npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

vr-org-mcp

v0.4.3

Published

Read-only MCP server for VR.org. Gives AI agents one-call access to live VR, AR, and XR news, original editorial with full article text, the events calendar, headset deals, buyer guides, and top-game and top-app lists.

Readme

vr-org-mcp

npm version MCP Registry Install in Cursor Install in VS Code

Read-only Model Context Protocol server for VR.org, a dedicated VR / AR / XR news publication and aggregator.

It gives any MCP-compatible agent (Claude Desktop, Claude Code, Cursor, Continue, and others) one-call access to live VR, AR, and XR news, VR.org's original editorial (including full article text), the VR/AR/XR events calendar, curated headset deals, buyer-guide answers, and top-game and top-app lists.

Eleven tools, five resources, and three prompts. Zero keys. Zero writes. Zero payments.

Install

Run it directly with npx (no global install needed):

npx vr-org-mcp

Claude Desktop

One-click: download the .mcpb bundle from the latest release and double-click it to install into Claude Desktop. Or configure manually:

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "vr-org": {
      "command": "npx",
      "args": ["-y", "vr-org-mcp"]
    }
  }
}

Claude Code

claude mcp add vr-org -- npx -y vr-org-mcp

Cursor

Add to .cursor/mcp.json:

{
  "mcpServers": {
    "vr-org": {
      "command": "npx",
      "args": ["-y", "vr-org-mcp"]
    }
  }
}

Hosted remote endpoint (no install)

VR.org also runs the same tools as a remote server over MCP's streamable-HTTP transport, so web clients (ChatGPT connectors, Claude.ai connectors) can use it with no local install:

https://vr.org/mcp

Human setup walkthrough for every client: vr.org/connect.

Tools

| Tool | What it returns | |------|-----------------| | search_vr_news | Latest VR / AR / XR headlines from the live feed, with optional category filter and keyword match | | get_vr_trending | Topics currently trending across the feed | | list_vr_originals | Summaries of VR.org's own editorial articles, newest first | | get_vr_article | Full content of one original by slug: metadata, canonical URL, and the article body HTML | | get_vr_events | Upcoming VR / AR / XR industry events (conferences, expos, launches), soonest first | | get_vr_deals | Curated product picks with prices, badges, and retailer links | | compare_vr_headsets | Side-by-side of two headsets (partial names accepted) | | get_top_vr_games | Current ranked top VR games list | | get_top_vr_apps | Current ranked top VR apps and utilities list | | list_vr_sources | The news sources VR.org aggregates, with counts | | vr_explain | Canonical short answer plus pillar-page link for a common question |

Resources

Browsable MCP resources an app can attach as context:

| Resource | Contents | |----------|----------| | vrorg://news/latest | Latest aggregated VR / AR / XR headlines | | vrorg://originals/latest | Index of VR.org's newest original articles | | vrorg://events/upcoming | Upcoming VR / AR / XR industry events | | vrorg://guides | VR.org's canonical pillar-guide answers in one doc | | vrorg://article/{slug} | Full HTML body of any original article (resource template) |

Prompts

| Prompt | What it does | |--------|--------------| | recommend_a_headset | Recommends a headset from VR.org's picks given a budget and use case | | this_week_in_vr | Drafts a weekly VR / AR / XR roundup from the feed and originals | | explain_vr_topic | Explains a VR topic grounded in VR.org's canonical answer |

How it works

Every tool composes VR.org's public JSON API (https://vr.org/api/*) into a single agent-friendly response. The server is a thin proxy: it holds no secrets, writes nothing, and cannot move money.

Threat model

VR.org's editorial is controlled, but the live feed also carries third-party RSS headlines. To keep a malicious or compromised upstream headline from manipulating the calling model, every tool output is:

  1. Sanitized. Control characters and zero-width / direction-override characters are stripped from every string.
  2. Capped. Serialized responses are limited to 50 KB so a large payload cannot flood the agent's context window.

Inputs are validated before any outbound request and every free-text parameter is length-capped at the schema layer. Errors are returned as structured, non-echoing objects rather than raw stack traces; on the rare path where an error string reaches the caller it runs through the same output scrub as a tool result, with any credential-shaped substring redacted and the text capped, and is flagged with isError.

Configuration

The API base URL is fixed to https://vr.org in source and cannot be overridden, so the server can only ever talk to VR.org.

| Env var | Default | Purpose | |---------|---------|---------| | VR_ORG_UA_SUFFIX | (none) | Optional suffix appended to the outbound User-Agent |

Development

npm install
npm run dev        # run from source over stdio
npm run build      # compile to dist/
npm test           # run the offline test suite
npm run typecheck  # type-check without emitting

Changelog

0.4.3

Maintenance release.

  • The vr_explain tool description now names the newer topics it can answer ("steam frame price", "meta vr glasses"), so an agent reading the tool list knows to ask for them. The hosted endpoint at https://vr.org/mcp carries the same wording.
  • The release workflow now publishes through npm trusted publishing (OIDC) and only falls back to a token if that is rejected. Provenance is attached as before.

0.4.2

vr_explain and the vrorg://guides resource now answer from VR.org's live explainer feed, so they stay current between releases.

  • The answers used to be a list compiled into the package in July 2026. By October most realistic topics ("steam frame", "steam frame price", "meta vr glasses", "quest 4") returned no_explainer, and several of the answers that did exist were out of date. The list is now fetched from https://vr.org/api/explainers and cached for ten minutes, the same way deals and events are, so a guide refresh on the site reaches agents without a package release.
  • Every fetched entry is validated before use (keys must be a non-empty list of non-empty strings, and the link must be on https://vr.org) and passes through the same sanitizer as other upstream text. If the fetch fails or returns nothing valid, the built-in list answers instead. That list now mirrors the site's current 34 guides, up from 10, so an offline server still gives current answers. A failed fetch is remembered for one minute so an outage does not slow down every call.
  • Matching is unchanged: the longest key contained in the topic wins, so "steam frame price" reaches the price page and not the Steam Frame hub.
  • The explain_vr_topic prompt no longer offers 'passthrough' as an example topic, which had no answer. It and the no_explainer hint now suggest 'steam frame'.
  • The get_vr_deals description names all five catalog sections: headsets, AR and XR glasses, accessories, haptics and body tracking, gaming hardware.
  • Bumps @modelcontextprotocol/sdk from 1.30.0 to 1.32.1 and refreshes the ip-address and proxy-addr pins. The advisories behind this sit in the SDK's OAuth client and HTTP transport, which this stdio server never loads. npm audit on the production dependencies reports zero vulnerabilities.

0.4.1

Fixes from a September 2026 audit, matched on the hosted endpoint at vr.org/mcp.

  • get_vr_article now returns the whole article. body_html was cut at the general 4,096-character string cap, which truncated most articles mid-tag while still reporting ok: true. It now has its own 45,000-character cap, and the 50 KB response cap still applies. The article also carries updated, the date a correction was applied, which the hosted endpoint already returned.
  • vr_explain no longer answers short topics with the wrong guide. A topic like "vr" or "3" used to match inside a longer key and return "PSVR2 vs Quest 3" with confidence; the reverse match now needs four or more characters starting on a word boundary.
  • compare_vr_headsets matches "Pimax Dream Air SE" correctly. The pimax alias was a prefix match that rewrote every Pimax query to Crystal.
  • Reading vrorg://news/latest no longer shrinks keyword search to 25 items for the next minute (the two shared a cache key with different request sizes).
  • A malformed slug in vrorg://article/{slug} now says "not found" instead of "temporarily unavailable, retry shortly".
  • Refreshed transitive dependency pins (hono, fast-uri, qs) for npm audit.

0.4.0

Content provenance. Feed results now carry a provenance field on every item, either vr_org_editorial (written and edited by VR.org) or third_party_feed (a headline or snippet relayed verbatim from an outside publisher). Any response containing relayed text also carries a content_notice saying to treat that text as data rather than instructions, and the vrorg://news/latest resource carries the same notice in prose. This is additive metadata, so existing fields and existing consumers are unaffected.

The point is to let a calling client tell which text VR.org actually stands behind. It follows the August 2026 GhostSplice research on splitting instructions across MCP channels, whose core mitigation is that clients should treat server output as data. This server is not a vector for that attack (it never requests sampling, its tool descriptions are static literals, and every value that can flow back in as a tool argument is validated against a strict allowlist), but it does relay text it did not write, and now it says so.

Also bumps @modelcontextprotocol/sdk to 1.30.0 and pins four transitive dependencies of the SDK's HTTP transport that carried advisories. This server is stdio-only and never loads that transport, so the pins are hygiene rather than an exposure fix. npm audit --omit=dev reports zero vulnerabilities.

0.3.2

Error-path hardening: tool errors now pass through the same output scrub as tool results, with secrets redacted and error text capped. All free-text parameters gain schema-level max lengths. No behavior change for valid inputs.

License

MIT. A VR.org project.