
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@rankcli/agent-runtime
Advanced tools
Core audit engine for RankCLI. Runs 280+ SEO checks and powers both the CLI and SaaS edge functions.
This package is isomorphic - it works in both Node.js and Deno environments:
packages/cli)packages/saas/supabase/functions)The isomorphic design uses native fetch API instead of Node-specific modules like axios or https.
src/
├── audit/
│ ├── engine.ts # Main audit orchestrator
│ ├── types.ts # Issue definitions & types
│ ├── deno-entry.ts # Deno-specific entry point
│ └── checks/ # Individual check modules
│ ├── crawlability.ts
│ ├── on-page.ts
│ ├── performance.ts
│ ├── security.ts
│ ├── ai-readiness.ts
│ └── ... (40+ check modules)
├── utils/
│ └── http.ts # Isomorphic HTTP utilities
├── content/ # Content generation
├── geo/ # GEO tracking
├── git/ # Git/PR helpers
└── index.ts # Main entry point
# Install dependencies
pnpm install
# Development mode (watches both Node and Deno bundles)
pnpm dev
# Run tests
pnpm test # Watch mode
pnpm test:run # Single run
# Build for production
pnpm build # Builds Node.js + Deno bundles
# Build only Deno bundle
pnpm build:deno
When you run pnpm dev, it:
This ensures both the CLI (Node.js) and edge functions (Deno) stay in sync during development.
| Script | Description |
|---|---|
pnpm dev | Watch mode - rebuilds Node + Deno on changes |
pnpm dev:node | Watch mode - Node.js only |
pnpm dev:deno | Watch mode - Deno bundle only |
pnpm build | Production build (Node.js + Deno) |
pnpm build:deno | Build Deno bundle only |
pnpm test | Run tests in watch mode |
pnpm test:run | Run tests once |
The Deno bundle is generated at:
packages/saas/supabase/functions/_shared/audit/
├── engine.bundle.js # Bundled audit engine
└── index.ts # Wrapper with cheerio import
Edge functions import from the shared bundle:
import { runFullAudit } from '../_shared/audit/index.ts';
scripts/build-deno.ts uses esbuild to bundle src/audit/deno-entry.tscheerio (imported from esm.sh at runtime)When adding new features to the audit engine:
fetch instead of axios or Node's http/httpssrc/utils/http.ts for HTTP requestsfs, path, dns, crypto, etc.)additional-checks.ts)pnpm test) and edge functionsIf using VS Code, these tasks are available (Cmd/Ctrl+Shift+P → "Tasks: Run Task"):
| Task | Description |
|---|---|
| Dev: Agent Runtime (with Deno watch) | Watches and rebuilds both bundles |
| Dev: SaaS Frontend | Runs the Vite dev server |
| Dev: Full Stack | Runs both in parallel |
| Build: Deno Bundle | One-time Deno bundle build |
| Deploy: Edge Functions | Deploys to Supabase |
When using the devcontainer:
pnpm dev in packages/agent-runtime to start watching for changesMain entry point for running audits:
import { runFullAudit } from '@rankcli/agent-runtime';
const report = await runFullAudit('https://example.com', {
maxPages: 10, // Max pages to crawl
includeAdvanced: true, // Run advanced checks
includeAI: false, // Run AI-powered analysis
});
console.log(report.overallScore); // 0-100
console.log(report.issues); // Array of issues
console.log(report.healthScores); // Category scores
console.log(report.checksRun); // Number of checks run
interface AuditIssue {
code: string; // e.g., 'TITLE_MISSING'
severity: 'error' | 'warning' | 'notice';
category: string; // e.g., 'on-page', 'security'
title: string; // Human-readable title
description?: string; // Detailed description
impact?: string; // SEO impact explanation
howToFix?: string; // Fix instructions
affectedUrls?: string[];
details?: Record<string, unknown>;
}
interface HealthScores {
crawlability: number; // 0-100
onPage: number;
content: number;
performance: number;
security: number;
socialMeta: number;
aiReadiness: number;
mobile: number;
}
src/audit/checks/ or add to an existing onesrc/audit/engine.ts to include in the audit flowsrc/audit/deno-entry.ts to export for Denopnpm build:deno to regenerate the bundle.test.ts fileExample check:
// src/audit/checks/my-check.ts
import { httpGet } from '../../utils/http.js';
import type { AuditIssue } from '../types.js';
export async function checkMyThing(url: string): Promise<AuditIssue[]> {
const issues: AuditIssue[] = [];
const response = await httpGet(url);
if (/* condition */) {
issues.push({
code: 'MY_ISSUE_CODE',
severity: 'warning',
category: 'my-category',
title: 'Issue title',
description: 'What this means',
howToFix: 'How to fix it',
affectedUrls: [url],
});
}
return issues;
}
Tests use Vitest:
# Run all tests
pnpm test:run
# Run specific test file
pnpm test:run src/audit/checks/social-meta.test.ts
# Run with coverage
pnpm test:coverage
MIT
FAQs
RankCLI agent runtime - executes SEO audits and fixes with AI
The npm package @rankcli/agent-runtime receives a total of 2,404 weekly downloads. As such, @rankcli/agent-runtime popularity was classified as popular.
We found that @rankcli/agent-runtime demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.