
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
forgetrail
Advanced tools
ForgeTrail: a persistent development system for building software with AI agents. CLI, Lite protocol, and methodology templates.
Forge the path. Keep the trail.
ForgeTrail gives your next coding session a place to start. It keeps the phase, decisions, and handoff in your repository so an agent can read them when you resume. Start with Lite for a small project. You do not have to run all seven phases to try the method.
ForgeTrail instructs the agent to read the ledger, preserve approved decisions, and pause at approval gates. The agent must write the handoff. Those updates are not automatic. Optional hooks enforce the checks documented for their supported host.
In session one, the agent drafts a Phase 1 brief, you approve it, and the agent logs the stack decision and a note for next time. In session two, a fresh chat reads that record, skips the settled questions, finishes the open Phase 1 item, and asks to move into Phase 2 with that phase's guidance. The record is the AppLedger ledger in appledger/: the phase in profiles/forgetrail.yaml, plus decision, lesson, and session records. pnpm dlx appledger init creates it. Labeled walk-through: content/examples/two-session-continuity.md.
Docs: forgetrail.dev/docs · Site: forgetrail.dev
You need a new empty project folder and a coding agent that can read files. Node is optional.
docs/GENESIS.md (what, not how).content/FORGETRAIL_LITE.md to .forgetrail/FORGETRAIL_LITE.md, or run pnpm dlx forgetrail install --lite --with-genesis-stub (Node.js 20+).The shortest supported first task is: create appledger/, draft docs/PHASE_1_BRIEF.md, and wait for approval. You do not have to run all seven phases. Full recipe: Try.
| Path | Who uses it | What it is |
|---|---|---|
| Lite | First path | One protocol file. The agent writes appledger/. |
CLI (forgetrail) | Node.js 20+ | Installer. Writes Lite and Cursor hooks, or the full template tree. Skips files that already exist. Does not run the agent. |
MCP (forgetrail-mcp) | Cursor or Claude | Phase guidance, templates, and lessons search. The ledger still lives in the app repo. |
pnpm dlx forgetrail install --lite --with-genesis-stub
pnpm dlx appledger init --name "Your app name"
MCP: npx -y forgetrail-mcp (0.4.2 or later finds the methodology without FORGETRAIL_ROOT). Prefer pnpm dlx on Windows. Do not add forgetrail to an app's dependencies. Do not merge the two packages.
A 7-phase playbook, a ledger in appledger/, and templates pre-loaded with first-party production lessons. Each project leaves decisions, lessons, and a session handoff that future work follows. Those lesson notes are not independent adoption evidence.
Optional hooks in content/hooks/ load the current phase at session start in Cursor or Claude Code, check ledger edits, and check for a session note at session stop. The agent still does the writing. Flags, MCP, and the phase table live in the docs.
pnpm --dir mcp-server install
pnpm run mcp:build
pnpm site:dev
Site (FilePress + docs mount): pnpm ship.
Apache-2.0 · Catalyst Forge LLC
FAQs
ForgeTrail: a persistent development system for building software with AI agents. CLI, Lite protocol, and methodology templates.
The npm package forgetrail receives a total of 566 weekly downloads. As such, forgetrail popularity was classified as not popular.
We found that forgetrail demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.