
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
LexQ CLI — manage policies, simulate rules, and deploy from the terminal. Built for humans and AI agents.
Manage policies, simulate rules, and deploy from the terminal. Built for humans and AI agents.
npm install -g @lexq/cli
Or run without installing:
npx @lexq/cli
Requires Node.js 18+.
# 1. Authenticate
lexq auth login
# Enter your API key (create one at console.lexq.io → Management → API Keys)
# 2. Verify
lexq auth whoami
# 3. Create a policy group
lexq groups create --json '{"name":"my-policy","priority":0}'
# 4. Create a draft version
lexq versions create --group-id <GROUP_ID> --json '{"commitMessage":"v1"}'
# 5. Add a rule
lexq rules create --group-id <GROUP_ID> --version-id <VERSION_ID> --json '{
"name": "VIP Discount",
"priority": 0,
"condition": {
"type": "SINGLE",
"field": "customer_tier",
"operator": "EQUALS",
"value": "VIP",
"valueType": "STRING"
},
"actions": [{
"type": "DISCOUNT",
"parameters": {"method":"PERCENTAGE","rate":10,"referenceFactKey":"payment_amount"}
}]
}'
# 6. Test
lexq analytics dry-run --version-id <VERSION_ID> --debug --mock \
--json '{"facts":{"customer_tier":"VIP","payment_amount":100000}}'
# 7. Deploy
lexq deploy publish --group-id <GROUP_ID> --version-id <VERSION_ID> --memo "v1"
lexq deploy live --group-id <GROUP_ID> --version-id <VERSION_ID> --memo "Initial deploy"
lexq auth login | logout | whoami
lexq status API health check
lexq groups list | get | create | update | delete
lexq groups ab-test start | stop | adjust
lexq versions list | get | create | update | delete | clone
lexq rules list | get | create | update | delete | reorder | toggle
lexq facts list | create | update | delete
lexq deploy publish | live | rollback | undeploy | history | detail | overview
lexq analytics dry-run | dry-run-compare | requirements
lexq analytics simulation start | status | list | cancel | export
lexq history list | get | stats
lexq integrations list | get | save | delete | config-spec
lexq logs list | get | action | bulk-action
| Flag | Description |
|---|---|
--format <json|table> | Output format (default: json) |
--api-key <key> | Override stored API key |
--base-url <url> | Override API base URL |
--dry-run | Preview the HTTP request without executing |
--verbose | Show request/response details |
--no-color | Disable colored output |
LexQ CLI ships with AI Agent Skills — structured documentation that AI coding agents can read to autonomously manage policies.
skills/
├── lexq-shared/SKILL.md Core concepts, auth, workflow
├── lexq-groups/SKILL.md Policy groups, conflict resolution, A/B testing
├── lexq-rules/SKILL.md Condition syntax, action types, mutex
├── lexq-simulation/SKILL.md Dry run, batch simulation, compare
├── lexq-execution/SKILL.md Execution history, stats, failure logs
└── lexq-recipes/SKILL.md 10 end-to-end recipes
.claude/CLAUDE.md Claude Code project context
AGENTS.md Universal agent guide (Cursor, Windsurf, Gemini CLI, Cline)
CONTEXT.md Platform architecture & glossary
Skills are included in the npm package. After installing @lexq/cli, agents can read skills from:
node_modules/@lexq/cli/skills/
node_modules/@lexq/cli/AGENTS.md
node_modules/@lexq/cli/CONTEXT.md
Or reference them directly in your project by copying the skills/ directory.
Config is stored at ~/.lexq/config.json:
{
"apiKey": "lxk_xxxxxxxxxxxxx",
"baseUrl": "https://api.lexq.io/api/v1/partners",
"format": "json"
}
git clone https://github.com/sanghyunp-dev/lexq-cli.git
cd lexq-cli
pnpm install
pnpm build
pnpm start -- groups list
pnpm typecheck # Type check
pnpm lint # ESLint
bash tests/e2e.sh # E2E tests (requires API key)
Run LexQ CLI as an MCP (Model Context Protocol) server for seamless AI agent integration:
lexq serve --mcp
This starts a stdio MCP server exposing 53 tools — the full LexQ API — to any MCP-compatible client.
Add to claude_desktop_config.json:
{
"mcpServers":{
"lexq":{
"command":"npx",
"args":[
"-y",
"@lexq/cli",
"serve",
"--mcp"
]
}
}
}
Settings → MCP Servers → Add:
npx-y @lexq/cli serve --mcp.vscode/mcp.json:
{
"servers":{
"lexq":{
"command":"npx",
"args":[
"-y",
"@lexq/cli",
"serve",
"--mcp"
]
}
}
}
Prerequisite:
lexq auth loginmust have been run once to store an API key in~/.lexq/config.json.
FAQs
LexQ CLI — manage policies, simulate rules, and deploy from the terminal. Built for humans and AI agents.
The npm package @lexq/cli receives a total of 748 weekly downloads. As such, @lexq/cli popularity was classified as not popular.
We found that @lexq/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.