
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
patchnote-agent
Advanced tools
This npm package is the installer wrapper for PatchXNote Agent. It downloads the matching native patchnote CLI binary from GitHub Releases, verifies checksums.txt, and installs it into a user-writable directory.
npx -y patchnote-agent@0.1.3 install --print-config
PatchXNote Agent runs a local stdio MCP server:
patchnote mcp serve
Agent V1 is read-only. It stores credentials in the OS-native keychain when available, exposes safe PatchXNote account projections through dedicated /v1/agent/** APIs, and does not expose raw audio, full transcripts, SK, full MAC values, hardware write actions, payment flows, or Admin APIs.
For full installation, MCP setup, security notes, and troubleshooting, read the GitHub documentation:
FAQs
Installer wrapper for the PatchXNote Agent CLI and local MCP server.
The npm package patchnote-agent receives a total of 10 weekly downloads. As such, patchnote-agent popularity was classified as not popular.
We found that patchnote-agent demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.