
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
CLI for bootstrapping projects with Dalhe base files.
dalhe init copies the template from src/template/init into the current directory, prepares the initial project structure, and runs openspec init --tools claude,codex.
dalhe skill lists, installs, removes, and updates skills maintained in src/template/skills, publishing them globally for Codex and Claude Code.
Official skills do not use prefixes.
dalhe update updates the global CLI installation and also updates OpenSpec.
Current template includes:
AGENTS.mdCLAUDE.md.ai-framework/DESIGN.md.ai-framework/RULES.mdDuring init, if any destination file already exists, execution stops and nothing is overwritten.
>=22.0.0Package on npm: https://www.npmjs.com/package/dalhe-cli
Install directly from npm:
npm install -g dalhe-cli
OpenSpec is installed automatically on the first dalhe init if it is not already available in PATH.
Install directly from repository:
npm install -g git+https://github.com/alexishida/dalhe-cli.git
OpenSpec is installed automatically on the first dalhe init if it is not already available in PATH.
Inside project repository:
npm install -g .
OpenSpec is installed automatically on the first dalhe init if it is not already available in PATH.
Go into folder where you want to create project base:
dalhe init
Example:
mkdir my-project
cd ./my-project
dalhe init
dalhe init
dalhe skill list
dalhe skill install <skill-name>
dalhe skill uninstall <skill-name>
dalhe skill update-all
dalhe update
dalhe --help
dalhe -h
dalhe --version
dalhe -v
init behavioropenspec is not available in PATH, runs npm install -g @fission-ai/openspec@latest.openspec init --tools claude,codex in current folder.npm to be installed in order to install OpenSpec automatically when needed.bin/dalhe.js: CLI entry point.src/commands: application commands.src/core: execution base and error handling.src/services: support services.src/template/init: base files copied by init.src/template/skills: skill helper files maintained in repository.test: automated tests..ai-framework/RULES.md: official project rules, including technical context and mandatory change guidelines.skill commandLists all skills available in src/template/skills.
Currently included skills:
rails8: support for development, refactoring, and review of Rails 8 apps.code-review: review of quality, architecture, and patterns in Rails code.security-audit: Rails security audit focused on OWASP, Brakeman, and common vulnerabilities.dalhe skill list
Installs a skill globally in both environments:
$CODEX_HOME/skills/<skill-name>.CODEX_HOME: uses ~/.codex/skills/<skill-name> on Linux and %USERPROFILE%\.codex\skills\<skill-name> on Windows.~/.claude/skills/<skill-name> on Linux and %USERPROFILE%\.claude\skills\<skill-name> on Windows.dalhe skill install rails8
Removes skill from both global destinations.
dalhe skill uninstall rails8
Reinstalls all skills from this CLI that are already installed in at least one managed destination, syncing current template version to Codex and Claude Code.
dalhe skill update-all
update commandUpdates CLI globally from official repository and syncs OpenSpec:
dalhe update
Behavior:
npm install -g git+https://github.com/alexishida/dalhe-cli.git.npm install -g @fission-ai/openspec@latest.npm.cmd on Windows.npm on Linux.npm to be installed and permission to update global packages.Any project change must keep this README.md updated whenever there is impact on behavior, usage, commands, flow, structure, requirements, or any relevant tool context.
npm install
npm test
node ./bin/dalhe.js --help
To test full flow without installing globally:
node ./bin/dalhe.js init
In this case, make sure npm is installed and available in PATH, so CLI can install OpenSpec automatically when needed.
MIT
If you need to renew npm authentication before publishing:
npm logout
npm login
npm whoami
npm publish
FAQs
CLI para iniciar projetos com arquivos base do Dalhe.
The npm package dalhe-cli receives a total of 12 weekly downloads. As such, dalhe-cli popularity was classified as not popular.
We found that dalhe-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.