
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@sonenta/mcp
Advanced tools
MCP server for Sonenta translation management. Pure TypeScript, no Python. Wires Claude Desktop and other MCP clients into your project's keys, translations, accessibility, and source-health tools.
Model Context Protocol server for Sonenta translation management — pure TypeScript, no Python, no uv, no bundled wheel. Runs on Node ≥18.
Wires Claude Desktop and other MCP clients into your Sonenta project's keys, translations, accessibility surfaces, source-health, and glossary tools — plus agent-observability tools (session_start / annotate / human_needed / session_end) that surface an agent's run as a live, timestamped thread in the Sonenta dashboard, and prompt-library reads (list_prompts / resolve_prompt) so agents can discover and reuse the project's curated prompts. propose_translation(s) carry ICU/CLDR plural_forms, and plural_categories returns the plural categories a language requires (babel-authoritative).
The launcher sends agent-identity headers on every request — X-Agent-Name / X-Agent-Type / X-Agent-Version (from SONENTA_AGENT_NAME / SONENTA_AGENT_TYPE / SONENTA_AGENT_VERSION, all optional) — so the backend can auto-open a live observability session even for agents that never call session_start. X-MCP-Session-Id is a per-process run id before session_start (the backend opens then adopts a single coarse session on it), then the returned session id (echoed), reverting to the run id after session_end — so each subagent's captured mutations route to its own session and concurrent subagents stay distinct.
Auto-wired by sonenta init / sonenta agents add. Manual .mcp.json:
{
"mcpServers": {
"sonenta": {
"command": "npx",
"args": ["-y", "@sonenta/mcp"],
"env": { "SONENTA_API_KEY": "<mcp:* key>", "SONENTA_PROJECTS": "<uuid,…>" }
}
}
}
Env: SONENTA_API_KEY / SONENTA_BASE_URL (default https://api.sonenta.dev) / SONENTA_PROJECTS
(legacy VERBUMIA_* accepted). With no key set, the server reads ~/.sonenta/credentials (from sonenta login).
FAQs
MCP server for Sonenta translation management. Pure TypeScript, no Python. Wires Claude Desktop and other MCP clients into your project's keys, translations, accessibility, and source-health tools.
The npm package @sonenta/mcp receives a total of 880 weekly downloads. As such, @sonenta/mcp popularity was classified as not popular.
We found that @sonenta/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.