
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Local-first CLI for planning, documentation, and execution workflows with agent assistance.
mcoda is a local-first CLI for planning, documentation, and execution workflows with agent assistance.
npm i -g mcodamcoda setup before other commands.mcoda --versionmcoda setup
mcoda set-workspace --workspace-root .
mcoda docs pdr generate --workspace-root . --project WEB --rfp-path docs/rfp/web.md --agent codex
docdex CLI for doc search and context stitching.docdex setup (or docdexd browser install) to install the headless Chromium browser used for web enrichment.~/.docdex; mcoda does not create repo-local .docdex folders.~/.docdex/agents.md exists, it is prepended to every agent run.~/.mcoda/workspaces/<fingerprint>/config.json for defaults (docdex URL, branch metadata, telemetry preferences).~/.mcoda/workspaces/<fingerprint>/mcoda.db for backlog, jobs, and telemetry.~/.mcoda/workspaces/<fingerprint>/docs/ for generated artifacts.mcoda docs pdr generate, mcoda docs sds generatemcoda openapi-from-docsmcoda create-tasks, mcoda task-sufficiency-audit, mcoda refine-tasks, mcoda order-tasksmcoda add-tests, mcoda work-on-tasks, mcoda code-review, mcoda qa-tasksmcoda backlog, mcoda taskmcoda jobs, mcoda tokens, mcoda telemetrymcoda gpu list, mcoda gpu ops, mcoda job artifact upload|run|status|logs|events|artifacts|cancel|retrymcoda self-hosted agent list, mcoda self-hosted agent details, mcoda self-hosted agent syncmcoda test-agent, mcoda agent-runmcoda update --checkmcoda work-on-tasks auto-runs the same test-harness bootstrap logic as mcoda add-tests when selected tasks require tests but no runnable harness exists.
mcoda create-tasks auto-runs a sufficiency pass (same engine as mcoda task-sufficiency-audit) to compare SDS coverage against generated backlog items and fill obvious planning gaps.
If that sufficiency pass errors, create-tasks continues (fail-open) and records audit failure details in job checkpoints/logs.
Environment variables are optional overrides for workspace settings:
MCODA_DOCDEX_URL to point at a docdex server.MCODA_API_BASE_URL or MCODA_JOBS_API_URL for job APIs.MCODA_MSWARM_NODE_BASE_URL, MCODA_MSWARM_NODE_ID, and MCODA_MSWARM_NODE_SIGNING_SECRET for owner-local generic GPU job commands.MCODA_TELEMETRY set to off to disable telemetry.MCODA_STREAM_IO=1 to emit agent I/O lines to stderr.mcoda self-hosted agent list reads direct self-hosted agents and opt-in
load-balanced aliases from mswarm when the configured API key allows it. Direct
entries stay pinned to one server. Load-balanced aliases are saved as auto
routes and let mswarm choose an eligible upgraded node for the requested model
or capability.
Use direct slugs for rollback or pinned-server workloads. Use auto aliases only when the product should allow mswarm to route around busy, drained, stale, or incompatible nodes.
import { McodaEntrypoint } from "mcoda";
await McodaEntrypoint.run(["--version"]);
Full docs live in the repository:
MIT - see LICENSE.
FAQs
Local-first CLI for planning, documentation, and execution workflows with agent assistance.
The npm package mcoda receives a total of 315 weekly downloads. As such, mcoda popularity was classified as not popular.
We found that mcoda demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.