
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@mohamedhabibwork/core
Advanced tools
Unified TypeScript queue primitives across providers, with typed native escape hatches and capability discovery. Zero runtime dependencies.
Portable queue primitives for TypeScript with typed native escape hatches and capability discovery. Zero runtime dependencies, ESM-only, runs on Node, Bun and Deno.
pnpm add @mohamedhabibwork/core
import { createQueue, defineJob } from "@mohamedhabibwork/core";
import { memory } from "@mohamedhabibwork/memory"; // any @mohamedhabibwork/* provider
const queue = createQueue({ name: "emails", provider: memory() });
const sendEmail = defineJob<{ to: string }, { id: string }>("email.send");
// 1. Portable — identical on every provider
await queue.send(sendEmail, { to: "ada@example.com" }, { delay: "30s" });
// 2. Provider-aware — `native` is the selected provider's own options, strongly typed
await queue.send(sendEmail, { to: "ada@example.com" }, { native: { /* provider options */ } });
// 3. Escape hatch — the provider SDK object, typed via ProviderTypes["nativeClient"]
queue.native();
// 4. Capability discovery — loud instead of silent
queue.supports("delayedDelivery"); // boolean
queue.assertCapability("fifo"); // throws UnsupportedCapabilityError
createQueue, defineJob, queue.send/dispatch, queue.sendBatch, queue.worker,
queue.schedule, queue.native/withNative, queue.capabilities/supports/assertCapability,
queue.describe/health/size/purge, queue.use/on, queue.connect/close,
createQueueRegistry, installGracefulShutdown, the full error taxonomy
(QueueKitError + 14 subclasses, retryable()/fatal() helpers), FakeClock,
JsonSerializer, and testing utilities under @mohamedhabibwork/core/testing
(captureJobs, waitForQueueEvent, waitForWorkerEvent).
Adapters implement QueueAdapter<TTypes> where TTypes extends ProviderTypes carries every
native surface:
import { defineQueueProvider, type ProviderTypes } from "@mohamedhabibwork/core";
interface MyTypes extends ProviderTypes {
connection: MyConnectionOptions;
send: MySendOptions; // shows up in queue.send(..., { native })
worker: MyWorkerOptions; // shows up in queue.worker(..., { native })
nativeMessage: MyDeliveryHandle;
nativeClient: MySdkClient;
// ...
}
export const myProvider = defineQueueProvider(
(config) => ({ id: "my-provider", capabilities, adapter, connection: config.connection, lazy: true }),
);
Rules for adapters:
cause — never swallow them.nativeClient() for anything you don't wrap.WorkerEngine) is exported for reuse: poll → decode → validate →
middleware → handler → ack / retry / dead-letter, with graceful shutdown and visibility
extension built in.Compiled under strict, exactOptionalPropertyTypes, noUncheckedIndexedAccess,
verbatimModuleSyntax, isolatedModules. No public any.
FAQs
Unified TypeScript queue primitives across providers, with typed native escape hatches and capability discovery. Zero runtime dependencies.
We found that @mohamedhabibwork/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.