
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
MCP server that finds coupon codes for any online store. Remote endpoint: https://mcp.trypinchy.com/mcp
(Streamable HTTP, no auth).
Shopping in a browser yourself? The same codes, tried for you at checkout: Pinchy – Coupon Finder & Auto Apply for Chrome.
{ "mcpServers": { "pinchy": { "type": "http", "url": "https://mcp.trypinchy.com/mcp" } } }
Claude Code: claude mcp add --transport http pinchy https://mcp.trypinchy.com/mcp
Clients that only speak stdio can run the npm package instead:
{ "mcpServers": { "pinchy": { "command": "npx", "args": ["-y", "pinchy-mcp"] } } }
find_coupons({ store, limit? }) — store is a domain or any URL on the store; limit defaults to 10 (max 50).
Returns { domain, storeName?, coupons: [{ code, description?, expiresAt?, successCount?, lastWorkedAt? }] },
ordered by how likely a code is to work. An unknown store returns an empty list.
pnpm install
pnpm dev # http://127.0.0.1:4020/mcp
pnpm test
Config is read from the environment, see .env.example. The process binds to 127.0.0.1 and trusts
CF-Connecting-IP for rate limiting, so expose it only through a proxy that sets that header.
Privacy: the server receives a store domain and nothing else. https://api.trypinchy.com/v1/ext/privacy
FAQs
MCP server that finds working coupon codes for any online store.
We found that pinchy-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.