
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
smallprint-mcp
Advanced tools
Read the Small Print record from inside an agent: an MCP server with four read-only tools for the small print of MCP servers, skills and plugins.
Small Print as an MCP server: four read-only tools over the public record of the tool descriptions, schemas and instructions of MCP servers, agent skills and plugins, hashed every version, diffed between versions, every change graded by a printed rule, public advisories joined by version.
{ "mcpServers": { "smallprint": { "command": "npx", "args": ["-y", "smallprint-mcp"] } } }
Tools:
lookup_entry(name): what the record holds for one entry.changes_since(name, since?, min_severity?): the releases that changed the small print, with each diff and the rule behind its grade.advisories_for(name, version?): the advisories that name it, attributed to their sources, with version ranges.changed_since_approval(name, approved): yes or no, before use: has the small print moved since the version, content hash or date that was reviewed. Answers start with UNCHANGED, CHANGED or UNKNOWN.Names: npm:@scope/name, pypi:name, mcp-registry:io.github.owner/server, skills.sh:owner/repo/skill, oci:ghcr.io/owner/image; a bare name is read as npm.
The server reads https://smallprint.dev/api and nothing else. No account, nothing about your machine is sent, and it never calls the tool it looked up. Rate limited to one entry per request; for the whole record see the site. The rules behind every grade: https://smallprint.dev/how-we-grade.
FAQs
Read the Small Print record from inside an agent: an MCP server with four read-only tools for the small print of MCP servers, skills and plugins.
We found that smallprint-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.