@quantakrypto/agent
Advanced tools
+0
-7
@@ -31,11 +31,4 @@ /** | ||
| } | ||
| /** | ||
| * Reject a base URL that would send the BYOK key over plaintext to a non-local | ||
| * host. A poisoned `baseURL` must not be able to redirect the API key + code | ||
| * context to an attacker endpoint over http (agent audit — provider spoofing). | ||
| * Plain http is permitted only for loopback (local LLM servers: Ollama/vLLM). | ||
| */ | ||
| export declare function assertSafeBaseUrl(baseURL: string | undefined): void; | ||
| /** Pick the adapter for `config.provider`. `fetchImpl` is injectable for tests. */ | ||
| export declare function resolveClient(config: LlmConfig, fetchImpl?: typeof fetch): LlmClient; | ||
| //# sourceMappingURL=client.d.ts.map |
@@ -1,1 +0,1 @@ | ||
| {"version":3,"file":"client.d.ts","sourceRoot":"","sources":["../src/client.ts"],"names":[],"mappings":"AAAA;;;GAGG;AACH,OAAO,KAAK,EAAE,UAAU,EAAE,MAAM,eAAe,CAAC;AAIhD,8CAA8C;AAC9C,MAAM,WAAW,UAAU;IACzB,MAAM,EAAE,MAAM,CAAC;IACf,IAAI,EAAE,MAAM,CAAC;IACb,0EAA0E;IAC1E,MAAM,EAAE,UAAU,CAAC;IACnB,SAAS,EAAE,MAAM,CAAC;CACnB;AAED,8EAA8E;AAC9E,MAAM,WAAW,SAAS;IACxB,QAAQ,CAAC,GAAG,EAAE,UAAU,GAAG,OAAO,CAAC,OAAO,CAAC,CAAC;CAC7C;AAED,gFAAgF;AAChF,MAAM,WAAW,SAAS;IACxB,QAAQ,EAAE,WAAW,GAAG,mBAAmB,CAAC;IAC5C,iFAAiF;IACjF,OAAO,CAAC,EAAE,MAAM,CAAC;IACjB,KAAK,EAAE,MAAM,CAAC;IACd,MAAM,EAAE,MAAM,CAAC;IACf,+DAA+D;IAC/D,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,4DAA4D;IAC5D,UAAU,CAAC,EAAE,MAAM,CAAC;CACrB;AAED;;;;;GAKG;AACH,wBAAgB,iBAAiB,CAAC,OAAO,EAAE,MAAM,GAAG,SAAS,GAAG,IAAI,CAcnE;AAED,mFAAmF;AACnF,wBAAgB,aAAa,CAAC,MAAM,EAAE,SAAS,EAAE,SAAS,GAAE,OAAO,KAAa,GAAG,SAAS,CAK3F"} | ||
| {"version":3,"file":"client.d.ts","sourceRoot":"","sources":["../src/client.ts"],"names":[],"mappings":"AAAA;;;GAGG;AACH,OAAO,KAAK,EAAE,UAAU,EAAE,MAAM,eAAe,CAAC;AAIhD,8CAA8C;AAC9C,MAAM,WAAW,UAAU;IACzB,MAAM,EAAE,MAAM,CAAC;IACf,IAAI,EAAE,MAAM,CAAC;IACb,0EAA0E;IAC1E,MAAM,EAAE,UAAU,CAAC;IACnB,SAAS,EAAE,MAAM,CAAC;CACnB;AAED,8EAA8E;AAC9E,MAAM,WAAW,SAAS;IACxB,QAAQ,CAAC,GAAG,EAAE,UAAU,GAAG,OAAO,CAAC,OAAO,CAAC,CAAC;CAC7C;AAED,gFAAgF;AAChF,MAAM,WAAW,SAAS;IACxB,QAAQ,EAAE,WAAW,GAAG,mBAAmB,CAAC;IAC5C,iFAAiF;IACjF,OAAO,CAAC,EAAE,MAAM,CAAC;IACjB,KAAK,EAAE,MAAM,CAAC;IACd,MAAM,EAAE,MAAM,CAAC;IACf,+DAA+D;IAC/D,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,4DAA4D;IAC5D,UAAU,CAAC,EAAE,MAAM,CAAC;CACrB;AAwBD,mFAAmF;AACnF,wBAAgB,aAAa,CAAC,MAAM,EAAE,SAAS,EAAE,SAAS,GAAE,OAAO,KAAa,GAAG,SAAS,CAK3F"} |
+1
-1
@@ -9,3 +9,3 @@ import { anthropicClient } from "./anthropic.js"; | ||
| */ | ||
| export function assertSafeBaseUrl(baseURL) { | ||
| function assertSafeBaseUrl(baseURL) { | ||
| if (!baseURL) | ||
@@ -12,0 +12,0 @@ return; |
@@ -1,1 +0,1 @@ | ||
| {"version":3,"file":"client.js","sourceRoot":"","sources":["../src/client.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,gBAAgB,CAAC;AACjD,OAAO,EAAE,sBAAsB,EAAE,MAAM,aAAa,CAAC;AA8BrD;;;;;GAKG;AACH,MAAM,UAAU,iBAAiB,CAAC,OAA2B;IAC3D,IAAI,CAAC,OAAO;QAAE,OAAO;IACrB,IAAI,CAAM,CAAC;IACX,IAAI,CAAC;QACH,CAAC,GAAG,IAAI,GAAG,CAAC,OAAO,CAAC,CAAC;IACvB,CAAC;IAAC,MAAM,CAAC;QACP,MAAM,IAAI,KAAK,CAAC,wBAAwB,OAAO,EAAE,CAAC,CAAC;IACrD,CAAC;IACD,MAAM,UAAU,GAAG,CAAC,WAAW,EAAE,WAAW,EAAE,OAAO,EAAE,KAAK,CAAC,CAAC,QAAQ,CAAC,CAAC,CAAC,QAAQ,CAAC,CAAC;IACnF,IAAI,CAAC,CAAC,QAAQ,KAAK,QAAQ,IAAI,CAAC,CAAC,CAAC,CAAC,QAAQ,KAAK,OAAO,IAAI,UAAU,CAAC,EAAE,CAAC;QACvE,MAAM,IAAI,KAAK,CACb,qCAAqC,CAAC,CAAC,QAAQ,KAAK,CAAC,CAAC,QAAQ,yEAAyE,CACxI,CAAC;IACJ,CAAC;AACH,CAAC;AAED,mFAAmF;AACnF,MAAM,UAAU,aAAa,CAAC,MAAiB,EAAE,YAA0B,KAAK;IAC9E,iBAAiB,CAAC,MAAM,CAAC,OAAO,CAAC,CAAC;IAClC,OAAO,MAAM,CAAC,QAAQ,KAAK,WAAW;QACpC,CAAC,CAAC,eAAe,CAAC,MAAM,EAAE,SAAS,CAAC;QACpC,CAAC,CAAC,sBAAsB,CAAC,MAAM,EAAE,SAAS,CAAC,CAAC;AAChD,CAAC","sourcesContent":["/**\n * The provider-agnostic LLM client contract. Adapters (anthropic.ts, openai.ts)\n * implement {@link LlmClient}; {@link resolveClient} picks one from config.\n */\nimport type { JsonSchema } from \"./validate.js\";\nimport { anthropicClient } from \"./anthropic.js\";\nimport { openAiCompatibleClient } from \"./openai.js\";\n\n/** A single structured completion request. */\nexport interface LlmRequest {\n system: string;\n user: string;\n /** JSON Schema the response MUST satisfy (validated + repair-retried). */\n schema: JsonSchema;\n maxTokens: number;\n}\n\n/** A provider adapter: turns an {@link LlmRequest} into schema-valid JSON. */\nexport interface LlmClient {\n complete(req: LlmRequest): Promise<unknown>;\n}\n\n/** BYOK provider configuration. `apiKey` is resolved from env by the caller. */\nexport interface LlmConfig {\n provider: \"anthropic\" | \"openai-compatible\";\n /** Override the provider's default base URL (e.g. a local or Azure endpoint). */\n baseURL?: string;\n model: string;\n apiKey: string;\n /** Sampling temperature; defaults to 0 for reproducibility. */\n temperature?: number;\n timeoutMs?: number;\n /** Repair retries on an invalid response. Defaults to 1. */\n maxRetries?: number;\n}\n\n/**\n * Reject a base URL that would send the BYOK key over plaintext to a non-local\n * host. A poisoned `baseURL` must not be able to redirect the API key + code\n * context to an attacker endpoint over http (agent audit — provider spoofing).\n * Plain http is permitted only for loopback (local LLM servers: Ollama/vLLM).\n */\nexport function assertSafeBaseUrl(baseURL: string | undefined): void {\n if (!baseURL) return;\n let u: URL;\n try {\n u = new URL(baseURL);\n } catch {\n throw new Error(`invalid LLM baseURL: ${baseURL}`);\n }\n const isLoopback = [\"localhost\", \"127.0.0.1\", \"[::1]\", \"::1\"].includes(u.hostname);\n if (u.protocol !== \"https:\" && !(u.protocol === \"http:\" && isLoopback)) {\n throw new Error(\n `refusing to send the API key over ${u.protocol}//${u.hostname} — the LLM baseURL must use https (http is allowed only for localhost).`,\n );\n }\n}\n\n/** Pick the adapter for `config.provider`. `fetchImpl` is injectable for tests. */\nexport function resolveClient(config: LlmConfig, fetchImpl: typeof fetch = fetch): LlmClient {\n assertSafeBaseUrl(config.baseURL);\n return config.provider === \"anthropic\"\n ? anthropicClient(config, fetchImpl)\n : openAiCompatibleClient(config, fetchImpl);\n}\n"]} | ||
| {"version":3,"file":"client.js","sourceRoot":"","sources":["../src/client.ts"],"names":[],"mappings":"AAKA,OAAO,EAAE,eAAe,EAAE,MAAM,gBAAgB,CAAC;AACjD,OAAO,EAAE,sBAAsB,EAAE,MAAM,aAAa,CAAC;AA8BrD;;;;;GAKG;AACH,SAAS,iBAAiB,CAAC,OAA2B;IACpD,IAAI,CAAC,OAAO;QAAE,OAAO;IACrB,IAAI,CAAM,CAAC;IACX,IAAI,CAAC;QACH,CAAC,GAAG,IAAI,GAAG,CAAC,OAAO,CAAC,CAAC;IACvB,CAAC;IAAC,MAAM,CAAC;QACP,MAAM,IAAI,KAAK,CAAC,wBAAwB,OAAO,EAAE,CAAC,CAAC;IACrD,CAAC;IACD,MAAM,UAAU,GAAG,CAAC,WAAW,EAAE,WAAW,EAAE,OAAO,EAAE,KAAK,CAAC,CAAC,QAAQ,CAAC,CAAC,CAAC,QAAQ,CAAC,CAAC;IACnF,IAAI,CAAC,CAAC,QAAQ,KAAK,QAAQ,IAAI,CAAC,CAAC,CAAC,CAAC,QAAQ,KAAK,OAAO,IAAI,UAAU,CAAC,EAAE,CAAC;QACvE,MAAM,IAAI,KAAK,CACb,qCAAqC,CAAC,CAAC,QAAQ,KAAK,CAAC,CAAC,QAAQ,yEAAyE,CACxI,CAAC;IACJ,CAAC;AACH,CAAC;AAED,mFAAmF;AACnF,MAAM,UAAU,aAAa,CAAC,MAAiB,EAAE,YAA0B,KAAK;IAC9E,iBAAiB,CAAC,MAAM,CAAC,OAAO,CAAC,CAAC;IAClC,OAAO,MAAM,CAAC,QAAQ,KAAK,WAAW;QACpC,CAAC,CAAC,eAAe,CAAC,MAAM,EAAE,SAAS,CAAC;QACpC,CAAC,CAAC,sBAAsB,CAAC,MAAM,EAAE,SAAS,CAAC,CAAC;AAChD,CAAC","sourcesContent":["/**\n * The provider-agnostic LLM client contract. Adapters (anthropic.ts, openai.ts)\n * implement {@link LlmClient}; {@link resolveClient} picks one from config.\n */\nimport type { JsonSchema } from \"./validate.js\";\nimport { anthropicClient } from \"./anthropic.js\";\nimport { openAiCompatibleClient } from \"./openai.js\";\n\n/** A single structured completion request. */\nexport interface LlmRequest {\n system: string;\n user: string;\n /** JSON Schema the response MUST satisfy (validated + repair-retried). */\n schema: JsonSchema;\n maxTokens: number;\n}\n\n/** A provider adapter: turns an {@link LlmRequest} into schema-valid JSON. */\nexport interface LlmClient {\n complete(req: LlmRequest): Promise<unknown>;\n}\n\n/** BYOK provider configuration. `apiKey` is resolved from env by the caller. */\nexport interface LlmConfig {\n provider: \"anthropic\" | \"openai-compatible\";\n /** Override the provider's default base URL (e.g. a local or Azure endpoint). */\n baseURL?: string;\n model: string;\n apiKey: string;\n /** Sampling temperature; defaults to 0 for reproducibility. */\n temperature?: number;\n timeoutMs?: number;\n /** Repair retries on an invalid response. Defaults to 1. */\n maxRetries?: number;\n}\n\n/**\n * Reject a base URL that would send the BYOK key over plaintext to a non-local\n * host. A poisoned `baseURL` must not be able to redirect the API key + code\n * context to an attacker endpoint over http (agent audit — provider spoofing).\n * Plain http is permitted only for loopback (local LLM servers: Ollama/vLLM).\n */\nfunction assertSafeBaseUrl(baseURL: string | undefined): void {\n if (!baseURL) return;\n let u: URL;\n try {\n u = new URL(baseURL);\n } catch {\n throw new Error(`invalid LLM baseURL: ${baseURL}`);\n }\n const isLoopback = [\"localhost\", \"127.0.0.1\", \"[::1]\", \"::1\"].includes(u.hostname);\n if (u.protocol !== \"https:\" && !(u.protocol === \"http:\" && isLoopback)) {\n throw new Error(\n `refusing to send the API key over ${u.protocol}//${u.hostname} — the LLM baseURL must use https (http is allowed only for localhost).`,\n );\n }\n}\n\n/** Pick the adapter for `config.provider`. `fetchImpl` is injectable for tests. */\nexport function resolveClient(config: LlmConfig, fetchImpl: typeof fetch = fetch): LlmClient {\n assertSafeBaseUrl(config.baseURL);\n return config.provider === \"anthropic\"\n ? anthropicClient(config, fetchImpl)\n : openAiCompatibleClient(config, fetchImpl);\n}\n"]} |
+2
-2
| { | ||
| "name": "@quantakrypto/agent", | ||
| "version": "0.4.4", | ||
| "version": "0.5.0", | ||
| "description": "BYOK LLM client for qScan triage and remediation. Native fetch, zero runtime dependencies.", | ||
@@ -36,3 +36,3 @@ "license": "Apache-2.0", | ||
| "dependencies": { | ||
| "@quantakrypto/core": "0.4.4" | ||
| "@quantakrypto/core": "0.5.0" | ||
| }, | ||
@@ -39,0 +39,0 @@ "scripts": { |
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
84551
-0.59%605
-1.14%+ Added
- Removed
Updated