
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
mdedit-cli
Advanced tools
mdedit-cliOfficial command-line interface for mdedit.ai.
Links:
npm install -g mdedit-cli
All APIs require authentication. Create an API key here:
mdedit config login --api-key <YOUR_KEY>
Config is stored at ~/.mdedit-cli/config.json.
MDEDIT_API_URL (default: https://apiv2.mdedit.ai)MDEDIT_API_KEYMDEDIT_WORKSPACE_IDMDEDIT_CONFIG_DIR (override config directory)mdedit --help
mdedit info
mdedit health
Apply a unique text replacement through the same article session used by live collaborators:
mdedit article edit <articleId> --replace "old text" --with "new text"
mdedit article edit <articleId> --ops-file ops.json --format json
An ops file is a non-empty JSON array of replace, insert, or delete operations with
quote, heading, section, or range anchors. The command exits 2 when an anchor is missing,
3 when an anchor is ambiguous, and 4 when an edit conflict is reported. In JSON mode,
the result or typed error is the only value written to stdout.
Review agents can comment and suggest with articles:read,reviews:write; accepting a
suggestion also requires articles:write because it changes article text.
mdedit review list <articleId> --status open --format json
mdedit review add <articleId> --quote "claim" --body "Needs a source."
mdedit review reply <articleId> --thread <reviewId> --body "Fixed."
mdedit review resolve <articleId> --thread <reviewId>
mdedit suggest <articleId> --quote "teh" --replace "the" --note "Typo"
One-shot review commands use the REST review resources directly, so listing or commenting
does not open a metered collaboration WebSocket. Mutations always use the
server-authoritative review-commands API.
Keep an article session open and stream newline-delimited JSON for agent loops:
mdedit article watch <articleId>
mdedit article watch <articleId> --workspace <workspaceId> --agent claude-code
mdedit article watch <articleId> --poll-interval 5000
Each stdout line is one complete JSON event. The stream starts with session.ready,
then reports article changes, review history events, and review snapshots. Ctrl+C
closes the live session cleanly. Non-collaborative articles use REST polling.
The CLI is designed to be used by AI agents without modification.
--format json for machine-readable output (human messages go to stderr)--yes on destructive commands to skip confirmation--file - (stdin) or --content-only (stdout)A comprehensive agent skill document is included with the CLI. It covers all commands, flags, workflows, and error handling in a format optimised for AI agents (Claude Code, Cursor, GitHub Copilot, etc.).
# View the skill
mdedit skill show
# Install the skill into all detected agent config files
mdedit skill install
# Install into a specific tool only
mdedit skill install --target claude # → CLAUDE.md
mdedit skill install --target cursor # → .cursor/rules/mdedit.mdc
mdedit skill install --target codex # → .github/copilot-instructions.md
# Install to home-directory (global) targets
mdedit skill install --global
An openclaw.json plugin manifest is included in the package. It defines every CLI tool as a structured, machine-readable entry that OpenClaw-compatible agents can load directly.
# Find the plugin manifest
node -e "console.log(require.resolve('mdedit-cli/openclaw.json'))"
FAQs
Command-line interface for mdedit.ai.
The npm package mdedit-cli receives a total of 379 weekly downloads. As such, mdedit-cli popularity was classified as not popular.
We found that mdedit-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.