
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
syncpen-mcp
Advanced tools
Connect Claude Code (or any MCP client) to your Syncpen workspace — the writing workspace your AI can actually write in. Your agent can search, read, draft, suggest, comment, organize, and publish in the same live documents you edit.
Don't have an account yet? Create one free at syncpen.io.
Add to your MCP configuration file (~/.mcp.json or project-level .mcp.json):
{
"mcpServers": {
"syncpen": {
"command": "npx",
"args": ["-y", "syncpen-mcp"],
"env": {
"SYNCPEN_API_KEY": "sp_your_api_key_here"
}
}
}
}
That's it! Claude Code will automatically download and run the MCP server.
| Tool | Description |
|---|---|
syncpen_search | Search documents by title and body content (full text) |
syncpen_read | Read a document's content as markdown |
syncpen_list_folders | List all folders |
syncpen_list_documents | List documents, optionally by folder |
syncpen_create | Create a new document — personal by default, or in a team space via teamId |
syncpen_update | Update a document's title and/or content |
syncpen_suggest_edit | Propose an edit as a pending suggestion a human accepts/rejects (doc unchanged until accepted) |
syncpen_list_suggestions | List a document's pending (or all) suggestions |
syncpen_list_comments | Read comment threads (with replies, line numbers, authors) |
syncpen_reply_comment | Reply to a comment thread (signed, notifies @mentions) |
syncpen_resolve_comment | Mark a comment thread resolved |
syncpen_move_document | Move a document into a folder, or to the root |
syncpen_delete_document | Delete a document (moved to trash) |
syncpen_create_folder | Create a folder (optionally nested) |
syncpen_rename_folder | Rename a folder |
syncpen_move_folder | Move a folder under a new parent, or to the root |
syncpen_delete_folder | Delete a folder and its contents (moved to trash) |
syncpen_publish | Publish a document to WordPress, Ghost, or Sanity |
syncpen_list_connections | List connected CMS targets and their connectionIds — personal by default, or scoped to a team via teamId/documentId |
syncpen_list_teams | List your team spaces (id, name, role, member count) |
syncpen_recent_changes | A time-ordered feed of who created/edited/trashed which documents, and when |
syncpen_related | Given a document, suggest what else to read — blends co-access (docs worked on together) with the /editor links |
syncpen_drive_list_files | List/search files in the user's connected Google Drive |
syncpen_drive_read_file | Read a Drive file's content (Google Docs and plain text files only) |
syncpen_news_search | Search recent world news via the user's connected World News API key |
syncpen_slack_list_channels | List public channels in the user's connected Slack workspace |
syncpen_slack_read_channel | Read a public Slack channel's recent message history |
syncpen_notion_search | Search pages in the user's connected Notion workspace |
syncpen_notion_read_page | Read a Notion page's top-level content |
Once configured, ask Claude Code:
For contributing or running from source:
git clone https://github.com/airbuzz/syncpen-mcp.git
cd syncpen-mcp
npm install
npm run build # or: npm run dev (watch mode)
Point your MCP config at the built entry (node /path/to/syncpen-mcp/dist/index.js). It uses the production API by default; set SYNCPEN_API_URL only to target a local instance.
MIT
FAQs
MCP server for SyncPen - connect Claude Code to your SyncPen documents
The npm package syncpen-mcp receives a total of 32 weekly downloads. As such, syncpen-mcp popularity was classified as not popular.
We found that syncpen-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.