
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
agentlog-sdk
Advanced tools
TypeScript SDK for agentlog - a local-first decision log daemon for agentic workflows
TypeScript client for agentlog - a local-first decision log daemon for agentic workflows.
npm install agentlog-sdk
import { AgentlogClient } from "agentlog-sdk";
const client = new AgentlogClient();
await client.write({ type: "decision", title: "Use PostgreSQL for persistence" });
const entries = await client.query({ text: "database" });
agentlogd daemon (see the main project README)import { AgentlogClient } from "agentlog-sdk";
const client = new AgentlogClient();
// Write a decision entry (session created automatically)
await client.write({
type: "decision",
title: "Use Redis for caching",
body: "Redis provides sub-millisecond reads and built-in TTL support.",
tags: ["infrastructure", "caching"],
files: ["config/redis.yaml"],
});
// Supported entry types: decision, attempt_failed, deferred, assumption, question
await client.write({ type: "assumption", title: "All users have Node 18+" });
await client.write({ type: "question", title: "Should we use async or sync HTTP client?" });
// Full-text search
const results = await client.query({ text: "database migration" });
// Search with filters
const filtered = await client.query({ text: "caching", type: "decision", limit: 5 });
// List entries by type
const entries = await client.log({ type: "decision" });
// List entries by session
const sessionEntries = await client.log({ session: "your-session-id" });
// List entries by tag
const tagEntries = await client.log({ tag: "infrastructure" });
// List entries from the last hour
const recentEntries = await client.log({ since: "1h" });
// Get a formatted text block for prompt injection
const context = await client.context({ query: "authentication" });
console.log(context);
// Output:
// # Recent decisions
//
// ## [decision] Use JWT for API auth (2026-03-15 10:30)
// JWTs are stateless and work well with our microservices architecture.
// Tags: auth, api
// Files: internal/auth/jwt.go
The SDK looks for the daemon socket at ~/.agentlog/agentlogd.sock by default. Override this with:
AGENTLOG_DIR environment variableagentlogDir constructor optionsocketPath constructor option (takes precedence)// Custom data directory
const client = new AgentlogClient({ agentlogDir: "/custom/path" });
// Explicit socket path
const client2 = new AgentlogClient({ socketPath: "/tmp/agentlogd.sock" });
import {
AgentlogClient,
AgentlogError,
ConnectionError,
DaemonNotRunningError,
} from "agentlog-sdk";
const client = new AgentlogClient();
try {
await client.write({ type: "decision", title: "Test entry" });
} catch (err) {
if (err instanceof DaemonNotRunningError) {
console.log("Start the daemon first: agentlog start");
} else if (err instanceof ConnectionError) {
console.log(`Connection failed: ${err.message}`);
} else if (err instanceof AgentlogError) {
console.log(`Unexpected error: ${err.message}`);
}
}
# Install dependencies
npm install
# Build
npx tsc
# Run tests
npx vitest run
# Run only unit tests (no daemon required)
npx vitest run tests/client.test.ts
FAQs
TypeScript SDK for agentlog - a local-first decision log daemon for agentic workflows
The npm package agentlog-sdk receives a total of 4 weekly downloads. As such, agentlog-sdk popularity was classified as not popular.
We found that agentlog-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.