
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@codragraph/harness
Advanced tools
Auto-tuned harnesses for AI agents — Meta-Harness algorithm with Pareto search over (accuracy, tokens, latency)
Auto-tuned harnesses for AI agents — Meta-Harness Algorithm 1 with Pareto search over (accuracy, tokens, latency).
Built on top of @codragraph/cli MCP tools (graph-aware code intelligence and FeatureCluster context packs) and works with any inference provider (Claude, Codex, OpenCode, OpenAI, Anthropic, Gemini, ...).
Developer preview. The package ships with single-proposer search, multi-role swarm search (Explorer + Exploiter + Critic), versioned recipe memory keyed on graph snapshots, and CLI / MCP entry points.
See RFC.md for the full design.
A harness is the code around a fixed base model that decides what to store, retrieve, and present at each step. Different harnesses produce different (accuracy, token-cost, latency) tradeoffs for the same task family.
codragraph-harness search runs an outer optimization loop:
zero-shot, few-shot, graph-aware).(accuracy, tokens, latencyMs).Reference: Meta-Harness paper, arXiv 2603.28052.
codragraph-harness search \
--task ./tasks/codebase-qa/tasks.json \
--seeds zero-shot,few-shot,graph-aware \
--iterations 20 \
--proposer claude-code \
--output ./runs/2026-04-29/
import { search } from "@codragraph/harness";
const frontier = await search({
taskSet: "./tasks/codebase-qa/",
iterations: 20,
proposer: "claude-code",
});
The same runtime is exposed as harness_run, harness_swarm_run, and
harness_recipes_* MCP tools from @codragraph/cli and via
@codragraph/sdk.
Install @codragraph/harness when you are optimizing agent behavior over a
task family. Pair it with:
| Pair with | Why |
|---|---|
@codragraph/cli | Supplies indexed repos, MCP tools, FeatureCluster packs, and graphstore snapshots |
@codragraph/sdk | Provides the programmatic graph client used by custom harness runners |
@codragraph/compress | Reduces prompt size when a harness loads large feature context packs |
Apache-2.0. You can use, modify, redistribute, bundle, and host this package commercially, subject to the Apache-2.0 notice and attribution requirements.
FAQs
Auto-tuned harnesses for AI agents — Meta-Harness algorithm with Pareto search over (accuracy, tokens, latency)
The npm package @codragraph/harness receives a total of 13 weekly downloads. As such, @codragraph/harness popularity was classified as not popular.
We found that @codragraph/harness demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.