
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@jawcode-dev/stats
Advanced tools
Local observability dashboard for AI usage statistics.
~/.jwc/agent/sessions/bun:sqlite| Metric | Calculation |
|---|---|
| Tokens/s | output_tokens / (duration / 1000) |
| Cache Rate | cache_read / (input + cache_read) * 100 |
| Error Rate | count(stopReason=error) / total_calls * 100 |
| Total Cost | Sum of usage.cost.total |
| Avg Latency | Mean of duration |
| TTFT | Mean of ttft (time to first token) |
# Start dashboard server (default: http://localhost:3847)
gjc stats
# Custom port
gjc stats --port 8080
# Print summary to console
gjc stats --summary
# Output as JSON (for scripting)
gjc stats --json
import { getDashboardStats, syncAllSessions } from "@jawcode-dev/stats";
// Sync session logs to database
const { processed, files } = await syncAllSessions();
// Get aggregated stats
const stats = await getDashboardStats();
console.log(stats.overall.totalCost);
console.log(stats.byModel[0].avgTokensPerSecond);
| Endpoint | Description |
|---|---|
GET /api/stats | Overall stats with all breakdowns |
GET /api/stats/models | Per-model statistics |
GET /api/stats/folders | Per-folder/project statistics |
GET /api/stats/timeseries | Hourly time series data |
GET /api/sync | Trigger sync and return counts |
~/.jwc/agent/sessions/ (JSONL files)~/.jwc/stats.db (SQLite)The web dashboard provides:
MIT
FAQs
Local observability dashboard for pi AI usage statistics
The npm package @jawcode-dev/stats receives a total of 0 weekly downloads. As such, @jawcode-dev/stats popularity was classified as not popular.
We found that @jawcode-dev/stats demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.