
Research
Active Supply Chain Attack Compromises @antv Packages on npm
Active npm supply chain attack compromises @antv packages in a fast-moving malicious publish wave tied to Mini Shai-Hulud.
ai-todo-cli
Advanced tools
CLI tool for AI agents to interact with ai-todo.
All commands are dynamically discovered from the server. All output is JSON.
npm install -g ai-todo-cli
ai-todo login
For headless environments:
ai-todo login --token <jwt>
ai-todo tasks:list
ai-todo tasks:list --filter today
ai-todo tasks:create --title "Review PR" --priority 1
ai-todo tasks:complete --id <task-id>
ai-todo tasks:delete --id <task-id>
ai-todo tasks:add-log --id <task-id> --content "Done with phase 1"
ai-todo spaces:list
Run ai-todo --help to see all available commands (fetched from server).
This package is published to npm via GitHub Actions when a tag like v0.1.3 is pushed.
npm version patch
git push origin main --follow-tags
The workflow will verify that the Git tag matches package.json before publishing.
This CLI is designed for AI agent integration. Key features:
/api/manifestMIT
FAQs
CLI tool for AI agents to interact with ai-todo
We found that ai-todo-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Active npm supply chain attack compromises @antv packages in a fast-moving malicious publish wave tied to Mini Shai-Hulud.

Security News
/Research
Socket detected malicious node-ipc versions with obfuscated stealer/backdoor behavior in a developing npm supply chain attack.

Security News
TeamPCP and BreachForums are promoting a Shai-Hulud supply chain attack contest with a $1,000 prize for the biggest package compromise.