
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@grekt/cli
Advanced tools
The package manager for AI coding tools. Manage prompts, rules, agents, and skills across Claude Code, Cursor, Windsurf, Copilot, Cline, and more - version-controlled, shareable, and synced.
Free to use. grekt is free for personal and commercial use. If you're building something with it, we'd love to hear about it. The source is available under BSL 1.1, which just means you can't use this code to build something that competes with grekt. Each version converts to MIT after two years.
AI coding assistants rely on project rules, custom instructions, and agent configurations - but there's no standard way to manage, share, or keep them in sync. grekt solves this:
.cursorrules, CLAUDE.md, .windsurfrules, etc.curl -fsSL https://cli.grekt.com/install.sh | sh
brew install grekt-labs/tap/grekt
npm install -g @grekt/cli
grekt init # Initialize a project
grekt add @scope/artifact-name # Add an artifact
grekt install # Install from lockfile
grekt sync # Sync to your AI tools
Artifacts can come from the public registry (@scope/name), GitHub (github:user/repo), GitLab (gitlab:host/user/repo), or a local path (./path).
grekt syncs to Claude Code, Cursor, Windsurf, Cline, GitHub Copilot, Aider, Continue, OpenCode, Amazon Q, and any tool following the agentskills.io standard (Codex, Gemini CLI, Devin, Amp, Zed, and others).
For the full command reference and guides, visit the documentation.
Requires Bun >= 1.0.
bun install
bun link # makes grekt available globally
bun test
See CONTRIBUTING.md. Feature requests and bug reports are welcome.
FAQs
AI tools versioned, synced, and shared across tools and teams
The npm package @grekt/cli receives a total of 2 weekly downloads. As such, @grekt/cli popularity was classified as not popular.
We found that @grekt/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.