{"_id":"@agent-beam/beam","_rev":"8-54fdf8493fd6ee00c228a8a820b7ffcc","name":"@agent-beam/beam","dist-tags":{"latest":"0.2.6"},"versions":{"0.1.0":{"name":"@agent-beam/beam","version":"0.1.0","license":"AGPL-3.0-only","_id":"@agent-beam/beam@0.1.0","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"bin":{"beam":"dist/cli.js"},"dist":{"shasum":"8047ae217d6ab597d21b1a78a2a913b88e4f213a","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.1.0.tgz","fileCount":66,"integrity":"sha512-A9aXzQfgkxMPbKUaf+YCA5vDhZWza6CmrqqykSbcyvn3dw+W7FRV2MHF2wXSiaOdzZ2AdxZB7XB739M6yfYM/w==","signatures":[{"sig":"MEUCIQDSzfsd5L7sUvHvZ1qMsP8HpGZKpUbeFBrlmCWUBxe8lAIgay5fePQEFEhIqi3ByqFNmpI/YeSH0mIIlXzZAkwijtw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":263100},"type":"module","engines":{"node":">=20.17.0"},"gitHead":"37807a91ba334845697f00a611c510e3677f78ae","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run typecheck && npm test && npm run build"},"_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"_npmVersion":"11.16.0","description":"Beam - local observation and heuristic risk scanning for AI agent activity","directories":{},"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.10.5"},"optionalDependencies":{"beam-enterprise":"^0.1.0"},"_npmOperationalInternal":{"tmp":"tmp/beam_0.1.0_1789030143335_0.18947527815924237","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agent-beam/beam","version":"0.2.0","license":"AGPL-3.0-only","_id":"@agent-beam/beam@0.2.0","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"bin":{"beam":"dist/cli.js"},"dist":{"shasum":"8b40bbde3401331b36a0f9ab58592dacb96ee376","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.2.0.tgz","fileCount":84,"integrity":"sha512-/G+wnknEp2pr21Iw1WVYPHBIdGZlAEQPGrTSlFdSBU1XLkd7KUyIwSdzYDeZEakbcZ7Inwcj3Alsy7mROct21w==","signatures":[{"sig":"MEQCIBAjf+4ZOZ/w061USMyK9d2OVny3MupQ4N0QrpcbKRKSAiB/JXRdluQZtMgtXN9yohrQ35io9aZs11Ny4ReNBJHFug==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCY5RwpJ4n/WzoUFVjlrAqmltxBVNlxFuGyogenn/WvrAIhAJiVjHwqG+uiqKefa2Qxh3UWQKGwYR5TbuFymtHi4yxj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":322748},"type":"module","engines":{"node":">=20.17.0"},"gitHead":"736434dc5caeb0157b2b88c860cfd3cf0264f62b","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run typecheck && npm test && npm run build"},"_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"_npmVersion":"11.16.0","description":"Beam - local observation and heuristic risk scanning for AI agent activity","directories":{},"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/beam_0.2.0_1789110493467_0.3087714054870718","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@agent-beam/beam","version":"0.2.1","license":"AGPL-3.0-only","_id":"@agent-beam/beam@0.2.1","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"bin":{"beam":"dist/cli.js"},"dist":{"shasum":"ff83f9668d311aa82cf8ca694381aa9cef08eaca","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.2.1.tgz","fileCount":87,"integrity":"sha512-QzHPwc0xDhJ6Ro+/NImXCSj6OWdF79ruQJ4IbVbrLJ05TS/X48tPLmPZYiLLw97K4RBP3AF8j7cBzgOjKwMuAQ==","signatures":[{"sig":"MEYCIQCk5/fpCm8Whf0zpgxY685HqxHdQx2JetbIbJL1xz0nlwIhANO2KSv1YNsRmOIKi8DHqUtNuIhiPdvyVqTgZdKbm2Bh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCsLMWeSR25a/TsY39ciAlFebIyWS8HPtgCnddwznFJYAIgXCC4arGhfuh3a/qLopagDgJAFmfUnQ2laxae5rJ9pns=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":337428},"type":"module","engines":{"node":">=20.17.0"},"gitHead":"93015e3aaffbf99c68b26f690783c855c2fc06c3","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run typecheck && npm test && npm run build"},"_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"_npmVersion":"11.16.0","description":"Beam - local observation and heuristic risk scanning for AI agent activity","directories":{},"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/beam_0.2.1_1789111317979_0.11982241932218507","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@agent-beam/beam","version":"0.2.2","license":"AGPL-3.0-only","_id":"@agent-beam/beam@0.2.2","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"bin":{"beam":"dist/cli.js"},"dist":{"shasum":"3b30abfa8b8749ff367a90b0b25addb0b307018f","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.2.2.tgz","fileCount":87,"integrity":"sha512-E2G8YNdHEzOL63JSUz1CuQ1ehYLs/8bjAJwTHrCB9kJFlM2Yg1OhFdmlDoOPs3rT0ZzArfQSO0Tp/TlXfoQkQg==","signatures":[{"sig":"MEUCIEDelOojB/+AH+7l9qvyFoLm/x6zHSFfJsZKJ1uSaZGfAiEAtwTV7jSwyxp8SxkkqOWhWdLbISb9Ptu7PTrAXgkW0nk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIGSCfBdeP5Jbl5r0JTCY3S5TehVAxaX8V/dH3iB86AGvAiEA/UO1v2qBWxfz90UwiRDRw8ZXuvKo8dLoSz79d66u21k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":337827},"type":"module","engines":{"node":">=20.17.0"},"gitHead":"ef262d3d1c4dd314ac600a644188461df49c9eeb","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run typecheck && npm test && npm run build"},"_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"_npmVersion":"11.16.0","description":"Beam - local observation and heuristic risk scanning for AI agent activity","directories":{},"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/beam_0.2.2_1789112524200_0.12829962068770495","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@agent-beam/beam","version":"0.2.3","license":"AGPL-3.0-only","_id":"@agent-beam/beam@0.2.3","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"bin":{"beam":"dist/cli.js"},"dist":{"shasum":"e9fd35300ae0459ce85067a512a376a513f42a26","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.2.3.tgz","fileCount":87,"integrity":"sha512-Unuq6psG4Lk2I+5AAmkWdP0wbdfcKSHHwJyRYq50GIHH1+TDydYWrup0PfnM324itCEUTZcmPXAXnBo4/zr8qQ==","signatures":[{"sig":"MEUCIQCa08p2C8SQBcviylAZKQaCaVAOUbZp2e4jaT4S1VUwhgIgJICzxDs8KxVGAP8kyEDpOsJJJgDPyZUg9ITlpMnWzps=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIBOlKqJuH1lM1WrwD5XIb3ycQZ3V3l039WzHVBZYv/fBAiEAmB/b5BiE8eRlfJoIT2TRfh3Qx8Sl3YFCzCco4ZgLMs8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":338258},"type":"module","engines":{"node":">=20.17.0"},"gitHead":"c078284a5ecf991dadad5ea5a3a786e7fab9e412","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run typecheck && npm test && npm run build"},"_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"_npmVersion":"11.16.0","description":"Beam - local observation and heuristic risk scanning for AI agent activity","directories":{},"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/beam_0.2.3_1789123008917_0.1323454890169613","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@agent-beam/beam","version":"0.2.4","keywords":["ai agent security","agent observability","claude code","claude code hooks","codex cli","cursor","mcp security","mcp scanner","model context protocol","prompt injection","llm security","secret redaction","risk scanning","heuristic detection","ai safety","cli"],"author":{"name":"Yash Thakker"},"license":"AGPL-3.0-only","_id":"@agent-beam/beam@0.2.4","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"homepage":"https://agentbeam.com","bugs":{"url":"https://github.com/whyashthakker/beam-cli/issues"},"bin":{"beam":"dist/cli.js"},"dist":{"shasum":"9fd3bd9428b044318dd03a5e2dacfa1545b31419","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.2.4.tgz","fileCount":144,"integrity":"sha512-uWMbPbSWVG79kcB+lcN+caA86UKDk9yryL/eZKNODqfF8BxuXgFw1T0uOmExxxcqHEwyPOwV0rqh2psVkOb8Ww==","signatures":[{"sig":"MEQCIDs7v1UplWUBrEAvTQZ64rYFCYZNP4gsAJIKsrN6jrxjAiABoFbbrAqXtKdE8Dz06GOyAiQPjMWiu0eJ3TyWdxBvqw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAdyomsVQ56s7bUwGThAOmgorCY1mI5jTwRP2zP2TkCYAiEAmJOKm4Eww/KLeNqbLatY9d4wQ96XVqouDsxEua1CBak=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":661246},"type":"module","engines":{"node":">=20.17.0"},"gitHead":"56c709e5285d5dc073e365d4fe78b078aa241795","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run validate:skills && npm run typecheck && npm test && npm run build","validate:skills":"node Skills/scripts/validate-skills.mjs"},"_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"repository":{"url":"git+https://github.com/whyashthakker/beam-cli.git","type":"git"},"_npmVersion":"11.16.0","description":"Local-first observation and heuristic risk scanning for AI coding agents (Claude Code, Codex, Cursor, Copilot CLI, Gemini). Redacts secrets, flags risky tool calls, scans skills and MCP configs offline.","directories":{},"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/beam_0.2.4_1789450823356_0.3823098941838705","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"name":"@agent-beam/beam","version":"0.2.5","keywords":["ai agent security","agent observability","claude code","claude code hooks","codex cli","cursor","mcp security","mcp scanner","model context protocol","prompt injection","llm security","secret redaction","risk scanning","heuristic detection","ai safety","cli"],"author":{"name":"Yash Thakker"},"license":"AGPL-3.0-only","_id":"@agent-beam/beam@0.2.5","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"homepage":"https://agentbeam.com","bugs":{"url":"https://github.com/whyashthakker/beam-cli/issues"},"bin":{"beam":"dist/cli.js"},"dist":{"shasum":"0eac0958c654331346af4b6d00d4450e2ee5a799","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.2.5.tgz","fileCount":156,"integrity":"sha512-gxnxb3OHCMORNXkibXqMJjgpzC76JuBvgCibvLXTB2VjlgQOLE4aiWTyEYZDGkC40IQ0vLNaDmh+IqnMHGc2Hw==","signatures":[{"sig":"MEUCICprLi9B1UcwSi1DQx3y+jWiVqyTidpQAcs2k9g8uXx4AiEAxNNhalXxCaOyYpozOLPBWluKOt1pCRoW835N2eFGuRk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIDpv+Kr8S5MAq/u4d4fc72ELc1R7mhnfow0AqfaqbOSWAiA6lTqGpb4aXxoRzLcyli5pDvxAEFdN7T9uzG5+6KwkVg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":699458},"type":"module","engines":{"node":">=20.17.0"},"gitHead":"1c070588b790d4d4a8f20219ae85e26a6c0f645f","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run validate:skills && npm run typecheck && npm test && npm run build","validate:skills":"node Skills/scripts/validate-skills.mjs"},"_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"repository":{"url":"git+https://github.com/whyashthakker/beam-cli.git","type":"git"},"_npmVersion":"11.16.0","description":"Local-first observation and heuristic risk scanning for AI coding agents (Claude Code, Codex, Cursor, Copilot CLI, Gemini). Redacts secrets, flags risky tool calls, scans skills and MCP configs offline.","directories":{},"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.20.2"},"_npmOperationalInternal":{"tmp":"tmp/beam_0.2.5_1789457506632_0.6943525697212629","host":"s3://npm-registry-packages-npm-production"}},"0.2.6":{"_id":"@agent-beam/beam@0.2.6","bin":{"beam":"dist/cli.js"},"bugs":{"url":"https://github.com/whyashthakker/beam-cli/issues"},"dist":{"shasum":"2a06221a4b4588e614a2014728b45b3700332318","tarball":"https://registry.npmjs.org/@agent-beam/beam/-/beam-0.2.6.tgz","fileCount":156,"integrity":"sha512-vLaxU2vLz5uBR+nDeerhxHscqWcoa//Jzo+hRSZfEUKngH8xDwYzBG+Vre6j5ZxshPGcrYBY5SKQOJQ1yhAWQA==","signatures":[{"sig":"MEYCIQCu5ZC0IvIvawj6yFa5DK9fJEzLSpRsEnqn83Zgt7zEdAIhAM3/CY7jW8baxFG1xt/rXibswlTdEAlIn+tHJ6xuQRyu","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICRZIFU8KlpPuGlwYimS3ILNQHFByeo/W0V+2OfGT5KfAiEA1fVAYxBe3o/pwQUVTkt5a4n64vVisK0K8py6qCZAuVI="}],"unpackedSize":707977},"name":"@agent-beam/beam","type":"module","author":{"name":"Yash Thakker"},"engines":{"node":">=20.17.0"},"gitHead":"1cccb49981acc278e4b45ac6fb6e66bb5eb35565","license":"AGPL-3.0-only","scripts":{"dev":"tsx src/cli.ts","test":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --runInBand","build":"tsc -p tsconfig.json && chmod +x dist/cli.js","setup":"npm run build && node dist/cli.js setup","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"node --no-warnings --experimental-vm-modules node_modules/jest/bin/jest.js --watch","build:watch":"tsc -p tsconfig.json --watch --preserveWatchOutput","setup:global":"bash scripts/setup-global.sh","prepublishOnly":"npm run validate:skills && npm run typecheck && npm test && npm run build","validate:skills":"node Skills/scripts/validate-skills.mjs"},"version":"0.2.6","_npmUser":{"name":"rahulsan008","email":"rahul@explainx.ai"},"homepage":"https://agentbeam.com","keywords":["ai agent security","agent observability","claude code","claude code hooks","codex cli","cursor","mcp security","mcp scanner","model context protocol","prompt injection","llm security","secret redaction","risk scanning","heuristic detection","ai safety","cli"],"repository":{"url":"git+https://github.com/whyashthakker/beam-cli.git","type":"git"},"_npmVersion":"11.16.0","description":"Local-first observation and heuristic risk scanning for AI coding agents (Claude Code, Codex, Cursor, Copilot CLI, Gemini). Redacts secrets, flags risky tool calls, scans skills and MCP configs offline.","directories":{},"maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"_nodeVersion":"24.18.1","dependencies":{"commander":"^13.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","ts-jest":"^29.4.5","typescript":"^5.7.2","@types/jest":"^30.0.0","@types/node":"^22.20.2"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/beam_0.2.6_1789534634728_0.1659706762517903"}}},"time":{"created":"2026-09-10T08:49:03.077Z","modified":"2026-09-16T04:57:14.982Z","0.1.0":"2026-09-10T08:49:03.482Z","0.2.0":"2026-09-11T07:08:13.575Z","0.2.1":"2026-09-11T07:21:58.093Z","0.2.2":"2026-09-11T07:42:04.282Z","0.2.3":"2026-09-11T10:36:48.998Z","0.2.4":"2026-09-15T05:40:23.471Z","0.2.5":"2026-09-15T07:31:46.742Z","0.2.6":"2026-09-16T04:57:14.812Z"},"bugs":{"url":"https://github.com/whyashthakker/beam-cli/issues"},"author":{"name":"Yash Thakker"},"license":"AGPL-3.0-only","homepage":"https://agentbeam.com","keywords":["ai agent security","agent observability","claude code","claude code hooks","codex cli","cursor","mcp security","mcp scanner","model context protocol","prompt injection","llm security","secret redaction","risk scanning","heuristic detection","ai safety","cli"],"repository":{"url":"git+https://github.com/whyashthakker/beam-cli.git","type":"git"},"description":"Local-first observation and heuristic risk scanning for AI coding agents (Claude Code, Codex, Cursor, Copilot CLI, Gemini). Redacts secrets, flags risky tool calls, scans skills and MCP configs offline.","maintainers":[{"name":"rahulsan008","email":"rahul@explainx.ai"},{"name":"ganesh-aisolo","email":"ganesh.mohane@explainx.ai"},{"name":"goyashy","email":"NYNANSNH@GMAIL.COM"}],"readme":"# Beam\n\nLocal observation and heuristic risk scanning for AI agent activity. Beam runs entirely on your machine: a loopback-only HTTP collector stores normalized events and scan reports in NDJSON files under `~/.beam`, and the `beam` CLI talks to it (or scans files completely offline).\n\nBeam does not execute, block, or approve anything an agent does. It observes, redacts secrets before persisting, and flags risky patterns for human review.\n\n## Install\n\n```bash\nnpm run setup:global\n```\n\nThis installs dependencies, builds, `npm link`s the `beam` binary globally, and starts a background watcher so the global command always reflects the current source — no manual rebuild needed after edits.\n\n## Security skills\n\nThe [Skills collection](Skills/README.md) contains 30 focused security workflows for AI agents, skills, MCP servers, models, application boundaries, secrets, dependencies, deployment, monitoring, and incident response. It includes [seven specialist reviewer roles](Skills/agents/README.md) in both Claude Code and Codex formats. The collection ships in the npm package and works with or without the Beam CLI; review and install only the skills and profiles relevant to your task.\n\n[Beam's setup guide](https://agentbeam.com/blog/beam-security-skills-and-subagents) explains installation and delegation. For advanced monitoring and control, or further self-hosting and ongoing monitoring guidance, visit [agentbeam.com](https://agentbeam.com).\n\n## Commands\n\n```bash\nbeam start                          # start the local collector (binds 127.0.0.1:4319)\nbeam start --port 4400              # use a different port\n\nbeam studio                         # open the activity dashboard in your browser\n\nbeam token                          # print the collector's pairing token\n\nbeam import events.ndjson           # send normalized events to /ingest\nbeam scan SKILL.md                  # scan offline for risky instructions\nbeam scan mcp.json --mcp            # scan an MCP config (checks version pinning)\nbeam scan SKILL.md --save           # also persist the report to the collector\n\nbeam hook claude-code < payload.json # forward a hook payload for the given agent (stdin)\n\nbeam agent list                     # supported agents and payload verification status\nbeam agent install cursor           # wire beam's hook into that agent's own config, non-destructively\nbeam agent install-all              # detect every agent actually installed on this machine and wire them all\n\nbeam rule list                      # the active rule catalog (built-in + custom + sequence), grouped by category\nbeam rule reload                    # apply edits to ~/.beam/rules.json into the running collector, no restart\n\nbeam service install                # run the collector as a background service (starts on login)\nbeam service status                 # is it installed / running\nbeam service stop                   # stop it\nbeam service start                  # start it again\nbeam service uninstall              # remove it\nbeam service logs                   # where its log files are (or the command to follow them)\n```\n\n`scan` runs entirely offline unless `--save` is passed — no collector required. `hook` never throws or blocks the calling agent; capture failures are logged to stderr only. This mirrors Beam's core rule: **observation must never become enforcement.**\n\n## Studio (activity dashboard)\n\n`beam start` or `beam service install` also serves a dashboard at `GET /` and `GET /studio` on the collector itself — no separate app, no build step, no dependency added to the package (plain HTML/CSS/JS, no fonts or CDNs). `beam studio` opens it in your default browser for you.\n\n- **Activity** — every captured event, searchable and filterable by agent/risk, with a detail drawer per action.\n- **Findings** — the subset with heuristic matches, with a per-event \"mark reviewed\" (a record of your assessment, never an approval or block).\n- **Skill & MCP scan** — paste or check a file's content and see findings live, same engine as `beam scan`.\n\nThe page itself carries no secret and needs no auth to load — only the API calls it makes do. `beam studio` reads the pairing token from disk and passes it once via a URL that's immediately scrubbed from the address bar (`history.replaceState`) after the page reads it. From there it's saved in that browser's `localStorage` (scoped to the collector's own origin, `127.0.0.1:4319` — no other site or app can read it), so reloading the tab or closing and reopening the browser stays connected without re-pairing. If the collector ever rejects the stored token (e.g. `beam service uninstall && beam service install` generates a new one), the page detects that and clears it automatically rather than looping silently. Use the **Disconnect** button to clear it yourself.\n\nSessions and Usage views from the original Sentinel console aren't ported yet — Activity/Findings/Scan cover the core loop first.\n\n## Multi-agent coverage\n\nDifferent agents send different JSON shapes to their hooks. `beam hook <agent>` picks the right adapter for the agent id you pass, and `beam agent install <agent>` writes beam's hook into that agent's real config file in its own native format, merging with (never overwriting) whatever hooks are already there.\n\n`npm run setup:global` runs `beam agent install-all` automatically at the end, so every agent it can detect on your machine gets wired without you having to know which ones you have installed. Detection uses each agent's own real, pre-existing files (e.g. `~/.codex/config.toml`, `~/.copilot/config.json`) — never a file beam itself writes — so an agent that was never actually installed won't get a hook, and one that's already wired won't get a duplicate entry on a second run.\n\n| Agent id | Config file `agent install` writes | Payload |\n|---|---|---|\n| `claude-code` | `~/.claude/settings.json` (`hooks.PreToolUse`) | Verified against Claude Code's docs |\n| `codex` | `~/.codex/hooks.json` (`hooks.PreToolUse`) | Same shape as Claude Code; verified |\n| `cursor` | `~/.cursor/hooks.json` (`hooks.preToolUse`) | Verified against Cursor's docs |\n| `copilot-cli` | `~/.copilot/hooks/beam.json` (`hooks.preToolUse`) | Verified (camelCase — translated internally) |\n| `gemini` | `~/.gemini/settings.json` (`hooks.BeforeTool`) | **Not verified** — Gemini CLI's stdin schema isn't published; capture uses a generic best-effort field adapter |\n| `opencode` | not built yet | discovery (config/artifact presence) only — OpenCode uses a generated TS plugin, not a JSON hook file |\n\nRun `beam agent list` for the current status of each. Adding a new agent means one entry in `src/agents.ts` (config path + how to merge the hook block) and, if its stdin payload uses different field names than `tool_name`/`tool_input`/`session_id`/`cwd`/`hook_event_name`, one adapter function in `src/hook-adapters.ts`.\n\nThis is an intentionally small first slice of what a full multi-agent observer could cover. Wider agent coverage, enforcement/blocking, and portable case bundles aren't built yet — tracked as future slices, not silently unsupported.\n\n## Forensic extraction (no hook required)\n\n`beam agent extract <agent>` reads an agent's own existing session/transcript files directly — no hook needed, and it works for history from *before* Beam was ever installed:\n\n```bash\nbeam agent extract claude-code              # preview: normalizes locally, prints JSON, nothing sent anywhere\nbeam agent extract claude-code --limit 20   # cap how many events the preview prints (default 200)\nbeam agent extract claude-code --save       # import into the running collector (dedupes by event_id)\nbeam agent extract codex --save\n```\n\nSupported today: **`claude-code`** (`~/.claude/projects/**/*.jsonl` — reads `tool_use` blocks out of assistant turns) and **`codex`** (`~/.codex/{sessions,archived_sessions}/**/*.jsonl` — reads `function_call` and `custom_tool_call` response items). Every extracted event gets `source: \"extract\"` and `phase: \"observed\"` so it's visibly distinct from a live hook capture (which is `\"proposed\"`/`\"completed hook\"`). Preview mode normalizes (and therefore redacts) locally without ever contacting the collector; `--save` sends the raw records through the same `/ingest` pipeline a live hook uses, batched under the collector's 2,000-record-per-request cap. Bounded like everything else in Beam: 50 MB max per transcript file, 20,000 parsed lines per file, 2,000 files walked per run.\n\nOther agents aren't wired yet — `beam agent extract <agent>` fails clearly rather than silently returning nothing for one that isn't supported.\n\n## Rule engine\n\nDetection has three layers now, all active in both `beam scan` (offline) and the running collector:\n\n- **Categorized built-in rules** — every rule has a `category` (`exec`, `exfil`, `impact`, `integrity`, `persistence`, `privilege`, `recon`, `secrets`, `source_control`), not just a flat id. `beam rule list` shows the full catalog grouped by category.\n- **Custom rules from `~/.beam/rules.json`** — extend detection without touching Beam's source. A JSON array of `{ id, pattern, severity, title?, explanation?, category? }`; `pattern` is a regex (case-insensitive). Loaded once at collector startup; a malformed entry is skipped and reported (`beam rule list` / `beam start`'s output shows why), never crashes the rest of detection.\n\n  ```json\n  [\n    { \"id\": \"internal_host\", \"pattern\": \"wiki\\\\.internal\\\\.corp\", \"severity\": \"high\", \"category\": \"exfil\", \"title\": \"Internal wiki referenced\" }\n  ]\n  ```\n\n  `beam rule reload` applies edits to the running collector immediately, no restart needed.\n- **Cross-event sequence rules** — some risk only shows up as a *pattern of actions*, not one action in isolation: a credential read followed by network activity later in the same session, or a network scan followed by remote code execution, even across separate, unrelated-looking tool calls that a single-event regex could never connect. Beam re-evaluates a session's recent events (last 50) whenever new events land, and attaches one composite finding to the event that completes the pattern — idempotently, so re-ingesting the same history never duplicates it.\n\nAll three feed the same `Finding[]` shape everywhere — Studio, `/export`, `/state` — so there's nothing separate to look at.\n\n## Running as a background service\n\n`beam start` in a terminal works, but closing that terminal stops the collector. `beam service install` instead registers it as a real background service:\n\n- **macOS**: a `launchd` user agent at `~/Library/LaunchAgents/ai.beam.collector.plist` (`RunAtLoad` + `KeepAlive`, so it starts on login and restarts if it crashes).\n- **Linux**: a `systemd --user` unit at `~/.config/systemd/user/beam.service` (`enable --now`, `Restart=always`).\n\nBoth embed the resolved `BEAM_DATA_DIR` directly into the service definition (launchd/systemd don't inherit your shell's environment), so `BEAM_DATA_DIR=/custom/path beam service install` keeps using that path even after a reboot. Logs go to `$BEAM_DATA_DIR/logs/`.\n\nThis is a userspace HTTP server, same as running `beam start` yourself — not kernel-level capture. Beam has nothing to observe at the kernel level: the actual signal comes from agents calling `beam hook <agent>` at the moment they're about to act, the same way whether run in a terminal or as a background service.\n\nWindows isn't supported yet (`beam service *` will say so and tell you to run `beam start` directly).\n\n## Configuration\n\n- `BEAM_HOME` — root config directory (default `~/.beam`).\n- `BEAM_DATA_DIR` — where events/scans/token are stored (default `$BEAM_HOME/data`).\n- `BEAM_TOKEN` — pairing token (skips reading the token file).\n- `BEAM_COLLECTOR_URL` — collector origin the CLI talks to (default `http://127.0.0.1:4319`); must stay on HTTP loopback.\n- `BEAM_PORT` — port `beam start` binds to (default `4319`).\n- `BEAM_ALLOWED_ORIGINS` — comma-separated browser origins allowed to call the collector (for a future local UI).\n\n## Connect a Claude Code hook\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [{\n      \"matcher\": \"\",\n      \"hooks\": [{\n        \"type\": \"command\",\n        \"command\": \"beam hook claude-code\"\n      }]\n    }]\n  }\n}\n```\n\nChoose `PreToolUse` to observe proposed actions before they run. `beam` must be on the agent's PATH (or use its absolute path).\n\n## API\n\nAll routes require `Authorization: Bearer <token>` and are bound to loopback only.\n\n- `GET /health` — collector version and retention.\n- `GET /state` — retained events, scans, reviews, rule catalog.\n- `GET /agents` — existence checks on common agent config/artifact locations, hook-install/payload-verification status; no contents are read.\n- `POST /ingest` — one normalized JSON object, JSON array, or NDJSON (up to 2 MB / 2,000 records; 100 KB per record).\n- `POST /v1/logs` — OTLP/HTTP **JSON** (not protobuf).\n- `POST /scan` — `{ \"name\": \"SKILL.md\", \"kind\": \"skill\", \"content\": \"...\" }` (or `kind: \"mcp\"`; max 500 KB).\n- `POST /review` — `{ \"id\": \"...\", \"reviewed\": true }`.\n- `POST /rules/reload` — reload `~/.beam/rules.json` into this running process; returns `{ path, loaded, errors }`.\n- `GET /export` — redacted event NDJSON.\n\n## Limits and guarantees\n\n- Retention: latest 10,000 events and 500 scan reports. Each accepted batch atomically replaces the bounded event file.\n- Known credential formats, assignments, auth headers, URL query strings, and private keys are redacted before persistence. Other sensitive text may remain; inspect exports before sharing.\n- Data directory mode `0700`, files `0600`. Token is generated once per data directory and reused across restarts.\n- The heuristic scanner is pattern matching, not semantic malware analysis or a safety guarantee. Findings require human review.\n\n## Development\n\n```bash\nnpm test\nnpm run typecheck\nnpm run build\n```\n\n## Related\n\n- [beam-mcp](https://github.com/whyashthakker/beam-mcp) — an MCP server exposing this CLI's scanning to MCP-compatible hosts. Open source.\n\n## License\n\nAGPL-3.0-only — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}