
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Sync your local Markdown specs with mdspec from the terminal. No editor required.
Option A — npm (requires Node.js 18+)
npm install -g mdspec-cli
Option B — Standalone binary (no Node.js) Download from GitHub Releases:
mdspec-macos-arm64mdspec-macos-x64mdspec-win-x64.exePut the file in your PATH. On macOS: chmod +x mdspec-macos-arm64.
Check it works:
mdspec whoami
You’ll see “Not signed in” until you log in.
Browser (recommended)
Opens mdspec in your browser; you sign in there and the CLI gets your token automatically.
mdspec login
Email + password
Sign in without a browser:
mdspec login --email you@example.com --password yourpassword
CI / scripts
Use a token (e.g. from a secret):
mdspec login --token YOUR_ACCESS_TOKEN
Or set MDSPEC_TOKEN=YOUR_ACCESS_TOKEN in the environment; then all commands use it and login/logout don’t change it.
Sign out
mdspec logout
From your repo root (or the folder that contains your specs):
mdspec init
You’ll be asked for:
my-company)product-docs).md specs live (default: current directory)This creates .mdspec/config.json. To skip prompts (e.g. in scripts):
mdspec init --org my-company --project product-docs --root docs/specs
mdspec status
Shows:
.md files not yet trackedmdspec track docs/auth.md
Then upload it:
mdspec sync docs/auth.md
First sync creates the spec on mdspec; later syncs upload new revisions.
mdspec sync docs/auth.md
mdspec sync --all
--force).--summary "Short description" for the revision, --force to upload even when the local hash matches.mdspec pull docs/auth.md
mdspec pull --all
Overwrites the local file with the latest spec content. If you have local changes, the command fails unless you use --force (and --yes to skip the overwrite prompt).
mdspec list
Shows two groups:
Pick from a list:
mdspec link
By slug:
mdspec link onboarding --path docs/onboarding.md
--path skips the “Save as” prompt. Use --yes to overwrite an existing file without being asked.
mdspec open # project page
mdspec open docs/auth.md # that spec’s page
These work with any command:
| Option | Description |
|---|---|
--json | Print machine-readable JSON instead of human-readable text |
--config <path> | Use a different config file |
--api <url> | Use a different API base (default: https://mdspec.dev/api) |
Examples
mdspec status --json
mdspec list --json
mdspec sync --all --json
Use --json in scripts and combine with jq or your own tooling.
mdspec untrack docs/old-spec.md
You’ll be asked to confirm. This only removes the file from the CLI’s tracking list; it does not delete the file on disk or the spec on mdspec.
| Goal | Command |
|---|---|
| Sign in | mdspec login |
| Sign out | mdspec logout |
| Who’s signed in | mdspec whoami |
| Link folder to project | mdspec init |
| What’s tracked / changed | mdspec status |
| Track a file | mdspec track <file> |
| Upload (sync) | mdspec sync [file] or mdspec sync --all |
| Download latest | mdspec pull [file] or mdspec pull --all |
| List remote specs | mdspec list |
| Download remote-only spec | mdspec link [slug] or mdspec link |
| Open in browser | mdspec open [file] |
| Untrack a file | mdspec untrack <file> |
sync or pull when you want..md files are tracked.MDSPEC_TOKEN and mdspec init --org ... --project ... --root ... plus mdspec sync --all --json for headless pipelines.mdspec login again.FAQs
CLI tool for syncing local Markdown files with mdspec
The npm package mdspec-cli receives a total of 0 weekly downloads. As such, mdspec-cli popularity was classified as not popular.
We found that mdspec-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.