
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
A headless CLI for Actual Budget — no server required. Import transactions, manage your budget, and automate your finances from the terminal or through an AI agent.
1. Install the CLI
npm install -g fscl
2. Set up your first budget
fscl init
If you run setup via npx fscl init, fscl prompts to install itself globally (npm install -g fscl) so fscl is available on your PATH afterward.
At the end of interactive setup, fscl offers to install the agent skill by running:
npx skills add fiscal-sh/fscl
If you skip it, run that command anytime.
3. Talk to your agent in plain language
FAQs
Headless CLI for Actual Budget
We found that fscl demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.