
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@roxyon/mcp
Advanced tools
Model Context Protocol server for Roxyon — lets any MCP-capable AI assistant build with LumenJS, use the Roxyon BaaS, and deploy to Roxyon infrastructure.
Model Context Protocol server for Roxyon. Gives any MCP-capable AI assistant the ability to build LumenJS apps, use the Roxyon BaaS, and deploy apps and web projects to Roxyon infrastructure.
Runs on stdio. A remote Streamable-HTTP transport with OAuth is planned (needs the M1.5 Personal Access Token work).
npm i -g @roxyon/mcp # or use npx, below
Authenticate once with the CLI (the MCP server reuses its stored login):
npm i -g @roxyon/cli
roxyon login
…or set ROXYON_TOKEN in the server's environment (CI / headless).
Claude Code — .mcp.json in a project, or claude mcp add:
{
"mcpServers": {
"roxyon": { "command": "npx", "args": ["-y", "@roxyon/mcp"] }
}
}
Cursor / Windsurf / Cline — same shape in their MCP settings.
Gemini CLI — ~/.gemini/settings.json → mcpServers → same shape.
Pass through ROXYON_TOKEN (and optionally ROXYON_API_URL,
ROXYON_CONSOLE_URL) via the client's env field when not using a stored login.
Tools — roxyon_whoami, roxyon_list_domains, roxyon_list_apps,
roxyon_init, roxyon_deploy (dry-run unless confirm:true), roxyon_app_status,
roxyon_logs, roxyon_restart, roxyon_env_get, roxyon_env_set,
roxyon_link_github. Every side-effecting tool requires confirm:true.
Resources — roxyon://docs/lumenjs (the full LumenJS V1 reference),
roxyon://docs/baas, roxyon://docs/deploy.
Prompts — scaffold-lumen-app, deploy-to-roxyon.
roxyon://docs/lumenjs + roxyon://docs/baas, writes the
app.roxyon_init { dir } → writes roxyon.json.roxyon_deploy { dir } → dry-run plan.roxyon_deploy { dir, confirm: true } → builds, uploads, waits for it to go
live (app runtimes) and reports the URL or the failure reason.FAQs
Model Context Protocol server for Roxyon — lets any MCP-capable AI assistant build with LumenJS, use the Roxyon BaaS, and deploy to Roxyon infrastructure.
The npm package @roxyon/mcp receives a total of 0 weekly downloads. As such, @roxyon/mcp popularity was classified as not popular.
We found that @roxyon/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.