
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
Catch the moment your agent drifts from its rules.
RuleDrift tests whether an AI agent still follows important instructions after a conversation becomes long or distracting.
Run it like a test suite when you change a prompt, model, memory system, or agent workflow. It runs locally and does not sit in front of production requests.
Requires Node.js 22+ and Ollama.
ollama pull qwen3:1.7b
npx rule-drift init
npx rule-drift test
No paid model API, account, backend, or telemetry is required.
npx -y rule-drift mcp --root /path/to/your/project
See the MCP setup guide for client configuration and safety details.
Contributions are welcome—see CONTRIBUTING.md. Licensed under MIT.
FAQs
Test whether AI agents retain critical instructions as conversations grow.
We found that rule-drift demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.