
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@jstn-sdk/meta-architect
Advanced tools
Meta-Architect skills bundle and orchestration tooling for verified engineering workflows.
Production-grade skills package and CLI for programmatic architecture, evidence-backed OSS selection, gate-driven review, and release-minded build unlocking.
[!IMPORTANT] Meta-Architect
v0.1.0is a production-grade skills line. It is not a lightweight demo branch. Fromv0.1.0onward, the package is expected to ship with stable skill contracts, deterministic packaging, explicit release gates, and honest install and publish surfaces.
Meta-Architect is a workflow layer for teams that want architecture, evidence, review, and release discipline before build execution.
It adds:
[!NOTE] Meta-Architect does not replace your coding runtime. It wraps that runtime with architecture, evidence, gate enforcement, and release-sensitive workflow control.
| npm package | meta-architect |
| CLI commands | ma, meta-architect |
| Runtime | Node.js >=20, npm @10 |
| Release line | v0.1.0 |
| License | MIT |
>=20>=10[!TIP] The most reliable default environment is a Unix-like shell with Git, Node.js, and an MCP-capable runtime already configured.
Meta-Architect is intended to be consumed as an installed package, not primarily as a git clone.
Default operator path:
npm install -g @openai/codex @jstn-sdk/meta-architect@latest
ma setup
ma
What this assumes:
ma setup is run inside the repository you want Meta-Architect to scaffoldma starts the local Codex session after scaffolding is in place[!IMPORTANT] The recommended default flow is package-first. The git clone path is for contributors and maintainers, not the main user-facing install story.
Meta-Architect’s repository workflow follows a stricter release posture focused on gated promotion:
main = release-facing protected branchdevelopment = normal integration branchfeature/* = short-lived contribution branchesdevelopmentdevelopmentdevelopment into main[!CAUTION]
mainis intended to be protected and exceptional. Maintainers should stop bypass-pushing tomainexcept for genuine emergency or admin recovery cases.
Install the consumer package directly:
npm install -g @openai/codex @jstn-sdk/meta-architect@latest
This gives you:
codexmameta-architectUse this path only if you want to work on Meta-Architect itself.
git clone https://github.com/JustineDevs/meta-architect.git
cd meta-architect
npm install
npm link
npm link makes ma and meta-architect available from the local checkout.
Initialize the repository you want Meta-Architect to govern:
ma setup
Then start the local Codex session through ma:
ma
Expected output:
meta-architect setup
====================
ready: .codex/agents
ready: .codex/prompts
ready: .ma/skills
ready: .ma/evidence
ready: mcp
ready: docs
ready: docs/qa
ready: sprint
ma with no arguments launches the local Codex CLI.
Legacy compatibility flags such as ma --madmax --high are still accepted, but they are no longer
the recommended path.
Add real repository-backed endpoints in mcp/servers.json.
Example:
{
"category": "meta-list",
"repo": "sindresorhus/awesome",
"endpoint": "https://gitmcp.io/sindresorhus/awesome"
}
Recommended starter endpoints:
https://gitmcp.io/sindresorhus/awesomehttps://gitmcp.io/dzharii/awesome-typescripthttps://gitmcp.io/sbilly/awesome-security[!IMPORTANT] Verified release evidence must come from repository-form GitMCP endpoints such as
https://gitmcp.io/{owner}/{repo}. A generic documentation endpoint such ashttps://gitmcp.io/docsdoes not count as VERIFIED evidence for build unlocking.
ma idea "Build a real-time collaborative whiteboard for product teams"
Expected effect:
.ma/decisions.jsonidea_status = CLEARma run '$arch'
ma run '$sage'
ma run '$flow'
ma run '$vet'
ma run '$vibe'
ma status
ma run '$build'
Expected status before $build:
Meta-Architect Status
=====================
Idea: CLEAR
Architecture: APPROVED
Evidence: VERIFIED
Logic: GREEN
Security: GREEN
Experience: GREEN
Build: LOCKED
Next allowed triggers:
$build
Expected build output:
Build gate is green.
Suggested branches:
- feature/ui
- feature/api
Optional worktree commands:
git worktree add ../ui feature/ui
git worktree add ../api feature/api
| Role | Name | GitHub |
| Creator / Maintainer | JustineDevs | @JustineDevs |
| Trigger | Purpose | Main output | Gate effect |
|---|---|---|---|
$arch | Produce the first-pass architecture blueprint | decision entry | architecture_status = APPROVED |
$sage | Ground major choices in configured GitMCP evidence | evidence records | `evidence_status = VERIFIED |
$flow | Review baseline logic and state transitions | logic review entry | `logic_status = GREEN |
$vet | Run baseline security and dependency review | audit and CVE records | `security_status = GREEN |
$vibe | Review developer and user experience implications | DX/UX outcome record | `experience_status = GREEN |
$build | Unlock bounded build planning | build-ready decision | build_status = READY |
Meta-Architect is intentionally fail-closed.
| Status | Meaning |
|---|---|
CLEAR | enough input exists to proceed |
APPROVED | the architecture lane produced an acceptable first-pass blueprint |
VERIFIED | live evidence was grounded through approved GitMCP sources |
PARTIAL | evidence is configured but live proof is incomplete or unavailable |
GREEN | the current baseline review passed |
RED | the lane is blocked or failed |
WAIVED | the lane was intentionally waived with a recorded reason |
LOCKED | downstream work is not allowed yet |
READY | the next gated step is allowed |
[!CAUTION]
$buildmust stay locked until the upstream release state in.ma/release.jsonsatisfies the gate contract. Meta-Architect is designed to stop on blockers rather than silently continue.
Meta-Architect has two related but different distribution surfaces.
| Surface | Purpose | Produced by |
|---|---|---|
| npm package | public package containing CLI, docs, scripts, and canonical skills | npm publish or npm pack |
| skills bundle | narrower tarball containing skills/ only | npm run skills:pack |
Required packaging commands:
npm run skills:manifest
npm run skills:validate
npm run skills:pack
npm run skills:install -- --path ./dist/installed-skills
npm run pack:inspect
Pre-publish rules:
skills/index.json must be currentnpm run skills:validate must passdist/meta-architect-skills.tgz must existnpm pack --dry-run must show only intended public files[!CAUTION] Do not claim npm, GitHub release, or any other publish channel until that channel has actually succeeded. Release documentation must match reality, not intent.
| Included | bin/, skills/, docs/, scripts/, index.js, README.md, LICENSE |
| Excluded | .ma/ runtime state, logs, caches, and temp install outputs |
| Path | Responsibility |
.codex/ | runtime prompts, hooks, and repo guidance |
skills/ | canonical public skill contracts |
plugins/meta-architect/ | plugin-oriented distribution surface |
docs/ | installation, publishing, and release documentation |
missions/ | reproducible scenario-driven workflows |
mcp/ | GitMCP endpoint and collection configuration |
scripts/ | validation, packing, and install helpers |
sprint/ | human-readable phased workflow documents |
| Surface | Purpose |
|---|---|
| Getting Started | end-to-end local onboarding |
| Skills Reference | trigger-by-trigger contract guide |
| Skills Publishing | source-to-package pipeline |
| MCP Setup | evidence endpoint policy |
| Plugin README | plugin distribution surface |
| Collaborative Whiteboard Mission | concrete scenario walkthrough |
| Release Spec | release and gate policy |
| Release Readiness | QA evidence for the v0.1.0 line |
[!WARNING] Runtime
.malogs, state, tmp, and cache files must not be shipped. Public docs must match actual package behavior. Publish statements must match reality. Skill contracts must stay aligned across canonical and plugin-facing copies.
FAQs
Meta-Architect skills bundle and orchestration tooling for verified engineering workflows.
We found that @jstn-sdk/meta-architect demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.