
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Agents author, humans edit: presentations, reports and one-pagers from an MCP server, with a WYSIWYG editor and a one-file HTML export.
Agents author. Humans edit. The frame lints.
decaframe is an MCP server that lets an AI agent write presentations, reports and one-pagers as
visual documents, a WYSIWYG editor a person opens on the same file, and an export to one HTML file
that opens anywhere.
It runs on your computer. Your agent starts it as a program, so it works wherever an agent can start one — the Claude and ChatGPT desktop apps, LM Studio, Cursor, Codex and twenty more — and not on a website or a phone. Per-agent instructions: https://decaframe.com/install
npm install -g decaframe
Node 22 or later. The headless browser the export renders with is downloaded once, in the background, the
first time deca runs, about 100 MB from Playwright's own servers. Until it lands, an export says so.
Almost every client takes the same block, in whichever file it keeps its MCP servers in:
{ "mcpServers": { "decaframe": { "command": "npx", "args": ["-y", "decaframe", "mcp"] } } }
Some want a command instead — claude mcp add --scope user decaframe -- npx -y decaframe mcp,
codex mcp add decaframe -- npx -y decaframe mcp — and Cursor, VS Code, LM Studio, Kiro and Goose
each publish a one-click install link. All of them, with the exact file path for each:
https://decaframe.com/install
Then add the skill, which teaches an agent to design rather than merely fill pages. One command writes it into about eighty agents:
npx skills add decaframe/decaframe
One plugin carries both halves. In Claude Code and the Claude desktop app:
claude plugin marketplace add decaframe/decaframe, then claude plugin install decaframe@decaframe.
In the ChatGPT desktop app: Settings › Plugins › Add › Add marketplace, source decaframe/decaframe,
then install it from the Marketplace tab. In Codex: codex plugin marketplace add decaframe/decaframe,
then codex plugin add decaframe@decaframe.
Then ask for a deck. The document is a .json file named from its title the first time you give it
one. It is written in the folder your agent works in — or, when the agent starts in a folder nobody
works in (a desktop app usually does), in Documents/Decaframe. DECAFRAME_DOC names it yourself.
deca open my-deck.json
Opens the editor at app.decaframe.com in a window of its own, talking to this process over
loopback — nothing about the document leaves your machine. An agent and the editor may hold the
same file at once: what either saves, the other sees. Chrome or Edge for that live connection.
An agent hands you the same link: get_document and export_html both carry one.
Ask the agent for export_html, or from the editor's menu. The file expects the internet for its
fonts, pictures and video, and degrades gracefully without it.
Commercial. See LICENSE.
FAQs
Agents author, humans edit: presentations, reports and one-pagers from an MCP server, with a WYSIWYG editor and a one-file HTML export.
We found that decaframe demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.