
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
Watches the things you have built - folders, repos and sites - and tells you what needs you. Runs entirely on your own machine.
It watches the things you have built. Point it at the folders where your projects live and it keeps an eye on them: work you have not saved, projects with no backup anywhere, sites that have gone down, dates about to pass. When something needs you, it says so in one line. When nothing does, it says that too.
Everything happens on your own machine. No account, no sign-in, no server of ours, nothing uploaded.
This npm package is af360 for a terminal and for an AI agent. It carries three things:
af360 mcp), so an agent can ask about your estate
instead of guessing;It is not the af360 desktop app. There is no window here: no sealed af360 window, no tray icon, and it does not watch anything while it is closed. It looks when you ask it to and then it stops.
The full Windows app is on the Microsoft Store: https://apps.microsoft.com/detail/9MZLSM8JB83W
You need Node.js 20.11 or newer. Then, in a terminal:
npx af360
To keep it around:
npm install -g af360
af360 how everything is right now, in one line
af360 open open the cockpit in your browser
af360 scan look around now and print what turns up
af360 ask ask what af360 last saw, without opening the window
(estate, projects, ahead, verify - add --json for the
same answer an AI agent gets)
af360 build which build of af360 this is (--verify re-reads the files)
af360 doctor is af360 already running? (add --fix to clear a leftover)
af360 mcp answer an AI agent's questions about this estate (read-only;
started by the agent's app, not usually typed by hand)
af360 --help this list
af360 --version which af360 this is
The bare af360 is instant on purpose: it prints the result of the last look
around and exits. It starts nothing and scans nothing. Use af360 scan when
you want it to actually go and look.
af360 mcp is an MCP server on stdio. It is read-only: it answers from
what af360 last saw and re-scans for nobody, so no agent can make af360 walk
your disk however often it likes. Configure it the way your agent's app
configures any other MCP server, with the command af360 mcp.
~/.af360/config.json
that you can read and delete.AF360_NO_UPDATE_CHECK=1.These commands work the same in Git Bash, Command Prompt and PowerShell. Forward slashes work everywhere, including on Windows.
npm install # install the toolchain
npm run dev # development server, opens your browser
npm run build # production build
npm run package # assemble dist/, the payload that ships to npm
npm start # run the built app the way a user gets it
npm pack # build the tarball, publish nothing
Setting an environment variable is the one thing each shell spells differently:
| Git Bash | AF360_NO_OPEN=1 npm run dev |
| Command Prompt | set AF360_NO_OPEN=1 && npm run dev |
| PowerShell | $env:AF360_NO_OPEN=1; npm run dev |
npm run dev and npm start both go through scripts/launch.mjs, which is
the only supported way to start af360. It binds loopback only, mints a session
token, and refuses to start a second copy on top of a running one. If port 3000
is busy with something that is not af360, it explains and moves to the next
free port.
app/ the rooms and the API
components/ Shell, the cockpit hook, folder picker
lib/ the engine: attention, disk radar, url health, expiry, insights
lib/attention THE attention engine - one computation feeds every surface
scripts/serve the launcher core: loopback bind, session token, port choice
bin/af360.mjs the CLI
shell/ the Windows window and the DPAPI bridge, in C#
docs/ the rulings, the ledger, the security model, the comp
The rule of the codebase: attention state derives from item statuses, in one place. A calm headline above an item that needs you is impossible by construction, not by discipline.
af360 runs a local HTTP server that knows your disk, so it is built to be
hostile-proof from the inside out: loopback-only binding on both addresses, a
per-session token on every API call, Host and Origin validation, no CORS, and
every byte read off your disk treated as untrusted input. The threat model is
written down in docs/SECURITY-MODEL.md, and SECURITY.md says how to report
a problem.
af360 by Afeleos
FAQs
Watches the things you have built - folders, repos and sites - and tells you what needs you. Runs entirely on your own machine.
The npm package af360 receives a total of 19 weekly downloads. As such, af360 popularity was classified as not popular.
We found that af360 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.