
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@archstone/init
Advanced tools
Turn an existing API into a compiling Archstone CDL manifest: a provenance-carrying draft model, pure YAML emission, a closed compile loop, and an IR-level diff harness. No LLM, on any path.
Capability inference from an existing API — reads an OpenAPI document, asks the questions no spec can answer, and drafts a Capability Definition Language (CDL) manifest that the real compiler has already compiled. It writes nothing at all if that manifest does not compile.
Part of Archstone, an open-source
Capability Platform: a company describes what it can do in CDL (business only, no
integration code); Archstone compiles that to a target-agnostic IR; an emitter turns the IR
into tools an AI agent can discover and call. This package is the onboarding path into that
pipeline — most users should install @archstone/cli
and run archstone init, rather than depending on this package directly.
npm install -g @archstone/cli
archstone init path/to/openapi.yaml --out manifest --company acme --domain catalog
The one answer it never guesses is effect — read, write or irreversible is the
difference between looking up a price and charging a card, and no spec says which. Where a
response could honestly be read two ways (which array in a payload is the actual result, and
which is diagnostics?), it asks rather than picking. With --probe it will also make one
read-only call to your real backend and record a genuine fixture, so archstone verify has
something true to replay later.
See the main repository README for
the full CDL format, worked examples, and a GIF of init running end to end against a demo
spec.
The root export (@archstone/init) is pure — no node:fs, no HTTP, no terminal, no clock. It
carries the draft model and the OpenAPI adapter, and derives every fact mechanically from the
source or a human answer, never from an LLM: the same input produces the same output on every
run. @archstone/init/loop is the only entry point that touches the filesystem — it owns the
closed compile loop that validates a draft before anything is written.
Apache-2.0
FAQs
Turn an existing API into a compiling Archstone CDL manifest: a provenance-carrying draft model, pure YAML emission, a closed compile loop, and an IR-level diff harness. No LLM, on any path.
The npm package @archstone/init receives a total of 1,290 weekly downloads. As such, @archstone/init popularity was classified as popular.
We found that @archstone/init demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.