
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@sponsorbook/mcp
Advanced tools
Research YouTube sponsors, inspect sponsorship evidence, and manage Sponsorbook lists from any MCP client.
Research YouTube sponsors from Claude, Codex, Cursor, and other MCP clients.
Sponsorbook MCP lets your agent find sponsors, inspect the videos and creators behind each relationship, explore similar brands, manage research lists, and work with verified contacts.
Sponsorbook MCP requires a Sponsorbook Pro workspace.
Use the hosted endpoint when your client supports remote MCP with authentication:
https://app.sponsorbook.io/mcp
For clients that launch a local MCP command:
{
"mcpServers": {
"sponsorbook": {
"command": "npx",
"args": ["-y", "@sponsorbook/mcp"]
}
}
}
Your browser opens on the first connection so you can sign in and choose your Sponsorbook workspace. Later connections reuse that authorization.
The package is a small open-source bridge for MCP clients that launch local commands. Sponsorbook's hosted MCP server performs the research and applies the same workspace permissions, contact reveal rules, and catalogue limits as the web app.
The hosted server and Sponsorbook catalogue are separate from this repository.
npm install
npm test
npm run test:live
Set SPONSORBOOK_MCP_URL to an HTTPS endpoint, or to an HTTP localhost endpoint, when testing another Sponsorbook deployment.
Please report vulnerabilities through GitHub private vulnerability reporting.
FAQs
Research YouTube sponsors, inspect sponsorship evidence, and manage Sponsorbook lists from any MCP client.
The npm package @sponsorbook/mcp receives a total of 16 weekly downloads. As such, @sponsorbook/mcp popularity was classified as not popular.
We found that @sponsorbook/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.