
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@skillforge/agent
Advanced tools
SkillForge agent sidecar — a tiny localhost HTTP proxy that lets any AI agent activate and run professional skills (content writing, brand design, GEO optimization) in the current conversation. No MCP restart needed.
Tiny localhost sidecar that lets any AI agent activate and use Clawminer in the current conversation, without restarting its MCP runtime.
The MCP spec has a hole: most MCP clients (Claude Code, Claude Desktop, Cursor, Cherry Studio) read their server list once at startup and freeze it. Adding a new MCP server means restarting the runtime and starting a fresh conversation — a dealbreaker for IM-hosted agents (OpenClaw on DingTalk/WeChat) where there is only one persistent chat window.
This package sidesteps the problem: instead of asking the agent to install a new MCP server, it spawns a minimal HTTP server on 127.0.0.1 and writes ~/.clawminer/local.json so the agent can discover it. The agent uses its existing fetch / bash / HTTP capability — no MCP machinery, no restart, no new session.
npx -y @clawminer/local@latest start
Output is a single line of JSON the agent can parse:
{"ok":true,"url":"http://127.0.0.1:19821","pid":12345,"settings_file":"/Users/you/.clawminer/local.json","activated":false,"hint_for_agent":"clawminer-local is running at http://127.0.0.1:19821. Not yet activated — POST http://127.0.0.1:19821/activate/request {\"email\":\"<user email>\"} to start the flow."}
The sidecar binds to loopback only. Kill it with clawminer-local stop or by sending SIGTERM to the pid.
Agents discover the sidecar by reading ~/.clawminer/local.json:
{
"version": 1,
"url": "http://127.0.0.1:19821",
"pid": 12345,
"started_at": "2026-04-15T10:30:00.000Z",
"api_base_url": "https://api.clawminer.network/api/v1",
"package": "@clawminer/local",
"package_version": "0.1.0"
}
A stale pid (process gone) is cleaned up automatically on the next start.
All endpoints return JSON and include a hint_for_agent field on errors so the model knows exactly what to do next.
| Method | Path | Description |
|---|---|---|
GET | /health | Liveness check |
GET | /status | Activation state, pid, started_at, hint_for_agent |
POST | /activate/request | Start the email+code bootstrap. Body: {email, locale?} |
POST | /activate/verify | Verify the 6-digit code. Body: {bootstrap_id, code} |
GET | /skills | List skills available to the activated user |
POST | /brain/run | Execute a skill. Body: {skill, input} |
On successful /activate/verify, the brain_key is persisted to ~/.clawminer/config.json (shared with @clawminer/mcp-server). Next start picks it up automatically and reports activated: true.
npx -y @clawminer/local@latest start &~/.clawminer/local.json to get the URL./activate/request./activate/verify with the code. Backend returns a brain_key, sidecar stores it.POST /brain/run with {skill, input}.All of this happens in a single conversation turn sequence. No MCP client reload, no runtime restart, no new session.
127.0.0.1 / ::1 / ::ffff:127.0.0.1. It is not reachable from the network.api.clawminer.network over HTTPS. brain_key is stored in ~/.clawminer/config.json with 0600 permissions.http, fs, os, crypto). The entire source is ~400 lines in one file. Audit it yourself: sdk/clawminer-local/src/index.ts.clawminer-local stop, or just kill <pid>. The settings file is removed on exit.This package is the fast-path activation companion to @clawminer/mcp-server. They are complementary, not competing:
@clawminer/local (this package) — immediate use in the current conversation via localhost HTTP. Runs in seconds, no config file edits, no runtime restart.@clawminer/mcp-server — proper MCP integration with schema-validated tools. Installed via claude mcp add or equivalent, activates after the next runtime cold start for a permanent upgrade.Both share ~/.clawminer/config.json so once you activate via @clawminer/local, the next time you restart your MCP runtime the MCP path picks up the same brain_key and the 7 MCP tools just work.
MIT
FAQs
SkillForge agent sidecar — a tiny localhost HTTP proxy that lets any AI agent activate and run professional skills (content writing, brand design, GEO optimization) in the current conversation. No MCP restart needed.
The npm package @skillforge/agent receives a total of 1 weekly downloads. As such, @skillforge/agent popularity was classified as not popular.
We found that @skillforge/agent demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.