
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
MCP server for temp.md — publish agent-made artifacts to one stable link that updates in place
MCP server for temp.md — give agent-made artifacts one stable public link that updates in place.
Publish an HTML, Markdown, CSV, or Mermaid artifact and get a canonical URL like amber-hill-9eb6.temp.md. Push new versions behind the same URL — no re-sharing, ever. Temps expire intentionally when the work goes cold (7-day active window, resets on every update) and can be restored within 7 days of expiry.
Remote — no install
claude mcp add --transport http tempmd https://api.temp.md/mcp
Remote MCP accepts inline UTF-8 or base64 files. Anonymous publishing needs no
credential. To publish directly into an account and use account tools, configure
the connection with Authorization: Bearer <tempmd_key_...>.
Local stdio — best for filesystem access and larger directories
claude mcp add tempmd -- npx -y tempmd-mcp
Cursor / Windsurf / any MCP client — add to your MCP config:
{
"mcpServers": {
"tempmd": {
"command": "npx",
"args": ["-y", "tempmd-mcp"]
}
}
}
No account or API key required — temp.md is anonymous-create-first. Claim a Temp later to keep it.
The remote transport is limited to 10 MiB and 20 inline files per bundle. The stdio package uses local paths and supports the full 50 MiB / 100-file bundle.
| Tool | Local stdio | Remote | What it does |
|---|---|---|---|
publish_temp | ✓ | ✓ | Publish a new artifact and get a stable public URL |
update_temp | ✓ | ✓ | Push a new version behind the same URL |
get_temp_status | ✓ | ✓ | Check lifecycle and restore eligibility |
restore_temp | ✓ | ✓ | Bring a recently expired Temp back at the same URL |
snapshot_temp | ✓ | ✓ | Freeze the current version as a fixed reference |
set_comments | ✓ | ✓ | Toggle pinned visitor comments |
list_temps | ✓ | ✓ | List local project records or account-owned Temps |
recover_update_token | — | ✓ | Rotate and recover a lost scoped update token |
publish_temp and update_temp accept spa_mode: true for client-routed
single-page apps. Leave it off for static sites so missing assets return 404.
Uploads are capped at 10 MB per file, 50 MB per bundle, and 100 files; publish
and update limits are 60/hour/IP and 120/hour/Temp/IP respectively.
publish_temp saves a record (Temp ID, URL, update token, expiry) to a .tempmd file in the project root. Every other tool reads that file automatically, so an agent can update the same Temp across sessions without you managing tokens. Tokens can also be passed explicitly via update_token.
Add .tempmd to .gitignore if the update token shouldn't be shared with everyone who can read the repo.
| Env var | Default | Purpose |
|---|---|---|
TEMPMD_API_URL | https://api.temp.md | Point at a different API (e.g. local dev http://localhost:8787) |
This repo mirrors the packages/mcp package from the temp.md monorepo, where development happens. Issues and feature requests are welcome here.
update_temp over publish_temp when the project already has a Temp for the artifact.FAQs
MCP server for temp.md — publish agent-made artifacts to one stable link that updates in place
We found that tempmd-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.