
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@sylphx/cli
Advanced tools
The Sylphx CLI: every Sylphx API method as a command. npm channel of the native sylphx binary.
Every Sylphx API method as a command, generated from the one schema, plus a small hand-written porcelain on the generated Rust SDK.
curl -fsSL https://github.com/SylphxAI/sylphx-clients/releases/latest/download/install.sh | sh # or: npm i -g @sylphx/cli · cargo install sylphx-cli
sylphx login # approve at sylphx.com/device; the org key goes to the OS keychain
sylphx login --api-key - # agents and CI: an Access key on stdin (or SYLPHX_API_KEY)
sylphx logout # revokes the key and forgets it
sylphx link --env orgs/…/envs/… # defaults for this directory (.sylphx/project.json)
sylphx data databases create main --spec.compute-units 2
sylphx data databases list -o json
sylphx mcp # the MCP server over stdio
sylphx <service> <collection> <verb> [NAME|PARENT|ID] [--flags]: flags
are the spec fields in dotted kebab-case (--spec.compute-units);
--from-file takes a whole request; --output table|json|yaml|name.main) expands below the linked env; parents default to the
linked project, else the key's scope.--no-wait to skip); --dry-run sets
validate_only; updates send the etag they read and a mask of the flags
given; destructive calls ask first (--yes to skip).sylphx api GET /v1/whoami is the raw escape hatch.generated/commands.json is sylphx-gen output; never edit it.
FAQs
The Sylphx CLI: every Sylphx API method as a command. npm channel of the native sylphx binary.
The npm package @sylphx/cli receives a total of 811 weekly downloads. As such, @sylphx/cli popularity was classified as not popular.
We found that @sylphx/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.