Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
robocorp-action-server
Advanced tools
Robocorp Action Server is a Python framework designed to simplify the deployment of actions (AI or otherwise).
An action
in this case is defined as a Python function (which has inputs/outputs defined), which is served by the Robocorp Action Server
.
The Robocorp Action Server
automatically generates an OpenAPI spec for your Python code, enabling different AI/LLM Agents to understand and call your Action. It also manages the Action lifecycle and provides full traceability of what happened during runs.
Action Server is available as a stand-alone fully signed executable and via pip install robocorp-action-server
.
We recommend the executable to prevent confusion in case you have multiple/crowded Python environments, etc.
# Install Robocorp Action Server
brew update
brew install robocorp/tools/action-server
# Download Robocorp Action Server
curl -o action-server.exe https://downloads.robocorp.com/action-server/releases/latest/windows64/action-server.exe
# Add to PATH or move to a folder that is in PATH
setx PATH=%PATH%;%CD%
# Download Robocorp Action Server
curl -o action-server https://downloads.robocorp.com/action-server/releases/latest/linux64/action-server
chmod a+x action-server
# Add to PATH or move to a folder that is in PATH
sudo mv action-server /usr/local/bin/
# Bootstrap a new project using this template.
# You'll be prompted for the name of the project (directory):
action-server new
# Start Action Server
cd my-project
action-server start --expose
👉 You should now have an Action Server running locally at: http://localhost:8080, so open that in your browser and the web UI will guide you further.
👉 Using the --expose
-flag, you also get a public internet-facing URL (something like "https://twently-cuddly-dinosaurs.robocorp.link") and the related token. These are the details that you need to configure your AI Agent to have access to your Action
An Action Package
is currently defined as a local folder that contains at least one Python file containing an action entry point (a Python function marked with @action
-decorator from robocorp.actions
).
The package.yaml
file is required for specifying the Python environment and dependencies for your Action (RCC will be used to automatically bootstrap it and keep it updated given the package.yaml
contents).
Note: the
package.yaml
is optional if the action server is not being used as a standalone (i.e.: if it was pip-installed it can use the same python environment where it's installed).
Start new projects with:
action-server new
Note: the action-server
executable should be automatically added to your python installation after pip install robocorp-action-server
, but if for some reason it wasn't pip-installed, it's also possible to use python -m robocorp.action_server
instead of action-server
.
After creating the project, it's possible to serve the actions under the current directory with:
action-server start
For example: When running action-server start
, the action server will scan for existing actions under the current directory, and it'll start serving those.
After it's started, it's possible to access the following URLs:
/index.html
: UI for the Action Server./openapi.json
: Provides the openapi spec for the action server./docs
: Provides access to the APIs available in the server and a UI to test it.Explore our docs for extensive documentation.
A list of releases and corresponding changes can be found in the changelog.
FAQs
Robocorp local task server
We found that robocorp-action-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.