
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
sharecut-mcp
Advanced tools
MCP server for ShareCut — create short links, re-point them after the QR is printed, read click analytics, and generate QR codes (free, no API key) from Claude, Cursor or any MCP client.
MCP server for ShareCut — generate QR codes, create trackable short links, re-point them after the QR is printed, and read their click analytics from Claude, Cursor, or any MCP client.
QR codes, link expansion and short-code checks are free and need no account.
Remote server, nothing to install:
claude mcp add --transport http sharecut https://sharecut.site/mcp
Or run this package over stdio:
npx sharecut-mcp
{
"mcpServers": {
"sharecut": {
"command": "npx",
"args": ["-y", "sharecut-mcp"],
"env": { "SHARECUT_API_KEY": "sc_live_..." }
}
}
}
SHARECUT_API_KEY is optional — leave it out and the three free tools still work.
| Tool | What it does |
|---|---|
create_qr | Renders any URL or text as a QR code: SVG, plus a PNG data URL with format: "png", and an optional hex color. The code is static — the destination is baked into the pattern, so once printed it points there forever. |
expand_short_link | Resolves a sharecut.site short link to its real destination and click count, without opening it. |
check_short_code | Tells you whether a custom short code is still free before you try to claim it. |
The interesting half. All of them act on the account the key belongs to.
update_link — the reason this server existsChanges where an existing short link points. A ShareCut QR encodes the short link, not the destination, so re-pointing the link redirects every copy already printed, shared or stuck on a wall — and the click history comes along.
That difference is the whole point. A poster, a menu, a business card or a product label outlives the URL printed on it. A static QR does not survive a site migration or a campaign change; this one does.
The short code itself is deliberately immutable here: changing it would break every copy already in circulation.
| Tool | What it does |
|---|---|
shorten_url | Creates a short link plus its QR code. Optional customCode, title and utm. Destinations are screened against Google Safe Browsing. |
shorten_urls_bulk | Up to 25 links in one call, with per-item results so one bad URL does not discard the rest. |
list_links | Lists your links with click counts — filter by kind or search term, sort by newest or most clicked. |
get_link | Destination, title, clicks, creation date and UTM settings for one link. |
get_link_analytics | Clicks over time, plus breakdowns by country, device, OS, browser and referrer. |
get_link_qr | The QR code of an existing link, using the artwork saved on it (frames, colours, logo) when there is one. |
delete_link | Permanent, and it releases the short code. Needs an explicit confirm. |
get_account | Plan, entitlements and how much API quota is left this month. Worth calling before a bulk run. |
Create it at sharecut.site/p/profile — API
access is part of the Business plan — then pass it as SHARECUT_API_KEY.
There is no programmatic sign-up: a person creates the key. See auth.md for the full authentication contract.
This package is a thin stdio bridge to https://sharecut.site/mcp. It moves
newline-delimited JSON-RPC to that endpoint and back, which means zero
dependencies (fast npx start) and no upgrades to chase: the tools live on the
server, so new ones reach you without touching your config.
Point SHARECUT_MCP_URL elsewhere to target a different deployment.
MIT
FAQs

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.