
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@tabnas/mcp
Advanced tools
The tabnas agent tooling: an MCP server (stdio) and the unified `tabnas` CLI, two front-ends over one core so they cannot disagree.
The tabnas agent tooling: an MCP
server (stdio) and the unified tabnas CLI, two thin front-ends over
one core so they cannot disagree — for the same request, the CLI's
--json output and the MCP tool result are byte-identical.
Six tools only: parse, validate_grammar, explain_parse_error,
test_grammar, list_plugins, describe_plugin. Five resources:
the serialized-grammar schema, the diagnostic schema, the error-code
registry, the plugin descriptors, and the engine's divergence record —
all bundled, generated copies of the fleet's contract files.
npm install -g @tabnas/mcp # the `tabnas` CLI
npx --yes @tabnas/mcp # run the MCP server (stdio)
tabnas parse [file|-] [--grammar g.json] [--json]
tabnas validate --grammar g.json [--json]
tabnas diagnose [file|-] [--grammar g.json] [--json]
tabnas test --spec fixtures.tsv [--grammar g.json] [--json]
tabnas plugins [name] [--json]
tabnas mcp # run the MCP server (stdio)
Exit codes: 0 success, 1 the operation said no (parse failure,
invalid grammar, fixture failures, unknown plugin), 2 usage error.
tabnas --help has the details. The CLI never touches the network.
tabnas mcp runs the stdio MCP server (the entry the skills package's
mcp.json invokes as npx --yes @tabnas/mcp@<x.y.z> mcp).
Serialized grammars and their options are validated before use by a
firewall that rejects a prototype-pollution key (__proto__,
constructor, prototype) anywhere in the tree, a ref key, a
non-builtin function reference, a plugins key, and grammars over 5000
rules: a grammar is data, never code.
Full documentation: github.com/tabnas/mcp.
FAQs
The tabnas agent tooling: an MCP server (stdio) and the unified `tabnas` CLI, two front-ends over one core so they cannot disagree.
The npm package @tabnas/mcp receives a total of 283 weekly downloads. As such, @tabnas/mcp popularity was classified as not popular.
We found that @tabnas/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.