
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
safe-upgrade-mcp
Advanced tools
MCP server for the Safe Upgrade Decision API: evidence-backed npm upgrade preflight and dependency audits for coding agents, paid per call via x402.
MCP server that gives coding agents two tools backed by the Safe Upgrade Decision API:
upgrade_decision — evidence-backed preflight for upgrading one npm package between two exact versions: version-change class, OSV vulnerabilities for both versions, license, and matching GitHub release notes.package_risk — computed supply-chain risk score (0-100) for one package version: install-script analysis, typosquat detection, publish anomalies, adoption and provenance signals.dependency_audit — audit a whole package.json dependencies map (max 100) in one call: vulnerabilities, deprecations, licenses, and distance behind latest.All endpoints are paid per call via x402 (USDC on Base): $0.02 per risk score, $0.50 per decision, $2.00 per audit. No account or API key — the payment is the authentication.
Requirements: Node 22+, and a wallet private key holding a little USDC on Base mainnet. Payments are signed locally; the key never leaves the MCP server process.
claude mcp add safe-upgrade -e PAYER_PRIVATE_KEY=0xYourKey -- npx -y safe-upgrade-mcp
{
"mcpServers": {
"safe-upgrade": {
"command": "npx",
"args": ["-y", "safe-upgrade-mcp"],
"env": { "PAYER_PRIVATE_KEY": "0xYourKey" }
}
}
}
Without PAYER_PRIVATE_KEY, tools respond with a clear payment-required message instead of results.
| Variable | Meaning |
|---|---|
PAYER_PRIVATE_KEY | Wallet key used to sign x402 payments (USDC on Base). Use a dedicated low-balance wallet. |
SAFE_UPGRADE_API_URL | Override the API base URL (defaults to the public deployment). |
FAQs
MCP server for the Safe Upgrade Decision API: evidence-backed npm upgrade preflight and dependency audits for coding agents, paid per call via x402.
The npm package safe-upgrade-mcp receives a total of 57 weekly downloads. As such, safe-upgrade-mcp popularity was classified as not popular.
We found that safe-upgrade-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.