
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
create-factory
Advanced tools
Create a Mastra Factory project: an agent-powered software delivery environment built on Mastra. Run `npm create factory` to scaffold and get started.
Mastra Factory is an open source environment for building software with coding agents. Connect your repository to turn issues into plans, implementations, and reviewed pull requests.
create-factory is the recommended way to scaffold your Mastra Factory. By default,
[!IMPORTANT] Make sure that you have Node.js 22.13.0 or later installed on your system.
Run the latest version directly with your package manager.
Using npm:
npx create-factory@latest
Using Yarn:
yarn dlx create-factory@latest
Using pnpm:
pnpm create factory@latest
The interactive setup asks where to create the project and helps configure your Mastra Factory project.
By default, the setup wizard provisions Mastra platform resources during setup, enabling you to fully run Mastra Factory on platform or locally with cloud-backed capabilities. If you prefer to self-host Mastra Factory, run the setup with the --no-platform flag.
npx create-factory@latest -- --no-platform
Pass --help to see all options:
npx create-factory@latest --help
See the package changelog for version history and release notes.
We have an open community Discord. Come and say hello and let us know if you have any questions or need any help getting things running.
FAQs
Create a Mastra Factory project: an agent-powered software delivery environment built on Mastra. Run `npm create factory` to scaffold and get started.
The npm package create-factory receives a total of 2,758 weekly downloads. As such, create-factory popularity was classified as popular.
We found that create-factory demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.