
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
The Model Context Protocol server for Kibi. It exposes a repository's branch-local Kibi knowledge base to coding agents as kb_* tools: search and query, modeling prose into typed facts, compiling and applying approved plans, upserts with dry runs, gap and coverage analysis, and validation with kb_check.
Install it in your repository alongside the CLI and core (Node.js 22+):
npm install --save-dev kibi-core kibi-cli kibi-mcp
npm exec -- kibi init
Every client starts the same project-local stdio server, with the repository as the working directory:
npx --no-install kibi-mcp
For example:
claude mcp add --scope project kibi -- npx --no-install kibi-mcp
codex mcp add kibi -- npx --no-install kibi-mcp
Cursor, VS Code, OpenCode and other MCP clients use command: npx with args: ["--no-install", "kibi-mcp"]. See Connect an agent for per-host configuration and the optional host plugins, and the MCP reference for every tool.
AGPL-3.0-or-later
FAQs
Model Context Protocol server for Kibi knowledge base
The npm package kibi-mcp receives a total of 975 weekly downloads. As such, kibi-mcp popularity was classified as not popular.
We found that kibi-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.