
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@grantex/autogen
Advanced tools
AutoGen / OpenAI function-calling integration for the Grantex delegated authorization protocol
AutoGen / OpenAI function-calling integration for the Grantex delegated authorization protocol.
Adds scope-enforced functions, a function registry, and audit logging for any agent using OpenAI-style function calling.
Homepage | Docs | Sign Up Free | GitHub
npm install @grantex/autogen @grantex/sdk
Create OpenAI function-calling tool definitions with built-in Grantex scope checks:
import { createGrantexFunction } from '@grantex/autogen';
const readCalendar = createGrantexFunction({
name: 'read_calendar',
description: 'Read upcoming calendar events',
parameters: {
type: 'object',
properties: {
date: { type: 'string', description: 'Date in YYYY-MM-DD format' },
},
required: ['date'],
},
grantToken, // JWT from Grantex token exchange
requiredScope: 'calendar:read', // must be in token's scp claim
func: async (args) => {
return await getCalendarEvents(args.date);
},
});
// Pass definition to the LLM
const response = await openai.chat.completions.create({
model: 'gpt-4',
tools: [readCalendar.definition],
messages,
});
// Execute when the LLM selects the tool
const result = await readCalendar.execute({ date: '2026-03-01' });
Use GrantexFunctionRegistry to manage multiple functions and dispatch tool calls by name:
import { createGrantexFunction, GrantexFunctionRegistry } from '@grantex/autogen';
const registry = new GrantexFunctionRegistry();
registry.register(readCalendar);
registry.register(sendEmail);
// Pass all definitions to the LLM
const response = await openai.chat.completions.create({
tools: registry.definitions,
messages,
});
// Dispatch the tool call
const toolCall = response.choices[0].message.tool_calls[0];
const result = await registry.execute(toolCall.function.name, JSON.parse(toolCall.function.arguments));
Wrap any function with withAuditLogging to log every invocation to the Grantex audit trail:
import { Grantex } from '@grantex/sdk';
import { withAuditLogging } from '@grantex/autogen';
const client = new Grantex({ apiKey: process.env.GRANTEX_API_KEY });
const audited = withAuditLogging(readCalendar, client, {
agentId: 'ag_01ABC...',
grantId: 'grnt_01XYZ...',
});
// Use audited.execute() — logs success/failure automatically
createGrantexFunction(options)Creates a Grantex-authorized function with an OpenAI tool definition and scope-enforced executor.
| Option | Type | Description |
|---|---|---|
name | string | Function name (matches ^[a-zA-Z0-9_-]+$) |
description | string | Description shown to the LLM |
parameters | JsonSchema | JSON Schema for function arguments |
grantToken | string | Grantex JWT from token exchange |
requiredScope | string | Scope required to invoke this function |
func | (args: T) => Promise<unknown> | Function implementation |
Returns { definition, execute }.
GrantexFunctionRegistry| Method | Description |
|---|---|
register(fn) | Register a function (chainable) |
definitions | All registered OpenAI tool definitions |
execute(name, args) | Execute a function by name |
withAuditLogging(fn, client, options)Wraps a GrantexFunction with audit logging.
| Option | Type | Description |
|---|---|---|
agentId | string | Agent ID for audit attribution |
grantId | string | Grant ID for the session |
@grantex/sdk >= 0.1.0This package is part of the Grantex ecosystem. See also:
@grantex/sdk — Core TypeScript SDKgrantex — Python SDK@grantex/langchain — LangChain integration@grantex/vercel-ai — Vercel AI SDK integration@grantex/mcp — MCP server for Claude Desktop / Cursor / WindsurfApache 2.0
FAQs
AutoGen / OpenAI function-calling integration for the Grantex delegated authorization protocol
The npm package @grantex/autogen receives a total of 19 weekly downloads. As such, @grantex/autogen popularity was classified as not popular.
We found that @grantex/autogen demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.