
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
srift-transfer
Advanced tools
Secure P2P file transfer, encrypted chat and MCP server for AI coding agents. Zero accounts, zero tokens, end-to-end encrypted. Works with Claude, Cursor, Continue, Zed, Codex and any MCP client.
Secure peer-to-peer file transfer and encrypted chat for AI agents and humans. Ships an MCP (Model Context Protocol) server so Claude, Cursor, Continue, Zed, Codex and any MCP-compatible agent can send and receive files directly — no accounts, no API keys, no cloud storage.
npm install -g srift-transfer
Coding agents can read and write files in their own sandbox, but they have no good way to get a file to you — or to another machine. Attaching, uploading and pasting all break down for anything large or binary.
SRIFT gives an agent one tool call that produces a link a human can open:
srift_quick_share({ filepath: "./build/report.pdf" })
→ https://srift.app/d/a1b2c3d
No signup on either end. Payloads are AES-256-GCM encrypted end-to-end; keys derive locally from the session ID (plus an optional room secret) and are never sent to the server.
npm install -g srift-transfer
srift quick-share ./report.pdf # public link, open anywhere
srift session start # long-lived room, host approves joins
srift status # daemon + session + transfers
srift doctor # full health check
Register SRIFT with any MCP client:
srift install-mcp # print config snippets for every supported IDE
srift install-mcp --auto # write directly into Claude Desktop's config
Or configure it manually:
{
"mcpServers": {
"srift": {
"command": "srift",
"args": ["mcp"]
}
}
}
Works in Claude Desktop, Claude Code, Cursor, Continue, Zed, Codex, Windsurf and any client speaking MCP 2025-06-18 (backward compatible with 2024-11-05).
| Transport | Endpoint |
|---|---|
| stdio | srift mcp |
| Streamable HTTP | POST http://127.0.0.1:3822/mcp |
| SSE (legacy) | GET http://127.0.0.1:3822/mcp/sse |
| Tool | Purpose |
|---|---|
srift_quick_share | One-step public download link for a file |
srift_start_session | Open a session; returns 7-character ID + URL |
srift_join_session | Request to join a session |
srift_session_status | Current session, peers, state |
srift_close_session | Tear down the session |
srift_send_file | Offer a file to joined peers |
srift_accept_transfer | Accept an incoming offer |
srift_list_transfers | List active transfers |
srift_approve_join / srift_reject_join / srift_kick_user | Host controls |
srift_send_chat / srift_chat_history | Encrypted chat |
srift_read_state | Read workspace state |
Resources: srift://session/status, srift://transfers/active, srift://chat/messages, srift://workspace/state, srift://docs/quickstart
Prompts: send_file_to_user, receive_file_from_user, start_collab_session
Sessions srift session start | join <id> | status | close
Transfers srift quick-share <file> [--ttl 15m] [--once] [--max-downloads N]
srift send <file> | receive <file-id> | list | monitor <file-id>
Public srift pubshare list | add <file> | revoke <token>
Host srift approve <id> | reject <id> | kick <id>
Chat srift chat send "<msg>" | chat history
Agents srift install-mcp [--auto] | bootstrap [dir] | info
Daemon srift daemon start | stop | restart | status
Maintenance srift status | doctor | logs | version | self-update | reset | config
Every command accepts --json for machine-readable output — intended for agent use.
webtorrent is an optional dependency — it pulls native modules that don't build everywhere. If it's unavailable, SRIFT logs a warning and falls back to WebSocket transfer; every other feature keeps working.
| Variable | Default | Purpose |
|---|---|---|
SRIFT_DAEMON_PORT | 3822 | Daemon port |
SRIFT_NO_UPDATE_CHECK | – | Set to 1 to disable update checks |
Config file: ~/.srift/config.json (srift config get|set|delete)
Node.js >= 20.
llms.txt — https://srift.app/llms.txtMIT
FAQs
Send any file as a download link from the CLI or an AI agent (MCP server). Encrypted P2P file transfer and chat, AgentNet for agent-to-agent. No account.
The npm package srift-transfer receives a total of 439 weekly downloads. As such, srift-transfer popularity was classified as not popular.
We found that srift-transfer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.