
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@tenetvault/mcp-server
Advanced tools
Local-first memory and rules layer for AI coding agents — MCP server and CLI.
Local-first memory and rules layer for AI coding agents — via Model Context Protocol.
npx -y @tenetvault/mcp-server@latest setup cursor
This initializes the vault and configures Cursor MCP in one step. Replace cursor with claude, codex, or all.
Verify with:
npx -y @tenetvault/mcp-server@latest doctor
mcp_write_enabled (default off) guards all write operationstenetvault setup <ide> # Auto-configure MCP (cursor|claude|codex|all)
tenetvault doctor [ide] # Diagnose activation issues (--json for CI)
tenetvault init # Initialize an encrypted vault at ~/.tenetvault/
# Non-interactive: tenetvault init --passphrase-file <private-0600-file>
tenetvault capture --title <t> --content <c> # Save a candidate growth memory
pbpaste | tenetvault capture --title <t> --kind lesson
tenetvault review today --approve 1,3 --reject 2 --complete
tenetvault start # Start daemon (Local API + vault runtime) + Web UI
tenetvault open # Start if needed and open the dashboard
tenetvault version # Show version
tenetvault flags list # List feature flags
tenetvault flags set <key> <on|off> # Toggle a feature flag
Full documentation is included in the source repository. The GitHub link is usable only when that repository is publicly available or the reader has access: github.com/tenetvault/tenetvault.
MIT
FAQs
Local-first memory and rules layer for AI coding agents — MCP server and CLI.
The npm package @tenetvault/mcp-server receives a total of 45 weekly downloads. As such, @tenetvault/mcp-server popularity was classified as not popular.
We found that @tenetvault/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.