
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
Crew Node is the open-source customer-side executor for the Crew ecosystem. It runs near customer repositories, enforces local execution policy, and exposes the current Runner ToolBackend compatibility endpoint:
POST /v1/tools/execute
It does not contain autonomous planning, model provider credentials, billing, credit ledgers, dashboards, or customer account logic.
git_status and git_diffpatch binary for the legacy patch aliasexport CREW_NODE_TOKEN=replace-me
export CREW_WORKSPACE_ROOT=/path/to/repos
export CREW_PORT=4321
export CREW_ALLOWED_COMMANDS=git,bun
export CREW_COMMAND_TIMEOUT_SECONDS=30
export CREW_OUTPUT_MAX_BYTES=65536
export CREW_REQUEST_MAX_BYTES=1000000
export CREW_AUDIT_DIR=.crew-audit
CREW_ALLOWED_COMMANDS is empty by default, so command execution is denied
unless explicitly allowed. Per-request policy can further restrict the env
allowlist, but cannot broaden it.
CREW_SANDBOX=none is the only supported MVP sandbox. docker is reserved for
a later implementation and fails at startup.
docker build -t crew-node:local .
mkdir -p workspace .crew-audit
docker run --rm -p 4321:4321 \
-e CREW_NODE_TOKEN=replace-me \
-e CREW_WORKSPACE_ROOT=/workspace \
-e CREW_ALLOWED_COMMANDS=git,bun,npm,pnpm,yarn,node,rg,sed,cat,ls,find,patch \
-e CREW_AUDIT_DIR=/audit \
-v "$PWD/workspace:/workspace" \
-v "$PWD/.crew-audit:/audit" \
crew-node:local
Or use:
CREW_NODE_TOKEN=replace-me docker compose -f docker-compose.example.yml up --build
Crew Node is the only public, customer-installed package in the Crew ecosystem. Publish this repository as open source and publish the npm package after the validation commands pass:
npm login
npm pack --dry-run
npm publish --access public
Customers install only this service on their VPS or private network. Crew Runner, Crew Gateway, and Crew Dashboard remain private hosted services run by Crew.
bun install
bun run start
Health check:
curl http://127.0.0.1:4321/healthz
Readiness check:
curl http://127.0.0.1:4321/readyz
Execute a read tool:
curl -s http://127.0.0.1:4321/v1/tools/execute \
-H "Authorization: Bearer $CREW_NODE_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"requestId": "demo-read",
"root": ".",
"tool": "read",
"input": { "path": "README.md" }
}'
Runner sends raw ToolBackend calls to POST /v1/tools/execute. Successful
responses are the raw tool result JSON expected by Runner, not wrapped in an
ok/result envelope. Non-2xx responses use a JSON error envelope.
{
"requestId": "optional-string",
"root": "absolute-or-relative-root-under-workspace",
"policy": {
"allowedCommands": ["optional", "override"],
"timeoutSeconds": 30,
"outputMaxBytes": 65536
},
"tool": "read-repo-file",
"input": {}
}
Production Runner tool IDs:
list-repo-filesread-repo-fileread-file-rangeoutline-filesearch-repowrite-repo-filedelete-repo-filerun-commandgit-diffgit-statusprepare-workspacefinalize-workspaceread-cumulative-diffcollect-safety-findingsLegacy aliases from the initial MVP remain available for local experiments:
read, search, write, patch, command, git_status, and git_diff.
Point Crew Runner at this service:
export CREW_EXECUTION_BACKEND=node
export CREW_NODE_URL=http://127.0.0.1:4321
export CREW_NODE_TOKEN=replace-me
export CREW_NODE_REQUIRED=true
The node service enforces the intersection of its local
CREW_ALLOWED_COMMANDS and Runner's per-request policy.allowedCommands.
Per-request policy can restrict local policy, but cannot broaden it.
CREW_WORKSPACE_ROOT; traversal and symlink escapes
are rejected..env, private keys, .npmrc, .netrc, .aws, and
.ssh are hidden from listing and refused on reads.run-command returns Runner-style CommandResult records, including
allowed: false for policy-denied commands.CREW_SANDBOX=none is the production mode for this milestone.CREW_SANDBOX=docker is recognized but intentionally rejected until
per-command container sandboxing is implemented post-MVP.501 not_implemented because the current
Runner source only implements POST /v1/tools/execute.bun test
bun run typecheck
ruby -e 'require "rexml/document"; ARGV.each { |path| REXML::Document.new(File.read(path)) }' CREW_*.xml
docker build -t crew-node:local .
FAQs
Customer-side executor for the Crew ecosystem.
The npm package crew-node receives a total of 5 weekly downloads. As such, crew-node popularity was classified as not popular.
We found that crew-node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.