
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@replen/mcp
Advanced tools
Replen MCP server: a local intelligence layer for AI coding agents. Surfaces libraries, algorithms and techniques matched to your repos, as tools your AI host (Claude Code, Codex, Cursor) can call. Pairs with the /replen skill.
Smarter AI Development workflows. MCP server that brings replen - the AI that asks "can we do this better?" on your codebase - inside Claude Code / Codex / any MCP host.
While your AI coding tool waits for prompts, replen reads your code against the ecosystem every morning. This MCP lets the agent act on the results without leaving chat:
replen ships 15 tools. Three moving parts sit behind them: Brainstem matches, Watchtower watches, Atlas remembers. The tools group under Brainstem, Atlas, and onboarding.
| Tool | Returns |
|---|---|
replen_match | The cwd repo's candidate inventory: repo metadata + cosine scores + whyShortlisted lines, everything Watchtower surfaced and Brainstem scored against this codebase's capabilities |
replen_record_triage | Records the agent's per-candidate verdict (adopt / port / cherry-pick / clean-room / upgrade / skip / defer) with score, effort, and reasoning |
replen_state | Records the user's action on a candidate: star / hide / handoff / surfaced |
replen_capture_insight | Stores a portfolio insight from triage: a transferable lesson or a sharpened boundary |
| Tool | Returns |
|---|---|
replen_leaps | Non-obvious cross-project / adjacency / cross-user connections from Atlas, each with a via path |
replen_recall | Memory across your whole portfolio: past verdicts, grounded reports, capabilities, and notes for a query |
replen_cart | Pulls a saved or built-in Atlas Cart's rows in-session (Blind spots, Triage board, Keystones, Brought in, Stale deferrals, By domain, or your saved carts) |
replen_queue | The awareness-to-action queue: list / add / done / dismiss items carried over from the Brief |
replen_handoff | Opens a handoff PR in the matched project's repo |
| Tool | Returns |
|---|---|
replen_onboard_state | Per-repo grounding state across the portfolio, the cheap pre-flight for /replen-onboard |
replen_set_capabilities | Writes a project's grounded capabilities + report (read locally by the agent, never uploaded as raw files) |
replen_set_tags | Writes a project's ranked domain tag cloud |
replen_set_versions | Writes a project's pinned direct-dependency + runtime versions |
replen_set_product | Groups sibling repos under one product |
Plus replen_help, the tool index.
The core tool is replen_match: it returns the cwd repo's candidate inventory (metadata + cosine + whyShortlisted) with no LLM call on our side, so the host agent reasons about fit against your actual open codebase in context, then records each call via replen_record_triage. Atlas now has two halves: the graph/explore view and Carts, browsable filterable views over your decision graph that replen_cart reads in-session.
Get your token from your replen /settings page → "Connect Claude Code", then run:
npx -y @replen/mcp setup --token=ing_xxxxxxxx --base=https://app.replen.dev
That writes the MCP entry into ~/.claude.json (with a backup of the original) and is fully idempotent - re-run it any time you rotate the token.
Restart Claude Code to pick up the new server.
mcpServers.replen to your Claude Code configcommand: "replen-mcp" - resolved via npx on each host launch, or npm i -g @replen/mcp for a slightly faster startupenv: DIGEST_BASE_URL + DIGEST_TOKEN.bak of your config is saved next to it for one-step recoveryIf you'd rather hand-edit your config, the block to add is:
{
"mcpServers": {
"replen": {
"command": "replen-mcp",
"env": {
"DIGEST_BASE_URL": "https://app.replen.dev",
"DIGEST_TOKEN": "ing_xxxxxxxx"
}
}
}
}
replen-mcp --version # print version
replen-mcp --help # show available subcommands
replen-mcp # run as stdio MCP server (your host spawns this; you usually don't run it directly)
You: anything new today for my project X?
Agent: [calls replen_match({repo: "you/my-project-x"})]
2 candidates for this repo, top one is roboflow/supervision - 38k★ - MIT -
cosine 0.71 · whyShortlisted: fills your "object tracking" capability.
Want me to triage them against your current codebase?
You: yes
Agent: [reads the candidate README + greps your src/ for related code]
supervision drops in for your hand-rolled annotation utilities and
deletes your ByteTrack reimplementation. Strong fit.
[calls replen_record_triage({repo: "roboflow/supervision", verdict: "adopt", ...})]
Recorded. Want a handoff PR?
You: yes
Agent: [calls replen_state({repo: "roboflow/supervision", status: "handed_off", ...})]
[calls replen_handoff({matchId: 96})]
PR opened: github.com/you/my-project-x/pull/142
replen_match / replen_cart / replen_recall / replen_leaps) cost nothing - pure JSON shuttle.replen_handoff is one GitHub write call. No LLM on our side.No additional replen-side cost vs the web dashboard - the MCP server queries the same API as app.replen.dev.
Apache-2.0 - see LICENSE. Permissive open source: free to use, modify, and redistribute for any purpose, with an explicit patent grant. "Replen" and the other named surfaces remain trademarks (Apache §6).
FAQs
Replen MCP server: a local intelligence layer for AI coding agents. Surfaces libraries, algorithms and techniques matched to your repos, as tools your AI host (Claude Code, Codex, Cursor) can call. Pairs with the /replen skill.
The npm package @replen/mcp receives a total of 20 weekly downloads. As such, @replen/mcp popularity was classified as not popular.
We found that @replen/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.