
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@kyma-api/gen
Advanced tools
Agent-first CLI for Kyma API — search, run, and manage 51+ generative AI models from Claude Code, Cursor, and Codex.
Agent-first CLI for Kyma API — search, run, and manage 51+ generative AI models from Claude Code, Cursor, Codex, or your terminal.
Status: scaffold. Command bodies are stubbed. Implementation lands slice by slice; the v0 surface is locked at 12 commands per
kyma-api/.internal/specs/kyma-gen/cli-shape.md.
curl https://kymaapi.com/install -fsS | bash
Or via npm:
npm install -g @kyma-api/gen
The kg short alias is auto-installed if kg is not already on your PATH
(opt-out via --no-kg; force via --kg).
kyma-gen setup # interactive: paste your ky-... key
kyma-gen models "logo design" # search the catalog
kyma-gen run recraft-v4 --help # introspect a model's input schema
kyma-gen run recraft-v4 --prompt "kyma wave" --download
Get a key at kymaapi.com/keys.
setup Configure API key + preferences
init Install the default kyma-gen skill bundle
skills Manage installed skill bundles (list | install | update | remove)
models Search/list models served by Kyma API
schema Get a model's input/output schema
run Run a model (sync or async)
status Check job status / fetch result / cancel
upload Upload a local file or URL to Kyma's storage
pricing Get pricing for a model
docs Search the kymaapi.com docs index
version Show CLI version + check for known update
update Self-update the binary
Run kyma-gen --help (or --json for the agent-readable schema) for the
full surface.
Source lives in
kyma-api/packages/kyma-gen.
Behavior specs live in
kyma-api/.internal/specs/kyma-gen
(internal).
MIT
FAQs
Agent-first CLI for Kyma API — search, run, and manage 51+ generative AI models from Claude Code, Cursor, and Codex.
We found that @kyma-api/gen demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.