
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@rak-ad/mcp
Advanced tools
RAK OS — media without an owner, for any country. An open MCP content language + free stack; first live node is Poland (articles, wire, per-region feeds, 4,800+ monitored sources) + AI editorial tools (research, writing, media, QA). Fork a node for yours.
RAK OS is an open content language for the agentic web + a free stack: give any country's media back to its people. The
@rak-ad/mcpModel Context Protocol client connects any AI agent to the RAK network. Poland (rak.guru) is the first live node — the proof: 4,800+ monitored local sources, 16 regions, hybrid RAG and a wire feed, 24/7, free for readers. Your country is next — fork a node.🕊️ Manifesto:
MANIFESTO.md(PL) · 👑 The Realm:REALM.md· 🏛️ Governance:GOVERNANCE.md🌍 Site/docs: https://rak.guru/mcp · 📦 npm:
@rak-ad/mcp· 🔌 Remote:https://rak.guru/api/mcp/rak/mcp📜 RAK language spec (v0.2):
SPEC.md— the open standard "write once → own it → cited by every agent".💸 Economics (the moat):
ECONOMICS.md— pay-per-AI-citation. Our own valuation + settlement layer; Stripe Connect is a swappable last-mile plugin.
@rak-ad/mcp connects Claude Desktop, Cursor, Windsurf, ChatGPT and any MCP agent to a RAK node. The reference node today is Poland (rak.guru / Kanał ZERO) — the live test — plus universal editorial tools (research + write). The same rak_<module>_<operation> tools work for any node you run.
RAK OS is how any country gives its local media back to its people: an open format + free tools any AI agent can read, and any community can run. Poland is the first live node — the test. If you build an AI agent and need fresh local information — from a specific region, county or city — the RAK node gives you that in one connection instead of scraping dozens of portals: a hybrid search, per-region feeds, a wire feed, and 4,800+ monitored sources (incl. a curated census of 1,709 local outlets). Reader tools are free and work anonymously (no key). Your country is next — fork a node.
rak_meta_* and rak_content_* anonymously, no key. A free index of the node — Poland today, your country next.mcp.json{
"mcpServers": {
"rak": {
"command": "npx",
"args": ["-y", "@rak-ad/mcp"],
"env": {
"RAK_API_KEY": "rk_...", // omit for anonymous (reader) access
"RAK_BASE_URL": "https://rak.guru"
}
}
}
}
POST https://rak.guru/api/mcp/rak/mcp
Authorization: Bearer <RAK_API_KEY> # omit for the anon tier
Api-Version: 2026-05
npx @modelcontextprotocol/inspector
| Tier | Key | Scope |
|---|---|---|
anon (reader) | no | content_*, rag_*, voice_*, legal_*, meta_* + web research / URL extract (daily caps) |
free | yes | as above + higher limits |
paid (subscriber) | yes | + writing, media, fact-check, deep research (on credits) |
partner | yes | read-only (content + RAG), no research |
internal | yes | full (publishing + crawl + distribution) |
Reading is free, forever, and needs no key. Only making things costs credits.
Free, no key (anon — 16 of the 44 tools):
content_search, content_get_article, content_list_section, content_wire_feed, content_region_feed,
rag_find_related, rag_semantic_search, rag_search_chunks, voice_search, legal_search,
meta_list_sources, meta_list_skills, meta_health, meta_list_agents,
plus research_web (5/day) and research_extract (15/day).
Zero credits. 30 requests/min per tool, per IP. Cache hits never count.
Free but needs a key: owned_publish / owned_list / owned_get / owned_verify (your own content + provenance),
qa_moderate, qa_uniqueness, write_plan, write_export — 0 credits on a paid tier key.
Costs credits (the creative layer, paid key):
| Tool | Credits |
|---|---|
content_create_poll | 0.05 |
research_fact_pack | 0.10 |
qa_fact_check | 0.15 |
research_extract · research_web (subscribers only) | 0.20 · 0.70 |
research_summarize | 0.70 |
research_deep | 1.10 |
write_edit | 0.40 |
write_draft · write_debate · write_document | 0.80 |
write_pipeline (per run) | 1.50 news · 3.00 deep dive |
media_tts | 0.25 |
media_generate_image | 0.55 (after the monthly quota) |
media_storyboard | 1.50 |
media_generate_song | 4.00 |
media_generate_video | 5.50–7.50 (after the monthly quota) |
Internal only (node operators): write_publish, crawl_*, distribution_publish.
Getting a key: self-service after your first credit top-up (max 5 active keys) — rk_ keys are tier paid,
scopes content:read + skills:action. Reader tools never need one.
Honest note on privacy: every tool call is logged for the attribution ledger (this is what makes pay-per-AI-citation possible) and for audit. Nothing about readers of the portal — this is the agent API.
rak_<module>_<op>) — 44 toolsAuthoritative surface: rak_meta_list_skills / schemas/tools.manifest.json.
| Module | Tools | Tier |
|---|---|---|
content | search, get_article, list_section, wire_feed, region_feed · create_poll (paid) | anon (reader) |
rag | find_related, semantic_search, search_chunks | anon (reader) |
voice | search — persona-knowledge RAG (a public figure's own words, source-backed) | anon (reader) |
legal | search — Polish-law corpus (ELI/ISAP), citable statute fragments | anon (reader) |
meta | list_sources, list_skills, health, list_agents | anon / discovery |
research | web, extract, fact_pack, summarize, deep | anon → paid |
write | draft, edit, plan, pipeline, publish, export, debate, document | paid → internal |
media | generate_image, generate_video, generate_song, storyboard, tts | paid |
qa | fact_check, moderate, uniqueness | paid |
owned | publish, list, get, verify | creator (paid+) |
crawl / distribution | crawl_search, crawl_add_source, crawl_subscribe, distribution_publish | internal |
Per-skill details: skills/.
rak_content_region_feed({ region: "mazowieckie", limit: 20 })rak_content_search({ query: "local government budget", section: "politics" })rak_meta_list_sources({ voivodeship: "malopolskie" })rak_content_wire_feed({ minScore: 70, limit: 25 })Is RAK OS free? Yes — reader tools (content, search, wire, region feeds, source census, RAG, persona/law search) are free and anonymous. Only the creative RAK tools for subscribers are paid.
How fresh is the data? The pipeline harvests and processes sources 24/7, in 10–15 minute cycles. The rak://health resource shows freshness and 24h volume.
How many sources? On the first node (Poland): 4,800+ monitored sources live right now — local portals, X accounts, RSS feeds, YouTube channels (live count: rak_meta_health.enabledCrawlSources) — including a curated census of 1,709 local media outlets across 16 regions (regional dailies, county portals, radio, TV, public bulletins) with per-region metadata via rak_meta_list_sources. Every country's node runs its own census.
How is it different from RSS/an API? It's an agent-native interface — ready, described tools with semantics, freshness and citations, working out of the box in any MCP client.
Commercial use? The @rak-ad/mcp client is MIT-licensed; access to content/tools follows the RAK ToS. Dedicated keys for partners/enterprise.
Reader tools need no key. An rk_ key (tier paid/partner/internal) is issued by the RAK team — contact via https://rak.guru. Scopes: content:read, skills:action. Keys are tenant-scoped.
RAK OS is an independent, self-funded project — no venture capital, no private equity, no big-media owner. It exists to keep local media out of the hands that usually capture it: legacy holdings and platform gatekeepers (News Corp, Axel Springer, Meta, TikTok, Google News, Amazon) that decide what most people read. On scanning mandates like Chat Control, the stance is plain: we would leave a market before wiring a scanning backdoor into a reader — see the Manifesto. It is a kingdom, honestly: one maintainer (the Crown, @Hei33enberg) holds the vision and the last word; the community builds and is credited in the open (REALM.md). Why this structure — and how it's kept hard to capture — is in the Manifesto and the Realm's absorption-proofing section.
The OS is MIT — fork your country's RAK, for free, forever.
rak_* directly today — connect over MCP against the SPEC.md, share one base and one citation market. Ship it and it's discoverable via rak_meta_list_agents. A one-command npx create-rak-agent scaffold is on the roadmap.REALM.md, L5). The RAK trademark and origin brand stay with the Crown (TRADEMARK.md); everything else is yours.SPEC.md (the contract) and the skills.RAK runs on Open Mercato — an open, inspectable runtime engine. We didn't reinvent the foundation; durability comes from boring, auditable infrastructure. If you want the same operational certainty under your own node, that's the engine.
CONTRIBUTING.md — humans and AI agents both (AGENTS.md).MIT (client). Access to content/API follows the RAK ToS.
Tags: open content language · media without an owner · local news for AI agents · agentic web · content provenance · pay-per-AI-citation · model context protocol · RAG · fork a node · Poland (first node) · Kanał ZERO · rak.guru · Claude · Cursor · Perplexity
FAQs
RAK OS — media without an owner, for any country. An open MCP content language + free stack; first live node is Poland (articles, wire, per-region feeds, 4,800+ monitored sources) + AI editorial tools (research, writing, media, QA). Fork a node for yours.
The npm package @rak-ad/mcp receives a total of 17 weekly downloads. As such, @rak-ad/mcp popularity was classified as not popular.
We found that @rak-ad/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.