
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@bosun-sh/ohtools
Advanced tools
Define tool registries with a fluent TypeScript API, explore them without side effects, run them through an Effect runtime, and expose them through MCP or CLI.
Create a new Bun TypeScript app:
npx @bosun-sh/ohtools create my-tools
cd my-tools
bun install
bun run ohtools:list
Or initialize an existing project:
npx @bosun-sh/ohtools init
Both commands install .agents/skills/ohtools so agents can discover Ohtools
project guidance locally.
Projects that do not already include the scaffolded skill can install the shared skill registry entry:
npx skills add https://github.com/bosun-sh/skills --skill ohtools
import { Ohtools, jsonSchema } from "@bosun-sh/ohtools";
export default new Ohtools().tool("hello", {
description: "Return a greeting.",
input: jsonSchema<{ name: string }>({
type: "object",
properties: { name: { type: "string" } },
required: ["name"]
}),
run: ({ name }) => ({ message: `Hello, ${name}` })
});
For modular apps, define tools once and compose hierarchy elsewhere:
import { Effect } from "effect";
import { Ohtools, defineGroup, defineTool, jsonSchema } from "@bosun-sh/ohtools";
const hello = defineTool({
id: "people.hello",
description: "Return a greeting.",
input: jsonSchema<{ name: string }>({
type: "object",
properties: { name: { type: "string" } },
required: ["name"]
}),
run: ({ name }) => ({ message: `Hello, ${name}` })
});
const people = defineGroup({ id: "people", description: "People tools." }, (group) =>
group.tool(hello)
);
const runtime = new Ohtools().group(people).runtime();
const result = await Effect.runPromise(runtime.runTool(hello, { name: "Ada" }));
result.output.message;
FAQs
Bun-first framework for explorable AI tools with MCP and CLI adapters.
The npm package @bosun-sh/ohtools receives a total of 5 weekly downloads. As such, @bosun-sh/ohtools popularity was classified as not popular.
We found that @bosun-sh/ohtools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.