
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@sylphx/cue
Advanced tools
Cue — video answers with timestamp-level proof. The default read returns container metadata, streams, chapters, and embedded subtitles. Scenes and frames are separate.
Cue gives agents a local video timeline they can search and cite. The default read returns container metadata, streams, chapters, and embedded subtitles. Scenes and frames are separate.
npx -y @sylphx/cue
For Claude Code:
claude mcp add cue -- npx -y @sylphx/cue
{
"sources": [{ "path": "/absolute/path/to/demo.mp4" }]
}
That call uses the fast profile. It returns container metadata, streams,
chapters, and embedded subtitles. It does not detect scenes, extract frames,
or run speech recognition.
Then ask:
“Which chapter covers the pricing change?”
Cue returns chapter and subtitle locators with timestamp_ms and the source
hash. It does not invent a transcript. A quote search matches embedded
subtitles only. Render or crop a frame afterwards with video_evidence, once
you have a timestamp.
| Ask your agent | Cue returns |
|---|---|
| “Find this quote.” | a timestamped match in embedded subtitles, when those subtitles exist |
| “Summarize this meeting.” | chapters and embedded subtitles |
| “Where is the code shown?” | one frame from video_evidence at a known timestamp |
| “What changed in this demo?” | scene boundaries when profile is quality or include_scenes is set |
| “Give me the useful moments.” | chapters, embedded subtitles, warnings, and gaps |
| Tool | Purpose |
|---|---|
read_video | Default fast profile: container metadata, streams, chapters, and embedded subtitles. Scenes are opt-in. |
search_video | Search embedded subtitle cues. It does not run speech recognition. |
video_evidence | Named follow-up: render, crop, or OCR one frame at a timestamp |
profile is fast: container metadata, streams, chapters, and embedded subtitles. No scenes, frames, or speech recognition.profile quality sets scene detection and keyframes only. It does not enable OCR or speech recognition.include_transcript stays off unless the caller sets it, including on quality.video_evidence.Every claim can point back to timestamp_ms, a stream index, a subtitle range,
or the source hash. A frame index is present only after video_evidence. When
keyframes are requested, structural keyframes are preferred over sampling every
frame.
| Product | Job |
|---|---|
| Citra | PDF answers with page-level proof |
| Iris | Image facts and pixel evidence |
| Spine | Repository architecture and impact |
| Locus | Exact code-chunk retrieval |
| Lookout | Web research with source excerpts |
Each product is independent. Install only the tools your agent needs.
bun install
bun run build
bun test
cargo test
bun run benchmark:public-proof
bun run benchmark:release-gate
MIT
FAQs
Cue — video answers with timestamp-level proof. The default read returns container metadata, streams, chapters, and embedded subtitles. Scenes and frames are separate.
The npm package @sylphx/cue receives a total of 301 weekly downloads. As such, @sylphx/cue popularity was classified as not popular.
We found that @sylphx/cue demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.