
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@smartmemory/compose
Advanced tools
Structured AI dev pipeline — goal-to-product orchestration with gates, iteration loops, and feature lifecycle management.
Compose is a CLI that drives a product idea from intent to shipped code. It runs YAML-defined multi-step pipelines on top of Stratum, dispatching each step to an AI agent (Claude or Codex), checking postconditions, and pausing at human gates between phases. Output: a feature folder with design, blueprint, plan, code, tests, review trail, and an updated ROADMAP.md — auditable end-to-end.

.stratum.yaml specs with typed contracts, ensure postconditions, and retry/on_fail routing. Specs are editable.compose new "REST API for managing team todo lists"
-> questionnaire (interactive)
-> research (claude) -> brainstorm (claude)
-> [gate] approve / revise / kill
-> roadmap (claude) -> [gate] -> scaffold (claude)
-> done: feature folders + ROADMAP.md ready
compose build TODO-1
-> design (claude) -> [gate]
-> blueprint (claude) -> verification (claude)
-> plan (claude) -> [gate]
-> decompose + parallel execute (worktree isolation)
-> claude review lenses + codex review + coverage sweep
-> docs + ship -> [gate]
-> done: feature implemented, reviewed, tested, documented
Prerequisites: Node.js 18+ and stratum-mcp on PATH (pip install stratum). Codex steps additionally need the OpenAI codex CLI. Full prereqs in docs/install.md.
git clone https://github.com/smartmemory/compose.git && cd compose && npm install
npx compose setup # global skill + stratum-mcp registration
ln -s "$(pwd)/bin/compose.js" ~/bin/compose && chmod +x ~/bin/compose # optional: bare `compose` command
Then in your project:
cd /path/to/your/project
npx compose init # writes .compose/, registers MCP, scaffolds ROADMAP and pipeline specs
npx compose new "what you want to build"
Add an isolated feature to an existing project:
npx compose feature AUTH-1 "JWT middleware with refresh tokens"
npx compose build AUTH-1
Topic-scoped reference:
compose init, compose setup, ~/bin symlink, compose install compatibility shim.new, import, feature, build, pipeline, init, setup, doctor, start).on_fail routing, Stratum IR v0.3..compose/*.json, pipeline specs, .mcp.json, ROADMAP.md, environment variables.compose pipeline editing reference.FAQs
Structured AI dev pipeline: your agent writes the code, Compose makes it prove it. Gated design decisions, enforced postconditions, and independent review from goal to shipped code.
The npm package @smartmemory/compose receives a total of 1,020 weekly downloads. As such, @smartmemory/compose popularity was classified as popular.
We found that @smartmemory/compose demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.