{"_id":"@agent-action-runner/core","_rev":"15-09ca1c8c2d42ffd368386252af2f4df1","name":"@agent-action-runner/core","dist-tags":{"latest":"0.8.2"},"versions":{"0.1.0":{"name":"@agent-action-runner/core","version":"0.1.0","keywords":["agent","actions","workflow","typescript","approval","audit","llm"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.1.0","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"a75902f99592004ef530ccd79da9a8cc55c7fc49","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.1.0.tgz","fileCount":26,"integrity":"sha512-7y/MOoKOaNp02Z59DlgEmDQT+OTDDU6wPdrAdFmGFLnQzb9tMhHnb5vtbEtGrOgQ/vVLn58bP1vt/SUz5tSn+Q==","signatures":[{"sig":"MEUCIGGqh3Lo82+9DWEJgZPDawhKxIaE5UQ4tXXi3piYv9TRAiEAt/cXnsUGth5ql6se0YWZLYyJoEzYtewSOuHnrDNs96o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45497},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"6a93b731abe5020f45162853d5a26c13be9b3737","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"doompy17","email":"brillarrz@gmail.com"},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.9.0","description":"Framework-agnostic core for Agent Action Runner.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.1.0_1777995924041_0.9560463052340094","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agent-action-runner/core","version":"0.2.0","keywords":["agent","actions","workflow","typescript","approval","audit","llm"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.2.0","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"8e0fa889560c9041ae6faa089ff89398110ce306","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.2.0.tgz","fileCount":26,"integrity":"sha512-2p0VATjN2rs5030WyS1K76z4SKohK0lS6uHhRZJsmFRHnISkR1xmxDuYhPYx2m0BbK4FQ7W0cgH1zvGnx1FM3w==","signatures":[{"sig":"MEUCIQDC8K4xH3h3teKF4nkGA5TTChh+qFb1+9HtgXFDc8TfNgIgQZElu4DI54BtapcDNuV/+ccMvh+mQ8QEdr8ZQEcBDmw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45497},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"aa48c5deb09854e7a38e8e8253601783ffd8c1e5","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"doompy17","email":"brillarrz@gmail.com"},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.9.0","description":"Framework-agnostic core for Agent Action Runner.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.2.0_1777997402009_0.35968393553187683","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@agent-action-runner/core","version":"0.3.0","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.3.0","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"23293a03bce02aecd4d72d7fd983fa95de5e282a","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.3.0.tgz","fileCount":26,"integrity":"sha512-dbTWe3cXzKgvvuvMf9y2gHMeczk9IYkW7FdHsSt1XxA6EdSAC5dceoi646MgCSfmIsGFD6pmraVIDG8RdhiCMg==","signatures":[{"sig":"MEQCIDkthkikag0pXKfVZzo/b4goBLPU+6/mz0lwWVIaa+gBAiArh/44SZXrKdXHeA5j4F/8gNKS33KF6PuwFW1d7il7Mw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":45696},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f9f4b8709bfd991f6ccd73c5a5aa6e42390d06f9","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"doompy17","email":"brillarrz@gmail.com"},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.9.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.3.0_1778068352086_0.12489731014220218","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@agent-action-runner/core","version":"0.4.1","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.4.1","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"f7ae92583840cfdeea4b22d54bc34c85e76011be","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.4.1.tgz","fileCount":34,"integrity":"sha512-9Se/znXKzW5WfCb/1xk1v+Pfk42hdEPYh3WiYwKDGnpS57ZK1VecY7nPpitRzwhh1krvqzgAhBEeRV6CMrJTmQ==","signatures":[{"sig":"MEUCIQDAQc+6CN4wvmiKEjQmHIAPMK3w9VI3CX3buwuD9uLGXgIgPsGwrzrAfvcONXfnhwXyZuv7wY+03Qsac7M0yX2p/3I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70912},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ef4c193d9da1068accee11b1014aa11c5e4b4cbf","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"doompy17","email":"brillarrz@gmail.com"},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.14.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.4.1_1778115996776_0.026877325798607465","host":"s3://npm-registry-packages-npm-production"}},"0.4.6":{"name":"@agent-action-runner/core","version":"0.4.6","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.4.6","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"de73046067db901fb9c9a81179786af682e7d54c","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.4.6.tgz","fileCount":34,"integrity":"sha512-O/D8MmZUVjit0VAoI7pPIjy7WHUq8HDTqS24me0F4y9HL1aziToVlCzzGCGMyrtdeGZO+rGiSg7nrfIo/4Wowg==","signatures":[{"sig":"MEUCIQCRnd95JTsk8D6ovMGz0ZUSVb3EJdEs/Fj2WaYrZRjCCAIgB9VcdazGy7NaBfz91Wmo5ibveoipjW65G2T5nruii6U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.4.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":76713},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"a9bf05189585662a18b0a2df5f76b4f36b695a46","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.4.6_1778122504187_0.3078144978815085","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agent-action-runner/core","version":"0.5.0","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.5.0","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"1424f2c5bf95c49332da9f41affbdc2320431352","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.5.0.tgz","fileCount":38,"integrity":"sha512-ODtz6AArkUnuSiOXxpC5Ue8UvS2r1CyF+ZDpTzhQCjl4wohqjc3Qqcad2K9ZXtsZH3YSIXPw6Ysvkhzvs/EqbA==","signatures":[{"sig":"MEQCIHR92cadKz3UJDAh+x3SbXOwibBH2mLgBUUThl4W+cLAAiAdO38HQv3b3o7zhD7/IzGCzMeUZoL51cAG0gfhjcqJRw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":78768},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"81d795afaf77240c0ea6d31b8c1cf2098bb0bbeb","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.5.0_1778129609318_0.0633989194644975","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@agent-action-runner/core","version":"0.6.0","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.6.0","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"2e997ed2948f9c3e8f06eb42a91a3dffca4fefe8","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.6.0.tgz","fileCount":38,"integrity":"sha512-FOYZoSGISarBggmz2KR0Kl4n01OOmDOvoLlUpJS6MLrQyuzS5YrZXtSb96ClXhOafNRPghpruGf+a63WWle7vQ==","signatures":[{"sig":"MEUCIAfnnwqXzOcDOYIRAQmWQ+yfUhF0F0z442KKtvUgrYomAiEAhx+1qEviEoLlz9ZAyor0NqQYRFgPvrFsnzeIgvh57T0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":93132},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c44e3012eb1ea754d3549fb1ae6d483bf10f6c1b","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.6.0_1778159982069_0.6594969501043493","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@agent-action-runner/core","version":"0.6.1","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.6.1","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"f2f95690af3ddae1ad17e32b3154e703cba16695","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.6.1.tgz","fileCount":38,"integrity":"sha512-RcNq+Q23ka4te4LG0UfJdgUy0DjDO9tSB//vv4HUAGoYbHFowas/B7QlCFPFvYs8iu3vhAKxnzizvtPmJT46aw==","signatures":[{"sig":"MEUCIQDGZMZgK3VocAtDjpIi6ZDAVL+zG11wXE8BwDUWHfdYngIgDm0HWl1a8EOBPItjaxqfAA5ntv2NgSixDg4H3bIRJj4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.6.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":96368},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b3ed647a6a4192a4acb3375b2d935453929f87bc","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.6.1_1778164793750_0.7937817296858314","host":"s3://npm-registry-packages-npm-production"}},"0.6.2":{"name":"@agent-action-runner/core","version":"0.6.2","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.6.2","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"991f9de9a6847258e2a509e5b8877e45508ad437","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.6.2.tgz","fileCount":42,"integrity":"sha512-EJE9OWifmsHtn3X/KAY4VuzwuALyF4cB/mfrmMDDD3iKjc9uUQtlgVts5Ep3RmTlzJxxZF5NJy4ifCJRq2lclw==","signatures":[{"sig":"MEUCIQCRTRmbmVOgzA1OYcI6AH92da1RJZkHxA0iZS7pOlXNZAIgZdXfVh6G7I6p/wnAG1wT0CbCpiJvirEb4Jdb1/B7Jy8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.6.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":115476},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"dfbfae92ff2e54578ab13979a47e47aa04f2db11","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.6.2_1778166670233_0.9243250976702899","host":"s3://npm-registry-packages-npm-production"}},"0.6.3":{"name":"@agent-action-runner/core","version":"0.6.3","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.6.3","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"9415414fc8ba8b32080edcd2b31860a47957f903","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.6.3.tgz","fileCount":42,"integrity":"sha512-xK5Bac8wQ6A1s2J0/IaD1WTG5ohrXxzzDL8yxwhYrPRsm3mqnrCQ/GypigVWggqMIdjeFLbK4tIhspxHFTGAZA==","signatures":[{"sig":"MEUCIQD0y9jvmOwvCLj0h0n7muU06KPpTUBAG0w7gKiMbTCP/gIgNv9/ZI2W2yIMWt+YZ+z1hnEfYAwqKT1h2RwaiLjyJl8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.6.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":117362},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"3f3c6ad854be65e7eb4f3b0aab6e1511854e62f7","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.6.3_1778331287197_0.5266766692720868","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@agent-action-runner/core","version":"0.7.0","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.7.0","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"9c1de60f47edff8405b71e1c502fef8ec2413c54","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.7.0.tgz","fileCount":42,"integrity":"sha512-TdLDErSyAcb25XjOoovQc/+aTtIBawiSUB7Ef8TzK5NFZVrbn1Iyh6T+SmVHMgUnRIzNvY30VhsLBvG2L7253g==","signatures":[{"sig":"MEQCIHubS30hAsq8NmqCjrr5noO6HbbirWiETPb0a6XXvHu2AiBC9HIfR+fZM/Ww7swZYRmU82rdLXYPwCz/kOVxWoRmvQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":120517},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"9f1f5dcc52c7f21d1dedd8e597dfd700f804da07","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.7.0_1778336335522_0.11845299008334753","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@agent-action-runner/core","version":"0.7.1","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.7.1","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"4264cd838b489aa7b6d0ef8bb9213285975c08a8","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.7.1.tgz","fileCount":42,"integrity":"sha512-FV2Df5ZU2K3y/Cz4ZhiNFCNjMo9uNSSurJp0kFxgq1boB0eppRXrmIhmHDRG+iIGouSStw/7Yp03urKb/SgJmg==","signatures":[{"sig":"MEQCIHdWDOE5Xwr98IG3LMOP58H4HX2auDThOLQAIhQbD6erAiBZA3pRnO2HJDbFjI+tPvB3rfm7PUWgxhI94DidMNyUzw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":121993},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c18d5415a7ae6cc17ec42a90b487da065264993a","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.7.1_1778338682784_0.2562530652324835","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@agent-action-runner/core","version":"0.8.0","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.8.0","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"0dab5946673078ecb62c0a654e9586bb15139f4f","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.8.0.tgz","fileCount":46,"integrity":"sha512-t8chwpkhLNszgYjywS6uEW1l65uEqkcF8Gz0IbG1GRzBmzEFKr9gx4dZfEOf/CD7lTqiQIYfOl7iQPrDvcihOw==","signatures":[{"sig":"MEQCIGyd8+xH0CuLpeip36Q3YOziv8FXwNU6XydJTaiGncYwAiAUYxddZ3l8Gw9beT8P/8xKX6/WM/g0QekyQ6H5bxRNVg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":130799},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"14ef4cec8048f5d88007e346f50f5ede46b093ab","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.8.0_1778340981987_0.3414948030574101","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"@agent-action-runner/core","version":"0.8.1","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"author":{"name":"Doompy"},"license":"Apache-2.0","_id":"@agent-action-runner/core@0.8.1","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"dist":{"shasum":"4eaa8008751284867de952c2b23d0ed5ae9ff3e2","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.8.1.tgz","fileCount":46,"integrity":"sha512-K+DXmRv/Q6xndhqbm2A+rBX2FCpisWJJHhZXfTGrgzz5mDj1L65AYG2XDukq5ilXXmdnq0DrmolpwBMsiKf6nQ==","signatures":[{"sig":"MEYCIQCMQLqQ+Vt6fAmGmFKugsA9G1JpxGG0iEZ9a3SnYQcqGAIhALLeCi4BuEp85oPzChSXqZGBjmPMmtxdNj5jlcQbfn9x","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.8.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":134431},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.18.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"778ad68e7a72b20643f9e80566041085c46b27c2","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"repository":{"url":"git+https://github.com/Doompy/agent-action-runner.git","type":"git","directory":"packages/core"},"_npmVersion":"11.11.0","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/core_0.8.1_1778343912348_0.5549368852957464","host":"s3://npm-registry-packages-npm-production"}},"0.8.2":{"name":"@agent-action-runner/core","version":"0.8.2","description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","license":"Apache-2.0","author":{"name":"Doompy"},"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"repository":{"type":"git","url":"git+https://github.com/Doompy/agent-action-runner.git","directory":"packages/core"},"homepage":"https://github.com/Doompy/agent-action-runner#readme","bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"engines":{"node":">=18.18.0"},"publishConfig":{"access":"public"},"sideEffects":false,"scripts":{"prepack":"npm run build","build":"tsc -p tsconfig.build.json","test":"vitest run","typecheck":"tsc -p tsconfig.json --noEmit"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"devDependencies":{"zod":"^4.1.13","vitest":"^4.0.14"},"gitHead":"37be6f225af7711a54c4d0ed8e315f8c82124d8f","_id":"@agent-action-runner/core@0.8.2","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-loFOJtmgeAgUgFizCbRIVZcZ8EeiFXwOt6S5fMZMAVAXkly5gRqhXh3+7UOasLLmUvc9IYNxnLjw4R8aHtki/w==","shasum":"41ae8fd9623ee426d0c869411e670cf6de2870f7","tarball":"https://registry.npmjs.org/@agent-action-runner/core/-/core-0.8.2.tgz","fileCount":46,"unpackedSize":134431,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-action-runner%2fcore@0.8.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEFDJMuU47Vic5Yz7SZQPbkGqf8bT6nmfWWW1nOtybSJAiA0+Q9TUHMJTRcoeBzIGcNIBDXgB3tG4o5TzKfdv3QdKg=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:7b9a1e15-8596-4753-aca3-ff89d51fe23d"}},"directories":{},"maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/core_0.8.2_1778383416461_0.6397038914555191"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-05T15:45:23.957Z","modified":"2026-05-10T03:23:36.950Z","0.1.0":"2026-05-05T15:45:24.225Z","0.2.0":"2026-05-05T16:10:02.243Z","0.3.0":"2026-05-06T11:52:32.235Z","0.4.1":"2026-05-07T01:06:36.920Z","0.4.6":"2026-05-07T02:55:04.341Z","0.5.0":"2026-05-07T04:53:29.446Z","0.6.0":"2026-05-07T13:19:42.205Z","0.6.1":"2026-05-07T14:39:53.895Z","0.6.2":"2026-05-07T15:11:10.393Z","0.6.3":"2026-05-09T12:54:47.369Z","0.7.0":"2026-05-09T14:18:55.668Z","0.7.1":"2026-05-09T14:58:02.970Z","0.8.0":"2026-05-09T15:36:22.129Z","0.8.1":"2026-05-09T16:25:12.492Z","0.8.2":"2026-05-10T03:23:36.631Z"},"bugs":{"url":"https://github.com/Doompy/agent-action-runner/issues"},"author":{"name":"Doompy"},"license":"Apache-2.0","homepage":"https://github.com/Doompy/agent-action-runner#readme","keywords":["typescript","ai-agent","llm","workflow","agent-workflow","tool-calling","mcp","approval","audit","dry-run","human-in-the-loop","zod","nestjs","express","fastify"],"repository":{"type":"git","url":"git+https://github.com/Doompy/agent-action-runner.git","directory":"packages/core"},"description":"Agent-safe action and workflow runner core for TypeScript backends with schema validation, approval, and audit.","maintainers":[{"name":"doompy17","email":"brillarrz@gmail.com"}],"readme":"# @agent-action-runner/core\n\nFramework-agnostic action registry and JSON workflow runner for TypeScript backends.\n\nUse this package when you want an agent to call existing service logic through named, schema-validated actions instead of giving the agent direct database access, internal API access, or arbitrary code execution.\n\nCore does not execute agent-generated TypeScript. It only runs handlers that your application registered as actions.\n\nExperimental / pre-1.0. Public APIs may change while the action, workflow, and approval contracts settle.\n\n## Install\n\n```bash\nnpm install @agent-action-runner/core zod\n```\n\n`zod` is a peer dependency because action input and output schemas are part of the public action contract.\n\n## What It Provides\n\n- In-memory action registry.\n- Sequential JSON workflow execution.\n- Zod input and output validation.\n- Action modes: `read`, `draft`, `dryRun`, `mutate`.\n- Server-controlled mode enforcement.\n- Policy, approval, and audit hooks.\n- Audit payload minimization for input, output, and error data.\n- Deterministic input hashing for approval checks.\n- Public stable hash helper for approval services.\n- Audit store helper for persistent audit adapters.\n- Restricted step output references.\n- Type-safe workflow authoring helpers.\n- Static workflow validation helpers.\n- Action metadata for API reuse documentation.\n- Workflow retry, timeout, and continue-on-error controls.\n- Idempotency key propagation for retry-safe mutation handlers.\n- Cooperative `AbortSignal` for cancellable handlers.\n- Small policy composition helpers.\n\n## Quickstart\n\n```ts\nimport { createRunner, fromStep } from '@agent-action-runner/core';\nimport { z } from 'zod';\n\nconst runner = createRunner({\n  audit: async (event) => {\n    console.log(event.actionName, event.status);\n  },\n});\n\nrunner.registerAction({\n  name: 'delivery.searchJobs',\n  mode: 'read',\n  description: 'Search delivery jobs by status.',\n  inputSchema: z.object({\n    status: z.array(z.string()),\n  }),\n  outputSchema: z.object({\n    jobIds: z.array(z.string()),\n  }),\n  handler: async (input) => {\n    return { jobIds: input.status.includes('FAILED') ? ['job_1'] : [] };\n  },\n});\n\nrunner.registerAction({\n  name: 'delivery.dryRunRetry',\n  mode: 'dryRun',\n  description: 'Validate retry candidates before mutation.',\n  inputSchema: z.object({\n    jobIds: z.array(z.string()),\n  }),\n  outputSchema: z.object({\n    retryable: z.array(z.string()),\n    blocked: z.array(z.string()),\n  }),\n  handler: async (input) => {\n    return { retryable: input.jobIds, blocked: [] };\n  },\n});\n\nconst result = await runner.executeWorkflow({\n  userId: 'operator_1',\n  workflow: {\n    workflowName: 'retry-failed-delivery-jobs',\n    steps: [\n      {\n        id: 'jobs',\n        action: 'delivery.searchJobs',\n        input: { status: ['FAILED'] },\n      },\n      {\n        id: 'dryRun',\n        action: 'delivery.dryRunRetry',\n        input: {\n          jobIds: fromStep('jobs', '/jobIds'),\n        },\n      },\n    ],\n  },\n});\n\nconsole.log(result.outputByStep.dryRun);\n```\n\n## Action Modes\n\n```ts\ntype ActionMode = 'read' | 'draft' | 'dryRun' | 'mutate';\n```\n\n| Mode | Intended Use |\n|---|---|\n| `read` | Query or inspect existing state. |\n| `draft` | Generate a draft without changing production state. |\n| `dryRun` | Validate a future mutation and calculate impact. |\n| `mutate` | Change production state. Requires explicit mode allowance and approval. |\n\nThe default allowed modes are `read`, `draft`, and `dryRun`. `mutate` is blocked unless the execution request includes it in `allowedModes`.\n\n## Registering Actions\n\n```ts\nrunner.registerAction({\n  name: 'report.generateDraft',\n  mode: 'draft',\n  description: 'Create a report draft for review.',\n  tags: ['reports'],\n  resourceType: 'report',\n  riskLevel: 'low',\n  examples: [\n    {\n      title: 'Create a report draft',\n      input: { reportId: 'report_1' },\n    },\n  ],\n  inputSchema: z.object({\n    reportId: z.string(),\n  }),\n  outputSchema: z.object({\n    draftId: z.string(),\n  }),\n  handler: async (input, ctx) => {\n    return {\n      draftId: `${ctx.userId}:${input.reportId}`,\n    };\n  },\n});\n```\n\nAction names must be unique. Handlers receive parsed input and an execution context with user id, action name, mode, workflow id, step id, metadata, approval token, approval context, cooperative `AbortSignal`, and optional idempotency key.\n\n## Executing One Action\n\n```ts\nconst result = await runner.executeAction({\n  userId: 'operator_1',\n  action: 'delivery.searchJobs',\n  input: {\n    status: ['FAILED'],\n  },\n});\n```\n\nUse `metadata` for request-scoped values that are useful to policies, handlers, or audit hooks.\n\n```ts\nawait runner.executeAction({\n  userId: 'operator_1',\n  action: 'delivery.searchJobs',\n  input: { status: ['FAILED'] },\n  metadata: {\n    requestId: 'req_123',\n    source: 'admin-console',\n  },\n});\n```\n\nUse `idempotencyKey` for `mutate` actions that may be retried or may time out from the runner's perspective while the underlying work continues:\n\n```ts\nawait runner.executeAction({\n  userId: 'operator_1',\n  action: 'delivery.executeRetry',\n  input: { jobIds: ['job_1'] },\n  allowedModes: ['mutate'],\n  approvalToken,\n  approvalContext,\n  idempotencyKey: `retry:job_1:${dryRunHash}`,\n});\n```\n\nThe raw key is available to the handler as `ctx.idempotencyKey`. Audit events only receive `idempotencyKeyHash`, a SHA-256 fingerprint for correlation. Core does not generate keys, reserve keys, lock rows, or replay results; applications own that behavior in their service or transaction layer.\n\n## Cooperative Cancellation\n\nHandlers receive `ctx.signal`, an `AbortSignal` for cooperative cancellation.\n\n```ts\nrunner.registerAction({\n  name: 'delivery.searchJobs',\n  mode: 'read',\n  handler: async (input, ctx) => {\n    return deliveryService.searchJobs(input, {\n      signal: ctx.signal,\n    });\n  },\n});\n```\n\nWhen `timeoutMs` expires, the runner rejects the attempt with `ActionTimeoutError` and aborts `ctx.signal`. This does not forcibly stop work already running in Node.js. Cancellation only happens if your handler passes the signal to APIs that honor it.\n\nYou can also pass a signal when executing a workflow. The runner forwards that signal to each step action and observes it during retry delays.\n\n```ts\nconst controller = new AbortController();\n\nawait runner.executeWorkflow({\n  userId: 'operator_1',\n  workflow,\n  signal: controller.signal,\n});\n```\n\nIf the workflow signal is aborted during a retry delay, the workflow fails with `WorkflowAbortedError`. Action handlers still use cooperative cancellation; a handler that ignores `ctx.signal` is not forcibly stopped.\n\n## Executing Workflows\n\nWorkflows are plain JSON data. They execute sequentially, and each step can reference outputs from earlier steps.\n\n```json\n{\n  \"workflowName\": \"retry-failed-delivery-jobs\",\n  \"steps\": [\n    {\n      \"id\": \"jobs\",\n      \"action\": \"delivery.searchJobs\",\n      \"input\": {\n        \"status\": [\"FAILED\"]\n      },\n      \"timeoutMs\": 1000,\n      \"idempotencyKey\": \"search-failed:2026-05-06\",\n      \"retry\": {\n        \"maxAttempts\": 2,\n        \"delayMs\": 50\n      }\n    },\n    {\n      \"id\": \"dryRun\",\n      \"action\": \"delivery.dryRunRetry\",\n      \"input\": {\n        \"jobIds\": {\n          \"$fromStep\": \"jobs\",\n          \"path\": \"/jobIds\"\n        }\n      }\n    }\n  ]\n}\n```\n\nUse `fromStep(stepId, path)` in TypeScript to create the same reference object:\n\n```ts\nfromStep('jobs', '/jobIds');\n```\n\nPaths are JSON Pointer strings. References can only resolve against previous step outputs.\n\n`retry.maxAttempts` includes the first attempt. `timeoutMs` marks the attempt as failed after the configured duration; it does not cancel underlying Node.js work that has already started. `idempotencyKey` must be a non-empty string when present and is passed to the step's action context. Use `continueOnError: true` only when downstream steps can safely consume a failed step result.\n\nFor `mutate` actions, retries should only be enabled when the underlying service is idempotent or protected by a transaction/idempotency key. A timeout can happen while the original work is still running.\n\n## Workflow Builder\n\nThe builder gives TypeScript checks for action inputs and previous step references while still producing the same JSON workflow definition.\n\n```ts\nimport {\n  createRunner,\n  defineAction,\n  defineActionCatalog,\n  defineWorkflow,\n  registerActionCatalog,\n} from '@agent-action-runner/core';\nimport { z } from 'zod';\n\nconst runner = createRunner();\n\nconst actions = defineActionCatalog({\n  searchJobs: defineAction({\n    name: 'delivery.searchJobs',\n    mode: 'read',\n    inputSchema: z.object({ status: z.array(z.string()) }),\n    outputSchema: z.object({ jobIds: z.array(z.string()) }),\n    handler: async () => ({ jobIds: ['job_1'] }),\n  }),\n  dryRunRetry: defineAction({\n    name: 'delivery.dryRunRetry',\n    mode: 'dryRun',\n    inputSchema: z.object({ jobIds: z.array(z.string()) }),\n    outputSchema: z.object({ retryable: z.array(z.string()) }),\n    handler: async (input) => ({ retryable: input.jobIds }),\n  }),\n});\n\nregisterActionCatalog(runner, actions);\n\nconst workflow = defineWorkflow('retry-failed-jobs')\n  .step('jobs', actions.searchJobs, { status: ['FAILED'] })\n  .step('dryRun', actions.dryRunRetry, ({ fromStep }) => ({\n    jobIds: fromStep('jobs', '/jobIds'),\n  }))\n  .build();\n```\n\nThe builder does not execute TypeScript code. It only creates a `WorkflowDefinition` for the existing JSON runner.\n\n## Workflow Validation\n\nUse `validateWorkflowDefinition()` before executing workflow JSON from files, CLI input, or generated agent plans.\n\n`executeWorkflow()` also runs this validation before any step handler starts and throws `WorkflowValidationError` when the workflow is invalid.\n\n```ts\nimport { validateWorkflowDefinition } from '@agent-action-runner/core';\n\nconst result = validateWorkflowDefinition(workflow, {\n  actions: runner.listActions().map((action) => ({\n    name: action.name,\n    mode: action.mode,\n  })),\n});\n\nif (!result.valid) {\n  console.error(result.issues);\n}\n```\n\nValidation catches:\n\n- missing or invalid workflow names\n- missing steps\n- duplicate step ids\n- unknown actions when an action catalog is supplied\n- invalid action modes\n- step `allowedModes` that exclude the known action mode\n- invalid retry, timeout, or continue-on-error controls\n- invalid idempotency keys\n- references to missing or future steps\n- unsupported input values\n\n## Approval Model\n\n`mutate` actions require both:\n\n- `mutate` in the execution `allowedModes`\n- an approval hook result of `{ approved: true }`\n\n```ts\nconst runner = createRunner({\n  approval: async ({ approvalToken, approvalContext }) => {\n    return verifyApprovalToken(approvalToken, approvalContext)\n      ? { approved: true, approvalId: 'approval_1' }\n      : { approved: false, reason: 'Invalid approval token.' };\n  },\n});\n```\n\nThe approval hook receives a normalized context:\n\n```ts\ntype ApprovalContext = {\n  userId: string;\n  actionName: string;\n  mode: 'read' | 'draft' | 'dryRun' | 'mutate';\n  inputHash: string;\n  resourceIds?: readonly string[];\n  dryRunHash?: string;\n  expiresAt?: string;\n  workflowId?: string;\n  stepId?: string;\n};\n```\n\nCore does not issue or sign approval tokens. Applications should bind approval tokens to the approval context fields they care about, especially `userId`, `actionName`, `inputHash`, `resourceIds`, `dryRunHash`, and `expiresAt`.\n\nUse `createStableHash()` when an approval service needs to calculate the same deterministic input hash as the runner:\n\n```ts\nimport { createStableHash } from '@agent-action-runner/core';\n\nconst inputHash = createStableHash({\n  userId: 'user_2',\n  reason: 'Repeated policy violations.',\n  dryRunHash: 'dry_run_hash',\n});\n```\n\nThe stable hash is based on normalized JSON-compatible input. Object properties with `undefined` values are treated as absent, so `{}` and `{ optional: undefined }` hash the same. In arrays, `undefined` is normalized like `null` to preserve array positions.\n\nInside a handler, call `ctx.requireApproval()` before performing a sensitive mutation when you want an explicit guard at the mutation point. This is a defense-in-depth check for actions that were already approved through `mutate` mode or `approvalRequired`; it does not start an interactive approval flow by itself.\n\n```ts\nhandler: async (input, ctx) => {\n  ctx.requireApproval();\n  return deliveryService.executeRetry(input.jobIds);\n}\n```\n\n## Policy Hook\n\nUse the policy hook for application-specific allow/deny checks before the handler runs.\n\n```ts\nconst runner = createRunner({\n  policy: async ({ action, context }) => {\n    if (action.mode === 'mutate' && context.metadata.environment !== 'staging') {\n      return { allowed: false, reason: 'Mutations are disabled outside staging.' };\n    }\n\n    return { allowed: true };\n  },\n});\n```\n\nSmall policy helpers are available when role/scope checks can be read from `context.metadata`.\n\n```ts\nimport {\n  allowModes,\n  composePolicies,\n  requireRole,\n  requireScope,\n} from '@agent-action-runner/core';\n\nconst runner = createRunner({\n  policy: composePolicies(\n    allowModes(['read', 'draft', 'dryRun']),\n    requireRole('admin', { actions: ['admin.disableUser'] }),\n    requireScope('delivery:write', { actions: ['delivery.executeRetry'] }),\n  ),\n});\n```\n\n`requireRole()` reads `metadata.roles` by default and `requireScope()` reads `metadata.scopes` by default. Both accept either a string or string array, and both support `metadataKey` when your application uses different metadata fields.\n\n## Audit Hook\n\nThe audit hook receives `started`, `succeeded`, and `failed` events.\n\nWorkflow retries add `attempt` and `maxAttempts` to audit events.\n\nAudit events do not include the raw `approvalToken` or raw `idempotencyKey`. When present, the event includes `approvalTokenHash` and `idempotencyKeyHash` instead.\n\n`approvalTokenHash` is a redacted fingerprint for audit correlation, not a secure approval token store. Approval services should use secret-backed HMACs or sufficiently random approval tokens for verification.\n\nBy default, audit payload behavior remains compatible with previous releases:\n\n```ts\nconst runner = createRunner({\n  auditDefaults: {\n    input: 'full',\n    output: 'full',\n    error: 'full',\n  },\n});\n```\n\nFor production systems, minimize stored payloads:\n\n```ts\nconst runner = createRunner({\n  auditDefaults: {\n    input: 'hash',\n    output: 'summary',\n    error: 'summary',\n    redactPaths: ['/password', '/token', '/secret'],\n  },\n  audit: createAuditHook(auditStore),\n});\n```\n\nActions can override runner defaults with `auditPolicy`:\n\n```ts\nrunner.registerAction({\n  name: 'admin.disableUser',\n  mode: 'mutate',\n  approvalRequired: true,\n  auditPolicy: {\n    input: 'hash',\n    output: 'summary',\n    error: 'summary',\n    redactPaths: ['/reason', '/profile/email'],\n  },\n  handler: async (input, ctx) => {\n    ctx.requireApproval();\n    return adminService.disableUser(input.userId, input.reason);\n  },\n});\n```\n\n`redactPaths` uses exact JSON Pointer paths, such as `/password`, `/profile/email`, or `/items/0/token`. Missing paths are ignored. Wildcards, globs, and regex paths are not currently supported.\n\nPayload modes:\n\n| Field | Modes |\n|---|---|\n| `input` | `full`, `redacted`, `hash`, `omit` |\n| `output` | `full`, `redacted`, `summary`, `hash`, `omit` |\n| `error` | `full`, `redacted`, `summary`, `omit` |\n\n`hash` stores `{ hash }` after redaction using `createStableHash()`. `output: 'summary'` stores only `outputSummary`. `error: 'summary'` stores `{ name, message }` and omits stack/cause fields.\n\nWhen no custom `summarizeOutput` hook is configured, `output: 'summary'` falls back to a safe shape summary such as `object`, `array(length=3)`, or `string`; it does not JSON-stringify the full output payload. If you keep `error: 'full'` while using `redactPaths`, `Error` objects may be cloned into serializable objects containing `name`, `message`, and `stack`. Production systems should prefer `error: 'summary'`.\n\n```ts\nimport { createAuditHook, createRunner, type AuditStore } from '@agent-action-runner/core';\n\nconst auditStore: AuditStore = {\n  async write(event) {\n    await persistentAuditStore.append({\n      executionId: event.executionId,\n      workflowId: event.workflowId,\n      stepId: event.stepId,\n      userId: event.userId,\n      actionName: event.actionName,\n      mode: event.mode,\n      status: event.status,\n      approvalTokenHash: event.approvalTokenHash,\n      createdAt: event.createdAt.toISOString(),\n    });\n  },\n};\n\nconst runner = createRunner({\n  audit: createAuditHook(auditStore),\n});\n```\n\nUse `summarizeOutput` when you want compact audit summaries instead of storing full output payloads.\n\n## Errors\n\nThe core package exports typed errors for common failure paths:\n\n- `ActionAlreadyRegisteredError`\n- `ActionNotFoundError`\n- `ActionTimeoutError`\n- `ModeNotAllowedError`\n- `PolicyRejectedError`\n- `ApprovalRequiredError`\n- `SchemaValidationError`\n- `InvalidStepReferenceError`\n- `DuplicateWorkflowStepError`\n- `InvalidAuditPolicyError`\n- `WorkflowExecutionError`\n- `WorkflowValidationError`\n\n## Public API\n\nCommon exports:\n\n- `createRunner`\n- `AgentActionRunner`\n- `fromStep`\n- `defineAction`\n- `defineActionCatalog`\n- `registerActionCatalog`\n- `defineWorkflow`\n- `validateWorkflowDefinition`\n- `createStableHash`\n- `createAuditHook`\n- `composePolicies`\n- `allowModes`\n- `requireRole`\n- `requireScope`\n- core types such as `ActionDefinition`, `ActionExample`, `ActionRiskLevel`, `AuditPayloadPolicy`, `AuditPayloadMode`, `WorkflowDefinition`, `ActionMode`, `AgentExecutionContext`, `ApprovalContext`, `AuditStore`\n\n## Examples\n\n- `examples/basic`\n- `examples/cli-basic`\n- `examples/delivery-ops`\n- `examples/express-admin-ops`\n- `examples/nestjs-admin-ops`\n- `examples/fastify-admin-ops`\n- `examples/persistent-admin-ops`\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}