
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
Zread.ai MCP Server - 连接 zread.ai 文档平台的 MCP 服务器,让 AI 助手能够阅读 GitHub 仓库文档、搜索代码、与仓库 AI 对话。
连接 Zread.ai 文档平台的 MCP 服务器,让 AI 助手能够阅读 GitHub 仓库文档、搜索代码、与仓库 AI 对话。
💡 提示 AI:这是一个 MCP (Model Context Protocol) 服务器,提供 9 个工具用于代码仓库分析。支持 Python 和 Node.js 两种实现,可通过
npx或uvx一行命令运行。核心功能包括文档查询、仓库搜索、AI 问答。
uvx zread-mcp
npx zread-mcp
# uvx (Python)
uvx --env ZREAD_TOKEN=your-token zread-mcp
# npx (Node.js) - Windows
set ZREAD_TOKEN=your-token && npx zread-mcp
# npx (Node.js) - macOS/Linux
ZREAD_TOKEN=your-token npx zread-mcp
uvx zread-mcp --transport http --port 3000
npx zread-mcp --transport http --port 3000
# uvx 从 PyPI 运行(推荐)
uvx zread-mcp
# uvx 从 GitHub 仓库运行
uvx --from git+https://github.com/ejfkdev/zread-mcp.git zread-mcp
# uv 运行远程脚本
uv run https://raw.githubusercontent.com/ejfkdev/zread-mcp/main/zread_mcp_server.py
# pipx 从 GitHub 运行
pipx run --spec git+https://github.com/ejfkdev/zread-mcp.git zread-mcp
# pipx 安装到本地
pipx install git+https://github.com/ejfkdev/zread-mcp.git
zread-mcp --transport http
# 本地运行
python zread_mcp_server.py
# pnpm
pnpm dlx ejfkdev/zread-mcp
# bun
bunx ejfkdev/zread-mcp
# 全局安装
npm install -g ejfkdev/zread-mcp
zread-mcp-server --transport http
{
"mcpServers": {
"zread": {
"command": "npx",
"args": ["-y", "zread-mcp-server"],
"env": {
"ZREAD_TOKEN": "your-token"
}
}
}
}
{
"mcpServers": {
"zread": {
"command": "uvx",
"args": ["--env", "ZREAD_TOKEN=your-token", "zread-mcp"]
}
}
}
部分高级功能(AI 问答、文件获取)需要 ZREAD_TOKEN:
prompt('复制token', JSON.parse(localStorage.getItem('CGX_AUTH_STORAGE')).state.token)
--transport {stdio,http,sse} 传输协议 (默认: stdio, http/sse 等价)
--host HOST HTTP 模式主机 (默认: 127.0.0.1)
--port PORT HTTP 模式端口 (默认: 3000)
--token TOKEN ZREAD_TOKEN
--no-token 强制无 Token 模式
-h, --help 显示帮助
| 工具 | 需要 Token | 说明 |
|---|---|---|
| fetch_documentation_page | 否 | 获取文档页面 |
| search_documentation | 否 | 搜索文档 |
| get_documentation_outline | 否 | 获取文档大纲 |
| discover_repositories | 否 | 发现推荐仓库 |
| find_repositories | 否 | 搜索仓库 |
| get_trending_repositories | 否 | 热门仓库榜单 |
| check_repository_status | 否 | 检查仓库状态 |
| ask_repo_ai | 是 | AI 智能问答 |
| fetch_repository_file | 是 | 获取源代码文件 |
# 克隆仓库
git clone https://github.com/ejfkdev/zread-mcp.git
cd zread-mcp
# Python 测试
python zread_mcp_server.py --test
# Node.js 测试
node zread-mcp-server.js --test
MIT License
FAQs
Zread.ai MCP Server - 连接 zread.ai 文档平台的 MCP 服务器,让 AI 助手能够阅读 GitHub 仓库文档、搜索代码、与仓库 AI 对话。
The npm package zread-mcp receives a total of 19 weekly downloads. As such, zread-mcp popularity was classified as not popular.
We found that zread-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.