
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@aishelf/service
Advanced tools
AIShelf local service for cross-platform file access — server only; see @aishelf/cli for the command-line front door
A lightweight background service that powers AIShelf clients - including the aishelf CLI, the VS Code extension, and other future clients. It acts as a centralized source of workflows, skills, prompts, and rules for all your AI tools across your local machine, handling authentication and registry management so that AIShelf tools can securely access your shared AI resources.
This package isn't meant to be installed or run directly. It's the server half of AIShelf — you set it up via aishelf service install, handled by the CLI.
For installation instructions and documentation, visit aishelf.dev/docs/installation.
MIT
FAQs
AIShelf local service for cross-platform file access — server only; see @aishelf/cli for the command-line front door
The npm package @aishelf/service receives a total of 21 weekly downloads. As such, @aishelf/service popularity was classified as not popular.
We found that @aishelf/service demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.