
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@striderlabs/mcp-bjs
Advanced tools
BJs Wholesale Club MCP server — search, cart, and order from BJs. By Strider Labs.
BJ's Wholesale Club MCP server for personal AI agents. Search products, manage your cart, check club inventory, find gas prices, manage coupons, and more — all from Claude or any MCP-compatible AI client.
npm install -g @striderlabs/mcp-bjs
Or use directly with npx:
npx @striderlabs/mcp-bjs
Install Chromium for browser automation:
npx patchright install chrome
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"bjs": {
"command": "npx",
"args": ["-y", "@striderlabs/mcp-bjs"]
}
}
}
{
"mcpServers": {
"bjs": {
"command": "striderlabs-mcp-bjs",
"transport": "stdio"
}
}
}
| Tool | Description |
|---|---|
bjs_status | Check login status and current session |
bjs_login | Initiate browser login (returns URL for manual sign-in) |
bjs_logout | Log out and clear saved session |
| Tool | Description |
|---|---|
bjs_search | Search products by keyword with optional club filter |
bjs_product_details | Full product details and pricing by URL |
bjs_check_inventory | Check in-stock status at a specific club |
| Tool | Description |
|---|---|
bjs_add_to_cart | Add item to cart by product URL |
bjs_view_cart | View cart contents with subtotal and total |
bjs_remove_from_cart | Remove an item from cart by name |
bjs_checkout | Start checkout: pickup, delivery, or ship |
| Tool | Description |
|---|---|
bjs_membership_info | Membership number, type, expiry, rewards balance |
bjs_membership_renew | Navigate to membership renewal page |
| Tool | Description |
|---|---|
bjs_coupons | Browse available digital coupons, optionally by category |
bjs_clip_coupon | Clip a coupon to your membership card |
bjs_my_coupons | View all clipped coupons |
| Tool | Description |
|---|---|
bjs_order_history | View past orders with status and total |
bjs_order_details | Full order details with items and tracking |
| Tool | Description |
|---|---|
bjs_find_clubs | Find BJ's clubs near a zip code |
bjs_gas_prices | Current gas prices at BJ's fuel stations |
Search for paper towels at BJ's, then check if the Bounty Select-A-Size is in stock at my nearest club.
bjs_find_clubs → find nearby club IDsbjs_search with query: "bounty paper towels" and clubIdbjs_check_inventory with the product URL and club IDAdd 2 packs of Kirkland bottled water to my cart and start in-club pickup checkout.
bjs_search with query: "bottled water"bjs_add_to_cart with quantity: 2bjs_view_cart to confirmbjs_checkout with fulfillmentType: "pickup"What are the gas prices at BJ's stations near 07001?
bjs_gas_prices with zipCode: "07001"Clip all available grocery coupons to my BJ's card.
bjs_coupons with category: "grocery"bjs_clip_coupon for each unclipped couponBJ's requires manual sign-in on first use:
bjs_login — the server opens a browser and returns the login URLbjs_status to confirm the session is active~/.strider/bjs/ and reused automaticallySession data is stored at ~/.strider/bjs/:
cookies.json — Browser session cookies (auto-refreshed)session.json — Membership info cachegit clone https://github.com/striderlabs/mcp-bjs
cd mcp-bjs
npm install
npm run build
npm start
By Strider Labs — MIT License
FAQs
BJs Wholesale Club MCP server — NOT IMPLEMENTED honest stub. By Strider Labs.
We found that @striderlabs/mcp-bjs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.