data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
@mastra/client-js
Advanced tools
JavaScript/TypeScript client library for the Mastra AI framework. This client provides a simple interface to interact with Mastra AI's APIs for agents, vectors, memory, tools, and workflows.
npm install @mastra/client-js
import { MastraClient } from '@mastra/client';
// Initialize the client
const client = new MastraClient({
baseUrl: 'http://localhost:4111', // Your Mastra API endpoint
});
// Example: Working with an Agent
async function main() {
// Get an agent instance
const agent = client.getAgent('your-agent-id');
// Generate a response
const response = await agent.generate({
messages: [{ role: 'user', content: "What's the weather like today?" }],
});
console.log(response);
}
The client can be configured with several options:
const client = new MastraClient({
baseUrl: string; // Base URL for the Mastra API
retries?: number; // Number of retry attempts (default: 3)
backoffMs?: number; // Initial backoff time in ms (default: 300)
maxBackoffMs?: number; // Maximum backoff time in ms (default: 5000)
headers?: Record<string, string>; // Custom headers
});
getAgents()
: Get all available agentsgetAgent(agentId)
: Get a specific agent instance
agent.details()
: Get agent detailsagent.generate(params)
: Generate a responseagent.stream(params)
: Stream a responseagent.getTool(toolId)
: Get agent tool detailsagent.evals()
: Get agent evaluationsagent.liveEvals()
: Get live evaluationsgetMemoryThreads(params)
: Get memory threadscreateMemoryThread(params)
: Create a new memory threadgetMemoryThread(threadId)
: Get a memory thread instancesaveMessageToMemory(params)
: Save messages to memorygetMemoryStatus()
: Get memory system statusgetTools()
: Get all available toolsgetTool(toolId)
: Get a tool instance
tool.details()
: Get tool detailstool.execute(params)
: Execute the toolgetWorkflows()
: Get all workflowsgetWorkflow(workflowId)
: Get a workflow instance
workflow.details()
: Get workflow detailsworkflow.execute(params)
: Execute the workflowworkflow.watch(params)
: Watch the workflowworkflow.resume(params)
: Resume the workflowgetVector(vectorName)
: Get a vector instance
vector.details(indexName)
: Get vector index detailsvector.delete(indexName)
: Delete a vector indexvector.getIndexes()
: Get all indexesvector.createIndex(params)
: Create a new indexvector.upsert(params)
: Upsert vectorsvector.query(params)
: Query vectorsgetLogs(params)
: Get system logsgetLog(params)
: Get specific log entrygetLogTransports()
: Get configured Log transportsgetTelemetry(params)
: Get telemetry dataThe client includes built-in retry logic for failed requests:
The client uses the native fetch
API internally for making HTTP requests. All requests are automatically handled with:
MIT
FAQs
The official TypeScript library for the Mastra Client API
The npm package @mastra/client-js receives a total of 1,552 weekly downloads. As such, @mastra/client-js popularity was classified as popular.
We found that @mastra/client-js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.