
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@gethmy/agent
Advanced tools
Push-based agent daemon for Harmony — picks up assigned cards, builds them in isolated git worktrees, and opens PRs. It runs where you put it.
Push-based agent daemon for Harmony, the shared surface for human–agent teams. It watches board assignments via Supabase Realtime, then implements and reviews cards with Claude CLI runs in isolated git worktrees. The agent runs where you put it: your laptop, a VPS, a VM, CI. Harmony owns the work, not the machine.
Built for failsafe auto mode: crashed daemons recover on restart, misconfigured columns fail fast, runaway costs trip a daily budget, and cards that can't pass build land in a dead-letter queue instead of bouncing forever.
npx @gethmy/mcp setup)# Run directly (works with any package manager)
npx @gethmy/agent@latest
# Or install globally
npm install -g @gethmy/agent
harmony-agent
Always pin
@latest. A barenpx @gethmy/agentreuses any previously cached version that satisfies the spec — so an old install in~/.npm/_npxcan shadow the current release and you'll get stale startup logs and CLI behavior.npx @gethmy/agent@latestre-resolves to the newest published version. If you ever suspect a stale run, clear the cache withrm -rf ~/.npm/_npx(or install globally to skip npx caching entirely).
npx @gethmy/mcp setup
~/.hmy/agent/config.json. Every field is optional — the snippet below shows the common options with their defaults. For the full schema (worktree, verification, completion, priority labels), see docs/agent-daemon.md:{
"agent": {
"poolSize": 3,
"pickupColumns": ["To Do"],
"claude": { "model": "claude-opus-5", "escalateModel": "claude-fable-5", "reviewModel": "sonnet" },
"review": {
"enabled": true,
"poolSize": 2,
"pickupColumns": ["Review"],
"moveToColumn": "Done",
"failColumn": "To Do"
},
"budget": {
"maxAttemptsPerCard": 3, // give up on a card after N failed runs
"dailyBudgetCents": 40000 // $400.00/day across all workers; -1 = no cap
// 10x sdk.maxBudgetUsd (#1058); keep in proportion
},
"sweep": {
"enabled": false, // the daemon claims its own next card
"maxCardsPerSweep": 10 // cards one sweep may claim before it stops.
// -1 opts out, and then dailyBudgetCents
// must be set. Only `sweep resume` clears
// it, so http.enabled must be true.
},
"http": {
"enabled": true,
"port": 47821,
"bindAddr": "127.0.0.1" // LOOPBACK ONLY. The control server is
// unauthenticated, so this is its whole
// access control — POST /sweep/stop is the
// kill switch. 0.0.0.0, "" or a LAN address
// refuse the daemon at startup (#1061);
// tunnel to loopback for remote access.
},
"timing": {
"heartbeatMs": 30000,
"staleHeartbeatMs": 120000,
"reconcileIntervalMs": 60000,
"worktreeGcIntervalMs": 300000
},
"retention": { // the daemon's own history; -1 = keep forever, 0 rejected
"runRecordDays": 14, // ended RunRecords in the state file
"runLogDays": 30 // ~/.hmy/agent/runs/*.log
}
}
}
harmony-agent [run] # Start the daemon (default)
harmony-agent status # Snapshot: workers, queues, DLQ, budget, sweep
harmony-agent sweep # Sweep caps + whether it is claiming
harmony-agent sweep stop # Kill switch: halt claiming within one heartbeat.
# In-flight runs are NOT cancelled.
harmony-agent sweep resume # Resume claiming and reset the card cap
harmony-agent health # Exit 0 if healthy, 1 otherwise
harmony-agent doctor # Preflight checks without starting the daemon
harmony-agent gc # One-shot worktree garbage collection
harmony-agent dlq list # List dead-lettered cards
harmony-agent dlq clear <cardId> # Release a card from the DLQ
harmony-agent help # Show usage
# Flags:
--pretty # Force colored human log output
--json # Force JSON (one record per line)
# Default: pretty on a TTY, JSON when piped
status, health, and dlq clear route through the running daemon's HTTP server (127.0.0.1:47821 by default). dlq clear falls back to a direct state-store write only when the daemon is offline.
verification.failColumn (default: To Do).Review.approved (PR created, Ready to Merge label) or rejected (findings posted, card moved back to pickup).agent-recovered label, ends their Harmony sessions, and cleans up worktrees.jq), a local HTTP status endpoint, and per-worker heartbeats so the reconciler can detect zombie runs within 2 minutes.Durable state lives at ~/.hmy/agent/state/<projectId>.json — one file per project, so two daemons on one machine never read or write each other's runs (#1057). Tracks live runs, per-card attempts and costs, daily spend, and DLQ markers. Atomic writes via write-to-tmp + rename. On the first start after upgrading, the daemon splits its own records out of the old machine-global ~/.hmy/agent/agent-state.json (a .pre-scope-backup copy is kept). The split is gated on its own <projectId>.json.migrated marker, so a failed or skipped attempt retries on the next start; a card record no worktree can attribute is copied into every project file rather than dropped.
Worktrees live at .harmony-worktrees/ inside your repo. A background sweep every 5 minutes removes directories older than 1 hour that no live run claims.
Every Claude CLI run writes a per-run log at ~/.hmy/agent/runs/<runId>-card-<shortId>.log — full stdout (NDJSON), stderr, parse errors, and an exit footer with tool-call and cost totals. Start there when a run ends silently or the card activity log shows only "Still working..." heartbeats.
See Debugging a Silent Run for interpretation table and retention notes.
See docs/agent-daemon.md for the full architecture.
FAQs
Push-based agent daemon for Harmony — picks up assigned cards, builds them in isolated git worktrees, and opens PRs. It runs where you put it.
The npm package @gethmy/agent receives a total of 322 weekly downloads. As such, @gethmy/agent popularity was classified as not popular.
We found that @gethmy/agent demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.