
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Agents author, humans edit: presentations, reports and one-pagers from an MCP server, with a WYSIWYG editor and a one-file HTML export.
Agents author. Humans edit. The frame lints.
decaframe is an MCP server that lets a coding agent write presentations, reports and one-pagers
as visual documents, a WYSIWYG editor a person opens on the same file, and an export to one HTML
file that opens anywhere.
npm install -g decaframe
Node 22 or later. The headless browser the export renders with is downloaded once, in the background, the
first time deca runs, about 100 MB from Playwright's own servers. Until it lands, an export says so.
Add the server to your client. For Claude Code, Cursor, Windsurf and most others the entry is:
{ "mcpServers": { "decaframe": { "command": "npx", "args": ["-y", "decaframe", "mcp"] } } }
Then ask for a deck. The document is written to document.json in the folder the agent works in;
set DECAFRAME_DOC to put it elsewhere.
The skill that teaches an agent to design with the tools installs into every agent on the machine:
npx skills add decaframe/decaframe
deca open document.json
Serves the editor on a free port and opens it in a window. An agent and the editor may hold the same file at once: what either saves, the other sees.
Ask the agent for export_html, or from the editor's menu. The file expects the internet for its
fonts, pictures and video, and degrades gracefully without it.
https://github.com/decaframe/decaframe
Commercial. See LICENSE.
FAQs
Agents author, humans edit: presentations, reports and one-pagers from an MCP server, with a WYSIWYG editor and a one-file HTML export.
The npm package decaframe receives a total of 43 weekly downloads. As such, decaframe popularity was classified as not popular.
We found that decaframe demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.