
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Connect your AI client to the workspace context in the Ikuna app running on your Mac.
ikuna-mcp 0.1.1 is listed in the official MCP Registry as io.github.RobertoHanas/ikuna-mcp.
npx.npx -y ikuna-mcp setup
Setup detects Claude Desktop, Codex, Claude Code, and Cursor, merges only Ikuna's entry into their existing configuration, retains the latest three backups, and verifies the local MCP handshake. Re-run the same command to repair stale or missing values, or make that intent explicit:
npx -y ikuna-mcp setup --repair
npx -y ikuna-mcp setup --client codex
Exit status 0 means every detected client was configured and the handshake passed, 1 means configuration was saved but verification needs a manual step, and 2 means no detected client could be configured.
For a client that is not detected automatically, add this entry to its mcpServers configuration, keeping your other servers:
"ikuna": { "command": "npx", "args": ["-y", "ikuna-mcp"] }
For clients such as Claude Desktop, Claude Code, and Cursor, a complete JSON configuration is:
{
"mcpServers": {
"ikuna": {
"command": "npx",
"args": ["-y", "ikuna-mcp"]
}
}
}
For Codex, add this to ~/.codex/config.toml:
[mcp_servers.ikuna]
command = "npx"
args = ["-y", "ikuna-mcp"]
startup_timeout_sec = 30
Restart or reconnect your MCP client after saving. Ask it to check Ikuna's health, then ask about your workspace. Your available tools depend on the capabilities enabled in Ikuna.
The first run downloads this small package from npm. Later runs use npm's cache. If your client cannot find npx, use the full executable path reported by command -v npx as command and ensure Node.js is on that client's PATH.
This package runs locally on macOS. It requires an Ikuna build that includes the MCP helper at Contents/bin/ikuna-mcp.
Custom installation locations are discovered automatically from the running app. To select a particular running bundle explicitly:
"ikuna": {
"command": "npx",
"args": ["-y", "ikuna-mcp", "--app-path", "/Applications/Ikuna.app"]
}
IKUNA_APP_PATH is the equivalent environment variable. A selected bundle must already be running. The optional IKUNA_MCP_CLIENT_ID environment variable is passed through to Ikuna for connection bookkeeping; it does not grant access.
MCP client → npx ikuna-mcp → Ikuna.app/Contents/bin/ikuna-mcp → local XPC bridge → Ikuna
The npm package discovers the running Ikuna bundle and launches its embedded native helper with the client's stdio streams. The native helper provides the signed XPC connection, request deadlines, and per-client protocol sessions. Ikuna remains responsible for tools, workspace data, approvals, and mutations. On the way back to the client, the package repairs the tools/list schema so an optional confirmation field stays optional and strict clients do not reject valid read calls; it changes no request, workspace data, or result. The package has no runtime dependencies, reads no workspace database, and opens no network listener.
The MCP Registry manifest is included as server.json. Maintainers can follow RELEASE.md to publish the npm package and listing together.
FAQs
Stdio bridge to the MCP server included with the Ikuna macOS app
The npm package ikuna-mcp receives a total of 41 weekly downloads. As such, ikuna-mcp popularity was classified as not popular.
We found that ikuna-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.