
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@smartmemory/compose
Advanced tools
Structured AI dev pipeline — goal-to-product orchestration with gates, iteration loops, and feature lifecycle management.
Compose is a CLI that drives a product idea from intent to shipped code. It runs YAML-defined multi-step pipelines on top of Stratum, dispatching each step to an AI agent (Claude or Codex), checking postconditions, and pausing at human gates between phases. Output: a feature folder with design, blueprint, plan, code, tests, review trail, and an updated ROADMAP.md — auditable end-to-end.

.stratum.yaml specs with typed contracts, ensure postconditions, and retry/on_fail routing. Specs are editable.compose new "REST API for managing team todo lists"
-> questionnaire (interactive)
-> research (claude) -> brainstorm (claude)
-> [gate] approve / revise / kill
-> roadmap (claude) -> [gate] -> scaffold (claude)
-> done: feature folders + ROADMAP.md ready
compose build TODO-1
-> design (claude) -> [gate]
-> blueprint (claude) -> verification (claude)
-> plan (claude) -> [gate]
-> decompose + parallel execute (worktree isolation)
-> claude review lenses + codex review + coverage sweep
-> docs + ship -> [gate]
-> done: feature implemented, reviewed, tested, documented
Starting from a fuzzy goal instead of a known feature? Use the planning lifecycle:
compose plan "a tool that summarizes my team's standups"
-> frame + research + ideate (ideas go to the ideabox) -> [gate]
-> converge + estimate -> writes build-ready feature.json + design.md -> [gate]
-> handoff: each feature ready for `compose build <CODE>`
compose build then picks up a plan-authored feature and ratifies its design rather than rewriting it.
Prerequisites: Node.js 18+ and stratum-mcp on PATH (pip install stratum-mcp, requires Python 3.11+). Codex steps additionally need the OpenAI codex CLI. Full prereqs in docs/install.md.
The package is published to npm as @smartmemory/compose. Pick one install style:
Option A — npm (recommended for users):
npm install -g @smartmemory/compose
compose setup # install bundled skills + register stratum-mcp (alias: compose sync)
Option B — git clone (for development):
git clone https://github.com/smartmemory/compose.git && cd compose && npm install
npx @smartmemory/compose setup # or: node bin/compose.js setup
ln -s "$(pwd)/bin/compose.js" ~/bin/compose && chmod +x ~/bin/compose # optional: bare `compose` command
Then in your project:
cd /path/to/your/project
compose init # writes .compose/, registers MCP, scaffolds ROADMAP, pipeline specs, contracts/vocabulary.yaml
compose new "what you want to build"
Add an isolated feature to an existing project:
compose feature AUTH-1 "JWT middleware with refresh tokens"
compose build AUTH-1
One command — auto-detects whether compose was installed via npm or git clone:
compose update
For npm installs, this runs npm install -g @smartmemory/compose@latest. For git clones, it runs git pull --ff-only && npm install. Either way it then refreshes the global skill and (if invoked from inside a Compose project) re-runs compose init to refresh .mcp.json and pipeline templates. Use compose update --force to bypass the dirty-tree check on git clones.
Check what you're running:
compose --version
compose setup (alias compose sync) mirrors compose-owned skills into your agent skill dirs (~/.claude/skills/, shared with Codex). Re-run it after a compose update or after editing skills locally — it's idempotent.
/compose — the build/fix lifecycle orchestrator (idea → design → blueprint → implement; or triage → fix → verify)./context-budget — read-only audit of the session-start loaded surface (agents, skills, rules, MCP tool schemas, CLAUDE.md chain). Estimates per-component token cost, classifies each into always / sometimes / rarely needed, and prints a ranked cut list with estimated reclaim. Never auto-applies cuts.compose update fetches a newer compose (npm or git) and then runs setup for you; use compose sync when there's no new version to pull — you just changed skills locally.
Compose can persist feature data to different backends via the tracker block in .compose/compose.json.
Default (local) — zero configuration required:
{ "tracker": { "provider": "local" } }
local is the default when no tracker block is present. All writes go to the filesystem exactly as before — no behavior change.
GitHub provider:
{
"tracker": {
"provider": "github",
"github": {
"repo": "owner/repo",
"projectNumber": 42,
"branch": "main",
"roadmapPath": "ROADMAP.md",
"changelogPath": "CHANGELOG.md",
"cacheTtlSeconds": 300,
"auth": { "tokenEnv": "GITHUB_TOKEN" }
}
}
}
The GitHub provider syncs features to Issues (one per feature), Projects v2 (Status custom field), and Contents API (roadmap + changelog files). Requires a token in the named env var (or gh auth login fallback) with repo and project scopes.
CLI verbs:
compose tracker status # show provider health + pending op-log + conflict ledger
compose tracker sync # reconcile op-log against remote provider
See docs/configuration.md for the full tracker config reference.
The mobile cockpit at /m can be reached from outside localhost — bring your own tunnel, compose handles auth and pairing:
npm run build # remote serves the built PWA from the API server
COMPOSE_REMOTE_AUTH=enabled compose start --host=0.0.0.0
compose remote pair --public-host=https://your-tunnel-host # prints a QR — scan it with your phone
compose remote status # bind, devices, tunnel reachability
How it works: binding beyond 127.0.0.1 refuses to start unless COMPOSE_REMOTE_AUTH=enabled is set. In remote mode every request needs a credential — there is deliberately no IP-based trust (tunnel daemons connect from loopback). Phones pair once via QR (5-minute single-use code) and stay authenticated for 30 days through rotating refresh tokens + 15-minute access JWTs; reuse of a rotated refresh token revokes the device. Devices are listable and revocable (compose remote list|revoke, or the cockpit's "Pair mobile" modal). Only port 4001 needs to be exposed — agent-server traffic is proxied through it.
Tunnel layer is yours: Tailscale (serve/funnel), Cloudflare Tunnel, or a reverse proxy on your own VPS+domain all work — the last is the most reliable from restrictive networks (e.g. mainland China, where trycloudflare.com/ngrok domains are commonly blocked; plain TLS on 443 to an unremarkable domain travels best). Pair the device before traveling: pairing needs a live round-trip, while an already-paired phone only needs refresh.
compose remote rotate-secret --yes invalidates every paired device (post-leak hammer).
Topic-scoped reference:
compose init, compose setup, ~/bin symlink, compose install compatibility shim.new, import, feature, build, pipeline, init, setup, doctor, start).on_fail routing, Stratum IR v0.3..compose/*.json, pipeline specs, .mcp.json, ROADMAP.md, environment variables.compose pipeline editing reference.build, fix, gsd, new, import, feature, roadmap, triage, qa-scope, pipeline, init/setup/update/doctor).FAQs
Structured AI dev pipeline: your agent writes the code, Compose makes it prove it. Gated design decisions, enforced postconditions, and independent review from goal to shipped code.
The npm package @smartmemory/compose receives a total of 1,020 weekly downloads. As such, @smartmemory/compose popularity was classified as popular.
We found that @smartmemory/compose demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.