
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
npx launchers for 5 Huginn MCP servers — materials database, math semantics, pixel vision, capability containers, workflow blueprints
npx 启动器,覆盖 Huginn 的 5 个 MCP server。每个 bin 只是一个薄包装:
找到对应 Python 命令并 spawn,stdio(MCP 传输)原样透传。
| bin | 对应 backend | 前置依赖 |
|---|---|---|
npx mat-db-mcp | 材料数据库 (MP/AFLOW/NOMAD/OQMD/NIST) | pip install matsci-mat-db-mcp |
npx math-anything-mcp | 数学语义/量纲/精度 | pip install matsci-math-anything-mcp |
npx vision-pixel-mcp | 像素取色/裁剪 | pip install matsci-vision-pixel-mcp |
npx capabilities-mcp | 能力集装箱 (只读) | pip install huginn-agent |
npx workflows-mcp | 工作流蓝图 (只读) | pip install huginn-agent |
依赖在运行时(Python 侧)解析:先把对应 pip 包装好,再
npx <bin>即可。 若 PATH 中mat-db-mcp之类与已有 Python 命令同名冲突,可只保留一个。
{
"mcpServers": {
"workflows-mcp": { "command": "npx", "args": ["workflows-mcp"] },
"mat-db-mcp": { "command": "npx", "args": ["mat-db-mcp"] }
}
}
npm run test:list # 打印 5 个 bin 名
FAQs
npx launchers for 5 Huginn MCP servers — materials database, math semantics, pixel vision, capability containers, workflow blueprints
The npm package huginn-mcp receives a total of 0 weekly downloads. As such, huginn-mcp popularity was classified as not popular.
We found that huginn-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.