
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@smartmemory/compose
Advanced tools
Structured AI dev pipeline — goal-to-product orchestration with gates, iteration loops, and feature lifecycle management.
Compose is a CLI that drives a product idea from intent to shipped code. It runs YAML-defined multi-step pipelines on top of Stratum, dispatching each step to an AI agent (Claude or Codex), checking postconditions, and pausing at human gates between phases. Output: a feature folder with design, blueprint, plan, code, tests, review trail, and an updated ROADMAP.md — auditable end-to-end.

.stratum.yaml specs with typed contracts, ensure postconditions, and retry/on_fail routing. Specs are editable.compose new "REST API for managing team todo lists"
-> questionnaire (interactive)
-> research (claude) -> brainstorm (claude)
-> [gate] approve / revise / kill
-> roadmap (claude) -> [gate] -> scaffold (claude)
-> done: feature folders + ROADMAP.md ready
compose build TODO-1
-> design (claude) -> [gate]
-> blueprint (claude) -> verification (claude)
-> plan (claude) -> [gate]
-> decompose + parallel execute (worktree isolation)
-> claude review lenses + codex review + coverage sweep
-> docs + ship -> [gate]
-> done: feature implemented, reviewed, tested, documented
Prerequisites: Node.js 18+ and stratum-mcp on PATH (pip install stratum-mcp, requires Python 3.11+). Codex steps additionally need the OpenAI codex CLI. Full prereqs in docs/install.md.
The package is published to npm as @smartmemory/compose. Pick one install style:
Option A — npm (recommended for users):
npm install -g @smartmemory/compose
compose setup # install bundled skills + register stratum-mcp (alias: compose sync)
Option B — git clone (for development):
git clone https://github.com/smartmemory/compose.git && cd compose && npm install
npx @smartmemory/compose setup # or: node bin/compose.js setup
ln -s "$(pwd)/bin/compose.js" ~/bin/compose && chmod +x ~/bin/compose # optional: bare `compose` command
Then in your project:
cd /path/to/your/project
compose init # writes .compose/, registers MCP, scaffolds ROADMAP and pipeline specs
compose new "what you want to build"
Add an isolated feature to an existing project:
compose feature AUTH-1 "JWT middleware with refresh tokens"
compose build AUTH-1
One command — auto-detects whether compose was installed via npm or git clone:
compose update
For npm installs, this runs npm install -g @smartmemory/compose@latest. For git clones, it runs git pull --ff-only && npm install. Either way it then refreshes the global skill and (if invoked from inside a Compose project) re-runs compose init to refresh .mcp.json and pipeline templates. Use compose update --force to bypass the dirty-tree check on git clones.
Check what you're running:
compose --version
compose setup (alias compose sync) mirrors compose-owned skills into your agent skill dirs (~/.claude/skills/, shared with Codex). Re-run it after a compose update or after editing skills locally — it's idempotent.
/compose — the build/fix lifecycle orchestrator (idea → design → blueprint → implement; or triage → fix → verify)./context-budget — read-only audit of the session-start loaded surface (agents, skills, rules, MCP tool schemas, CLAUDE.md chain). Estimates per-component token cost, classifies each into always / sometimes / rarely needed, and prints a ranked cut list with estimated reclaim. Never auto-applies cuts.compose update fetches a newer compose (npm or git) and then runs setup for you; use compose sync when there's no new version to pull — you just changed skills locally.
Compose can persist feature data to different backends via the tracker block in .compose/compose.json.
Default (local) — zero configuration required:
{ "tracker": { "provider": "local" } }
local is the default when no tracker block is present. All writes go to the filesystem exactly as before — no behavior change.
GitHub provider:
{
"tracker": {
"provider": "github",
"github": {
"repo": "owner/repo",
"projectNumber": 42,
"branch": "main",
"roadmapPath": "ROADMAP.md",
"changelogPath": "CHANGELOG.md",
"cacheTtlSeconds": 300,
"auth": { "tokenEnv": "GITHUB_TOKEN" }
}
}
}
The GitHub provider syncs features to Issues (one per feature), Projects v2 (Status custom field), and Contents API (roadmap + changelog files). Requires a token in the named env var (or gh auth login fallback) with repo and project scopes.
CLI verbs:
compose tracker status # show provider health + pending op-log + conflict ledger
compose tracker sync # reconcile op-log against remote provider
See docs/configuration.md for the full tracker config reference.
Topic-scoped reference:
compose init, compose setup, ~/bin symlink, compose install compatibility shim.new, import, feature, build, pipeline, init, setup, doctor, start).on_fail routing, Stratum IR v0.3..compose/*.json, pipeline specs, .mcp.json, ROADMAP.md, environment variables.compose pipeline editing reference.build, fix, gsd, new, import, feature, roadmap, triage, qa-scope, pipeline, init/setup/update/doctor).FAQs
Structured AI dev pipeline: your agent writes the code, Compose makes it prove it. Gated design decisions, enforced postconditions, and independent review from goal to shipped code.
The npm package @smartmemory/compose receives a total of 1,020 weekly downloads. As such, @smartmemory/compose popularity was classified as popular.
We found that @smartmemory/compose demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.