
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@railhook/mcp
Advanced tools
Railhook's MCP server for stdio clients — a bridge to the remote server at /mcp
A stdio bridge to Railhook's MCP server, for clients that only start local processes, such as Claude Desktop.
Clients that support remote servers (Claude Code, Cursor) should connect to
https://railhook.io/mcp, or <your origin>/mcp when self-hosted, and skip this package. The
bridge passes tools/list and tools/call through and has no tools of its own.
Requires Node.js 18 or later.
{
"mcpServers": {
"railhook": {
"command": "npx",
"args": ["-y", "@railhook/mcp"],
"env": {
"RAILHOOK_API_KEY": "your-project-api-key"
}
}
}
}
| Variable | Required | Meaning |
|---|---|---|
RAILHOOK_API_KEY | yes | A project API key. A READ_ONLY key allows the read tools and refuses every write. |
RAILHOOK_BASE_URL | no | Default https://railhook.io. Set it to your origin when self-hosted. |
The key is sent as Authorization: Bearer <key> and is never logged.
Tools: send_event, list_endpoints, create_endpoint, list_subscriptions,
create_subscription, list_deliveries, get_delivery, replay_delivery. Each acts on the
project the key belongs to.
Full guide: https://railhook.io/docs/tools/mcp/
npm ci
npm test
npm run build
MIT
FAQs
Railhook's MCP server for stdio clients — a bridge to the remote server at /mcp
The npm package @railhook/mcp receives a total of 293 weekly downloads. As such, @railhook/mcp popularity was classified as not popular.
We found that @railhook/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.