
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
spiderbrain
Advanced tools
A committed understanding layer for your repo: give it one (create) and read it (blast radius, keystones, MCP server for AI agents). The one command; wraps @spiderbrain/read + @spiderbrain/create.
A committed understanding layer for your repo, and the one command to work with it. A repo
tells an AI agent what the code is; it never tells it what matters, what a change
reaches, or why anything was built the way it was. spiderbrain fixes that.
export SPIDERBRAIN_API_KEY=sb_live_... # https://spiderbrain.ai/dashboard?tab=keys
npx spiderbrain create
Writes a source-free .spiderbrain/ folder and an AGENTS.md block. Commit both.
When a repo has a .spiderbrain/ folder, any agent or developer can use it offline:
npx spiderbrain mcp # an MCP server for Claude Code / Cursor
npx spiderbrain blast src/db.ts # what a change here reaches
npx spiderbrain keystones # the load-bearing files
spiderbrain is a thin dispatcher over two independently installable packages:
@spiderbrain/read — consume: reader,
CLI, MCP server. Zero dependencies.@spiderbrain/create — produce:
fetch your scored brain and write the understanding set.A CI job that only publishes understanding can depend on @spiderbrain/create alone; an MCP
config that only reads can point at @spiderbrain/read. spiderbrain is what you type when
you just want the thing.
MIT.
FAQs
A deterministic context layer for your repo, committed beside the code: blast radius, keystones, and an MCP server that gives agents answers with receipts. The one command; wraps @spiderbrain/read + @spiderbrain/create.
The npm package spiderbrain receives a total of 20 weekly downloads. As such, spiderbrain popularity was classified as not popular.
We found that spiderbrain demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.