
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@livewiki/cli
Advanced tools
livewiki command-line interface — living documentation anchored to code, verifiable against hallucination.
The livewiki command — living repository documentation, anchored to code
and verifiable against hallucination.
Full guide, philosophy, and benchmarks: github.com/eduardoabreu81/livewiki
Requires Node.js 24 or newer.
npm install -g @livewiki/cli
(or prefix every command with npx @livewiki/cli)
livewiki init # index the repo + create the wiki layout (zero tokens)
livewiki install # wire your agent (MCP server, hooks, skill) — optional
livewiki status # open documentation debt, risk-ranked
livewiki verify # anti-hallucination gate — exits non-zero on any issue
livewiki view # self-contained offline site with search and Mermaid
Writing docs can be done two ways: your own agent in-session (no extra
API key — livewiki install sets it up), or an unattended full-repo run
(livewiki init --batch with a provider preset in
.livewiki/config.json and the key in an env var). Both produce the same
wiki and mix freely.
@livewiki/mcp — MCP
server for any MCP client (Claude Code, Cursor, Codex, …)@livewiki/core — the
library underneath: indexer, anchors, ledger, pipelineMIT
FAQs
livewiki command-line interface — living documentation anchored to code, verifiable against hallucination.
The npm package @livewiki/cli receives a total of 32 weekly downloads. As such, @livewiki/cli popularity was classified as not popular.
We found that @livewiki/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.