{"_id":"@apilium/mayros-lobster","name":"@apilium/mayros-lobster","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.1":{"name":"@apilium/mayros-lobster","version":"0.1.1","description":"Lobster workflow tool plugin (typed pipelines + resumable approvals)","license":"MIT","type":"module","publishConfig":{"access":"public"},"dependencies":{"@sinclair/typebox":"^0.34.0"},"peerDependencies":{"@apilium/mayros":">=0.1.0"},"mayros":{"extensions":["./index.ts"]},"_id":"@apilium/mayros-lobster@0.1.1","_integrity":"sha512-6MOP8tr0AkBIDr6Y7LNf714K/K9ROX9090Ara7g1WaK4lMetacNVQHBTchbJYw5Nd7I4qb/s9ZsP6eT321Xu2w==","_resolved":"/private/var/folders/_y/k11qcrj94k32_yl6486p9bsc0000gn/T/cbf685c303d7cc64cbdd649cc1351ea8/apilium-mayros-lobster-0.1.1.tgz","_from":"file:apilium-mayros-lobster-0.1.1.tgz","_nodeVersion":"24.8.0","_npmVersion":"11.6.0","dist":{"integrity":"sha512-6MOP8tr0AkBIDr6Y7LNf714K/K9ROX9090Ara7g1WaK4lMetacNVQHBTchbJYw5Nd7I4qb/s9ZsP6eT321Xu2w==","shasum":"dca59c060726cf79e1daf7b27f9b358b6b9a036d","tarball":"https://registry.npmjs.org/@apilium/mayros-lobster/-/mayros-lobster-0.1.1.tgz","fileCount":10,"unpackedSize":36247,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCVWMfzMecfYVSBCo4BUjMSMc+LWFZA0k8Mr/3O/xzyPgIgJrm5lPhABwHkMHopI8GL4RyaqLWN6nkhS9f4pt3beWU="}]},"_npmUser":{"name":"apilium-ai","email":"it@apilium.com"},"directories":{},"maintainers":[{"name":"apilium-ai","email":"it@apilium.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mayros-lobster_0.1.1_1772217439297_0.10806986667075691"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-27T18:37:19.175Z","0.1.1":"2026-02-27T18:37:19.451Z","modified":"2026-02-27T18:37:19.720Z"},"maintainers":[{"name":"apilium-ai","email":"it@apilium.com"}],"description":"Lobster workflow tool plugin (typed pipelines + resumable approvals)","license":"MIT","readme":"# Lobster (plugin)\n\nAdds the `lobster` agent tool as an **optional** plugin tool.\n\n## What this is\n\n- Lobster is a standalone workflow shell (typed JSON-first pipelines + approvals/resume).\n- This plugin integrates Lobster with Mayros _without core changes_.\n\n## Enable\n\nBecause this tool can trigger side effects (via workflows), it is registered with `optional: true`.\n\nEnable it in an agent allowlist:\n\n```json\n{\n  \"agents\": {\n    \"list\": [\n      {\n        \"id\": \"main\",\n        \"tools\": {\n          \"allow\": [\n            \"lobster\" // plugin id (enables all tools from this plugin)\n          ]\n        }\n      }\n    ]\n  }\n}\n```\n\n## Using `mayros.invoke` (Lobster → Mayros tools)\n\nSome Lobster pipelines may include a `mayros.invoke` step to call back into Mayros tools/plugins (for example: `gog` for Google Workspace, `gh` for GitHub, `message.send`, etc.).\n\nFor this to work, the Mayros Gateway must expose the tool bridge endpoint and the target tool must be allowed by policy:\n\n- Mayros provides an HTTP endpoint: `POST /tools/invoke`.\n- The request is gated by **gateway auth** (e.g. `Authorization: Bearer …` when token auth is enabled).\n- The invoked tool is gated by **tool policy** (global + per-agent + provider + group policy). If the tool is not allowed, Mayros returns `404 Tool not available`.\n\n### Allowlisting recommended\n\nTo avoid letting workflows call arbitrary tools, set a tight allowlist on the agent that will be used by `mayros.invoke`.\n\nExample (allow only a small set of tools):\n\n```jsonc\n{\n  \"agents\": {\n    \"list\": [\n      {\n        \"id\": \"main\",\n        \"tools\": {\n          \"allow\": [\"lobster\", \"web_fetch\", \"web_search\", \"gog\", \"gh\"],\n          \"deny\": [\"gateway\"],\n        },\n      },\n    ],\n  },\n}\n```\n\nNotes:\n\n- If `tools.allow` is omitted or empty, it behaves like \"allow everything (except denied)\". For a real allowlist, set a **non-empty** `allow`.\n- Tool names depend on which plugins you have installed/enabled.\n\n## Security\n\n- Runs the `lobster` executable as a local subprocess.\n- Does not manage OAuth/tokens.\n- Uses timeouts, stdout caps, and strict JSON envelope parsing.\n- Ensure `lobster` is available on `PATH` for the gateway process.\n","readmeFilename":"README.md","_rev":"1-b7faa9de96ce0291eb9bf399f140fba5"}