
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@tabnas/mcp
Advanced tools
The tabnas agent tooling: an MCP server (stdio) and the unified `tabnas` CLI, two front-ends over one core so they cannot disagree.
The tabnas agent tooling: an MCP
server (stdio) and the unified tabnas CLI, two thin front-ends over
one core so they cannot disagree: for the same request, the CLI's
--json output and the MCP tool result are byte-identical.
Six tools only: parse, validate_grammar, explain_parse_error,
test_grammar, list_plugins, describe_plugin. Five resources:
the serialized-grammar schema, the diagnostic schema, the error-code
registry, the plugin descriptors, and the engine's divergence record.
all bundled, generated copies of the fleet's contract files.
npm install -g @tabnas/mcp # the `tabnas` CLI
npx --yes @tabnas/mcp # run the MCP server (stdio)
tabnas parse [file|-] [--grammar g.json] [--json]
tabnas validate --grammar g.json [--json]
tabnas diagnose [file|-] [--grammar g.json] [--json]
tabnas test --spec fixtures.tsv [--grammar g.json] [--json]
tabnas plugins [name] [--json]
tabnas mcp # run the MCP server (stdio)
Exit codes: 0 success, 1 the operation said no (parse failure,
invalid grammar, fixture failures, unknown plugin), 2 usage error.
tabnas --help has the details. The CLI never touches the network.
tabnas mcp runs the stdio MCP server (the entry the skills package's
mcp.json invokes as npx --yes @tabnas/mcp@<x.y.z> mcp).
Serialized grammars and their options are validated before use by a
firewall that rejects a prototype-pollution key (__proto__,
constructor, prototype) anywhere in the tree, a ref key, a
non-builtin function reference, a plugins key, and grammars over 5000
rules: a grammar is data, never code.
Full documentation: github.com/tabnas/mcp.
FAQs
The tabnas agent tooling: an MCP server (stdio) and the unified `tabnas` CLI, two front-ends over one core so they cannot disagree.
We found that @tabnas/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.