
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
@withpica/mcp-server-directory
Advanced tools
MCP Server for the withPICA Public Directory — enables AI assistants to search verified works and creators
MCP server for the withPICA public directory — read-only search over works, recordings and creators that rights holders have chosen to publish. No account, no API key, no setup.
claude mcp add withpica-directory -- npx --yes @withpica/mcp-server-directory@latest
Who wrote this song. What the ISWC is. Which recordings exist of a work and what their ISRCs are. Which creators match a name, an ISNI or an IPI. Which published recordings sit in a tempo, key, energy or mood range. And, in one call, the rights chain for a work: writers, publishers, recording, audio.
Every entry is published deliberately by its rights holder, with attested credits and verified identifiers.
GET https://withpica.com/api/public/directory/worksGET https://withpica.com/api/public/directory/peopleGET https://withpica.com/api/public/directory/search?q={query}GET https://withpica.com/api/public/directory/recordingsGET https://withpica.com/api/public/directory/consent?iswc={iswc}100 requests/minute unauthenticated. Licensing keys unlock extended fields and their own limits.
withpica.com publishes a blanket TDM reservation at https://withpica.com/.well-known/tdmrep.json ("tdm-reservation": 1). Nothing here is licensed for text-and-data mining or model training by default.
The consent endpoint above is the granular counterpart: ask it about an identifier and it reports what the rights holders have actually cleared, and at what level. A work is cleared at a level only when every credited contributor has granted at least that level; one refusal blocks it. Read no_assertion_published literally — it means no permission is published for that identifier, which is not a maybe.
11 tools, all read-only:
directory_chain — Graph lookup — resolves a query, ISWC, or ISRC to its full rights chain in one calldirectory_list_people — Browse and filter creators in the PICA public directorydirectory_list_works — Browse and filter verified musical works in the PICA public directorydirectory_lookup_isrc — Shortcut: look up the work(s) associated with a recording identifier (ISRC)directory_lookup_person — Get full details of a creator by global creator ID (UUID), ISNI, IPI number, or MusicBrainz IDdirectory_lookup_work — Get full details of a single work by ISWC or work UUIDdirectory_release_notes — Returns recent releases of the PICA directory MCP server — what shipped in the public catalogue surface itselfdirectory_search — Convenience fan-out across works and creators — runs list_works and list_people with the same query and returns the uniondirectory_search_recordings — Find tracks by BPM, key, energy, danceability, duration, and moredirectory_skill_get — Returns the full methodology body for one directory skill — markdown with step-by-step instructions and tool chainsdirectory_skill_list — Returns the list of downloadable directory skill methodologies — name, description, trigger phrasesGenerated for @withpica/mcp-server-directory@1.4.2. © 2024-2026 Withpica Ltd. All rights reserved. MIT licensed.
FAQs
MCP Server for the withPICA Public Directory — enables AI assistants to search verified works and creators
The npm package @withpica/mcp-server-directory receives a total of 7 weekly downloads. As such, @withpica/mcp-server-directory popularity was classified as not popular.
We found that @withpica/mcp-server-directory demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.