npm package @pulse-circle/mcp receives a total of 39 weekly downloads. As such, @pulse-circle/mcp popularity was classified as not popular.
We found that @pulse-circle/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.