
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
Local-first CLI for planning, documentation, and execution workflows with agent assistance.
mcoda is a local-first CLI for planning, documentation, and execution workflows with agent assistance.
npm i -g mcodamcoda setup before other commands.mcoda --versionmcoda setup
mcoda set-workspace --workspace-root .
mcoda docs pdr generate --workspace-root . --project WEB --rfp-path docs/rfp/web.md --agent codex
docdex CLI for doc search and context stitching.docdex setup (or docdexd browser install) to install the headless Chromium browser used for web enrichment.~/.docdex; mcoda does not create repo-local .docdex folders.~/.docdex/agents.md exists, it is prepended to every agent run.~/.mcoda/workspaces/<fingerprint>/config.json for defaults (docdex URL, branch metadata, telemetry preferences).~/.mcoda/workspaces/<fingerprint>/mcoda.db for backlog, jobs, and telemetry.~/.mcoda/workspaces/<fingerprint>/docs/ for generated artifacts.mcoda docs pdr generate, mcoda docs sds generatemcoda openapi-from-docsmcoda create-tasks, mcoda task-sufficiency-audit, mcoda refine-tasks, mcoda order-tasksmcoda add-tests, mcoda work-on-tasks, mcoda code-review, mcoda qa-tasksmcoda backlog, mcoda taskmcoda jobs, mcoda tokens, mcoda telemetrymcoda gpu list, mcoda gpu ops, mcoda job artifact upload|run|status|logs|events|artifacts|cancel|retrymcoda self-hosted agent list, mcoda self-hosted agent details, mcoda self-hosted agent syncmcoda test-agent, mcoda agent-runmcoda update --checkmcoda work-on-tasks auto-runs the same test-harness bootstrap logic as mcoda add-tests when selected tasks require tests but no runnable harness exists.
mcoda create-tasks auto-runs a sufficiency pass (same engine as mcoda task-sufficiency-audit) to compare SDS coverage against generated backlog items and fill obvious planning gaps.
If that sufficiency pass errors, create-tasks continues (fail-open) and records audit failure details in job checkpoints/logs.
Environment variables are optional overrides for workspace settings:
MCODA_DOCDEX_URL to point at a docdex server.MCODA_API_BASE_URL or MCODA_JOBS_API_URL for job APIs.MCODA_MSWARM_NODE_BASE_URL, MCODA_MSWARM_NODE_ID, and MCODA_MSWARM_NODE_SIGNING_SECRET for owner-local generic GPU job commands.MCODA_TELEMETRY set to off to disable telemetry.MCODA_STREAM_IO=1 to emit agent I/O lines to stderr.mcoda self-hosted agent list reads direct self-hosted agents and opt-in
load-balanced aliases from mswarm when the configured API key allows it. Direct
entries stay pinned to one server. Load-balanced aliases are saved as auto
routes and let mswarm choose an eligible upgraded node for the requested model
or capability.
Use direct slugs for rollback or pinned-server workloads. Use auto aliases only when the product should allow mswarm to route around busy, drained, stale, or incompatible nodes.
import { McodaEntrypoint } from "mcoda";
await McodaEntrypoint.run(["--version"]);
Full docs live in the repository:
MIT - see LICENSE.
FAQs
Local-first CLI for planning, documentation, and execution workflows with agent assistance.
The npm package mcoda receives a total of 120 weekly downloads. As such, mcoda popularity was classified as not popular.
We found that mcoda demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.