
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@yocoolab/mcp-server
Advanced tools
MCP server that exposes Yocoolab feedback threads, design selections, and activity events as tools for Claude Code and other MCP-compatible clients.
MCP (Model Context Protocol) server that exposes Yocoolab feedback threads, design selections, and activity events as tools for Claude Code and other MCP-compatible clients.
With this installed, your AI coding assistant can:
One command:
npx -y @yocoolab/mcp-server@2 setup
The setup wizard auto-detects your installed AI agents (Claude Code, Cursor, Cline, Roo Code, Windsurf) and writes the correct MCP config for each. Restart your agent and the yocoolab server appears with all tools available.
initis kept as an alias forsetupfor backwards compatibility with v1.0.x install instructions.
If you'd rather configure manually, the equivalent ~/.mcp.json looks like:
{
"mcpServers": {
"yocoolab": {
"command": "npx",
"args": ["-y", "@yocoolab/mcp-server@2"],
"env": {
"YOCOOLAB_API_URL": "https://app.yocoolab.com",
"YOCOOLAB_TOKEN": "<your-yocoolab-jwt>",
"GITHUB_TOKEN": "<your-github-pat>",
"YOCOOLAB_BRIDGE_PORT": "9800",
"YOCOOLAB_BRIDGE_WORKSPACE": "/absolute/path/to/your/workspace"
}
}
}
}
The @2 version pin keeps you on the v2 major line — you'll receive bug fixes and new features automatically, but a future v3 with breaking changes won't break your setup. (Pin to @1 if you need Node 18 support — v1.x will receive security patches for 90 days after v2.0.)
repo scope, if you want to use the PR-creation tools (create_pr_for_thread). The token is auto-detected if you have the GitHub CLI installed and authenticated (gh auth login). No GITHUB_TOKEN env var needed in that case. Otherwise, create one at github.com/settings/tokens/new?scopes=repo.| Env var | Required | Default | Description |
|---|---|---|---|
YOCOOLAB_TOKEN | no | — | Your Yocoolab JWT (from the Chrome extension). When unset, thread feedback tools are disabled but bridge / companion / activity tools still work. |
YOCOOLAB_API_URL | no | https://app.yocoolab.com | Yocoolab API base URL |
GITHUB_TOKEN | only for PR tools | — | GitHub PAT with repo scope. Auto-detected — if gh CLI is installed and authenticated (gh auth token), no env var is needed. Placeholder values like <your GitHub PAT> are detected and safely ignored. |
YOCOOLAB_BRIDGE_PORT | no | 9800 | Local port for the HTTP bridge to the Chrome extension |
YOCOOLAB_BRIDGE_WORKSPACE | no | process.cwd() | Absolute path to your project workspace, used to resolve file references in selections |
YOCOOLAB_AGENT_NAME | no | Claude Code | Display name shown in the Chrome extension's agent picker |
YOCOOLAB_AGENT_TYPE | no | claude-code | Agent type identifier (claude-code, roo, cline, cursor, windsurf, or custom) |
yocoolab-mcp Run the MCP server (used by your agent via .mcp.json)
yocoolab-mcp setup Interactive setup — auto-detects agents and writes their configs
yocoolab-mcp init Alias for `setup` (backwards compatible with v1.0.x)
yocoolab-mcp --help Show this help
The mcp-server command is a synonym for yocoolab-mcp. Either works.
The server exposes tools across several categories:
list_open_threads, get_thread_context, add_thread_message, mark_thread_addressed, create_pr_for_threadget_latest_selection, get_selection_history, get_element_context, find_source_for_selection, ai_analyze_pageget_recent_events, get_activity_summary, get_files_touched, get_companion_messages, reply_to_companionget_ai_conversationsget_deployment_previewpendo_list_guides, pendo_page_analytics, pendo_feature_usage, pendo_track_eventFor full tool descriptions and parameters, your MCP client will list them after the server starts.
yocoolab-mcp: command not found — make sure you're on v1.0.1 or newer. Run npx -y @yocoolab/mcp-server@latest setup to get the current release.
[yocoolab] Warning: YOCOOLAB_TOKEN not set — thread feedback tools are disabled without a token, but bridge / companion / activity tools still work. To enable everything, run yocoolab-mcp setup to (re)generate the config with your JWT.
Tools don't appear in your agent after install — restart your agent completely (quit & reopen). MCP servers load at startup.
Port 9800 is already in use — another instance of the MCP server is running, or another app has the port. Set YOCOOLAB_BRIDGE_PORT to a different value (e.g. 9801) in your .mcp.json.
Verbose diagnostic logs — set DEBUG=yocoolab:* in your env block. All diagnostic output goes to stderr (so it doesn't interfere with the MCP stdio protocol on stdout).
PR creation says "GitHub token not configured" — the create_pr_for_thread tool needs a GitHub token. Two ways to fix:
gh auth login. The server picks up the token automatically.repo scope and add GITHUB_TOKEN: "ghp_..." to your MCP config's env block.
If your config has a placeholder value like <your GitHub PAT>, the server detects it and shows a helpful message instead of crashing with a 401.git clone https://github.com/Yocoolab/mcp-server.git
cd mcp-server
npm install
npm run build # compile TypeScript to dist/
npm test # run the vitest suite
npm run dev # tsc --watch
See CONTRIBUTING.md for the full contributor workflow.
npm audit signatures and CodeQL static analysis in CI on every PR.Apache 2.0 — © 2026 Yocoolab
FAQs
MCP server that exposes Yocoolab feedback threads, design selections, and activity events as tools for Claude Code and other MCP-compatible clients.
The npm package @yocoolab/mcp-server receives a total of 64 weekly downloads. As such, @yocoolab/mcp-server popularity was classified as not popular.
We found that @yocoolab/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.