
Security News
/Research
Popular node-ipc npm Package Infected with Credential Stealer
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.
@qoder-ai/qodercli
Advanced tools
Qoder CLI 是Qoder品牌下的 CLI AI 编程助手,将强大的 AI 编程能力直接带入你的终端。
需要 Node.js >= 20.0.0
全局安装:
npm install -g @qoder-ai/qodercli
npm install -g @qoder-ai/qodercli@latest
npm install -g @qoder-ai/qodercli@beta
在当前目录启动交互式会话:
qodercli
指定模型:
qodercli -m <model-name>
非交互模式(适合脚本调用):
qodercli -p "解释这个代码仓库的架构"
分析现有代码:
cd your-project/
qodercli
> 给我总结一下昨天的所有代码变更
生成代码:
qodercli
> 帮我写一个 Express 中间件,实现请求频率限制
调试问题:
qodercli
> 这个测试为什么会失败?帮我修复它
Qoder CLI 使用自有认证体系,支持以下认证方式:
qodercli
# 首次运行自动打开浏览器引导登录
或显式执行登录命令:
qodercli login
后台每 30 分钟自动刷新 token,无需手动干预
如果环境不支持自动打开浏览器,设置
NO_BROWSER=1后 CLI 会打印 URL 供手动访问。
适用于 CI/CD 流水线或无浏览器环境:
export QODER_PERSONAL_ACCESS_TOKEN="your-pat-token"
qodercli
PAT 可在 Qoder 账号设置页 (https://qoder.com/account/integrations) 创建和管理。
| 环境变量 | 说明 |
|---|---|
QODER_PERSONAL_ACCESS_TOKEN | PAT 令牌,设置后自动使用 PAT 认证 |
QODER_CONFIG_DIR | 自定义配置目录(默认 ~/.qoder) |
NO_BROWSER | 设置后禁止自动打开浏览器 |
| 命令 | 说明 |
|---|---|
/login 或 /signin | 在会话中执行登录 |
/logout 或 /signout | 退出登录(需确认) |
在配置文件中添加 MCP 服务器,扩展 CLI 的能力
FAQs
Qoder AI CLI - AI-powered coding assistant
The npm package @qoder-ai/qodercli receives a total of 10,191 weekly downloads. As such, @qoder-ai/qodercli popularity was classified as popular.
We found that @qoder-ai/qodercli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.

Security News
TeamPCP and BreachForums are promoting a Shai-Hulud supply chain attack contest with a $1,000 prize for the biggest package compromise.

Security News
Packagist urges PHP projects to update Composer after a GitHub token format change exposed some GitHub Actions tokens in CI logs.