
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
HEIDES installer. Downloads the prebuilt HEIDES binary for your platform and exposes the heides command. Deterministic code analysis harness for AI agents.
Installs the prebuilt HEIDES binary for your platform and exposes the heides command. HEIDES is a deterministic code analysis harness that gives AI agents senses, memory and judgment for code.
npm install -g heides
heides --help
On install, the matching binary is downloaded from GitHub Releases into the package bin/ folder. No Rust toolchain needed.
| OS | Arch | Asset |
|---|---|---|
| Linux (glibc) | x64 | heides-x86_64-unknown-linux-gnu |
| Linux (glibc) | arm64 | heides-aarch64-unknown-linux-gnu |
| Android (Termux) | arm64 | heides-aarch64-linux-android |
| macOS | arm64 | heides-aarch64-apple-darwin |
| macOS | x64 | heides-x86_64-apple-darwin |
| Windows | x64 | heides-x86_64-pc-windows-msvc.exe |
Linux arm64 and Android are mapped to real release assets, not errors. The one
family that stops the installer is musl, so Alpine needs a source build
(cargo install heides) or a manual pick from the
releases page. Any other
unmapped platform errors the same way.
The published package version is the single source of truth for which binary tag gets downloaded, and a test fails the build if the two ever drift.
npm install -g heides # binary tag follows the package version
HEIDES_VERSION=0.15.0 npm install -g heides # same variable the curl installer uses
HEIDES_BIN_VERSION=0.15.0 npm install -g heides # binary specific pin, wins over HEIDES_VERSION
Both variables take a bare version such as 0.15.0. A leading v is accepted
and stripped, so v0.15.0 does not turn into a vv0.15.0 tag that 404s.
Same as the native binary:
heides scan .
heides check .
heides mcp # MCP server over stdio for agents
package.json is the single source of truth for the downloaded binary tag, and
npm test fails if it ever drifts from what the installer uses. heides@0.15.0
installs the HEIDES 0.15.0 binary. HEIDES_BIN_VERSION or HEIDES_VERSION
override it for a pin.
npm uninstall -g heides
MIT. See LICENSE. Binary builds follow the HEIDES repo license.
Links: npm | GitHub | Tawakkul Labs
FAQs
HEIDES installer. Downloads the prebuilt HEIDES binary for your platform and exposes the heides command. Deterministic code analysis harness for AI agents.
The npm package heides receives a total of 1,960 weekly downloads. As such, heides popularity was classified as popular.
We found that heides demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.