
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
orchestrix
Advanced tools
Orchestrix - Universal AI Agent Framework for Coordinated AI-Driven Development
像交响乐指挥家一样协调专业化AI代理,通过标准化工作流程完成复杂项目开发。
Orchestrix 的成功在于 专业化代理的协调配合 和 标准化流程的严格执行,通过协调而非控制,实现复杂项目的高质量交付。
📚 深入了解 Orchestrix 设计哲学。
# 通用安装
npx orchestrix install
# Claude Code 自动化安装 (推荐)
npx orchestrix install -i claude-code
此命令将自动检测并为您配置本地开发环境,支持 Cursor, Claude Code, Windsurf, Trae, Roo 等主流IDE。Claude Code用户可享受全自动化协作体验。
*help 查看可用命令,然后通过 *analyst 启动项目。📘 查看完整的 用户指南 了解更多操作细节。
Orchestrix 的工作流程分为两个主要阶段,确保从宏观规划到微观实现的平稳过渡。
graph LR
A[Analyst<br/>项目分析] --> B[PM<br/>需求文档]
B --> C[UX-Expert<br/>UI规范]
C --> D[Architect<br/>技术架构]
D --> E[PM<br/>需求对齐]
E --> F[PO<br/>质量验证]
F --> G[PO<br/>文档拆分]
graph LR
G[PO<br/>文档拆分] --> H[SM<br/>故事创建+质量评估]
H --> I{智能决策矩阵}
I -->|高质量+低复杂度| J[Dev<br/>功能实现]
I -->|需要审查| K[Architect<br/>技术审核]
K -->|通过| J
K -->|需修订| L[SM<br/>故事修订]
L -->|自动批准| J
L -->|第2轮审查| K
J --> M[QA<br/>代码审查]
M -->|通过| N[Done]
M -->|需修复| J
流程细节请参考 工作流程指南。
| 代理角色 | 专业领域 | 核心输出 |
|---|---|---|
| Analyst | 需求分析、市场调研 | project-brief.md |
| PM | 产品管理、需求规范 | prd.md |
| UX-Expert | 用户体验设计 | front-end-spec.md |
| Architect | 技术架构设计 | architecture.md |
| PO | 质量保证、一致性验证 | 质量检查报告 |
| 代理角色 | 专业领域 | 核心职责 |
|---|---|---|
| Scrum Master | 敏捷管理 | 用户故事创建、迭代管理 |
| Dev | 代码实现 | 功能开发、技术实现 |
| QA | 质量控制 | 代码审查、测试验证 |
*help # 查看帮助信息
*analyst # 切换到需求分析师
*pm # 切换到产品经理
*architect # 切换到架构师
*kb-mode # 启用知识库模式
SM (Scrum Master):
*draft - 创建新故事*revise - 根据反馈修订故事*story-checklist - 执行质量验证Architect:
*review-story {story_id} - 技术审核故事*create-doc {template} - 创建架构文档Dev (Developer):
*develop-story {story_id} - 实现故事功能*review-qa {story_id} - 应用QA反馈修复QA:
*review {story_id} - 执行代码审查*gate {story_id} - 创建质量门决策npx orchestrix install # 安装或更新框架
npx orchestrix status # 查看安装状态
npx orchestrix list # 列出所有可用代理
| IDE | 语法 | 示例 |
|---|---|---|
| Cursor/Windsurf | @agent-name | @pm, @dev |
| Claude Code | /agent-name | /pm, /dev |
| Roo Code | 模式选择 | orchestrix-pm |
MIT License - 详见 LICENSE
🎼 为专业AI代理协作而设计 | ❤️ 服务全球开发者社区
FAQs
Orchestrix - Universal AI Agent Framework for Coordinated AI-Driven Development
The npm package orchestrix receives a total of 36 weekly downloads. As such, orchestrix popularity was classified as not popular.
We found that orchestrix demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.