
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@bosun-sh/ohtools
Advanced tools
Bun-first framework for explorable AI tools with MCP and CLI adapters.
Define tool registries with a fluent TypeScript API, explore them without side effects, run them through an Effect runtime, and expose them through MCP or CLI.
Use the published
@bosun-sh/ohtools
package for npm-backed CLI, install, and version operations.
Create a new Bun TypeScript app:
npx @bosun-sh/ohtools create my-tools
cd my-tools
bun install
bun run ohtools:list
Or initialize an existing project:
npx @bosun-sh/ohtools init
Both commands install .agents/skills/ohtools so agents can discover Ohtools
project guidance locally.
Projects that do not already include the scaffolded skill can install the shared skill registry entry:
npx skills add https://github.com/bosun-sh/skills --skill ohtools
import { Ohtools, jsonSchema } from "@bosun-sh/ohtools";
export default new Ohtools().tool("hello", {
description: "Return a greeting.",
input: jsonSchema<{ name: string }>({
type: "object",
properties: { name: { type: "string" } },
required: ["name"]
}),
run: ({ name }) => ({ message: `Hello, ${name}` })
});
For modular apps, define tools once and compose hierarchy elsewhere:
import { Effect } from "effect";
import { Ohtools, defineGroup, defineTool, jsonSchema } from "@bosun-sh/ohtools";
const hello = defineTool({
id: "people.hello",
description: "Return a greeting.",
input: jsonSchema<{ name: string }>({
type: "object",
properties: { name: { type: "string" } },
required: ["name"]
}),
run: ({ name }) => ({ message: `Hello, ${name}` })
});
const people = defineGroup({ id: "people", description: "People tools." }, (group) =>
group.tool(hello)
);
const runtime = new Ohtools().group(people).runtime();
const result = await Effect.runPromise(runtime.runTool(hello, { name: "Ada" }));
result.output.message;
FAQs
Bun-first framework for explorable AI tools with MCP and CLI adapters.
The npm package @bosun-sh/ohtools receives a total of 0 weekly downloads. As such, @bosun-sh/ohtools popularity was classified as not popular.
We found that @bosun-sh/ohtools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.