New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

af360

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

af360

Watches the things you have built - folders, repos and sites - and tells you what needs you. Runs entirely on your own machine.

latest
npmnpm
Version
0.1.15
Version published
Weekly downloads
209
95.33%
Maintainers
1
Weekly downloads
 
Created
Source

af360

It watches the things you have built. Point it at the folders where your projects live and it keeps an eye on them: work you have not saved, projects with no backup anywhere, sites that have gone down, dates about to pass. When something needs you, it says so in one line. When nothing does, it says that too.

Everything happens on your own machine. No account, no sign-in, no server of ours, nothing uploaded.

What this package is, and what it is not

This npm package is af360 for a terminal and for an AI agent. It carries three things:

  • the CLI below, which answers from the last look around;
  • the MCP server (af360 mcp), so an agent can ask about your estate instead of guessing;
  • the Windows bridge, so a connected GitHub token is encrypted by Windows (DPAPI) rather than kept in plain text.

It is not the af360 desktop app. There is no window here: no sealed af360 window, no tray icon, and it does not watch anything while it is closed. It looks when you ask it to and then it stops.

The full Windows app is on the Microsoft Store: https://apps.microsoft.com/detail/9MZLSM8JB83W

Getting started

You need Node.js 20.11 or newer. Then, in a terminal:

npx af360

To keep it around:

npm install -g af360

The commands

af360            how everything is right now, in one line
af360 open       open the cockpit in your browser
af360 scan       look around now and print what turns up
af360 ask        ask what af360 last saw, without opening the window
                 (estate, projects, ahead, verify - add --json for the
                 same answer an AI agent gets)
af360 build      which build of af360 this is (--verify re-reads the files)
af360 doctor     is af360 already running? (add --fix to clear a leftover)
af360 mcp        answer an AI agent's questions about this estate (read-only;
                 started by the agent's app, not usually typed by hand)
af360 --help     this list
af360 --version  which af360 this is

The bare af360 is instant on purpose: it prints the result of the last look around and exits. It starts nothing and scans nothing. Use af360 scan when you want it to actually go and look.

Pointing an AI agent at it

af360 mcp is an MCP server on stdio. It is read-only: it answers from what af360 last saw and re-scans for nobody, so no agent can make af360 walk your disk however often it likes. Configure it the way your agent's app configures any other MCP server, with the command af360 mcp.

What it does not do

  • No accounts. There is nobody to sign in as.
  • No servers of ours. af360 runs on your machine and answers only your machine. It listens on 127.0.0.1 and [::1] and refuses everything else.
  • Nothing is uploaded. Not your paths, not your project names, not anything it finds. Your settings sit in a plain file at ~/.af360/config.json that you can read and delete.
  • It never writes to your projects. It looks, it does not touch. It runs no git command that changes anything.
  • One exception, stated plainly: once a day af360 can ask the public npm registry whether a newer af360 exists, and print one line if there is. It sends nothing about you or your machine. Switch it off in Settings, or set AF360_NO_UPDATE_CHECK=1.

Working on af360 itself

These commands work the same in Git Bash, Command Prompt and PowerShell. Forward slashes work everywhere, including on Windows.

npm install        # install the toolchain
npm run dev        # development server, opens your browser
npm run build      # production build
npm run package    # assemble dist/, the payload that ships to npm
npm start          # run the built app the way a user gets it
npm pack           # build the tarball, publish nothing

Setting an environment variable is the one thing each shell spells differently:

Git BashAF360_NO_OPEN=1 npm run dev
Command Promptset AF360_NO_OPEN=1 && npm run dev
PowerShell$env:AF360_NO_OPEN=1; npm run dev

npm run dev and npm start both go through scripts/launch.mjs, which is the only supported way to start af360. It binds loopback only, mints a session token, and refuses to start a second copy on top of a running one. If port 3000 is busy with something that is not af360, it explains and moves to the next free port.

How it is put together

app/            the rooms and the API
components/     Shell, the cockpit hook, folder picker
lib/            the engine: attention, disk radar, url health, expiry, insights
lib/attention   THE attention engine - one computation feeds every surface
scripts/serve   the launcher core: loopback bind, session token, port choice
bin/af360.mjs   the CLI
shell/          the Windows window and the DPAPI bridge, in C#
docs/           the rulings, the ledger, the security model, the comp

The rule of the codebase: attention state derives from item statuses, in one place. A calm headline above an item that needs you is impossible by construction, not by discipline.

Security

af360 runs a local HTTP server that knows your disk, so it is built to be hostile-proof from the inside out: loopback-only binding on both addresses, a per-session token on every API call, Host and Origin validation, no CORS, and every byte read off your disk treated as untrusted input. The threat model is written down in docs/SECURITY-MODEL.md, and SECURITY.md says how to report a problem.

af360 by Afeleos

Keywords

local-first

FAQs

Package last updated on 16 Sep 2026

Related posts