
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@greenhill/callx
Advanced tools
像 codex、claude、opencode 一样用 npm install -g 安装的 AI 召唤器。
callx 是一个 Node CLI:
call~/.config/callx运行时只认这一套结构:
~/.config/callx/
├── providers.json
├── skillpacks/
│ ├── code-skill/
│ └── send-email/
├── sprites/
│ ├── claude-01/
│ └── open-01/
└── .default
前置条件:
npm install -g opencode-ainpm install -g @anthropic-ai/claude-code安装:
npm install -g @greenhill/callx
如果你是在本地开发这个仓库,也可以直接:
npm install -g .
第一次运行任意 call 命令时,如果 ~/.config/callx 不存在,会自动创建:
~/.config/callx/providers.json~/.config/callx/skillpacks/~/.config/callx/sprites/然后编辑:
$EDITOR ~/.config/callx/providers.json
示例:
{
"deepseek": {
"base_url": "https://api.deepseek.com/v1",
"api_key": "sk-xxx",
"format": "openai"
},
"minimax": {
"base_url": "https://api.minimaxi.com/anthropic",
"api_key": "sk-xxx",
"format": "anthropic"
}
}
call -l
call -d open-01
call
call claude-01
call open-01 -a run "hi"
call -s
call update
如果是通过 npm 全局安装的,直接:
call update
它会执行 npm 全局升级,不会改动 ~/.config/callx。配置里的 providers.json、sprites/、skillpacks/ 都由用户自己维护。
发 npm 包之前,先确保:
npm login --registry=https://registry.npmjs.org/常用命令:
npm run pack:check
npm run release:patch
npm run publish:npm
如果想一步完成升级版本并发布:
npm run release:patch:publish
版本管理建议:
patchminormajormkdir -p ~/.config/callx/sprites/my-agent/{agents,commands,modes,plugins,skills,tools,themes}
cat > ~/.config/callx/sprites/my-agent/config.json <<'EOF'
{
"cli": "opencode",
"provider": "deepseek",
"model": "deepseek/deepseek-chat",
"autoupdate": true,
"skill_links": ["code-skill"]
}
EOF
然后:
call -l
call my-agent
providers.json 是唯一运行时 provider 配置skillpacks/ 是技能源目录sprites/ 是所有 AI 角色目录skill_links 链接到自己的 skills/FAQs
AI runtime switcher for Claude Code and OpenCode
The npm package @greenhill/callx receives a total of 1 weekly downloads. As such, @greenhill/callx popularity was classified as not popular.
We found that @greenhill/callx demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.