
Research
/Security News
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
Miasma Mini Shai-Hulud hits @immobiliarelabs Backstage plugins, targeting GitLab and LDAP auth packages on npm.
@graph8/devex
Advanced tools
Canonical Cursor governance + spec-driven development rules for graph8 repos.
A template payload + CLI consumed by npx g8 init to bootstrap:
.cursor/rules/* — Cursor enforcement rulesmanifesto.md, standards.md, playbook.md, AGENTS.mdspecs/ — Spec-driven development scaffoldingIn any target repo:
npx @graph8/devex init
Then commit the created files. Done.
npx @graph8/devex initBootstrap governance + Cursor rules into current repo.
Safe mode (default):
npx @graph8/devex init
Force mode:
npx @graph8/devex init --force
npx @graph8/devex doctorCheck repo DevEx health and report issues.
npx @graph8/devex doctor
Reports:
.cursorrules.cursor/rules/)| File | Purpose |
|---|---|
00-principles.mdc | Core engineering philosophy |
10-governance.mdc | Rule severity levels, dependency rules |
20-spec-protocol.mdc | When/how to create specs before coding |
90-emergency.mdc | Hard stops, escalation triggers |
| File | Purpose |
|---|---|
manifesto.md | Engineering philosophy |
standards.md | Technical standards and constraints |
playbook.md | Team process and SLOs |
AGENTS.md | Quick commands for AI agents |
| File | Purpose |
|---|---|
specs/backlog.md | Tracks active and completed specs |
.cursorrules to .cursor/rules/This repo is versioned via git tags (e.g. v1.0.0).
The CLI defaults to the version it was published with.
# Install dependencies
npm install
# Build
npm run build
# Test locally
node dist/index.js init
| Scenario | Behavior |
|---|---|
| Standard file missing | Create |
| Standard file exists | Skip |
| Standard file modified | Report only |
| Custom rule file | Leave untouched |
.cursorrules present | Warn; do not delete |
Overwrite requires explicit --force.
FAQs
DevEx bootstrap CLI for spec-driven development with Cursor
The npm package @graph8/devex receives a total of 35 weekly downloads. As such, @graph8/devex popularity was classified as not popular.
We found that @graph8/devex demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Miasma Mini Shai-Hulud hits @immobiliarelabs Backstage plugins, targeting GitLab and LDAP auth packages on npm.

Security News
Rolldown paused Rust React Compiler integration after a 5MB binary size increase raised concerns about shipping React-specific code to all Vite users.

Security News
/Research
Mini Shai-Hulud expands into the Go ecosystem after hitting LeoPlatform npm packages and targeting GitHub Actions workflows.