
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
posecode-mcp
Advanced tools
Model Context Protocol server for Posecode — let any LLM agent validate, ROM-check, and get a render link for a .posecode movement, natively.
A Model Context Protocol server for Posecode.
It gives any MCP-capable agent (Claude Desktop, Cursor, …) a native way to show
movement: learn the .posecode language, validate a movement against healthy
range-of-motion limits, and get a link that animates it as a 3D figure.
This closes the loop the playground left open — no copy-pasting a system prompt or shuttling text between a chat window and the editor.
| Tool | What it does |
|---|---|
posecode_authoring_guide | Returns the Posecode authoring guide (grammar, joints, actions, example) so the model can write valid .posecode. |
validate_posecode | Parses a .posecode document and returns errors plus any range-of-motion safety clamps (the angles that were out of healthy range). |
render_posecode | Validates, then returns a permalink that renders the movement in the Posecode playground. Hand it to the user to watch. |
validate_posecode / render_posecode flag invalid documents as MCP error results so
the model knows to fix and retry.
It's a TypeScript server; run it with tsx
(no build step needed):
npm start -w posecode-mcp # tsx src/stdio.ts
{
"mcpServers": {
"posecode": {
"command": "npx",
"args": ["-y", "tsx", "/ABSOLUTE/PATH/TO/posecode/packages/posecode-mcp/src/stdio.ts"],
"env": { "POSECODE_BASE_URL": "https://posecode.org" }
}
}
}
POSECODE_BASE_URL is optional — it sets the playground that render permalinks
point at (defaults to the hosted playground).
render_posecode builds its links with posecode-share — the same
permalink primitive the playground uses — and validates with
posecode-parser. The server holds no rendering itself; 3D math
runs client-side when the link is opened.
FAQs
Model Context Protocol server for Posecode: let any LLM agent validate, ROM-check, and get a render link for a .posecode movement, natively.
The npm package posecode-mcp receives a total of 63 weekly downloads. As such, posecode-mcp popularity was classified as not popular.
We found that posecode-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.