
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@pymodel/react-frontend-skills-mcp
Advanced tools
Read-only MCP server for 18 production-grade React frontend agent skills.
Read-only Model Context Protocol server for the 18 skills in PyModel/react-frontend-skills.
The npm package is self-contained: every Markdown skill and reference file is copied into the package tarball during npm pack/npm publish. Runtime access does not require a network connection or a repository checkout.
Run directly with npm:
npx -y @pymodel/react-frontend-skills-mcp
For MCP clients that use an mcpServers JSON object:
{
"mcpServers": {
"react-frontend-skills": {
"command": "npx",
"args": ["-y", "@pymodel/react-frontend-skills-mcp"]
}
}
}
The server uses stdio transport. Do not wrap it with a command that writes non-protocol output to stdout.
| Tool | Purpose |
|---|---|
list_skills | List all skills with descriptions, file counts, and resource URIs. |
search_skills | Search documentation with an optional exact skill filter and a bounded result count. |
get_skill | Return the complete SKILL.md for an exact skill name. |
get_reference | Return one Markdown file by skill name and relative path. |
All tools declare read-only, non-destructive, idempotent annotations. Search returns source paths, line numbers, excerpts, scores, and resource URIs. Results are capped at 20 entries per call.
react-skills://catalog — JSON catalog of all skills.react-skills://file/{id} — complete Markdown skill or reference file.resources/list enumerates every available Markdown file, so clients can discover and read source material without guessing paths.
From the repository root:
cd mcp
npm install
npm test
npm run check
npm pack --dry-run
During repository development, the server reads ../skills. Published tarballs read the generated data/skills directory. To test another trusted checkout explicitly:
REACT_FRONTEND_SKILLS_DIR=/absolute/path/to/skills npm start
The configured directory must exist and contain skill folders with SKILL.md files. Tool inputs never become filesystem paths; files are indexed at startup and served from the in-memory catalog.
prepack copies the repository's canonical skills/ tree into data/skills. postpack removes that generated directory so duplicated skill content is not committed. Packaging fails unless the packaged skill directories match the source skills/ tree and each has a SKILL.md.
MIT © 2026 Mohamed Elkholy
FAQs
Read-only MCP server for 18 production-grade React frontend agent skills.
We found that @pymodel/react-frontend-skills-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.