
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@nomark-ai/pro
Advanced tools
NOMARK Pro — trust contract, instinct engine, governance, critical-field gate
Enterprise extensions for the NOMARK engine. Adds trust contracts, instinct capture, governance lifecycles, critical-field gates, and team sync on top of @nomark-ai/engine.
npm install @nomark-ai/engine @nomark-ai/pro
Requires Node.js 18+ and @nomark-ai/engine >= 0.1.0.
import { createEngine } from '@nomark-ai/pro'
import { parseLedger } from '@nomark-ai/engine'
const entries = parseLedger(ledgerContent)
const engine = createEngine({
entries,
context: 'code',
trust: true,
instincts: true,
governance: true,
criticalFields: true,
})
// Process input through the full engine
const result = engine.process('draft the email to the client', {
schema: 'communication',
fields: ['recipient', 'tone', 'content_facts'],
})
// Check which fields need human confirmation
for (const gate of result.gate ?? []) {
if (gate.tier === 'critical_ask') {
console.log(`Confirm required: ${gate.field}`)
}
}
Governs agent autonomy based on demonstrated reliability. Trust score starts at 1.0, earned in drops (verified story completions) and lost in buckets (breach events S0–S4).
| Autonomy Level | Score Range | Restrictions |
|---|---|---|
| Full | 1.5+ | Unrestricted |
| Trusted | 1.0–1.49 | Normal operation |
| Supervised | 0.5–0.99 | Mandatory verification |
| Restricted | 0.2–0.49 | No autonomous dispatch |
| Probation | 0.0–0.19 | Owner confirmation required |
Pattern capture with confidence lifecycle. Instincts progress from pending through proven to promoted, with observation counting and confidence tracking.
import { createInstinctStore, captureInstinct, reinforceInstinct } from '@nomark-ai/pro'
let store = createInstinctStore()
store = captureInstinct(store, 'fmt-01', 'prefers bullet points', ['format'], now)
store = reinforceInstinct(store, 'fmt-01', now) // confidence increases
Stage-based execution with trust gates, artifact tracking, and audit trails. Ships with a default CODE_LIFECYCLE config or accepts custom stage definitions.
import { createLifecycle, advanceStage, CODE_LIFECYCLE } from '@nomark-ai/pro'
const lifecycle = createLifecycle(CODE_LIFECYCLE, new Date().toISOString())
// Advance through stages: think → plan → build → verify
Schema-level inference tiers that prevent autonomous agent action on high-risk fields:
| Tier | Name | Agent Behavior |
|---|---|---|
| 1 | Inferable | Resolve from preferences |
| 2 | Defaultable | Use defaults, allow override |
| 3 | Critical Ask | Must confirm with human |
Built-in schemas for creative, decision, and communication request types. Extensible with custom schemas.
Multi-user team management with shared preference layers and Supabase-backed sync.
Business Source License 1.1
FAQs
NOMARK Pro — trust contract, instinct engine, governance, critical-field gate
The npm package @nomark-ai/pro receives a total of 11 weekly downloads. As such, @nomark-ai/pro popularity was classified as not popular.
We found that @nomark-ai/pro demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.