
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
Hand a finished implementation from one context to another, in a form an AI agent can act on.
Hand finished work to another context.
Solve something non-trivial in one agent session. Run one command. Open a session in another repo, on another machine, or with a teammate, and the agent there already knows the whole story: the problem, the decisions and why, the steps, how to verify, and what went wrong along the way.
npm i -g passalong
passalong setup # installs the Claude Code capture skill + registers the MCP server
passalong login # optional: sync guides across machines and get share links
/passalong-capture, or
run passalong share yourself.passalong pull <id> in the target repo, or paste the link to any
agent with the Passalong MCP server. The guide lands in its context; it implements, adapting the
parts marked ASSUMES:.passalong done <id> when it landed. passalong promote <id> if it keeps getting pulled.passalong share [file] [--to team[/handle]] publish a guide → id + link; --to hands it to a team or teammate
passalong pull <id|link> fetch a guide into ./.passalong/ (git-ignored) and print it
passalong inbox guides handed to you that you have not pulled yet
passalong board waiting on you, in flight, landed, worth keeping
passalong activity [--all] what happened while you were away; clears unless --all
passalong list [query] your guides and your teams', local and synced
passalong open <id> [--print] view a guide in the browser (or the terminal)
passalong hub open your synced guides in the browser
passalong works <id> you tried it and it holds up
passalong broken <id> <why> you tried it and it does not — the author is told, with your reason
passalong done <id> deprecated: mark consumed
passalong promote <id> deprecated: mark promoted
passalong rm <id> delete a guide locally and from sync
passalong export [dir] dump every guide as plain markdown
passalong login [token] create an account, or attach this machine with a token from your hub
passalong me [--handle H] [--name N] [--email E] who you are to teammates
passalong team current team and its members
passalong team create <name> start a team (you become its owner)
passalong team invite [email] make an invite link (mailed when an email is given)
passalong team join <link> accept an invite
passalong team use <slug> switch the current team
passalong setup install the Claude Code capture skill + register the MCP server
passalong mcp run the MCP server over stdio
passalong version print the installed version (also -v, --version)
A team is the unit of sharing. Members can find, pull, and mark consumed every guide shared to the team; a guide can also be handed to one person, who sees it in their inbox (and by email when the server has mail configured).
passalong me --handle lukman # how teammates address you
passalong team create Khaime # you become owner; "khaime" is now current
passalong team invite ada@example.com # or no email: prints a link to send yourself
passalong team join <link> # on Ada's machine — or she just opens the link
passalong share --to khaime/ada # hand this guide to Ada
passalong inbox # on Ada's side: what was handed to you
passalong activity # back on your side: it landed, and who pulled it
A receiver who tries the work reports back with passalong works <id> or passalong broken <id> <why>.
That is separate from done, which means implemented: a verdict means it actually runs, a failing
one has to say why, and the author sees it on their board and in their inbox.
Sign in at the hub with an email and password, and mint
an API token there for the CLI and MCP servers — named, revocable, and shown once. Your password
never goes near the terminal. passalong login with no arguments still makes an account without
any of that; add an email and password later to be able to sign in from a browser and recover it.
Not everyone who receives a guide implements it. Every guide page has a Verify view
(?view=verify) that leads with Problem, Verification and Gotchas and folds the implementation
away — for a tester or anyone checking the work rather than doing it. Invites are accepted in the
browser, so a teammate needs no terminal to be part of a team.
passalong activity is the other half of the transfer: it tells you when someone pulled a guide
you handed over, when they marked it consumed, and when an invite was taken up. A handoff
addressed to a person is also emailed; a team-wide share is not, because mail nobody is
named in is the first thing people filter out. Guides that keep getting pulled get a nudge to
promote them into the team's small set of maintained references.
passalong setup registers the server with Claude Code. For other clients, run passalong mcp over stdio.
Tools: search_guides, inbox, get_guide, publish_guide (with to), guide_template, set_guide_status.
Plain markdown with frontmatter in ~/.passalong/guides. Yours to edit, grep, and commit.
passalong export dumps everything. Works with no account; passalong login adds sync and share links.
Point at a self-hosted server with PASSALONG_API=https://your-host before passalong login.
FAQs
Hand tasks, bugs and finished work to AI coding agents, and get back a write-up with evidence.
The npm package passalong receives a total of 341 weekly downloads. As such, passalong popularity was classified as not popular.
We found that passalong demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.