
Security News
6 AppSec CTOs Debate Open Source Supply Chain Security at Black Hat
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.
@archstone/runtime
Advanced tools
Runtime (#5 Registry, #7 MCP emitter): list/resolve tools over IR, serve over stdio.
Runtime — the capability Registry (list/resolve tools over the IR) and the MCP emitter:
lowers IR tools to MCP tools/list + typed outputSchema, dispatches tools/call through
a binding's connector and response mapping, and serves the result over stdio (or any
transport, e.g. Streamable HTTP on Cloudflare Workers).
Part of Archstone, an open-source
Capability Platform. This package is the third stage of the compiler pipeline
(schema → compiler → runtime → cli) — most users should install
@archstone/cli instead of depending on
this package directly.
Apache-2.0
FAQs
Archstone runtime — a capability registry over compiled IR, and the MCP emitter that serves it as agent-callable tools over stdio or HTTP.
The npm package @archstone/runtime receives a total of 1,292 weekly downloads. As such, @archstone/runtime popularity was classified as popular.
We found that @archstone/runtime demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.

Research
/Security News
Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.