
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@whenlabs/when
Advanced tools
Six tools. One install.
A single installable toolkit that brings six WhenLabs developer tools into your Claude Code workflow. After install, the tools are exposed over a single MCP server and Claude calls them automatically when relevant.
npx @whenlabs/when install
One-time setup. The installer:
whenlabs) in your Claude Code configurationvelocity-mcp registration (velocity is now bundled)| Tool | Purpose |
|---|---|
| aware | Auto-detect stack and generate AI context files (CLAUDE.md, .cursorrules, …) |
| berth | Detect port conflicts before starting dev servers |
| envalid | Validate .env files against a schema |
| stale | Detect documentation drift between docs and code |
| vow | Scan dependency licenses and validate against policy |
| velocity | Time coding tasks and learn from historical data |
Seven endpoints across the six tools:
| Endpoint | What it does |
|---|---|
aware_sync | Detect stack and regenerate AI context files |
berth_check | Scan project for port conflicts |
envalid_validate | Validate .env files against schema |
stale_scan | Detect documentation drift |
vow_scan | Scan licenses and validate against policy |
velocity_start_task | Start timing a coding task |
velocity_end_task | End timing and record results |
All seven are served by the single whenlabs MCP server (stdio, Node 20+). Fix/init/auxiliary commands remain available via each tool's CLI (npx @whenlabs/<tool> --help).
when init # Onboard a project — detect stack, bootstrap configs, run all checks
when doctor # Run all six tools and show a unified health report
when install # Register MCP server in Claude Code
when uninstall # Remove MCP server
For per-tool operations, use the tool directly:
npx @whenlabs/stale scan
npx @whenlabs/envalid validate
npx @whenlabs/berth check
npx @whenlabs/aware sync
npx @whenlabs/vow scan
If you're not using the install command, add this to your Claude Code MCP config:
{
"mcpServers": {
"whenlabs": {
"command": "npx",
"args": ["-y", "-p", "@whenlabs/when@latest", "when-mcp"]
}
}
}
The -p flag is required — @whenlabs/when ships two bins (when and when-mcp), and npx @whenlabs/when when-mcp runs the default when bin with when-mcp as an unknown subcommand.
MIT — see LICENSE
FAQs
The WhenLabs developer toolkit — 6 tools, one install
We found that @whenlabs/when demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.