
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@livewiki/cli
Advanced tools
livewiki command-line interface — living documentation anchored to code, verifiable against hallucination.
The livewiki command builds a Markdown wiki beside your code, detects when
documentation becomes stale, and validates its references.
Full guide and dated benchmark archive: github.com/eduardoabreu81/livewiki
Requires Node.js 24 or newer.
npm install -g @livewiki/cli
You can also prefix commands with npx @livewiki/cli.
livewiki init
This indexes the repository and creates the wiki skeleton without calling an LLM.
Connect livewiki to your coding agent:
livewiki install
Through the MCP server, the agent can call livewiki_next_task, read the
returned source paths, and submit each page with livewiki_write_doc and the
returned taskId. This uses the model from the agent's existing session and
requires no provider, model, or API credential in livewiki. The queue owns
priority, bounded attempts, checkpoints, validation, and resume.
For an unattended API-backed bootstrap, run the interactive wizard:
livewiki config
It writes provider settings to .livewiki/config.json and stores the API key
separately at ~/.livewiki/credentials.json, without echoing the key during
input. On POSIX the credentials file uses mode 0600; on Windows it inherits
the user profile's ACL. Check presence and origin without printing the value:
livewiki config show
Environment variables take precedence and remain available for CI and other headless environments:
export ANTHROPIC_API_KEY=sk-ant-...
livewiki init --batch
In PowerShell, set the key with
$env:ANTHROPIC_API_KEY = "sk-ant-...". For ollama and lmstudio the
credential is optional: leave it empty for a local server, or supply one with a
custom base URL to reach an authenticated remote endpoint.
After the bootstrap, the active agent uses the same MCP connection and its existing session to inspect debt and update affected pages as code changes.
livewiki index # detect changed, moved, and deleted symbols
livewiki status # show open documentation debt
livewiki verify # validate references and wiki artifacts
livewiki view # build the self-contained offline site
Bootstrap and maintenance are consecutive phases: create the initial corpus once, then keep it current incrementally.
@livewiki/mcp — MCP
server for stdio-capable clients@livewiki/core — the
indexer, anchor ledger, batch pipeline, and verification libraryMIT
FAQs
livewiki command-line interface — living documentation anchored to code, verifiable against hallucination.
The npm package @livewiki/cli receives a total of 32 weekly downloads. As such, @livewiki/cli popularity was classified as not popular.
We found that @livewiki/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.