
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Use Prefab from Claude and other AI agents: list your macOS project templates, create them, and deploy them.
An MCP server for Prefab, so an agent can see your templates and deploy one for you.
"Set up a new client folder for Northwind, autumn campaign, on my Desktop"
| Tool | Does |
|---|---|
list_templates | Every template, what it creates, what it asks for |
describe_template | One template in full: structure, placeholders, actions |
preview_deploy | What a deploy would create, and what values are still missing. Creates nothing |
deploy_template | Creates the folders, filling in the values given |
list_watched_folders | Folders Prefab is watching, and the rules on them |
list_globals | Library-wide placeholders, actions and value presets |
Works with any client that speaks MCP over stdio.
As a bundle - download prefab.mcpb from the
releases page and double-click it. Clients
that install MCP bundles, Claude Desktop among them, bring their own Node, so there is nothing else
to install.
From the command line (Claude Code, and anything with the same idea):
claude mcp add prefab -- npx -y prefab-mcp
In a config file - Cursor, Zed, and most others:
{
"mcpServers": {
"prefab": { "command": "npx", "args": ["-y", "prefab-mcp"] }
}
}
Then switch on Let agents and scripts control Prefab in Prefab's Settings ▸ Permissions. It is off by default; reading your templates works without it, creating and deploying does not.
That switch arrives in Prefab 1.1.6. On an earlier version the reading tools work and the rest say so.
Requires macOS, Prefab installed and opened once, and Node 18+ (except for the .mcpb route).
Prefab is sandboxed and has no network access, so it cannot host anything. This server runs beside
it instead: it reads the library straight out of the app group
(~/Library/Group Containers/group.VFDG327T66.prefab) and asks the app to deploy through the
same prefab:// URL the Finder extension uses. Two consequences worth knowing:
preview_deploy and deploy_template both check
first and say so, rather than leaving a permission dialog on screen that an agent cannot answer.
Grant folders in Prefab, under Settings ▸ Permissions.Nothing here writes to Prefab's library. The app owns those files, and editing them behind its back would be overwritten the next time it saves.
npm test # checks placeholder resolution matches the app's Swift, case for case
npm run try '[["list_templates",{}]]' # call a tool the way a client does
src/resolve.js is a deliberate duplicate of RenamePattern.swift. If you change one, change the
other - npm test compiles the Swift and compares the two.
FAQs
Use Prefab from Claude and other AI agents: list your macOS project templates, create them, and deploy them.
We found that prefab-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.