
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
brianbooms-mcp
Advanced tools
MCP server: Brian Booms x402 product catalog as callable agent tools (search, product details, live 402 payment requirements). Read-only — never executes payments.
Puts the Brian Booms x402 product catalog inside AI agents as callable tools. Any MCP-capable agent can search the catalog, read license terms, fetch live x402 payment requirements, and complete a purchase — without opening a browser.
Made with Suno (catalog ethics: disclose on first mention of how the music is made).
| Tool | What it does |
|---|---|
search_catalog(query, max_price?) | Search 33 agent-buyable digital products (music licenses, sample packs, commissions, wallpapers; $0.05–$999 USDC) |
get_product(sku) | Full details: price, buy URL, delivery, license-terms summary |
buy_product(sku, partner?) | Fetches the live HTTP 402 from the buy URL and returns payment requirements + step-by-step x402 signing instructions. Optional partner id attributes the purchase to a Booms Partner (20% revenue share) |
get_market() | The 33 AP2 market listings (machine-readable directory) |
Read-only by design. The server never signs, submits, or executes a payment.
buy_product returns what to sign, not a completed purchase. The catalog
itself requires explicit human authorization, one purchase per request.
pip install mcp
// Claude Desktop / claude-code MCP config
{
"mcpServers": {
"brianbooms": {
"command": "python3",
"args": ["/path/to/brianbooms-mcp/server.py"]
}
}
}
Or with uvx / pipx once published to npm/PyPI (not yet published).
buy_product(sku) → gets the 402 requirementsNetwork: Base eip155:8453, asset USDC. Catalog loads live from
https://brianbooms.com/.well-known/purchase-catalog.json at startup with a
local fallback copy (catalog-fallback.json).
server.py — the MCP server (stdio)catalog-fallback.json — local catalog copy used if the hub is unreachablepackage.json — npm wrapper metadata (for registry publishing)FAQs
MCP server: Brian Booms x402 product catalog as callable agent tools (search, product details, live 402 payment requirements). Read-only — never executes payments.
The npm package brianbooms-mcp receives a total of 466 weekly downloads. As such, brianbooms-mcp popularity was classified as not popular.
We found that brianbooms-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.