
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
@svgrid/mcp
Advanced tools
Model Context Protocol (MCP) server for SvGrid. Exposes example sources, docs, and API reference to AI assistants.
The official Model Context Protocol server for SvGrid.
Point any MCP-capable client - Claude Desktop, Claude Code, Cursor, Zed - at this server and the model answers with accurate, version-pinned facts about SvGrid: real prop, method, and event names, plus every demo's source as grounding. No hallucinated APIs, no stale blog posts.
Why this beats pasting docs into the chat. A model working from memory invents plausible SvGrid APIs, because it learned from a mix of other grids and older versions. Pasting docs helps for one question and then falls out of the context window. This server puts the current API surface and 370+ working demo sources one tool call away, for every question, pinned to the version you installed.
| Tool | Purpose |
|---|---|
list_examples | Every demo: id, title, and one-line blurb. |
get_example_source | Full .svelte source for a demo by id. |
list_docs | Every documentation page (slug + title). |
get_doc | Markdown for a single doc by slug. |
search_docs | Case-insensitive substring search across the docs. |
get_api_reference | The curated public-API surface, grouped by category. |
introspect_source | Studio: infer an EntitySchema from a Drizzle file or sample rows. |
scaffold_entity | Studio: generate SvelteKit files for a single entity. |
The studio_* tools let an agent build and edit the same validated project model the visual designer uses - add entities, screens, blocks, components, wire data sources, theme, RBAC, auth, the typed data layer, and the deploy target - then generate the full runnable app or export the studio.config.json the designer can Load. Every edit runs through the model's own functions + validateProject, so the agent can't produce an invalid app.
| Tool | Purpose |
|---|---|
studio_new_project / studio_load_project | Start fresh, or load an existing studio.config.json. |
studio_describe_project / studio_get_config | Inspect the model / export it as studio.config.json. |
studio_capabilities | List block kinds, component keys, theme presets, data-source kinds, deploy targets. |
studio_add_entity | Add a table/model (+ default screen), by schema or introspection. |
studio_add_screen / studio_add_block / studio_add_component | Compose screens from data blocks + UI components. |
studio_set_entity_source | Bind an entity to memory / SQL / Supabase / REST / PGlite. |
studio_set_theme / studio_set_access / studio_set_auth / studio_set_data_layer / studio_set_deploy_target | Configure app-wide features. |
studio_validate | Report errors + warnings. |
studio_generate_app | Emit every file of the runnable SvelteKit app. |
A typical session: studio_new_project → studio_add_entity (×N) → studio_set_entity_source → studio_set_data_layer → studio_set_auth → studio_generate_app → write the files and run svelte-check.
# One-shot via npx (no install)
npx @svgrid/mcp
# Or install globally, then run the bin
npm install -g @svgrid/mcp
svgrid-mcp
The server speaks MCP over stdio: stdout is reserved for JSON-RPC, logs go to stderr.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or
%APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"svgrid": {
"command": "npx",
"args": ["-y", "@svgrid/mcp"]
}
}
}
Restart Claude Desktop and open a new chat - the tools above are now available.
claude mcp add svgrid -- npx -y @svgrid/mcp
Then run /mcp in a session to confirm svgrid is listed. Ask something like
"using svgrid, build a grid that groups by department and shows a sparkline per row"
and the model will pull the relevant demo sources before generating code.
Add the same mcpServers block to the editor's MCP configuration:
{
"mcpServers": {
"svgrid": { "command": "npx", "args": ["-y", "@svgrid/mcp"] }
}
}
cd packages/mcp
pnpm build
node dist/index.js
pnpm build first runs scripts/build-manifests.mjs, which reads
examples/src/demos/*.svelte and docs/**/*.md from the workspace and inlines
them into src/data.ts, so the published package is fully self-contained.
Commercial. Part of the SvGrid Enterprise offering; see svgrid.com/pricing.
The MIT @svgrid/grid core is free for any use.
SvGrid™ and sv-grid™ are trademarks of jQWidgets Ltd.
FAQs
Model Context Protocol (MCP) server for SvGrid. Exposes example sources, docs, and API reference to AI assistants.
The npm package @svgrid/mcp receives a total of 182 weekly downloads. As such, @svgrid/mcp popularity was classified as not popular.
We found that @svgrid/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.