
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@trigguard/mcp
Advanced tools
TrigGuard MCP — execution authorization over stdio (PERMIT/DENY/SILENCE/ESCALATE)
@trigguard/mcpInstall: npx @trigguard/mcp
MCP identifier (registry): io.github.TrigGuard-AI/trigguard
npm package: @trigguard/mcp
Implementation: @trigguard/mcp-server (kept as a compatibility package)
TrigGuard authorizes execution. It does not execute actions.
MCP client → @trigguard/mcp → @trigguard/mcp-server → @trigguard/agent-sdk → POST /v1/authorize
{
"mcpServers": {
"trigguard": {
"command": "npx",
"args": ["-y", "@trigguard/mcp"],
"env": {
"TRIGGUARD_GATEWAY_URL": "https://api.trigguardai.com",
"TRIGGUARD_API_KEY": "${env:TRIGGUARD_API_KEY}",
"TRIGGUARD_ORG_ID": "${env:TRIGGUARD_ORG_ID}"
}
}
}
}
npx @trigguard/mcp-server still works. Prefer @trigguard/mcp.
FAQs
TrigGuard MCP — execution authorization over stdio (PERMIT/DENY/SILENCE/ESCALATE)
We found that @trigguard/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.