
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
upshift-mcp
Advanced tools
Upshift's reference MCP server — site audit, template match, and live pricing as MCP tools.
Upshift's reference MCP server. Three tools, deployed remote, on MCP spec revision 2026-07-28.
It exists to do two jobs at once: be genuinely useful to an agent, and be the worked example a buyer looks at before paying us to build theirs. Every price it quotes is generated from the live store, so it cannot invent one.
https://mcp.upshiftsites.com/mcp
{
"mcpServers": {
"upshift": { "type": "http", "url": "https://mcp.upshiftsites.com/mcp" }
}
}
Or run the same server locally, for clients that spawn a command rather than call a URL. Nothing to clone or build — it is published on npm:
{
"mcpServers": {
"upshift": { "command": "npx", "args": ["-y", "upshift-mcp"] }
}
}
The same binary from a shell. stdio is the default; --http serves the full
Worker on localhost instead:
npx upshift-mcp
| Tool | Does |
|---|---|
upshift_site_audit(url) | Fetches a live page and reports structured data, llms.txt, robots.txt, title and meta budgets, headings, alt-text coverage, HTTPS and document weight, with a 0-100 score and a fix for each finding. |
upshift_template_match(industry, needs?) | Ranks the 14 website template lines against a trade, with live demo links, store links and real prices, and explains why each matched. |
upshift_quote(job_type, scope?) | The real price table for MCP server work and for websites. |
Free and rate limited to 20 calls/minute per IP.
src/
worker.ts Cloudflare entrypoint: routing, origin policy, rate limit
server.ts The three tools; the one place production layers are applied
audit.ts Audit rules — pure, so every rule is testable without a network
safe-fetch.ts The SSRF guard for the one tool that takes a caller's URL
match.ts Template matching
services.ts What we charge for MCP work
catalog.generated.ts Template lines + prices, generated from the store
landing.ts The page a human gets at /
evals/ 12 qa_pairs, run over the real protocol
test/ 32 tests: protocol conformance + the pure logic
npm install
npm run dev # http://127.0.0.1:8788/mcp
npm run ci:verify # typecheck + tests + evals
wrangler dev needs macOS 13.5+ and will not boot on the build machine, so
npm run dev serves the production src/worker.ts on Node against an
in-memory KV. Same handler, same routes, same tools — not a second
implementation. Deployment is still wrangler deploy.
Prices come from ../upshift-agency-site/src/data/store.ts. After changing
them there:
npm run gen:catalog
Live since 2026-08-16 at https://mcp.upshiftsites.com/mcp. KV namespace
and custom domain are provisioned; npm run deploy ships a new version.
com.upshiftsites/mcp, published active against
the DNS-verified namespace.upshift-mcp —
npx upshift-mcp runs this same server locally.In docs/VALIDATION.md — what is verified, what is not, and the four real bugs the eval suite caught during the build (one of them a security bypass). That document is the argument for shipping evals alongside a server, which is the part of this we sell.
MIT. Lift anything useful. If you would rather we built and ran it for you, that is at https://upshiftsites.com/store/mcp-server-service/.
FAQs
Upshift's reference MCP server — site audit, template match, and live pricing as MCP tools.
The npm package upshift-mcp receives a total of 34 weekly downloads. As such, upshift-mcp popularity was classified as not popular.
We found that upshift-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.