
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
ghostlight
Advanced tools
Governed browser automation over your own authenticated Chromium session, for AI coding agents. Thin npm launcher for the ghostlight binary.
Delightful, responsible browser automation for AI coding agents. Ghostlight gives any MCP client access to your own authenticated Chromium session, keeps the work visible, and adds inspectable boundaries when you want them. All-open is a first-class default.
This npm package is a thin launcher. On first run it downloads the version-matched Ghostlight
binaries from the GitHub release and caches them under ~/.ghostlight/bin/, so there are no
runtime dependencies. A bare npx ghostlight starts the MCP server your client talks to;
npx ghostlight install connects the browser side.
Install the service, browser connection, and detected MCP-client entries in one idempotent step:
npx -y ghostlight install
The command opens the current extension walkthrough on the first run. Until the Chrome Web Store listing is public, the walkthrough provides the manual release-archive path. Restart your MCP clients when both halves are installed. Full walkthrough, client buttons, and manual paths: https://sylin.org/ghostlight/
For a client the installer does not recognize, use Ghostlight as this stdio server:
{ "command": "npx", "args": ["-y", "ghostlight"] }
FAQs
Governed browser automation over your own authenticated Chromium session, for AI coding agents. Thin npm launcher for the ghostlight binary.
The npm package ghostlight receives a total of 513 weekly downloads. As such, ghostlight popularity was classified as not popular.
We found that ghostlight demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.