
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
CLI for bootstrapping projects with Dalhe base files.
dalhe init copies the template from src/template/init into the current directory, prepares the initial project structure, and runs openspec init --tools claude,codex.
dalhe skill lists skills from the official git repository, and installs, removes, and updates skills maintained in src/template/skills, publishing them globally for Codex and Claude Code.
Official skills use the dl- prefix.
dalhe update updates the global CLI installation and also updates OpenSpec.
Current template includes:
AGENTS.mdCLAUDE.md.ai-framework/DESIGN.md.ai-framework/RULES.mdDuring init, if any destination file already exists, execution stops and nothing is overwritten.
>=22.0.0Package on npm: https://www.npmjs.com/package/dalhe-cli
Install directly from npm:
npm install -g dalhe-cli
OpenSpec is installed automatically on the first dalhe init if it is not already available in PATH.
Install directly from repository:
npm install -g git+https://github.com/alexishida/dalhe-cli.git
OpenSpec is installed automatically on the first dalhe init if it is not already available in PATH.
Inside project repository:
npm install -g .
OpenSpec is installed automatically on the first dalhe init if it is not already available in PATH.
Go into folder where you want to create project base:
dalhe init
Example:
mkdir my-project
cd ./my-project
dalhe init
dalhe init
dalhe skill list
dalhe skill install <skill-name>
dalhe skill install-all
dalhe skill uninstall <skill-name>
dalhe skill uninstall-all
dalhe skill update <skill-name>
dalhe skill update
dalhe skill update-all
dalhe update
dalhe --help
dalhe -h
dalhe --version
dalhe -v
init behavioropenspec is not available in PATH, runs npm install -g @fission-ai/openspec@latest.openspec init --tools claude,codex in current folder.npm to be installed in order to install OpenSpec automatically when needed.bin/dalhe.js: CLI entry point.src/commands: application commands.src/core: execution base and error handling.src/services: support services.src/template/init: base files copied by init.src/template/skills: skill helper files maintained in repository.test: automated tests..ai-framework/RULES.md: official project rules, including technical context and mandatory change guidelines.skill commandLists all skills available in the official git repository (src/template/skills), fetched directly from GitHub.
If the remote repository is unreachable or not configured, it falls back to listing the skills shipped with the currently installed CLI version. The remote request has a 5-second timeout, including reading the response body. Invalid responses also trigger the local fallback.
Currently included skills:
dl-matching-decomp: reconstructing source to match reference binaries, with reproducible builds and byte-for-byte verification.dl-rails-8: support for development, refactoring, and review of Rails 8 apps.dl-rails-code-audit: structured Rails 7/8 audits focused on security, code smells, conventions, and Oracle or MariaDB/MySQL concerns.dl-nodejs-dev: support for developing and maintaining Node.js projects.dl-pure-ruby: support for developing and maintaining pure Ruby projects.dl-code-review: Rails code quality, architecture, and pattern analysis without modifying code.dl-electron-react: building, scaffolding, and structuring Electron desktop apps with React and TypeScript.dl-rayban-meta-sdk: building and integrating iOS/Android apps with Meta Wearables DAT for Ray-Ban Meta glasses, including the Gen 1 mobile path.dalhe skill list
To force listing the installed version locally (no network), set DALHE_CLI_SKIP_REMOTE_SKILL_LIST=1.
Local listing checks template files concurrently and skips global installation status checks. Bulk installation and removal also skip this redundant status scan.
Installs a skill globally in both environments:
$CODEX_HOME/skills/<skill-name> when CODEX_HOME is explicitly configured.CODEX_HOME: uses ~/.agents/skills/<skill-name> on Linux and %USERPROFILE%\.agents\skills\<skill-name> on Windows.~/.claude/skills/<skill-name> on Linux and %USERPROFILE%\.claude\skills\<skill-name> on Windows./, \, : and null characters are rejected, as are the names . and ...SKILL.md file; a directory with that name is not a valid template.~/.claude/commands/<skill-name>.md, which is also removed on uninstallation.dalhe skill install dl-rails-8
Installs all skills shipped with this CLI globally for both Codex and Claude Code.
dalhe skill install-all
Removes skill from both global destinations.
dalhe skill uninstall dl-rails-8
Removes all skills shipped with this CLI from both global destinations.
dalhe skill uninstall-all
Updates an installed skill directly from src/template/skills in the latest commit of the official GitHub repository's default branch. You do not need to update the CLI first.
dalhe skill update dl-rails-8
DALHE_CLI_SKIP_REMOTE_SKILL_LIST=1 only affects listing; it does not disable remote updates.Updates all skills present in the official GitHub repository that are already installed in at least one managed destination. This includes installed skills absent from the bundled CLI templates. Skills absent from GitHub are left untouched; uninstalled skills are not installed.
dalhe skill update
# Equivalent:
dalhe skill update-all
update commandUpdates CLI globally from official repository, syncs OpenSpec, and synchronizes globally installed skills:
dalhe update
Behavior:
npm install -g git+https://github.com/alexishida/dalhe-cli.git.npm install -g @fission-ai/openspec@latest.dalhe skill update-all).npm.cmd on Windows.npm on Linux.npm to be installed and permission to update global packages.Any project change must keep this README.md updated whenever there is impact on behavior, usage, commands, flow, structure, requirements, or any relevant tool context.
npm install
npm test
node ./bin/dalhe.js --help
To test full flow without installing globally:
node ./bin/dalhe.js init
In this case, make sure npm is installed and available in PATH, so CLI can install OpenSpec automatically when needed.
MIT
If you need to renew npm authentication before publishing:
npm logout
npm login
npm whoami
npm publish
FAQs
CLI para iniciar projetos com arquivos base do Dalhe.
The npm package dalhe-cli receives a total of 12 weekly downloads. As such, dalhe-cli popularity was classified as not popular.
We found that dalhe-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.