
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
@wipcomputer/wip-ai-devops-toolbox
Advanced tools
The complete AI DevOps toolkit for AI-assisted development teams.
Your AI writes code. But does it know how to release it? Check license compliance? Protect your identity files? Sync private repos to public? Follow a real development process?
AI DevOps Toolbox is the complete toolkit. Built by a team of humans and AIs shipping real software together.
Open your AI and paste this:
Read wip.computer/install/wip-ai-devops-toolbox.txt
Then explain:
1. What is AI DevOps Toolbox?
2. What does it install on my system?
3. What changes for us? (this AI)
4. What changes across all my AIs?
Check if AI DevOps Toolbox is already installed.
If it is, show me what I have and what's new.
Then ask:
- Do you have questions?
- Want to see a dry run?
If I say yes, run: ldm install wipcomputer/wip-ai-devops-toolbox --dry-run
Show me exactly what will change. Don't install anything until I say "install".
Your agent will read the spec, explain everything, and do a dry-run install first so you can see exactly what changes before anything is written to your system.
Every tool ships as one or more interfaces: the ways you and your AI can use it. CLI runs in your terminal. Module imports into your code. MCP connects to any AI that supports Model Context Protocol. OC Plugin plugs into the OpenClaw agent platform. Skill teaches your AI how to use the tool via a SKILL.md file (works in both Claude Code and OpenClaw). CC Hook runs automatically inside Claude Code on specific events.
As Andrej Karpathy said: "Apps are for people. Tools are for LLMs, and increasingly, LLMs are the ones using software."
Universal Installer
Dev Guide
ai/ folder standard.LDM Dev Tools.app
Repo Visibility Guard
-private counterpart. Catches accidental exposure of internal plans, todos, and development context before it happensRepo Manifest Reconciler
Repo Init
ai/ directory in any repo. Plans, notes, ideas, dev updates, todos. One command.ai/ contents to ai/_sort/ai_old/ so you can sort at your own pace. Nothing is deleted.README Formatter
Forced Git Worktrees
Branch Guard
Identity File Protection
License Guard
readme-license scans all your repos and applies a standard license block to every README in one command. Removes duplicate license sections from sub-tool READMEsLicense Rug-Pull Detection
Release Pipeline
Private-to-Public Sync
ai/ folders automatically. Creates a PR, merges it, cleans up branchesPost-Merge Branch Naming
--merged-YYYY-MM-DD. Preserves history without cluttering your branch listSkill Publish to Website
.publish-skill.json to your repo with name and websiteRepo. On release, SKILL.md is copied to yoursite.com/install/{name}.txt and deployed automatically. Any AI can fetch the URL and get clean, parseable instructions. Like robots.txt but for agent install prompts.Make Discoverable in Claude Code
.claude-plugin/plugin.json from your existing interfaces./plugin marketplace. No manual config.| # | Tool | CLI | Module | MCP | OC Plugin | Skill | CC Hook |
|---|---|---|---|---|---|---|---|
| Setup & Onboarding | |||||||
| 1 | Universal Installer | Y | Y | Y | |||
| 2 | Dev Guide | ||||||
| Infrastructure | |||||||
| 3 | LDM Dev Tools.app | ||||||
| Repo Management | |||||||
| 4 | Repo Visibility Guard | Y | Y | Y | Y | Y | Y |
| 5 | Repo Manifest Reconciler | Y | Y | Y | Y | ||
| 6 | Repo Init | Y | Y | ||||
| 7 | README Formatter | Y | Y | ||||
| 8 | Forced Git Worktrees | Y | Y | ||||
| 9 | Branch Guard | Y | |||||
| License, Compliance, and Protection | |||||||
| 10 | Identity File Protection | Y | Y | Y | Y | Y | |
| 11 | License Guard | Y | |||||
| 12 | License Rug-Pull Detection | Y | Y | Y | Y | ||
| Release & Deploy | |||||||
| 13 | Release Pipeline | Y | Y | Y | Y | ||
| 14 | Private-to-Public Sync | Y | Y | ||||
| 15 | Post-Merge Branch Naming | Y | Y | ||||
| 16 | Skill Publish to Website | Y | |||||
| 17 | Make Discoverable in Claude Code | Y |
AI DevOps Toolbox installs into LDM OS, the local runtime for AI agents.
Run ldm install to see other components you can add.
Dual-license model designed to keep tools free while preventing commercial resellers.
MIT All CLI tools, MCP servers, skills, and hooks (use anywhere, no restrictions).
AGPLv3 Commercial redistribution, marketplace listings, or bundling into paid services.
AGPLv3 for personal use is free. Commercial licenses available.
Yes, freely:
Need a commercial license:
Using these tools to build your own software is fine. Reselling the tools themselves is what requires a commercial license.
By submitting a PR, you agree to the Contributor License Agreement.
Built by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).
FAQs
The complete AI DevOps toolkit for AI-assisted development teams.
We found that @wipcomputer/wip-ai-devops-toolbox demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.