
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@galaxy-stack/ai-coder-core
Advanced tools
Platform-neutral runtime for the Galaxy AI Coder single agent. Core exception under @galaxy-stack, versioned by the galaxy-blackhole organization. Consumed by galaxy-code (Blackhole CLI), galaxy-vscode-extension, and galaxy-desktop.
Provider-neutral, platform-neutral runtime for the Galaxy AI Coder single agent. The same core is intended for:
galaxy-code v2 — deterministic Node.js CLI laboratory;galaxy-vscode-extension — VS Code host adapters;galaxy-desktop — Tauri host adapters.The single-agent runtime, context manager, prompt assembler, tool registry, approval policy, checkpoint format, trace protocol, lexical retrieval, and completion gate are implemented and covered by deterministic tests.
galaxy-code v2 is the reference conformance host. VS Code and Desktop should
not copy runtime logic; they should implement the same ports and pass the same
host conformance fixtures first.
This package is still pre-integration: only galaxy-code passes the full
conformance gate today. Optional MCP, semantic retrieval, background terminal
sessions, and subagents are outside the current runtime baseline.
Work in progress keeps an explicit semver pre-release tag (x.y.z-alpha.N) and
publishes under the alpha dist tag, so latest never moves on unverified work.
A plain x.y.z is a verified line: it ships only once the 25-prompt
end-to-end flow completes against it, and its fixes are journalled in
galaxy-code/docs/TEST_FAILURE_ANALYSIS.md. 1.0.0 remains the API-stability
milestone; 0.y.z may still change shape before then.
Every behavior- or API-level fix lands in CHANGELOG.d
as a dated fragment (date, time, area, before/after, regression requirement)
and is compiled into CHANGELOG.md at release time. When reading
any audit or live run, compare the recorded packageVersion against
CHANGELOG.md before concluding that a fixed defect recurred.
Publishing is automated through npm trusted publishing (OIDC, no stored npm
token): every push to main runs the conformance gate and
.github/workflows/publish.yml publishes the
package only when package.json carries a version that npm does not have yet.
Pre-release versions publish under the alpha dist tag, so
npm install @galaxy-stack/ai-coder-core@latest only ever lands on a verified
line.
Install the verified line, or track development explicitly:
npm install @galaxy-stack/ai-coder-core
npm install @galaxy-stack/ai-coder-core@alpha
The package is ESM-only and requires Node.js 20 or newer. It does not bundle a model provider, filesystem adapter, command runner, credential store, or UI. Each host supplies those capabilities through typed ports.
AiCoderRunController owns each run lifecycle; one controller may host
multiple distinct run IDs, while every run still has exactly one AI. A host
constructs the adapter set once, passes a complete request to start, observes
typed runtime events, and awaits the handle result. The same request fields
plus a trusted durable checkpoint are used by resume.
import {
AiCoderRunController,
type AiCoderRunDependencies,
type AiCoderRunRequest,
} from "@galaxy-stack/ai-coder-core";
export async function runCoder(
dependencies: AiCoderRunDependencies,
request: AiCoderRunRequest,
) {
const controller = new AiCoderRunController(dependencies);
const handle = controller.start(request);
// A UI may call handle.pause(), handle.cancel(), or
// handle.resolveApproval(requestId, decision) while result is pending.
return await handle.result;
}
Required dependencies are a CodingModelAdapter and an
AiCoderRuntimeToolExecutor. Production hosts should also provide a trusted
run store, trace port, workspace verifier, and output-spill adapter when their
completion requirements enable those guarantees. galaxy-code is the
reference implementation and conformance test host.
| Export | Purpose |
|---|---|
AiCoderRunController | Start, resume, pause, cancel, and resolve approvals for a run. |
AiCoderRunRequest / AiCoderRunResult | Typed task input, budgets, completion requirements, and terminal result. |
AiCoderRunDependencies | Model, tools, persistence, trace, workspace verification, clock, and event adapters. |
AiCoderRuntimeEvent | Model, tool, checkpoint, retry, context-pressure, state, and completion-rejection telemetry. |
evaluateAiCoderCompletion | Pure completion-evidence evaluation for tests and host diagnostics. |
createAiCoderRunCheckpoint / assertAiCoderRunCheckpoint | Durable checkpoint creation and validation. |
AiCoderToolRegistry | Canonical tool registration and model-facing registry snapshots. |
Focused subpath exports are available at /ports, /tools, /context,
/prompt, /approval, /retrieval, and /runtime. The API is pre-1.0:
pin an exact alpha version in production-like hosts and review
CHANGELOG.md before upgrading.
AiCoderTaskContract. If command.run is active, the
host must supply the exact concrete non-interactive interpreter contract;
the runtime refuses missing/unknown shell metadata before a model request.beforeHash, delete has a null afterHash, and at least
one hash is non-null. Later validation has explicit workspace/path scope.satisfied; waived does not close
a required criterion.trusted_host provenance assertion).unknown unless the
host returns a structured result. Hosts must honor the supplied signal and
absolute deadline.noProgressPolicy
(advisory by default: escalating nudges at observationNudgeThresholds,
blocked only after the final threshold; strict preserves the older
first-incident accounting).request
-> capability + tool-policy snapshot
-> core-owned prompt snapshot + canonical user-task contract
-> bounded context assembly
-> one streamed model round
-> zero or more correlated tool calls
-> atomic batch preflight (IDs, budget, visible registry, canonical JSON)
-> sequential per-call schema/policy/approval/host adapter
-> bounded untrusted observation + trusted declared effects
-> repeat
-> evidence-ready tool-free finalization turn
-> final report candidate
-> model-actionable evidence gate
-> runtime-owned final-report persistence (when a store is configured)
-> completion-gate trace + durable trace flush (when trace is configured)
-> fresh workspace fingerprint
-> deterministic completion gate
-> completed
See ARCHITECTURE.md, PROMPT_CONTRACT.md, TOOL_EFFECT_PROFILE.md, and HOST_CONFORMANCE.md for integration contracts.
src/
├── approval/ # fail-closed approval policy
├── context/ # context budget, token ledger, checkpoints, output bounds
├── ports/ # host capability interfaces and PortResult
├── prompt/ # versioned system prompt assembly
├── retrieval/ # bounded provider-neutral lexical evidence
├── runtime/ # run controller, state machine, completion gate, trace emitter
└── tools/ # schemas, descriptors, registry and provider protocol
The platform-neutral root supports Node.js 20+. Full development checks and optional SQLite adapters require Node.js 22.13+ (CI covers Node 22 and 24).
npm install
npm run verify
Optional fast pre-push gate:
git config core.hooksPath .githooks
npm run verify runs strict TypeScript checks, all source tests, a clean build,
and a public dist smoke test. npm pack --dry-run should also be checked
before publishing or consuming the package from another repository.
npm test writes TEST_ERROR_LOG.md and per-run evidence under
.galaxy/tests/: timestamped assertion results, failure stacks, test counts,
commit and source fingerprint. The reporter is development-only and runs without
a galaxy-code checkout. Raw tsx --test invocations bypass this reporter.
The deterministic/live/replay host gate lives in the private testing/ workspace:
cd testing
npm ci
npm run test:local
The runtime also supports prompt.agentProfile: "assistant" | "research" alongside the default coding profile. contextData is bounded, snapshotted and wrapped as untrusted context; it never changes approval or validation evidence.
@galaxy-stack/ai-coder-core/agent exports AgentMemoryPort, AgentSkillsPort, AgentToolExecutor, CompositeToolExecutor, memory/skill tool factories and profile types. Optional .../adapters/node/* exports provide the shared Ollama/Node tools, MCP SDK client, directory skill loader and SQLite memory. They are not imported through the platform-neutral root. The SQLite adapter requires Node >=22.13.
The executable lab moved into testing/; it is private and excluded from the npm package. Production CLI/TUI lives in the sibling galaxy-code repository. See docs/AGENT_PLATFORM.md for APIs, current scope, commands and rollout boundaries.
FAQs
Platform-neutral runtime for the Galaxy AI Coder single agent. Core exception under @galaxy-stack, versioned by the galaxy-blackhole organization. Consumed by galaxy-code (Blackhole CLI), galaxy-vscode-extension, and galaxy-desktop.
The npm package @galaxy-stack/ai-coder-core receives a total of 1,638 weekly downloads. As such, @galaxy-stack/ai-coder-core popularity was classified as popular.
We found that @galaxy-stack/ai-coder-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.