
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
openfoodfacts-mcp
Advanced tools
MCP server for the Open Food Facts API - search, read, and contribute to the world's largest open food database.
Look up a product by name: "How many calories in a Sainsbury's buffalo chicken wrap?" -> searches by name, finds the product, and returns nutrition data.
Look up a product by barcode: "What's in this product with barcode 3017620422003?" -> fetches Nutella's ingredients, Nutri-Score, and nutrition data.
Find healthy options: "Search for breakfast cereals with Nutri-Score A" -> searches with category and nutrition grade filters.
Contribute data: "Add the product name and brand for barcode 12345678" -> creates or updates a product entry on Open Food Facts.
Explore the database: "What brands of organic chocolate are in the database?" -> uses autocomplete and search to explore.
Follow the instructions on install-mcp, which generates the right config for your MCP client (Claude Code, Claude Desktop, Cursor, Cline, VS Code, and more).
Set OFF_USER_AGENT to identify your app (e.g. openfoodfacts-mcp/1.2.0 (you@example.com)). For write operations (adding/editing products, uploading images), also set OFF_USER_ID and OFF_PASSWORD.
| Variable | Required | Description |
|---|---|---|
OFF_USER_AGENT | Yes | User-Agent string, e.g. "AppName/1.0 (email@example.com)" |
OFF_USER_ID | No | Open Food Facts username (for write operations) |
OFF_PASSWORD | No | Open Food Facts password (for write operations) |
OFF_COUNTRY | No | Country subdomain (default: world) |
| Tool | Description | Auth |
|---|---|---|
get_product | Get product info by barcode | No |
search_products_standard | Search with structured filters (brand, category, Nutri-Score) | No |
search_products_lucene | Search with Lucene syntax, negation, and boolean logic | No |
autocomplete | Autocomplete brands, categories, labels, etc. | No |
add_or_edit_product | Add or update a product | Yes |
upload_image | Upload a product image | Yes |
select_image | Select, crop, and rotate an image | Yes |
call_api | Call any OFF API endpoint directly | Depends |
get_api_docs | Get OFF API documentation | No |
Pull requests are welcomed on GitHub! To get started:
npm installnpm run test to run testsnpm run buildVersions follow the semantic versioning spec.
To release:
npm version <major | minor | patch> to bump the versiongit push --follow-tags to push with tagsFAQs
MCP server for the Open Food Facts API
We found that openfoodfacts-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.