
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@promptbook/utils
Advanced tools
Turn your company's scattered knowledge into AI ready Books
.book files with syntax highlighting and IntelliSensehejny/promptbook) for seamless containerized usageo3-mini, GPT-4 and other leading LLMsโ Warning: This is a pre-release version of the library. It is not yet ready for production use. Please look at latest stable release.
@promptbook/utils@promptbook/utils is one part of the promptbook ecosystem.To install this package, run:
# Install entire promptbook ecosystem
npm i ptbk
# Install just this package to save space
npm install @promptbook/utils
Comprehensive utility functions for text processing, validation, normalization, and LLM input/output handling in the Promptbook ecosystem.
The utils package provides a rich collection of utility functions that are essential for working with LLM inputs and outputs. It handles common tasks like text normalization, parameter templating, validation, and postprocessing, eliminating the need to implement these utilities from scratch in every promptbook application.
This package offers utilities across multiple domains:
The prompt template tag function helps format prompt strings for LLM interactions. It handles string interpolation and maintains consistent formatting for multiline strings and lists and also handles a security to avoid prompt injection.
import { prompt } from '@promptbook/utils';
const promptString = prompt`
Correct the following sentence:
> ${unsecureUserInput}
`;
The prompt name could be overloaded by multiple things in your code. If you want to use the promptTemplate which is alias for prompt:
import { promptTemplate } from '@promptbook/utils';
const promptString = promptTemplate`
Correct the following sentence:
> ${unsecureUserInput}
`;
There is a function templateParameters which is used to replace the parameters in given template optimized to LLM prompt templates.
import { templateParameters } from '@promptbook/utils';
templateParameters('Hello, {name}!', { name: 'world' }); // 'Hello, world!'
And also multiline templates with blockquotes
import { templateParameters, spaceTrim } from '@promptbook/utils';
templateParameters(
spaceTrim(`
Hello, {name}!
> {answer}
`),
{
name: 'world',
answer: spaceTrim(`
I'm fine,
thank you!
And you?
`),
},
);
// Hello, world!
//
// > I'm fine,
// > thank you!
// >
// > And you?
These functions are useful to count stats about the input/output in human-like terms not tokens and bytes, you can use
countCharacters, countLines, countPages, countParagraphs, countSentences, countWords
import { countWords } from '@promptbook/utils';
console.log(countWords('Hello, world!')); // 2
Splitting functions are similar to counting but they return the split parts of the input/output, you can use
splitIntoCharacters, splitIntoLines, splitIntoPages, splitIntoParagraphs, splitIntoSentences, splitIntoWords
import { splitIntoWords } from '@promptbook/utils';
console.log(splitIntoWords('Hello, world!')); // ['Hello', 'world']
Normalization functions are used to put the string into a normalized form, you can use
kebab-case
PascalCase
SCREAMING_CASE
snake_case
kebab-case
import { normalizeTo } from '@promptbook/utils';
console.log(normalizeTo['kebab-case']('Hello, world!')); // 'hello-world'
capitalize, decapitalize, removeDiacritics,...POSTPROCESS command in promptbookSometimes you need to postprocess the output of the LLM model, every postprocessing function that is available through POSTPROCESS command in promptbook is exported from @promptbook/utils. You can use:
spaceTrimextractAllBlocksFromMarkdown, <- Note: Exported from @promptbook/markdown-utilsextractAllListItemsFromMarkdown <- Note: Exported from @promptbook/markdown-utilsextractBlockextractOneBlockFromMarkdown <- Note: Exported from @promptbook/markdown-utilsprettifyPipelineStringremoveMarkdownCommentsremoveEmojisremoveMarkdownFormatting <- Note: Exported from @promptbook/markdown-utilsremoveQuotestrimCodeBlocktrimEndOfCodeBlockunwrapResultVery often you will use unwrapResult, which is used to extract the result you need from output with some additional information:
import { unwrapResult } from '@promptbook/utils';
unwrapResult('Best greeting for the user is "Hi Pavol!"'); // 'Hi Pavol!'
BOOK_LANGUAGE_VERSION - Current book language versionPROMPTBOOK_ENGINE_VERSION - Current engine versionVALUE_STRINGS - Standard value stringsSMALL_NUMBER - Small number constantrenderPromptbookMermaid - Render promptbook as Mermaid diagramdeserializeError - Deserialize error objectsserializeError - Serialize error objectsforEachAsync - Async forEach implementationisValidCsvString - Validate CSV string formatisValidJsonString - Validate JSON string formatjsonParse - Safe JSON parsingisValidXmlString - Validate XML string formatprompt - Template tag for secure prompt formattingpromptTemplate - Alias for prompt template tag$getCurrentDate - Get current date (side effect)$isRunningInBrowser - Check if running in browser$isRunningInJest - Check if running in Jest$isRunningInNode - Check if running in Node.js$isRunningInWebWorker - Check if running in Web WorkerCHARACTERS_PER_STANDARD_LINE - Characters per standard line constantLINES_PER_STANDARD_PAGE - Lines per standard page constantcountCharacters - Count characters in textcountLines - Count lines in textcountPages - Count pages in textcountParagraphs - Count paragraphs in textsplitIntoSentences - Split text into sentencescountSentences - Count sentences in textcountWords - Count words in textCountUtils - Utility object with all counting functionscapitalize - Capitalize first letterdecapitalize - Decapitalize first letterDIACRITIC_VARIANTS_LETTERS - Diacritic variants mappingstring_keyword - Keyword string type (type)Keywords - Keywords type (type)isValidKeyword - Validate keyword formatnameToUriPart - Convert name to URI partnameToUriParts - Convert name to URI partsstring_kebab_case - Kebab case string type (type)normalizeToKebabCase - Convert to kebab-casestring_camelCase - Camel case string type (type)normalizeTo_camelCase - Convert to camelCasestring_PascalCase - Pascal case string type (type)normalizeTo_PascalCase - Convert to PascalCasestring_SCREAMING_CASE - Screaming case string type (type)normalizeTo_SCREAMING_CASE - Convert to SCREAMING_CASEnormalizeTo_snake_case - Convert to snake_casenormalizeWhitespaces - Normalize whitespace charactersorderJson - Order JSON object propertiesparseKeywords - Parse keywords from inputparseKeywordsFromString - Parse keywords from stringremoveDiacritics - Remove diacritic markssearchKeywords - Search within keywordssuffixUrl - Add suffix to URLtitleToName - Convert title to name formatspaceTrim - Trim spaces while preserving structureextractParameterNames - Extract parameter names from templatenumberToString - Convert number to stringtemplateParameters - Replace template parametersvalueToString - Convert value to stringparseNumber - Parse number from stringremoveEmojis - Remove emoji charactersremoveQuotes - Remove quote characters$deepFreeze - Deep freeze object (side effect)checkSerializableAsJson - Check if serializable as JSONclonePipeline - Clone pipeline objectdeepClone - Deep clone objectexportJson - Export object as JSONisSerializableAsJson - Check if object is JSON serializablejsonStringsToJsons - Convert JSON strings to objectsdifference - Set difference operationintersection - Set intersection operationunion - Set union operationtrimCodeBlock - Trim code block formattingtrimEndOfCodeBlock - Trim end of code blockunwrapResult - Extract result from wrapped outputisValidEmail - Validate email address formatisRootPath - Check if path is root pathisValidFilePath - Validate file path formatisValidJavascriptName - Validate JavaScript identifierisValidPromptbookVersion - Validate promptbook versionisValidSemanticVersion - Validate semantic versionisHostnameOnPrivateNetwork - Check if hostname is on private networkisUrlOnPrivateNetwork - Check if URL is on private networkisValidPipelineUrl - Validate pipeline URL formatisValidUrl - Validate URL formatisValidUuid - Validate UUID format๐ก This package provides utility functions for promptbook applications. For the core functionality, see @promptbook/core or install all packages with
npm i ptbk
Rest of the documentation is common for entire promptbook ecosystem:
For most business applications nowadays, the biggest challenge isn't about the raw capabilities of AI models. Large language models like GPT-5 or Claude-4.1 are extremely capable.
The main challenge is to narrow it down, constrain it, set the proper context, rules, knowledge, and personality. There are a lot of tools which can do exactly this. On one side, there are no-code platforms which can launch your agent in seconds. On the other side, there are heavy frameworks like Langchain or Semantic Kernel, which can give you deep control.
Promptbook takes the best from both worlds. You are defining your AI behavior by simple books, which are very explicit. They are automatically enforced, but they are very easy to understand, very easy to write, and very reliable and portable.

We have created a language called Book, which allows you to write AI agents in their native language and create your own AI persona. Book provides a guide to define all the traits and commitments.
You can look at it as prompting (or writing a system message), but decorated by commitments.
Persona commitmentPersonas define the character of your AI persona, its role, and how it should interact with users. It sets the tone and style of communication.

Knowledge commitmentKnowledge Commitment allows you to provide specific information, facts, or context that the AI should be aware of when responding.
This can include domain-specific knowledge, company policies, or any other relevant information.
Promptbook Engine will automatically enforce this knowledge during interactions. When the knowledge is short enough, it will be included in the prompt. When it is too long, it will be stored in vector databases and RAG retrieved when needed. But you don't need to care about it.

Rule commitmentRules will enforce specific behaviors or constraints on the AI's responses. This can include ethical guidelines, communication styles, or any other rules you want the AI to follow.
Depending on rule strictness, Promptbook will either propagate it to the prompt or use other techniques, like adversary agent, to enforce it.

Action commitmentAction Commitment allows you to define specific actions that the AI can take during interactions. This can include things like posting on a social media platform, sending emails, creating calendar events, or interacting with your internal systems.

Books can be useful in various applications and scenarios. Here are some examples:
Create your own chat shopping assistant and place it in your eShop. You will be able to answer customer questions, help them find products, and provide personalized recommendations. Everything is tightly controlled by the book you have written.
Create your own AI agent, which will look at your emails and reply to them. It can even create drafts for you to review before sending.
Do you love Vibecoding, but the AI code is not always aligned with your coding style and architecture, rules, security, etc.? Create your own coding agent to help enforce your specific coding standards and practices.
This can be integrated to almost any Vibecoding platform, like GitHub Copilot, Amazon CodeWhisperer, Cursor, Cline, Kilocode, Roocode,...
They will work the same as you are used to, but with your specific rules written in book.
Do you have an app written in TypeScript, Python, C#, Java, or any other language, and you are integrating the AI.
You can avoid struggle with choosing the best model, its settings like temperature, max tokens, etc., by writing a book agent and using it as your AI expertise.
Doesn't matter if you do automations, data analysis, customer support, sentiment analysis, classification, or any other task. Your AI agent will be tailored to your specific needs and requirements.
Even works in no-code platforms!
Now you want to use it. There are several ways how to write your first book:
We have written ai asistant in book who can help you with writing your first book.
Copy your own behavior, personality, and knowledge into book and create your AI twin. It can help you with your work, personal life, or any other task.
Or you can pick from our library of pre-written books for various roles and tasks. You can find books for customer support, coding, marketing, sales, HR, legal, and many other roles.
Take a look at the simple starter kit with books integrated into the Hello World sample applications:
Promptbook project is ecosystem of multiple projects and tools, following is a list of most important pieces of the project:
| Project | About |
|---|---|
| Book language |
Book is a human-understandable markup language for writing AI applications such as chatbots, knowledge bases, agents, avarars, translators, automations and more.
There is also a plugin for VSCode to support .book file extension
|
| Promptbook Engine | Promptbook engine can run applications written in Book language. It is released as multiple NPM packages and Docker HUB |
| Promptbook Studio | Promptbook.studio is a web-based editor and runner for book applications. It is still in the experimental MVP stage. |
Hello world examples:
Join our growing community of developers and users:
| Platform | Description |
|---|---|
| ๐ฌ Discord | Join our active developer community for discussions and support |
| ๐ฃ๏ธ GitHub Discussions | Technical discussions, feature requests, and community Q&A |
| ๐ LinkedIn | Professional updates and industry insights |
| ๐ฑ Facebook | General announcements and community engagement |
| ๐ ptbk.io | Official landing page with project information |
| ๐ธ Instagram @promptbook.studio | Visual updates, UI showcases, and design inspiration |
See detailed guides and API reference in the docs or online.
For information on reporting security vulnerabilities, see our Security Policy.
This library is divided into several packages, all are published from single monorepo. You can install all of them at once:
npm i ptbk
Or you can install them separately:
โญ Marked packages are worth to try first
โญ ptbk - Bundle of all packages, when you want to install everything and you don't care about the size
promptbook - Same as ptbk
โญ๐งโโ๏ธ @promptbook/wizard - Wizard to just run the books in node without any struggle
@promptbook/core - Core of the library, it contains the main logic for promptbooks
@promptbook/node - Core of the library for Node.js environment
@promptbook/browser - Core of the library for browser environment
โญ @promptbook/utils - Utility functions used in the library but also useful for individual use in preprocessing and postprocessing LLM inputs and outputs
@promptbook/markdown-utils - Utility functions used for processing markdown
(Not finished) @promptbook/wizard - Wizard for creating+running promptbooks in single line
@promptbook/javascript - Execution tools for javascript inside promptbooks
@promptbook/openai - Execution tools for OpenAI API, wrapper around OpenAI SDK
@promptbook/anthropic-claude - Execution tools for Anthropic Claude API, wrapper around Anthropic Claude SDK
@promptbook/vercel - Adapter for Vercel functionalities
@promptbook/google - Integration with Google's Gemini API
@promptbook/deepseek - Integration with DeepSeek API
@promptbook/ollama - Integration with Ollama API
@promptbook/azure-openai - Execution tools for Azure OpenAI API
@promptbook/fake-llm - Mocked execution tools for testing the library and saving the tokens
@promptbook/remote-client - Remote client for remote execution of promptbooks
@promptbook/remote-server - Remote server for remote execution of promptbooks
@promptbook/pdf - Read knowledge from .pdf documents
@promptbook/documents - Integration of Markitdown by Microsoft
@promptbook/documents - Read knowledge from documents like .docx, .odt,โฆ
@promptbook/legacy-documents - Read knowledge from legacy documents like .doc, .rtf,โฆ
@promptbook/website-crawler - Crawl knowledge from the web
@promptbook/editable - Editable book as native javascript object with imperative object API
@promptbook/templates - Useful templates and examples of books which can be used as a starting point
@promptbook/types - Just typescript types used in the library
@promptbook/color - Color manipulation library
โญ @promptbook/cli - Command line interface utilities for promptbooks
๐ Docker image - Promptbook server
The following glossary is used to clarify certain concepts:
Note: This section is not a complete dictionary, more list of general AI / LLM terms that has connection with Promptbook
| Data & Knowledge Management | Pipeline Control |
|---|---|
|
|
| Language & Output Control | Advanced Generation |
|
|
If you have a question start a discussion, open an issue or write me an email.
See CHANGELOG.md
This project is licensed under BUSL 1.1.
We welcome contributions! See CONTRIBUTING.md for guidelines.
You can also โญ star the project, follow us on GitHub or various other social networks.We are open to pull requests, feedback, and suggestions.
Need help with Book language? We're here for you!
We welcome contributions and feedback to make Book language better for everyone!
FAQs
Promptbook: Turn your company's scattered knowledge into AI ready books
The npm package @promptbook/utils receives a total of 728,202 weekly downloads. As such, @promptbook/utils popularity was classified as popular.
We found that @promptbook/utils demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.ย It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.