
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
Event-driven AI agents with native MCP tools. Webhooks & RSS feeds in. MCP tools out. AI agent in the middle.
Stripe webhook ──→ Recipe ──→ Conta Azul MCP (create invoice)
GitHub webhook ──→ Recipe ──→ Slack MCP (post message)
HN RSS feed ──→ Recipe ──→ Slack MCP (daily digest)
Any event ──→ Recipe ──→ Any MCP server
This is the main package that re-exports @lucianfialho/hooklaw-core and @lucianfialho/hooklaw-cli.
npx hooklaw start
No config file? HookLaw launches an interactive setup wizard in your browser — pick a provider, choose an event source, select integrations, and you're running.
Or install globally:
npm install -g hooklaw
hooklaw start
@modelcontextprotocol/sdkserver:
port: 3007
providers:
anthropic:
api_key: ${ANTHROPIC_API_KEY}
mcp_servers:
slack:
transport: stdio
command: npx
args: ["-y", "@anthropic/mcp-server-slack"]
recipes:
pr-review:
description: "Review PRs and post feedback"
slug: github
mode: async
agent:
provider: anthropic
model: claude-sonnet-4-6
instructions: "Review the PR and provide feedback."
memory:
enabled: true
window_size: 10
tools: [github]
chain:
on_success: [notify-slack]
approval:
enabled: true
logs:
retention_days: 30
Full documentation at github.com/lucianfialho/hooklaw.
MIT
FAQs
Webhook orchestrator with AI agents and MCP tools. BYOK, self-hosted.
The npm package hooklaw receives a total of 6 weekly downloads. As such, hooklaw popularity was classified as not popular.
We found that hooklaw demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.