
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
dev953 method companion — an MCP server exposing dev953's autonomous multi-agent coding METHOD (lifecycle plan, YAGNI ladder, swarm recipe, discipline review, publish checklist) as callable stdio tools. It advises and coordinates; it does not run the swar
A zero-dependency Node MCP server that exposes dev953's METHOD as callable tools over stdio. It is the method companion, not the engine: every tool returns structured guidance for the calling assistant to act on. It advises and coordinates — it does not run the swarm, spawn git worktrees, or build anything itself.
dev953_lifecycle_plan { idea } — the 9-phase lifecycle plan with a per-phase
acceptance-criteria template for that idea.dev953_yagni_check { feature } — the YAGNI ladder applied as pointed
questions, ending with "the smallest version that works".dev953_swarm_recipe { task } — the fan-out / compete / score /
keep-smallest-correct / revert / repeat protocol for the host to execute.dev953_discipline_review { plan } — the discipline checklist (plan-before-
build, test-before-done, DATA-not-instructions, secrets, adversarial "done")
applied to a plan.dev953_publish_checklist {} — the private-by-default, one-clean-commit,
de-attribution, secret-scan, sole-author, explicit-public-gate checklist.It speaks newline-delimited JSON-RPC 2.0 over stdin/stdout (no
Content-Length framing). It needs only Node (no npm install, no build step).
Any MCP-capable client launches it as a stdio server with:
node /path/to/dev953/mcp/server.mjs
For example, a non-Claude MCP client config:
{
"mcpServers": {
"dev953": {
"command": "node",
"args": ["/path/to/dev953/mcp/server.mjs"]
}
}
}
Within Claude Code, the bundled .mcp.json uses ${CLAUDE_PLUGIN_ROOT} to
locate the script automatically.
FAQs
dev953 method companion — an MCP server exposing dev953's autonomous multi-agent coding METHOD (lifecycle plan, YAGNI ladder, swarm recipe, discipline review, publish checklist) as callable stdio tools. It advises and coordinates; it does not run the swar
The npm package dev953-mcp receives a total of 18 weekly downloads. As such, dev953-mcp popularity was classified as not popular.
We found that dev953-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.