
Security News
The Next Open Source Security Race: Triage at Machine Speed
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.
@promptbook/javascript
Advanced tools
Promptbook: Turn your company's scattered knowledge into AI ready books
Turn your company's scattered knowledge into AI ready Books
โ Warning: This is a pre-release version of the library. It is not yet ready for production use. Please look at latest stable release.
@promptbook/javascript@promptbook/javascript is one part of the promptbook ecosystem.To install this package, run:
# Install entire promptbook ecosystem
npm i ptbk
# Install just this package to save space
npm install @promptbook/javascript
JavaScript execution engine for Promptbook, providing secure JavaScript code execution within promptbook pipelines and script tasks.
This package provides a secure JavaScript execution environment for Promptbook pipelines. It enables the execution of JavaScript code in SCRIPT tasks, allowing for complex data transformations, calculations, and logic within promptbook workflows while maintaining security and isolation.
The package provides JavaScript execution capabilities:
SCRIPT tasksBOOK_LANGUAGE_VERSION - Current book language versionPROMPTBOOK_ENGINE_VERSION - Current engine versionJavascriptEvalExecutionTools - JavaScript execution tools using evalJavascriptExecutionTools - Standard JavaScript execution toolsPOSTPROCESSING_FUNCTIONS - Built-in postprocessing functions for JavaScriptextractVariablesFromJavascript - Extract variable dependencies from JavaScript code๐ก This package provides JavaScript execution for promptbook applications. For the core functionality, see @promptbook/core or install all packages with
npm i ptbk
Rest of the documentation is common for entire promptbook ecosystem:
Nowadays, the biggest challenge for most business applications isn't the raw capabilities of AI models. Large language models such as GPT-5.2 and Claude-4.5 are incredibly capable.
The main challenge lies in managing the context, providing rules and knowledge, and narrowing the personality.
In Promptbook, you can define your context using simple Books that are very explicit, easy to understand and write, reliable, and highly portable.
|
Paul Smith |
We have created a language called Book, which allows you to write AI agents in their native language and create your own AI persona. Book provides a guide to define all the traits and commitments.
You can look at it as "prompting" (or writing a system message), but decorated by commitments.
Commitments are special syntax elements that define contracts between you and the AI agent. They are transformed by Promptbook Engine into low-level parameters like which model to use, its temperature, system message, RAG index, MCP servers, and many other parameters. For some commitments (for example RULE commitment) Promptbook Engine can even create adversary agents and extra checks to enforce the rules.
Persona commitmentPersonas define the character of your AI persona, its role, and how it should interact with users. It sets the tone and style of communication.
|
Paul Smith & Associรฉs |
Knowledge commitmentKnowledge Commitment allows you to provide specific information, facts, or context that the AI should be aware of when responding.
This can include domain-specific knowledge, company policies, or any other relevant information.
Promptbook Engine will automatically enforce this knowledge during interactions. When the knowledge is short enough, it will be included in the prompt. When it is too long, it will be stored in vector databases and RAG retrieved when needed. But you don't need to care about it.
|
Paul Smith & Associรฉs |
Rule commitmentRules will enforce specific behaviors or constraints on the AI's responses. This can include ethical guidelines, communication styles, or any other rules you want the AI to follow.
Depending on rule strictness, Promptbook will either propagate it to the prompt or use other techniques, like adversary agent, to enforce it.
|
Paul Smith & Associรฉs |
Team commitmentTeam commitment allows you to define the team structure and advisory fellow members the AI can consult with. This allows the AI to simulate collaboration and consultation with other experts, enhancing the quality of its responses.
|
Paul Smith & Associรฉs |
!!!@@@
!!!@@@
!!!@@@
Promptbook project is ecosystem of multiple projects and tools, following is a list of most important pieces of the project:
| Project | About |
|---|---|
| Agents Server | Place where you "AI agents live". It allows to create, manage, deploy, and interact with AI agents created in Book language. |
| Book language |
Human-friendly, high-level language that abstracts away low-level details of AI. It allows to focus on personality, behavior, knowledge, and rules of AI agents rather than on models, parameters, and prompt engineering.
There is also a plugin for VSCode to support .book file extension
|
| Promptbook Engine | Promptbook engine can run AI agents based on Book language. It is released as multiple NPM packages and Promptbook Agent Server as Docker Package Agent Server is based on Promptbook Engine. |
Join our growing community of developers and users:
| Platform | Description |
|---|---|
| ๐ฌ Discord | Join our active developer community for discussions and support |
| ๐ฃ๏ธ GitHub Discussions | Technical discussions, feature requests, and community Q&A |
| ๐ LinkedIn | Professional updates and industry insights |
| ๐ฑ Facebook | General announcements and community engagement |
| ๐ ptbk.io | Official landing page with project information |
| ๐ธ Instagram @promptbook.studio | Visual updates, UI showcases, and design inspiration |
See detailed guides and API reference in the docs or online.
For information on reporting security vulnerabilities, see our Security Policy.
This library is divided into several packages, all are published from single monorepo. You can install all of them at once:
npm i ptbk
Or you can install them separately:
โญ Marked packages are worth to try first
โญ ptbk - Bundle of all packages, when you want to install everything and you don't care about the size
promptbook - Same as ptbk
โญ๐งโโ๏ธ @promptbook/wizard - Wizard to just run the books in node without any struggle
@promptbook/core - Core of the library, it contains the main logic for promptbooks
@promptbook/node - Core of the library for Node.js environment
@promptbook/browser - Core of the library for browser environment
โญ @promptbook/utils - Utility functions used in the library but also useful for individual use in preprocessing and postprocessing LLM inputs and outputs
@promptbook/markdown-utils - Utility functions used for processing markdown
(Not finished) @promptbook/wizard - Wizard for creating+running promptbooks in single line
@promptbook/javascript - Execution tools for javascript inside promptbooks
@promptbook/openai - Execution tools for OpenAI API, wrapper around OpenAI SDK
@promptbook/anthropic-claude - Execution tools for Anthropic Claude API, wrapper around Anthropic Claude SDK
@promptbook/vercel - Adapter for Vercel functionalities
@promptbook/google - Integration with Google's Gemini API
@promptbook/deepseek - Integration with DeepSeek API
@promptbook/ollama - Integration with Ollama API
@promptbook/azure-openai - Execution tools for Azure OpenAI API
@promptbook/fake-llm - Mocked execution tools for testing the library and saving the tokens
@promptbook/remote-client - Remote client for remote execution of promptbooks
@promptbook/remote-server - Remote server for remote execution of promptbooks
@promptbook/pdf - Read knowledge from .pdf documents
@promptbook/documents - Integration of Markitdown by Microsoft
@promptbook/documents - Read knowledge from documents like .docx, .odt,โฆ
@promptbook/legacy-documents - Read knowledge from legacy documents like .doc, .rtf,โฆ
@promptbook/website-crawler - Crawl knowledge from the web
@promptbook/editable - Editable book as native javascript object with imperative object API
@promptbook/templates - Useful templates and examples of books which can be used as a starting point
@promptbook/types - Just typescript types used in the library
@promptbook/color - Color manipulation library
โญ @promptbook/cli - Command line interface utilities for promptbooks
๐ Docker image - Promptbook server
The following glossary is used to clarify certain concepts:
Note: This section is not a complete dictionary, more list of general AI / LLM terms that has connection with Promptbook
| Data & Knowledge Management | Pipeline Control |
|---|---|
|
|
| Language & Output Control | Advanced Generation |
|
|
If you have a question start a discussion, open an issue or write me an email.
See CHANGELOG.md
This project is licensed under BUSL 1.1.
We welcome contributions! See CONTRIBUTING.md for guidelines.
You can also โญ star the project, follow us on GitHub or various other social networks.We are open to pull requests, feedback, and suggestions.
Need help with Book language? We're here for you!
We welcome contributions and feedback to make Book language better for everyone!
FAQs
Promptbook: Turn your company's scattered knowledge into AI ready books
The npm package @promptbook/javascript receives a total of 1,222 weekly downloads. As such, @promptbook/javascript popularity was classified as popular.
We found that @promptbook/javascript demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.ย It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.

Security News
gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.