{"_id":"@arijitkb22/snayu","_rev":"3-660bbcc542e16c6ecb0a31dda3be9eea","name":"@arijitkb22/snayu","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@arijitkb22/snayu","version":"1.0.0","keywords":["mcp","ai-agents","copilot","claude","cursor","connector","llm","tools"],"author":{"name":"Arijit Bera"},"license":"MIT","_id":"@arijitkb22/snayu@1.0.0","maintainers":[{"name":"arijitkb22","email":"arijitkumarbera22@gmail.com"}],"homepage":"https://github.com/arijitkb22/snayu#readme","bugs":{"url":"https://github.com/arijitkb22/snayu/issues"},"bin":{"snayu":"src/index.js"},"dist":{"shasum":"11104ff03ef53471c25bd3d3eaf4c07293673938","tarball":"https://registry.npmjs.org/@arijitkb22/snayu/-/snayu-1.0.0.tgz","fileCount":48,"integrity":"sha512-IWeHs3FMASX+SPs0MPCuZHLNzOpo+r228JddNQTlo9hse+HhhC1ckcm4solJKlrfpSXNC9qAQpfQEh4BbPI69A==","signatures":[{"sig":"MEYCIQDvbfH12ZgdLVRXlSH61f/3ohprnYNfhb+CZ2y9KsTHmQIhAOsOXCVz5bU806AUdRbs+HmT9raaoYJUcqlJni6Ykc4A","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":508943},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"a4fa8ddb1a4022be5fc6f7906cb041e808b66fd1","scripts":{"ui":"node src/web/server.js","dev":"node --watch src/index.js","mcp":"node src/mcp/server.js","start":"node src/index.js","prepublishOnly":"node -e \"console.log('✅ Ready to publish snayu')\""},"_npmUser":{"name":"arijitkb22","email":"arijitkumarbera22@gmail.com"},"repository":{"url":"git+https://github.com/arijitkb22/snayu.git","type":"git"},"_npmVersion":"11.6.2","description":"Snayu (স্নায়ু) — the nervous system for your AI agents. Connect once, use everywhere. A single MCP server that bridges all your services to all your AI agents.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"zod":"^3.0.0","open":"^10.0.0","express":"^4.18.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"optionalDependencies":{"pg":"^8.0.0","@aws-sdk/client-s3":"^3.0.0","@aws-sdk/lib-dynamodb":"^3.0.0","@elastic/elasticsearch":"^8.0.0","@aws-sdk/client-dynamodb":"^3.0.0","@aws-sdk/client-cloudwatch":"^3.1045.0","@aws-sdk/credential-providers":"^3.0.0","@aws-sdk/client-cloudwatch-logs":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/snayu_1.0.0_1778498347758_0.7048368702912695","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@arijitkb22/snayu","version":"1.0.1","keywords":["mcp","ai-agents","copilot","claude","cursor","connector","llm","tools"],"author":{"name":"Arijit Bera"},"license":"MIT","_id":"@arijitkb22/snayu@1.0.1","maintainers":[{"name":"arijitkb22","email":"arijitkumarbera22@gmail.com"}],"homepage":"https://github.com/arijitkb22/snayu#readme","bugs":{"url":"https://github.com/arijitkb22/snayu/issues"},"bin":{"snayu":"src/index.js"},"dist":{"shasum":"579ce41eff9e23f79f17f29011640d82413ce3d7","tarball":"https://registry.npmjs.org/@arijitkb22/snayu/-/snayu-1.0.1.tgz","fileCount":48,"integrity":"sha512-UPs2GnVzquTsguyP0OlqVs9U6k3O9tXdfbAn8qSUrbX6WQHTUWk508SCbruu1nfs+RYO9fYYgw7cG7/iFxBjdA==","signatures":[{"sig":"MEYCIQD8oNc+GmbqN1u7fAjOEBUEZwNXPZm7LA5iH2BtIA1P7QIhANgj38WqK2adE6/EO+cAYemUKZLC2HPfSJCZIkmDf696","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":522221},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"28b054358e8e05fbef3ec2ba1b51f5c327f4da54","scripts":{"ui":"node src/web/server.js","dev":"node --watch src/index.js","mcp":"node src/mcp/server.js","start":"node src/index.js","prepublishOnly":"node -e \"console.log('✅ Ready to publish snayu')\""},"_npmUser":{"name":"arijitkb22","email":"arijitkumarbera22@gmail.com"},"repository":{"url":"git+https://github.com/arijitkb22/snayu.git","type":"git"},"_npmVersion":"11.6.2","description":"Snayu (স্নায়ু) — the nervous system for your AI agents. Connect once, use everywhere. A single MCP server that bridges all your services to all your AI agents.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"zod":"^3.0.0","open":"^10.0.0","express":"^4.18.0","@modelcontextprotocol/sdk":"^1.0.0"},"_hasShrinkwrap":false,"optionalDependencies":{"pg":"^8.0.0","@aws-sdk/client-s3":"^3.0.0","@aws-sdk/lib-dynamodb":"^3.0.0","@elastic/elasticsearch":"^8.0.0","@aws-sdk/client-dynamodb":"^3.0.0","@aws-sdk/client-cloudwatch":"^3.1045.0","@aws-sdk/credential-providers":"^3.0.0","@aws-sdk/client-cloudwatch-logs":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/snayu_1.0.1_1778501422136_0.1586806972301249","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@arijitkb22/snayu","version":"1.0.2","description":"Snayu (স্নায়ু) — the nervous system for your AI agents. Connect once, use everywhere. A single MCP server that bridges all your services to all your AI agents.","type":"module","main":"src/index.js","bin":{"snayu":"src/index.js"},"keywords":["mcp","ai-agents","copilot","claude","cursor","connector","llm","tools"],"author":{"name":"Arijit Bera"},"license":"AGPL-3.0","homepage":"https://github.com/arijitkb22/snayu#readme","repository":{"type":"git","url":"git+https://github.com/arijitkb22/snayu.git"},"bugs":{"url":"https://github.com/arijitkb22/snayu/issues"},"engines":{"node":">=18.0.0"},"scripts":{"start":"node src/index.js","mcp":"node src/mcp/server.js","ui":"node src/web/server.js","dev":"node --watch src/index.js","prepublishOnly":"node -e \"console.log('✅ Ready to publish snayu')\""},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","express":"^4.18.0","open":"^10.0.0","zod":"^3.0.0"},"optionalDependencies":{"@aws-sdk/client-cloudwatch":"^3.1045.0","@aws-sdk/client-cloudwatch-logs":"^3.0.0","@aws-sdk/client-dynamodb":"^3.0.0","@aws-sdk/client-ec2":"^3.0.0","@aws-sdk/client-ecs":"^3.0.0","@aws-sdk/client-eks":"^3.0.0","@aws-sdk/client-iam":"^3.0.0","@aws-sdk/client-lambda":"^3.0.0","@aws-sdk/client-rds":"^3.0.0","@aws-sdk/client-route-53":"^3.0.0","@aws-sdk/client-s3":"^3.0.0","@aws-sdk/client-sns":"^3.0.0","@aws-sdk/credential-providers":"^3.0.0","@aws-sdk/lib-dynamodb":"^3.0.0","@elastic/elasticsearch":"^8.0.0","pg":"^8.0.0"},"gitHead":"51343785eff9623faeba29c3d7a512f64c772e3b","_id":"@arijitkb22/snayu@1.0.2","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-LMO3hC6vX0DhyBSfaAypHRdI+y7hBSUWopsR2oD9lGuUO9RvYLlWgSiJ5F1T1zlj21IzKshCnFAsA/ex5kOS9A==","shasum":"2c8bd695d5654cf86955320f3a60e3b084e4d6bc","tarball":"https://registry.npmjs.org/@arijitkb22/snayu/-/snayu-1.0.2.tgz","fileCount":72,"unpackedSize":796097,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC6sjlSUdduOQ/c1KgxKLQvoj6ajwbFcD04mnoy8Fk4xAIhALDw8wzcuKhMrATpg7GMSZgLduzMoXb78vEI5xN/LJ8G"}]},"_npmUser":{"name":"arijitkb22","email":"arijitkumarbera22@gmail.com"},"directories":{},"maintainers":[{"name":"arijitkb22","email":"arijitkumarbera22@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/snayu_1.0.2_1778866575444_0.9085311390204622"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-11T11:19:07.595Z","modified":"2026-05-15T17:36:15.793Z","1.0.0":"2026-05-11T11:19:07.887Z","1.0.1":"2026-05-11T12:10:22.344Z","1.0.2":"2026-05-15T17:36:15.696Z"},"bugs":{"url":"https://github.com/arijitkb22/snayu/issues"},"author":{"name":"Arijit Bera"},"license":"AGPL-3.0","homepage":"https://github.com/arijitkb22/snayu#readme","keywords":["mcp","ai-agents","copilot","claude","cursor","connector","llm","tools"],"repository":{"type":"git","url":"git+https://github.com/arijitkb22/snayu.git"},"description":"Snayu (স্নায়ু) — the nervous system for your AI agents. Connect once, use everywhere. A single MCP server that bridges all your services to all your AI agents.","maintainers":[{"name":"arijitkb22","email":"arijitkumarbera22@gmail.com"}],"readme":"# ⚡ Snayu (স্নায়ু) — AI Agent Platform\n\n> **The nervous system for your AI agents.** Connect your services once, build agents that think, and run them from any IDE.\n\n---\n\n## What Is Snayu?\n\nSnayu is a **Model Context Protocol (MCP) server** that gives AI agents (GitHub Copilot, Claude, Cursor, Windsurf) real-time access to your infrastructure — databases, cloud services, APIs, and more.\n\nBut it's more than a connector. Snayu includes a **no-code agent builder** with 16 pre-built agents that follow structured investigation protocols, ask clarifying questions before acting, and deliver results to your team.\n\n---\n\n## Quick Start\n\n### 1. Install\n\n```bash\n# From npm (fastest)\nnpm install @arijitkb22/snayu\n\n# Or clone the repo\ngit clone https://github.com/arijitkb22/snayu.git\ncd snayu\nnpm install\n```\n\n### 2. Start the Web Dashboard\n\n```bash\nnpm start\n```\n\nOpens at **http://localhost:3456** — configure connections, install agents, manage everything.\n\n### 3. Connect to Your IDE\n\nAdd to your project's `.vscode/mcp.json` (update the path to where you cloned snayu):\n\n```json\n{\n  \"servers\": {\n    \"snayu\": {\n      \"type\": \"stdio\",\n      \"command\": \"node\",\n      \"args\": [\"/path/to/snayu/src/mcp/server.js\"]\n    }\n  }\n}\n```\n\nOpen Copilot Chat → **Agent mode** → all your services + agents are available!\n\n---\n\n## 🎯 Using Snayu Agents\n\n### The `snayu` Dispatcher\n\nEvery IDE gets a single **`snayu`** tool. Just invoke it to see all agents:\n\n```\nYou: snayu\n→ Shows all 16 available agents with tags\n```\n\nTo run a specific agent:\n\n```\nYou: snayu pr_review_agent — review PR #42\nYou: snayu aws_infrastructure_investigator — checkout is timing out\nYou: snayu incident_response_agent — check for errors in the last hour\n```\n\n### Three Ways to Invoke\n\n| Method | How | Works In |\n|--------|-----|----------|\n| **Natural language** | Just type `snayu` | VS Code (with copilot-instructions.md) |\n| **Tool reference** | Type `#mcp_snayu_snayu` in chat | **Any IDE** with MCP configured |\n| **Prompt shortcut** | Type `#snayu` | VS Code (with .github/copilot/snayu.prompt.md) |\n\n> **Tip:** `#mcp_snayu_snayu` works universally across all IDEs — VS Code, Cursor, Windsurf, Claude Desktop. It forces the LLM to call the snayu tool directly.\n\n### Available Agents\n\n| Tag | Agent | What It Does |\n|-----|-------|-------------|\n| `pr_review_agent` | 🔬 PR Review Agent | Reviews PRs with inline GitHub comments, suggestion blocks, security scan, cross-references prod logs |\n| `aws_infrastructure_investigator` | 🏗️ AWS Infrastructure Investigator | Acts like a Staff SRE — correlates alarms → metrics → logs → DB to find root cause |\n| `incident_response_agent` | 🚨 Incident Response Agent | Rapid triage during outages — searches logs, checks DB, alerts Teams |\n| `defect_triage_agent` | 🎯 Defect Triage Agent | Jira ticket → investigate → fix code → create PR → update Jira → notify Teams |\n| `bug_investigation_agent` | 🐛 Bug Investigation Agent | Cross-service bug investigation with Teams report |\n| `database_performance_monitor` | 📊 Database Performance Monitor | Table sizes, dead tuples, unused indexes, active connections |\n| `service_health_checker` | 🏥 Service Health Checker | Full health check across PostgreSQL, CloudWatch, DynamoDB, S3 |\n| `security_log_scanner` | �� Security Log Scanner | Scans for failed logins, unauthorized access, privilege escalation |\n| `schema_data_explorer` | 🔍 Schema & Data Explorer | Deep-dive into database schema, tables, columns |\n| `quick_query_runner` | ⚡ Quick Query Runner | Run a SQL query and send results to Teams |\n| `daily_standup_reporter` | 📋 Daily Standup Reporter | Morning summary — overnight errors, DB activity |\n| `daily_digest_to_teams` | 💬 Daily Digest to Teams | End-of-day digest — errors, DB stats, S3 changes |\n| `cost_storage_analyzer` | 📈 Cost & Storage Analyzer | S3 buckets, PostgreSQL bloat, DynamoDB sizes |\n| `data_migration_validator` | 🗄️ Data Migration Validator | Compare schemas, table structures, row counts |\n| `environment_diff_agent` | 🔄 Environment Diff Agent | Compare two PostgreSQL environments before deployment |\n| `dead_code_unused_resource_detector` | 🧹 Dead Code Detector | Find unused indexes, empty tables, wasted storage |\n\n---\n\n## 🧠 LLM Wiki — Persistent Memory for AI Agents\n\nSnayu agents don't start from scratch every session. They build and maintain **persistent knowledge bases** that compound over time.\n\n### Global Project Wiki\n\nEvery Snayu installation has a **global wiki** (`wiki/`) — 7 structured pages that agents read at session start and update after making changes:\n\n| Page | What's Inside |\n|------|--------------|\n| `architecture` | Tech stack, folder structure, key patterns |\n| `decisions` | Architecture decisions with rationale (ADR-lite) |\n| `troubleshooting` | Known issues, fixes, gotchas |\n| `runbook` | Common tasks, commands, deployment steps |\n| `changelog` | Recent changes and updates |\n| `context` | Current state, active work, handoff notes |\n| `agents` | Agent configs, invocation methods |\n\n**Tools:** `wiki_read`, `wiki_write`, `wiki_search`, `wiki_status`, `wiki_compact`\n\n### Per-Repo Knowledge Wiki\n\nEvery GitHub repo gets its own wiki that the **PR Review agent** incrementally builds. Wikis can live **locally in your repo** (`.snayu/wiki/`) or centrally in Snayu's install directory.\n\n#### Local Wiki (Recommended)\n\n```bash\n# Agent creates .snayu/wiki/ in your repo\n# Commit it — your team's AI agents instantly get context\n.snayu/\n├── README.md           # Why this exists\n└── wiki/\n    ├── code-structure.md\n    ├── pr-reviews.md\n    ├── risk-map.md\n    ├── standards.md\n    └── changelog.md\n```\n\n**Tools:** `repo_wiki_init_local`, `repo_wiki_init`, `repo_wiki_read`, `repo_wiki_write`, `repo_wiki_search`, `repo_wiki_status`, `repo_wiki_context`, `repo_wiki_list`\n\n### How Knowledge Compounds\n\n1. **1st PR Review** → Agent analyzes repo, creates code-structure + standards pages\n2. **After 5 reviews** → Risk map identifies fragile areas, recurring issues tracked\n3. **After 10 reviews** → Risk scores are data-driven, reviews are deeply contextual\n4. **Ongoing** → Every developer contributes, every review enriches the knowledge\n\n### Shared Team Knowledge (Hosted)\n\nWhen Snayu runs on a shared server, all developers read/write the **same wiki**:\n\n```\nDev A (VS Code) ──MCP──┐\nDev B (Cursor)  ──MCP──┤──→ Snayu Server ──→ wiki/ (shared)\nDev C (Claude)  ──MCP──┘\n```\n\n- Concurrent write safety via in-memory locks\n- Zero config for individual developers\n- Knowledge from one dev's debug session helps another dev's PR review\n\n---\n\n## 🧠 How Agents Work\n\nSnayu agents aren't rigid workflows — they're **prompt-driven**. Each agent carries a **systemPrompt** that tells the LLM exactly how to investigate.\n\n### The Flow\n\n```\nYou: \"snayu pr_review_agent — review PR #42\"\n  ↓\nCopilot calls snayu({ agent: \"pr_review_agent\", task: \"review PR #42\" })\n  ↓\nSnayu returns the agent's systemPrompt + tool list (NOT execution)\n  ↓\nCopilot reads the prompt → Phase 0: asks clarifying questions\n  ↓\nYou answer → Copilot follows the investigation protocol\n  ↓\nCopilot calls individual tools (CloudWatch, PostgreSQL, GitHub API, Teams)\n  ↓\nResults delivered — inline PR comments, Teams alerts, RCA reports\n```\n\n### Phase 0: Context Before Action\n\nEvery agent starts with **Phase 0** — it asks targeted questions before doing any work:\n\n**🔬 PR Review Agent asks:**\n- \"Any reference PR for team coding style?\"\n- \"Do you have a coding standards doc?\"\n- \"Specific concerns? Security, performance, breaking changes?\"\n\n**🏗️ Infrastructure Investigator asks:**\n- \"Any specific service to focus on?\" (Lambda, ECS, RDS)\n- \"What symptoms are you seeing?\" (timeouts, 5xx, OOM)\n- \"Any time window?\" (last 30 min, since deploy)\n\n---\n\n## Supported Services (34+)\n\n| Category | Services |\n|----------|----------|\n| 🗄️ **Databases** | PostgreSQL, MySQL, MongoDB, DynamoDB, Snowflake, Redis |\n| ☁️ **AWS** | S3, CloudWatch, SQS, SNS, Lambda, EC2, ECS, EKS, RDS, IAM, Route53, DynamoDB |\n| 🔍 **Search** | Elasticsearch / OpenSearch |\n| ⚙️ **DevOps** | GitHub, GitLab, Jira, Confluence |\n| 💬 **Communication** | Slack, Microsoft Teams, SendGrid |\n| 📈 **Monitoring** | Datadog, PagerDuty, Splunk |\n| 🤖 **AI** | OpenAI, Databricks |\n| 🔧 **Custom** | Any REST API, Any Webhook, Notion, Kubernetes |\n\n---\n\n## Architecture\n\n```\n┌─────────────────────────────────────────────┐\n│           Your IDE (VS Code, Cursor, etc.)  │\n│                                             │\n│   You: \"snayu pr_review_agent — review #42\" │\n│         ↓                                   │\n│   Copilot ←→ MCP Protocol (stdio)           │\n└──────────────────────┬──────────────────────┘\n                       │\n          ┌────────────▼────────────┐\n          │   Snayu MCP Server      │\n          │                         │\n          │  ┌───────────────────┐  │\n          │  │ snayu dispatcher  │  │  ← Single tool, 16 agents\n          │  └───────────────────┘  │\n          │  ┌───────────────────┐  │\n          │  │ Adapter Tools     │  │  ← CloudWatch, PostgreSQL, S3...\n          │  └───────────────────┘  │\n          │  ┌───────────────────┐  │\n          │  │ Meta Tools        │  │  ← Self-service connection mgmt\n          │  └───────────────────┘  │\n          └────────────┬────────────┘\n                       │\n     ┌─────────────────┼─────────────────┐\n     │                 │                 │\n┌────▼─────┐    ┌──────▼──────┐   ┌─────▼─────┐\n│CloudWatch│    │ PostgreSQL  │   │  Teams    │\n│ DynamoDB │    │ MySQL       │   │  Slack    │\n│ S3, SQS  │    │ MongoDB     │   │  GitHub   │\n└──────────┘    └─────────────┘   └───────────┘\n```\n\n---\n\n## IDE Configuration\n\n### VS Code / GitHub Copilot\n\n`.vscode/mcp.json`:\n```json\n{\n  \"servers\": {\n    \"snayu\": {\n      \"type\": \"stdio\",\n      \"command\": \"node\",\n      \"args\": [\"/path/to/connector/src/mcp/server.js\"]\n    }\n  }\n}\n```\n\n### Claude Desktop\n\n`~/Library/Application Support/Claude/claude_desktop_config.json`:\n```json\n{\n  \"mcpServers\": {\n    \"snayu\": {\n      \"command\": \"node\",\n      \"args\": [\"/path/to/connector/src/mcp/server.js\"]\n    }\n  }\n}\n```\n\n### Cursor / Windsurf\n\nSame format as VS Code — place in `~/.cursor/mcp.json` or `.windsurf/mcp.json`.\n\n---\n\n## Project Structure\n\n```\nconnector/\n├── src/\n│   ├── core/\n│   │   ├── agent-builder.js      # Agent builder + MCP tool registration\n│   │   ├── default-agents.js     # 16 agent templates with systemPrompts\n│   │   ├── registry.js           # Service catalog & connection storage\n│   │   ├── adapter-manager.js    # Adapter lifecycle management\n│   │   ├── wiki.js               # Global LLM Wiki (persistent memory)\n│   │   └── repo-wiki.js          # Per-repo knowledge wikis\n│   ├── adapters/                 # 35 service adapters\n│   ├── governance/               # 🛡️ Governance engine\n│   │   ├── index.js              # 9-step pipeline middleware\n│   │   ├── audit-log.js          # Crash-safe JSONL audit trail + token/cost tracking\n│   │   ├── policy-engine.js      # Allow/deny rules by tool/agent/connection\n│   │   ├── rate-limiter.js       # Token-bucket rate limits\n│   │   ├── prompt-guard.js       # Injection & jailbreak detection\n│   │   ├── guardrails.js         # Secrets & PII scanning\n│   │   ├── approvals.js          # Human-in-the-loop approval queue\n│   │   ├── alerts.js             # Real-time violation alerts\n│   │   ├── security-report.js    # Compliance report generator\n│   │   ├── system-monitor.js     # AI system action tracker\n│   │   └── patterns.js           # Regex patterns for detection\n│   ├── mcp/\n│   │   └── server.js             # MCP server + snayu dispatcher + wiki tools\n│   └── web/\n│       └── server.js             # Express dashboard + API\n├── data/\n│   ├── connections.json          # Persisted connections\n│   ├── built-agents.json         # Installed agents with systemPrompts\n│   └── governance/\n│       ├── stats.json            # Cumulative stats (calls, tokens, cost)\n│       ├── alerts.json           # Recent governance alerts\n│       ├── policies.json         # Policy rules\n│       └── audit/\n│           └── audit-YYYY-MM-DD.jsonl  # Daily append-only audit logs\n├── wiki/                         # LLM Wiki — persistent agent memory\n│   ├── _index.md\n│   ├── architecture.md\n│   ├── context.md\n│   ├── changelog.md\n│   └── repos/                    # Per-repo knowledge wikis\n├── docs/                         # Architecture & strategy docs\n│   ├── GOVERNANCE_ARCHITECTURE.md\n│   ├── GOVERNANCE_STRATEGY.md\n│   ├── MARKET_ANALYSIS.md\n│   └── GREENFIELD_OPPORTUNITIES.md\n├── Dockerfile\n├── .github/\n│   ├── copilot-instructions.md   # Auto-injected into Copilot conversations\n│   └── copilot/snayu.prompt.md   # #snayu prompt shortcut\n└── mcp.json                      # Ready-to-use MCP config\n```\n\n---\n\n## Scripts\n\n| Command | Description |\n|---------|-------------|\n| `npm start` | Start the web dashboard + connector |\n| `npm run mcp` | Run the MCP server directly |\n| `npm run dev` | Start with auto-reload |\n\n---\n\n## 🛡️ Governance Engine\n\nSnayu includes a production-grade **governance layer** that wraps every tool call with a full security and observability pipeline — before and after execution.\n\n### The Pipeline\n\nEvery tool call flows through this chain:\n\n```\nTool Call\n   │\n   ▼\n[1] Policy Check      → Is this tool allowed for this agent/connection?\n   │\n   ▼\n[2] Prompt Guard      → Scan input for injection attempts & jailbreaks\n   │\n   ▼\n[3] Input Guard       → Scan args for secrets, PII, API keys\n   │\n   ▼\n[4] Rate Limiter      → Enforce per-tool / per-connection call budgets\n   │\n   ▼\n[5] Approval Gate     → Require human approval for destructive actions\n   │\n   ▼\n[6] Execute           → Run the actual tool\n   │\n   ▼\n[7] Output Guard      → Scan output for leaked secrets / sensitive data\n   │\n   ▼\n[8] Alert Engine      → Fire alerts on policy violations or anomalies\n   │\n   ▼\n[9] Audit Log         → Persist enriched entry to append-only JSONL\n```\n\n### Governance Modules\n\n| Module | File | What It Does |\n|--------|------|-------------|\n| **Middleware** | `governance/index.js` | Orchestrates the full 9-step pipeline |\n| **Audit Log** | `governance/audit-log.js` | Crash-safe append-only JSONL + stats |\n| **Policy Engine** | `governance/policy-engine.js` | Allow/deny rules by tool, agent, connection |\n| **Rate Limiter** | `governance/rate-limiter.js` | Token-bucket rate limits per tool/connection |\n| **Prompt Guard** | `governance/prompt-guard.js` | Detects injection, jailbreak, manipulation |\n| **Guardrails** | `governance/guardrails.js` | Scans for secrets, PII, API keys in I/O |\n| **Approvals** | `governance/approvals.js` | Human-in-the-loop approval queue |\n| **Alerts** | `governance/alerts.js` | Real-time alerts on violations & anomalies |\n| **Security Report** | `governance/security-report.js` | Full security & compliance report generator |\n| **System Monitor** | `governance/system-monitor.js` | Tracks all AI system actions independently |\n| **Patterns** | `governance/patterns.js` | Regex patterns for secrets/PII detection |\n\n### Audit Log — Every Tool Call, Fully Documented\n\nEach audit entry is a rich JSON record stored in **daily-rotated JSONL files** at `data/governance/audit/audit-YYYY-MM-DD.jsonl`.\n\n**Example entry:**\n```json\n{\n  \"id\": \"evt_3a9f12bc44e71a08\",\n  \"timestamp\": \"2026-05-14T09:18:30.638Z\",\n  \"toolName\": \"postgresql_mnz1wzbl__query\",\n  \"action\": \"query\",\n  \"service\": \"postgresql\",\n  \"connectionName\": \"local postgres\",\n  \"connectionId\": \"postgresql_mnz1wzbl\",\n  \"callerClient\": \"Visual Studio Code\",\n  \"callerVersion\": \"1.105.1\",\n  \"inputSummary\": \"sql: SELECT current_database(), current_user, now() as server_time | limit: 100\",\n  \"outputSummary\": \"329 chars\",\n  \"durationMs\": 12,\n  \"allowed\": true,\n  \"blocked\": false,\n  \"model\": \"claude-sonnet-4\",\n  \"inputTokens\": 87,\n  \"outputTokens\": 17,\n  \"totalTokens\": 104,\n  \"estimatedCost\": 0.001059\n}\n```\n\n**Every entry captures:**\n\n| Field | Description |\n|-------|-------------|\n| `toolName` | Exact MCP tool called |\n| `action` | Semantic action (query, search, scan, send…) |\n| `service` | Service type (postgresql, cloudwatch, s3…) |\n| `connectionName` | Human-readable connection name |\n| `callerClient` | IDE that made the call (VS Code, Cursor…) |\n| `callerVersion` | Exact IDE version |\n| `inputSummary` | What was asked — no raw payloads, just intent |\n| `outputSummary` | What was returned — row counts, char length |\n| `durationMs` | Execution time |\n| `allowed / blocked` | Policy decision |\n| `model` | LLM model used for the session |\n| `inputTokens / outputTokens / totalTokens` | Estimated token usage |\n| `estimatedCost` | USD cost estimate for this call |\n\n### Crash-Safe Writes\n\nAudit writes use **`appendFileSync`** — the entry is fully on disk before execution returns. If the server crashes mid-session, no audit entries are lost.\n\nOn restart, stats are automatically **rebuilt from the JSONL files** — no stale in-memory counters.\n\n### Token & Cost Tracking\n\nSnayu estimates tokens and USD cost for every tool call using a **12-model pricing table**:\n\n| Model | Input ($/1M tokens) | Output ($/1M tokens) |\n|-------|--------------------|--------------------|\n| `gpt-4o` | $2.50 | $10.00 |\n| `gpt-4o-mini` | $0.15 | $0.60 |\n| `claude-sonnet-4` | $3.00 | $15.00 |\n| `claude-3.5-sonnet` | $3.00 | $15.00 |\n| `claude-3-opus` | $15.00 | $75.00 |\n| `claude-3-haiku` | $0.25 | $1.25 |\n| *(+ 6 more)* | … | … |\n\nToken estimation uses the `chars / 4` heuristic (±20% accuracy for English text). Costs accumulate in `data/governance/stats.json` and are visible in the dashboard.\n\n### Governance Dashboard\n\nThe **Governance** tab in the dashboard (`http://localhost:3456`) shows:\n\n- **Total Calls / Blocked / Errors / Redacted** — lifetime counters\n- **Total Tokens (est.)** — cumulative token usage across all sessions\n- **Est. Cost (USD)** — cumulative cost estimate\n- **Audit Log Table** — every call with Time, Service, Action, Duration, Status\n- **Detail Modal** — click any row to see full entry including token breakdown, input/output summary, caller info\n- **CSV Export** — download the full audit log with all enriched fields\n\n### Governance Tools (MCP)\n\nThese tools are available directly in your IDE via MCP:\n\n| Tool | Description |\n|------|-------------|\n| `governance__generate_security_report` | Full security & compliance report with risk score |\n| `governance__get_blocked_actions` | All denied tool calls with reasons |\n| `governance__get_dangerous_actions` | Detected dangerous commands (rm -rf, sudo, force push…) |\n| `governance__get_governance_stats` | Real-time stats — calls, blocked, cost, tokens |\n| `governance__get_pending_approvals` | Tool calls awaiting human review |\n| `governance__get_recent_alerts` | Recent policy violations and findings |\n| `governance__get_system_activity` | Full AI action monitor (terminal, file writes, git ops) |\n| `governance__query_audit_logs` | Query audit trail with filters |\n| `governance__scan_for_prompt_injection` | Scan any text for injection/jailbreak attempts |\n| `governance__scan_text_for_secrets` | Scan text for API keys, PII, credentials |\n\n### Toggle Governance\n\n```bash\n# Via API\ncurl -X POST http://localhost:3456/api/governance/toggle \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"enabled\": true}'\n```\n\nOr toggle the switch on the Governance dashboard tab.\n\n---\n\n## Security\n\n- Credentials stored locally in `data/connections.json`\n- Passwords masked in API responses\n- Database queries are read-only (SELECT only)\n- All data stays on your machine\n- AWS credentials auto-refresh from `~/.aws/credentials`\n- All AI tool calls logged to tamper-evident append-only JSONL audit trail\n- Input/output scanned for secrets, PII, and prompt injection on every call\n\n---\n\n## License\n\nMIT\n","readmeFilename":"README.md"}