
Research
/Security News
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
create-askalf
Advanced tools
Create an AI workforce that thinks, heals, remembers, and evolves. One command. No Docker.
One command. Full AI workforce. No Docker.
npx create-askalf
Sets up AskAlf — an AI workforce that thinks, heals, remembers, and evolves with a nervous system, immune system, collective memory, dream cycles, and natural selection. Runs in a single Node.js process.
npx create-askalf
Interactive setup:
http://localhost:3000npx create-askalf --quick
Skips prompts. Auto-detects Claude OAuth if logged in, falls back to ANTHROPIC_API_KEY env var.
npx create-askalf doctor
Built-in diagnostic and repair tool. Auto-detects your install type (Docker or standalone), checks prerequisites, verifies config, fixes broken secrets, and offers AI-powered troubleshooting via Claude Code.
http://localhost:3000 — fleet view, organism tab, settings, terminalWorks with whatever you have. Priority chain:
| Priority | Provider | Config |
|---|---|---|
| 1 | Claude OAuth | claude login (uses subscription) |
| 2 | Anthropic API | ANTHROPIC_API_KEY |
| 3 | OpenAI API | OPENAI_API_KEY |
| 4 | Ollama local | OLLAMA_URL (default localhost:11434) |
No provider is required at install time — configure any one later in ~/.askalf/.env.
Outgrew standalone? One command:
bash scripts/migrate-to-docker.sh
Exports PGlite data, generates Docker .env, imports into PostgreSQL. Your standalone data stays untouched.
curl -fsSL https://get.askalf.org | bash
Full stack: PostgreSQL + pgvector, Redis, Ollama, SearxNG, headless Chromium. 6 containers at localhost:3001 in 60 seconds.
MIT — askalf.org
FAQs
Create an AI workforce that thinks, heals, remembers, and evolves. One command. No Docker.
We found that create-askalf demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.

Research
/Security News
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.

Security News
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.