
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@optiprune/cli
Advanced tools
CLI for resilient static dead-code analyzer for TypeScript and JavaScript workspaces.
Most dead-code analyzers just guess. They look at import graphs and hope they don't miss anything critical. This leads to false positives, broken builds, and developer frustration.
OptiPrune is different. We use formal logic, isolated execution, and a high-performance engine to not just find dead code, but to mathematically prove it.
"Stop Guessing, Start Proving."
While other tools are throttled by the N-API bottleneck, OptiPrune utilizes the Yuku Engine written in Zig. It minimizes the overhead between native performance and the JavaScript runtime.
OptiPrune is the first analyzer to use a real SMT Solver (Z3). We don't just analyze if a function is exported; we analyze if the code inside the function is logically reachable.
if conditions) that are completely invisible to Knip.Dynamic imports are the final boss of static analysis. OptiPrune solves this through a WASM-based QuickJS sandbox. We securely execute critical code snippets to resolve paths at runtime.
| Feature | Knip | OptiPrune |
|---|---|---|
| Engine | Babel / OXC (Standard) | Yuku / Zig (Hyper-Speed) |
| Logic Analysis | Heuristics (Guessing) | Z3 SMT Solver (Proving) |
| Dynamic Paths | Pattern Matching | WASM Sandbox Execution |
| Interface Audit | Ignores Members | Deep Member-Level Analysis |
| Framework Support | Plugins (Core-Level) | 7-Layer Semantic Context |
| False Positives | High (in complex setups) | Near-Zero (Context Aware) |
OptiPrune operates in seven specialized layers to guarantee maximum accuracy:
Tested on a NestJS project with 1000+ files.
Install Optiprune as a dev dependency via pnpm, npm, or yarn:
pnpm add -D @optiprune/core
# or
npm install --save-dev @optiprune/core
# or
yarn add -D @optiprune/core
---
## Usage
Run Optiprune from your project root:
```bash
npx @optiprune/cli
| Flag | Description | Default |
|---|---|---|
-r, --rootDir | Project root directory | process.cwd() |
-e, --entry | Entry point patterns (glob) | [] |
-i, --ignore | Patterns to ignore | [] |
--no-report-unused-exports | Disable unused export reporting | false |
--fail-on | Fail on confidence (high/medium/low/none) | high |
--json | Output as JSON | false |
--sarif | Output as SARIF | false |
--skip-3 | Skip Layer 3 (SMT Constraint Solver) | false |
--skip-4 | Skip Layer 4 (Concolic Execution Proofs) | false |
--fix <targets...> | Required fix targets: files, exports, dependencies, devDependencies, or conditions | none |
--confidence <level> | Minimum fix confidence: high, medium+, low+, or all | high |
--force | Override the configured confidence safety boundary | false |
--dry-run | Report planned fixes without modifying files | false |
For example, to fix files, exports, dependencies, and development dependencies with low-confidence findings included, run:
npx @optiprune/cli analyze --fix files exports dependencies devDependencies --confidence low+
Use --force only when you explicitly accept fixes below the configured safety boundary:
npx @optiprune/cli analyze --fix exports --confidence high --force
--confidence, --force, and --dry-run require at least one --fix target. Unsupported or unknown targets are rejected before analysis begins.
OptiPrune isn't just a tool. It's a technical statement. Help us save the world from dirty code.
GitHub: DreamLongYT/optiprune Web: opti.drml.int.yt
To setup OptiPrune, see config.md for more
FAQs
CLI for resilient static dead-code analyzer for TypeScript and JavaScript workspaces.
The npm package @optiprune/cli receives a total of 204 weekly downloads. As such, @optiprune/cli popularity was classified as not popular.
We found that @optiprune/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.