
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
marklayer-mcp
Advanced tools
MCP server that pipes MarkLayer element feedback into any coding agent (Claude Code, Codex, OpenCode, Cursor, Windsurf, Cline).
MCP server that pipes MarkLayer element-level feedback straight into your coding agent.
Point at any element on any webpage in the browser, type "make this red", hit Send. Tell your coding agent "drain MarkLayer" — it acts.
Works with Claude Code, Codex CLI, OpenCode, Cursor, Windsurf, Cline, and any other MCP-compatible agent.
npx -y marklayer-mcp setup
The wizard opens your browser, the MarkLayer extension auto-pairs the session — no token to paste — then writes the right MCP config to every coding agent installed on your machine. Same flow as wrangler login or stripe login.
Restart your coding agent(s) afterward to load the new MCP server.
Skip the browser pairing by setting the token explicitly:
MARKLAYER_TOKEN=ml_… npx -y marklayer-mcp setup
Get the token from the extension's Connect coding agent dialog → Show advanced.
If you'd rather edit each agent's config by hand, the snippets are at https://marklayer.app/agents.
| Variable | Purpose |
|---|---|
MARKLAYER_TOKEN | Optional. Skips browser pairing. Format ml_…. |
MARKLAYER_BASE_URL | Optional. Override API origin (default: marklayer.app) |
FAQs
MCP server that bridges MarkLayer annotations to AI coding agents.
The npm package marklayer-mcp receives a total of 121 weekly downloads. As such, marklayer-mcp popularity was classified as not popular.
We found that marklayer-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.