
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@shaftware/componecat-mcp
Advanced tools
Stdio bridge for the Componecat MCP server — connect stdio-only MCP clients to your organization's software component catalog at app.componecat.ai.
Componecat is a software component catalog: a hierarchical, richly-typed registry of every system, service, and library your organization operates — with structured metadata, Git integration, hosted documentation, endpoint definitions, dependency relationships, and team ownership. Its MCP server gives AI agents the organizational context they're usually missing, so they can answer with your architecture instead of guessing.
This repository is the public home of the server's MCP registry metadata (server.json) and the @shaftware/componecat-mcp stdio bridge. The server itself is part of the hosted Componecat app:
https://app.componecat.ai/api/mcp
Registry name: com.shaftware/componecat · Transport: Streamable HTTP · Website: componecat.ai · Docs: docs.componecat.ai
Catalogs are private and organization-scoped, so the endpoint requires authentication (see Authorization). You'll need a Componecat account — sign up at app.componecat.ai.
Click an install badge above, or add to your mcp.json:
{
"servers": {
"componecat": {
"type": "http",
"url": "https://app.componecat.ai/api/mcp"
}
}
}
claude mcp add --transport http componecat https://app.componecat.ai/api/mcp
Add a custom connector: Settings → Connectors → Add custom connector, with URL https://app.componecat.ai/api/mcp.
Add to Cursor, or add to ~/.cursor/mcp.json:
{
"mcpServers": {
"componecat": {
"url": "https://app.componecat.ai/api/mcp"
}
}
}
Add a connector in Settings → Connectors (developer mode) with the server URL https://app.componecat.ai/api/mcp.
For clients that only speak stdio, the bridge in this repo proxies to the remote endpoint via mcp-remote (OAuth completes in your browser):
{
"mcpServers": {
"componecat": {
"command": "npx",
"args": ["-y", "@shaftware/componecat-mcp"]
}
}
}
Self-hosted Componecat instance? Point the bridge at it with COMPONECAT_MCP_URL=https://your-instance.example.com/api/mcp.
Componecat implements the standard MCP authorization flow with OAuth 2.1:
Access is scoped: you grant an agent read or write access per resource category (catalog entities, teams, schema), and can scope a token down to specific entities. A read-only grant is enough for an agent that only needs context.
60 tools, each annotated with read-only / destructive / idempotent hints so clients can gate confirmation appropriately.
Search & browse
global_search · search_catalog (full-text with typo tolerance, or a structured query language — field:value, AND/OR/NOT, comparisons, ranges) · list_catalog_entities · get_catalog_entity · list_by_owner · list_entity_kind_definitions · get_current_organization
Relationships & impact analysis
get_relationships · get_relationship_kinds · add_relationship · remove_relationship · get_impact_analysis (transitive downstream impact of a change)
Interfaces & endpoints
get_interfaces · create_interface · update_interface · delete_interface · import_interface_spec (import OpenAPI/AsyncAPI specs)
Documentation
get_documentation · create_documentation_section · update_documentation_section · delete_documentation_section · list_documentation_links · create_documentation_link · update_documentation_link · delete_documentation_link
Git-sourced documentation (sections synced from Markdown in your repos)
configure_git_sourced_documentation · list_git_sourced_documentation · update_git_sourced_documentation · remove_git_sourced_documentation · sync_git_sourced_documentation
Activity log
list_activity_log_entries · add_activity_log_entry · delete_activity_log_entry
Catalog maintenance
create_catalog_entity · update_catalog_entity · delete_catalog_entity · update_entity_field_values
Schema definitions (entity kinds, custom fields, relationship kinds)
create_entity_kind_definition · update_entity_kind_definition · delete_entity_kind_definition · list_entity_field_definitions · create_entity_field_definition · update_entity_field_definition · delete_entity_field_definition · add_kind_field_assignment · update_kind_field_assignment · remove_kind_field_assignment · list_relationship_kind_definitions · create_relationship_kind_definition · update_relationship_kind_definition · delete_relationship_kind_definition
Teams & ownership
list_teams · get_team · create_team · update_team · delete_team · add_team_members · remove_team_member
Product documentation
list_componecat_documentation · read_componecat_documentation — Componecat's own docs, so an agent can walk you through setup instead of guessing.
The server also exposes the catalog as MCP resources: every entity is readable as its componecat.yaml descriptor, and a kind's entities can be listed without knowing the taxonomy in advance.
depends-on edges, reads the target's interface spec, and writes a correct client.The contents of this repository (registry metadata and the stdio bridge) are MIT licensed. The Componecat application itself is a hosted product and is not open source.
FAQs
Stdio bridge for the Componecat MCP server — connect stdio-only MCP clients to your organization's software component catalog at app.componecat.ai.
The npm package @shaftware/componecat-mcp receives a total of 77 weekly downloads. As such, @shaftware/componecat-mcp popularity was classified as not popular.
We found that @shaftware/componecat-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.