
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
writulos-mcp
Advanced tools
MCP server for Writulos — generate code documentation inside Cursor, Claude, and any MCP-compatible AI agent.
Official MCP server for Writulos Scribe — generate markdown documentation for your code inside Cursor, Claude Desktop, and any MCP-compatible AI agent.
No install needed. Run directly with npx:
npx writulos-mcp
Or install globally:
npm install -g writulos-mcp
Add this to .cursor/mcp.json in your project root:
{
"mcpServers": {
"writulos": {
"command": "npx",
"args": ["-y", "writulos-mcp"],
"env": {
"WRITULOS_API_KEY": "writ_YOUR_API_KEY"
}
}
}
}
Restart Cursor. Then in the AI chat, ask:
Document all the files in this project using writulos
The generated docs come back in the chat — ask Cursor to save them wherever you
keep documentation. The server itself only writes a run log to
docs/writulos.log (set WRITULOS_OUTPUT_DIR to move it), recording each run
and how many generations you have left this month.
generate_docsGenerate markdown documentation for a single code file.
Inputs:
code (required) — the source codefilename (optional) — e.g. auth.jscontext (optional) — extra context about the filegenerate_docs_batchGenerate markdown documentation for up to 20 files in one request.
Inputs:
files (required) — array of { code, filename?, context? } objectsMIT
FAQs
MCP server for Writulos — generate code documentation inside Cursor, Claude, and any MCP-compatible AI agent.
The npm package writulos-mcp receives a total of 21 weekly downloads. As such, writulos-mcp popularity was classified as not popular.
We found that writulos-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.