
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
progi
Advanced tools
Progi teaches your agent how you like to get things done. So you can do your best work without re-explaining your process or losing context between sessions.
Add Progi to your MCP client config (GH Copilot / Cursor / Claude Code / etc):
{
"mcpServers": {
"progi": {
"command": "uvx",
"args": ["progi"]
}
}
}
Progi Monitoring starts automatically at http://127.0.0.1:8000.
If you want to start Monitoring on a different port:
{
"mcpServers": {
"progi": {
"command": "uvx",
"args": ["progi"],
"env": {
"PROGI_WEB_PORT": "8080"
}
}
}
}
1. Describe your workflow
"Hey Progi, help me create workflow for creating integrations, reviewing code, and publishing PRs."
Describe your process in plain language. You can be detailed or just provide a rough idea. Progi stores it as a structured workflow with per-step playbooks.
2. Run tasks, stay in the loop
"Hey Progi, start a new task, we need to review a new docs PR in the repo." Your agent loads the workflow, works through each step using your playbooks, and loops you in at critical checkpoints to review output.
3. Monitor progress
Progi Monitoring gives you a live view of every running and completed task — status, progress, and the full output history across all your workflows.
4. Optimize as you go
Tweak playbooks between runs. Because workflows live in a database and survive context resets, every future task picks up your changes automatically — your process gets sharper with each iteration.
| Tool | Description |
|---|---|
create_task | Create a new task under a given workflow (status todo); returns a preview of its first step |
list_tasks | List tasks, optionally filtered by status and/or workflow |
start_or_continue_task | Main work-loop entry point — starts or resumes a task and returns the current step's playbook, input data, and output spec |
update_progress_notes | Overwrite a task's progress notes (mid-step save point) |
submit_output | Mark the current step complete, store its output, and advance to the next step (or mark done) |
| Tool | Description |
|---|---|
get_process_skeleton_prompt | Return the Pass 1 system prompt for turning a plain-language description into a structured workflow skeleton |
get_playbook_authoring_prompt | Return the Pass 2 system prompt for authoring a step's playbook (injects workflow context) |
save_workflow | Persist a new workflow, its steps, and playbooks |
list_workflows | Return all workflows with their ordered steps |
update_playbook | Replace the playbook content for a step |
Authoring is two passes: Pass 1 turns a plain-language description into a structured skeleton; Pass 2 authors each step's playbook. save_workflow persists both.
| Variable | Default | Purpose |
|---|---|---|
PROGI_DB_PATH | OS data dir (platformdirs) | SQLite file location |
PROGI_WEB_HOST | 127.0.0.1 | Web UI bind host |
PROGI_WEB_PORT | 8000 | Web UI port |
PROGI_NO_WEB | 0 | Set to 1 to disable the web UI |
Run modes: uvx progi (MCP + web UI), uvx progi --no-web (MCP only), uvx progi-web (web UI only).
Use an absolute path for
PROGI_DB_PATH
FAQs
An MCP-native workflow engine that teaches your agent how you like to get things done.
The pypi package progi receives a total of 52 weekly downloads. As such, progi popularity was classified as not popular.
We found that progi demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.