{"_id":"@elnora-ai/vanta","_rev":"3-e4e162dbdfbd4c6497f8a9cd2d4a2f7e","name":"@elnora-ai/vanta","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@elnora-ai/vanta","version":"0.1.0","keywords":["vanta","compliance","soc2","iso27001","security","grc","claude-code","claude-code-plugin","cli","agent","elnora"],"author":{"name":"Elnora AI","email":"opensource@elnora.ai"},"license":"Apache-2.0","_id":"@elnora-ai/vanta@0.1.0","maintainers":[{"name":"risto.jamul","email":"risto.jamul@elnora.ai"},{"name":"carmen.kivisild","email":"carmen.kivisild@elnora.ai"}],"homepage":"https://github.com/Elnora-AI/elnora-vanta","bugs":{"url":"https://github.com/Elnora-AI/elnora-vanta/issues"},"bin":{"elnora-vanta":"dist/main.js"},"dist":{"shasum":"9268d0ec261be3547735a766854bd31b706169e5","tarball":"https://registry.npmjs.org/@elnora-ai/vanta/-/vanta-0.1.0.tgz","fileCount":95,"integrity":"sha512-hON9A87FIHgkfKuCxWDMBwiwqutoGhwInGHHX6U14H1k4W2Mx6WmKuEPmbfeEr/aLthQbXzoX4KkiHq7rQ9JpQ==","signatures":[{"sig":"MEUCIFYHLv5l0gFUC9v/4Io6jOD0R9f6BN1+b9Ys3rT0iLrhAiEAglqv/qrjJQ+NxoCXGmigoINwu2gV6I1uhON3yonnaGw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165310},"main":"dist/main.js","type":"module","types":"./dist/main.d.ts","engines":{"node":">=20"},"gitHead":"40119e81159c981db2d384ad228c3c8b98229097","scripts":{"dev":"tsx src/main.ts","lint":"biome check src/ __tests__/ scripts/","test":"vitest run","build":"tsc","format":"biome format --write src/ __tests__/ scripts/","lint:fix":"biome check --write src/ __tests__/ scripts/","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"carmen.kivisild","email":"carmen.kivisild@elnora.ai"},"repository":{"url":"git+https://github.com/Elnora-AI/elnora-vanta.git","type":"git"},"_npmVersion":"11.12.1","description":"Read-only Vanta compliance CLI and Claude Code plugin — frameworks, tests, controls, documents, and vulnerabilities as agent-friendly JSON","directories":{},"_nodeVersion":"25.9.0","dependencies":{"commander":"^15.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.33.0","devDependencies":{"tsx":"^4.22.4","vitest":"^4.1.7","typescript":"^7.0.2","@types/node":"^26.1.1","@biomejs/biome":"^2.4.10"},"_npmOperationalInternal":{"tmp":"tmp/vanta_0.1.0_1784065059838_0.6798806953321996","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@elnora-ai/vanta","version":"0.1.1","keywords":["vanta","compliance","soc2","iso27001","security","grc","claude-code","claude-code-plugin","cli","agent","elnora"],"author":{"name":"Elnora AI","email":"opensource@elnora.ai"},"license":"Apache-2.0","_id":"@elnora-ai/vanta@0.1.1","maintainers":[{"name":"risto.jamul","email":"risto.jamul@elnora.ai"},{"name":"carmen.kivisild","email":"carmen.kivisild@elnora.ai"}],"homepage":"https://github.com/Elnora-AI/elnora-vanta","bugs":{"url":"https://github.com/Elnora-AI/elnora-vanta/issues"},"bin":{"elnora-vanta":"dist/main.js"},"dist":{"shasum":"bf550af00676c44c784b4515a680778b80efb982","tarball":"https://registry.npmjs.org/@elnora-ai/vanta/-/vanta-0.1.1.tgz","fileCount":93,"integrity":"sha512-Z4qOZptg8be/ZFhRYxV57Vm42nOhCWZk4CnUsWJ+x0JjzQF/aaf/Qlm2sC6RgHNk8yxkn+5bS/aI6eccIHt29A==","signatures":[{"sig":"MEUCIGBhbY+7u5SXQVbvj+izJMZBDY+3L/4/uUGc498rnDWTAiEAivbKDy3uOkmtTXn6rQiiMkPdMMGyrCFN4hxLWflUjW8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@elnora-ai%2fvanta@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":156342},"main":"dist/main.js","type":"module","types":"./dist/main.d.ts","engines":{"node":">=20"},"gitHead":"d21a7b8cf3136a75259fa7e649732fe1618fee8e","scripts":{"dev":"tsx src/main.ts","lint":"biome check src/ __tests__/ scripts/","test":"vitest run","build":"tsc","format":"biome format --write src/ __tests__/ scripts/","lint:fix":"biome check --write src/ __tests__/ scripts/","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5247b742-62ea-46cb-bbca-353e46e57d80"}},"repository":{"url":"git+https://github.com/Elnora-AI/elnora-vanta.git","type":"git"},"_npmVersion":"11.16.0","description":"Read-only Vanta compliance CLI and Claude Code plugin — frameworks, tests, controls, documents, and vulnerabilities as agent-friendly JSON","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^15.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.33.0","devDependencies":{"tsx":"^4.22.4","vitest":"^4.1.7","typescript":"^7.0.2","@types/node":"^26.1.1","@biomejs/biome":"^2.4.10"},"_npmOperationalInternal":{"tmp":"tmp/vanta_0.1.1_1784095810038_0.8188347048102205","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@elnora-ai/vanta","version":"0.1.2","description":"Vanta compliance CLI and Claude Code plugin — the complete documented REST API (321 operations) as agent-friendly JSON, with dry-run-by-default write safety","type":"module","bin":{"elnora-vanta":"dist/main.js"},"main":"dist/main.js","engines":{"node":">=20"},"publishConfig":{"access":"public"},"scripts":{"build":"tsc","dev":"tsx src/main.ts","test":"vitest run","test:watch":"vitest","lint":"biome check src/ __tests__/ scripts/","lint:fix":"biome check --write src/ __tests__/ scripts/","format":"biome format --write src/ __tests__/ scripts/","typecheck":"tsc --noEmit","spec:fetch":"tsx scripts/fetch-specs.ts","generate":"tsx scripts/generate-operations.ts"},"keywords":["vanta","compliance","soc2","iso27001","security","grc","claude-code","claude-code-plugin","cli","agent","elnora"],"author":{"name":"Elnora AI","email":"opensource@elnora.ai"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/Elnora-AI/elnora-vanta.git"},"bugs":{"url":"https://github.com/Elnora-AI/elnora-vanta/issues"},"homepage":"https://github.com/Elnora-AI/elnora-vanta","packageManager":"pnpm@10.33.0","devDependencies":{"@biomejs/biome":"^2.5.5","@types/node":"^26.1.1","tsx":"^4.22.4","typescript":"^7.0.2","vitest":"^4.1.7"},"dependencies":{"commander":"^15.0.0"},"gitHead":"09c8e734d17cbfa8676db3a0948190b530e70d7c","types":"./dist/main.d.ts","_id":"@elnora-ai/vanta@0.1.2","_nodeVersion":"24.20.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-foGL798nCno1zi6F57oN7ziDPYzmMxppRC1nM8XLsHxZASZc5xntI3pUos250CjI3PLdpd1KX9vgKkTQwItLQA==","shasum":"61a74413100fa3e3b7cd416cc1f51d0d5d28d19b","tarball":"https://registry.npmjs.org/@elnora-ai/vanta/-/vanta-0.1.2.tgz","fileCount":111,"unpackedSize":441253,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@elnora-ai%2fvanta@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFzzLNfzGPUPiXZcfyYOv75pJpcZbHHlz+VBKPK6Q2DdAiA1jX3NaDuzDZUZdL1xjPt2J4IIMaoWiplDqdRttiSgmg=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5247b742-62ea-46cb-bbca-353e46e57d80"}},"directories":{},"maintainers":[{"name":"risto.jamul","email":"risto.jamul@elnora.ai"},{"name":"carmen.kivisild","email":"carmen.kivisild@elnora.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vanta_0.1.2_1788842090844_0.6736996236097184"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-14T21:37:39.701Z","modified":"2026-09-08T04:34:51.294Z","0.1.0":"2026-07-14T21:37:40.009Z","0.1.1":"2026-07-15T06:10:10.170Z","0.1.2":"2026-09-08T04:34:50.988Z"},"bugs":{"url":"https://github.com/Elnora-AI/elnora-vanta/issues"},"author":{"name":"Elnora AI","email":"opensource@elnora.ai"},"license":"Apache-2.0","homepage":"https://github.com/Elnora-AI/elnora-vanta","keywords":["vanta","compliance","soc2","iso27001","security","grc","claude-code","claude-code-plugin","cli","agent","elnora"],"repository":{"type":"git","url":"git+https://github.com/Elnora-AI/elnora-vanta.git"},"description":"Vanta compliance CLI and Claude Code plugin — the complete documented REST API (321 operations) as agent-friendly JSON, with dry-run-by-default write safety","maintainers":[{"name":"risto.jamul","email":"risto.jamul@elnora.ai"},{"name":"carmen.kivisild","email":"carmen.kivisild@elnora.ai"}],"readme":"# elnora-vanta\n\n**Your Vanta compliance programme from the terminal. Ask what is failing, pull the evidence, fix what you can, and let an AI agent work on it with you. Reads run straight away, and a write shows you the request before it sends it.**\n\n[![License](https://img.shields.io/badge/license-Apache%202.0-blue.svg)](LICENSE)\n[![npm](https://img.shields.io/npm/v/@elnora-ai/vanta)](https://www.npmjs.com/package/@elnora-ai/vanta)\n[![CI](https://github.com/Elnora-AI/elnora-vanta/actions/workflows/ci.yml/badge.svg)](https://github.com/Elnora-AI/elnora-vanta/actions)\n\nIn your first ten minutes you can:\n\n- See where you stand: `/vanta-status` gives framework completion, failing tests and overdue vulnerabilities in one shot.\n- Triage vulnerabilities properly, filtering by severity, CVE, or what has blown its SLA.\n- Reach the whole documented Vanta API, 321 operations across 38 resource groups, as `elnora-vanta api <group> <command>`.\n- Reach the parts of Vanta that have no public REST endpoint, among them the answer library, knowledge base, privacy assessments and access reviews, through `elnora-vanta mcp`.\n- Ask the compliance-auditor agent an open question like \"what is blocking our audit?\" and get an answer grounded in your live data.\n\n> The binary is `elnora-vanta`, not `vanta`. Vanta and other tools may claim the bare name, so we keep our own.\n\n> **A write takes a deliberate flag.** Without `--confirm` a write prints the request it would send and stops. A destructive operation also wants `--force`, and `--dry-run` beats both. See [Write safety](#write-safety).\n\n---\n\n## Install\n\nThe CLI and the Claude Code plugin are two installs. The plugin shells out to the `elnora-vanta` binary, so do the CLI first even if you only want the plugin.\n\n### 1. Install the CLI\n\n```sh\nnpm install -g @elnora-ai/vanta\nelnora-vanta --version\n```\n\nCreate a Vanta OAuth client (below), then check it works:\n\n```sh\nelnora-vanta frameworks list\n```\n\n### 2. Add the Claude Code plugin (optional)\n\nRun these as two separate slash commands, waiting for the first to finish:\n\n```\n/plugin marketplace add Elnora-AI/elnora-vanta\n```\n\n```\n/plugin install vanta-workspace@elnora-vanta\n```\n\n`/plugin` should then list `vanta-workspace` as enabled. If `elnora-vanta --version` fails, go back to step 1, because the skills need the binary on PATH.\n\n### Codex, Cursor, and other agents\n\nInstall the CLI, then drop [`AGENTS.md`](AGENTS.md) at your project root. Those agents read it natively and map intent to CLI commands. The plugin is Claude Code only. To have an agent do the install, point it at [`INSTALL_FOR_AGENTS.md`](INSTALL_FOR_AGENTS.md), a runbook that creates the OAuth client, collects credentials and smoke-tests, pausing for you at each step.\n\n---\n\n## Vanta OAuth setup\n\nThe OAuth client is yours: you create it, you hold the secret, and it stays on your machine.\n\n1. Go to [app.vanta.com/settings/api](https://app.vanta.com/settings/api) and create an OAuth client with the `client_credentials` grant.\n2. Choose its scopes deliberately.\n   - `vanta-api.all:read` alone is the safest default. Reads work, and writes fail at Vanta itself, so the CLI's flags are not the last line of defence.\n   - Add `vanta-api.all:write` if you intend to change things. The CLI still asks for `--confirm`, and `--force` when destructive, and the credential can now modify your compliance data.\n3. Copy the client ID and secret.\n4. Save them:\n   ```sh\n   mkdir -p ~/.config/elnora-vanta\n   printf 'VANTA_CLIENT_ID=your-client-id\\nVANTA_CLIENT_SECRET=your-client-secret\\n' >> ~/.config/elnora-vanta/.env\n   chmod 600 ~/.config/elnora-vanta/.env\n   ```\n5. Run `elnora-vanta frameworks list` and you should see your enrolled frameworks.\n\nCredentials resolve from the process environment first, then `~/.config/elnora-vanta/.env` (or `$VANTA_CONFIG_DIR/.env`), then a `.env` beside the CLI. Tokens are cached at mode `0600` and refreshed when they expire.\n\n### Regions\n\nThe default API base is `https://api.vanta.com`. EU and Australian tenants set one of:\n\n```sh\nVANTA_API_BASE_URL=https://api.eu.vanta.com\nVANTA_API_BASE_URL=https://api.aus.vanta.com\n```\n\nRequests are pinned to those three hosts, and any other base URL is rejected.\n\n---\n\n## Using it\n\n### Everyday commands\n\n`frameworks`, `tests`, `controls`, `documents`, `vulns`, `risks`, `people`, `policies`, `vendors`, `groups`, `integrations`, `computers`, `vuln-assets`, `vuln-remediations`. These are read-only by construction and cover the usual questions:\n\n```sh\nelnora-vanta vulns list --severity CRITICAL --overdue\nelnora-vanta policies list --framework soc2\nelnora-vanta tests list --limit 20\n```\n\nFrameworks are discovered per organisation, so run `elnora-vanta frameworks list` to see yours. Where the docs show an id like `soc2`, it is an example rather than an assumption.\n\n### The full API\n\nEverything Vanta documents lives under `api`, generated from the OpenAPI specs in `spec/`. Search instead of guessing command names:\n\n```sh\nelnora-vanta api search \"policy\"             # find operations by name, path or summary\nelnora-vanta api search --risk destructive   # everything that can delete\nelnora-vanta api controls list-controls\nelnora-vanta api --help                      # all 38 groups\n```\n\nSome endpoint families answer `403` on a standard management client, among them integration connectors, secrets, security tasks, user accounts, per-device records, audits and contracts. Vanta gates those on a differently scoped app, so the request is correct and Vanta is declining it.\n\nTo pick up Vanta API changes: `pnpm spec:fetch && pnpm generate && pnpm build`\n\n### Capabilities outside the REST API\n\nThe answer library, knowledge base, privacy assessments, access reviews, TPRM assessment automations and policy generation live on Vanta's hosted MCP server. That wants a Vanta Admin sign-in rather than the service token:\n\n```sh\nelnora-vanta mcp login                        # browser, once\nelnora-vanta mcp tools                        # what your tenant exposes, with risk and arguments\nelnora-vanta mcp tools --name generatePolicy  # one tool's input schema\nelnora-vanta mcp call getSlas\n```\n\nThe tool list is read from your own tenant at run time, so it reflects the Vanta features you have. `mcp call` follows the same write rules as `api`. EU and Australian tenants set `VANTA_MCP_URL`, pinned to Vanta's three MCP hosts.\n\n### Output\n\nCommands print JSON to stdout, and errors go to stderr as `{error, suggestion}`. Global flags: `--compact`, `--output json|table|csv`, `--fields <list>`, `--no-color`, plus `--page-size` and `--limit` on lists. Shell completion comes from `elnora-vanta completion bash|zsh|fish|powershell`.\n\nExit codes: `0` success, `2` usage, `3` auth, `4` not found, `5` rate limit, `6` a write refused for want of `--confirm` or `--force`.\n\n---\n\n## Write safety\n\n| Risk | Operations | To run it |\n|---|---|---|\n| `read` | `GET` | runs immediately |\n| `write` | `POST`, `PUT`, `PATCH` | `--confirm` |\n| `destructive` | `DELETE`, and anything that deactivates, archives, revokes, removes or offboards | `--confirm` and `--force` |\n\nWithout the flags you get the request that would have been sent, and nothing goes to Vanta:\n\n```console\n$ elnora-vanta api vendors delete-by-id VENDOR-ID\n{\n  \"dryRun\": true,\n  \"wouldRequest\": { \"operationId\": \"DeleteById\", \"method\": \"DELETE\", \"path\": \"/vendors/VENDOR-ID\", \"risk\": \"destructive\" },\n  \"blocked\": \"This destructive operation was not sent.\",\n  \"addFlags\": [\"--confirm\", \"--force\"]\n}\n```\n\nA refusal exits `6`, so a script or an agent can tell it apart from success. `--dry-run` wins over `--confirm`, which means an agent handed a ready-made command line still cannot change anything. The plugin's hook goes further and blocks `--force`, keeping deletions with a person at a terminal.\n\nReads and writes use separate OAuth scopes and separate cached tokens, so an install that only reads asks for the read scope alone. Requests go to `api.vanta.com`, `api.eu.vanta.com` or `api.aus.vanta.com` and nowhere else. Credentials sit in a `0600` file, tokens are cached at `0600`, and secrets are redacted on every error path.\n\nFull details, including the limits of each layer, are in [SAFETY.md](SAFETY.md).\n\n---\n\n## What the plugin adds\n\n| Surface | What it does |\n|---|---|\n| `vanta-workspace` skill | Routes a question to the right command, and reads the cached reference before calling the API |\n| `compliance-auditor` agent | Answers open questions on audit readiness, failing tests and evidence gaps from live data |\n| `/vanta-status` | Posture snapshot: framework completion, failing tests, overdue vulnerabilities |\n| `/vanta-sync` | Regenerates the cached compliance reference from live data |\n| `/vanta-vulns` | Vulnerability triage by severity, overdue SLA and CVE |\n| `/vanta-report` | A compliance report drafted from live data |\n| SessionStart hook | Says when the cached reference has gone stale |\n| PreToolUse hook | Blocks `--force`, so an agent cannot execute a destructive operation |\n\n### The compliance reference cache\n\nThe plugin keeps a snapshot of your compliance data so agents can answer posture questions without an API round trip. It ships as `references/*.template.md` with obviously fake rows, and `/vanta-sync` writes the real files to `$VANTA_REFERENCES_DIR`, or beside the templates if that is unset.\n\nTreat the generated files as sensitive, because they are your live security posture: failing controls, open vulnerabilities, evidence gaps. They are gitignored, and a CI guard fails the build if generated data is ever committed. Every real row comes from your own synced cache, and this repository ships none of it.\n\n---\n\n## Part of the Elnora family\n\nOpen-source agent tooling from [Elnora AI](https://github.com/Elnora-AI): free, config-driven tools that wire Claude Code, or any AI coding agent, into the systems you run your company on. Each one works standalone, and they chain together when you install several.\n\n<!-- ELNORA-FAMILY:START -->\n- [elnora-linear](https://github.com/Elnora-AI/elnora-linear) — Linear issue management — search, bulk edit, agents, and a config-driven curator\n- [elnora-slack](https://github.com/Elnora-AI/elnora-slack) — the entire Slack Web API as a CLI plus agent skills with a draft-and-approve send gate\n- [elnora-whatsapp](https://github.com/Elnora-AI/elnora-whatsapp) — read, search, and send WhatsApp from your own paired account, 100% local\n- [elnora-google-workspace](https://github.com/Elnora-AI/elnora-google-workspace) — Gmail, Calendar, Drive, Docs, Sheets, Forms, Tasks, plus any Google API via Discovery\n- [elnora-merit-aktiva](https://github.com/Elnora-AI/elnora-merit-aktiva) — Merit Aktiva accounting and Merit Palk payroll as a CLI and plugin\n- [elnora-luma](https://github.com/Elnora-AI/elnora-luma) — Luma (lu.ma) events — all 61 public API endpoints as a spec-driven CLI with safety guardrails\n- [elnora-travel](https://github.com/Elnora-AI/elnora-travel) — a real travel agent — live flights, hotels, Airbnb, Booking.com, and routes in one itinerary\n- [elnora-websearch-tools](https://github.com/Elnora-AI/elnora-websearch-tools) — web search — Exa, Tavily, Perplexity, Firecrawl, and Valyu CLIs and skills in one plugin\n- [knowledge-vault](https://github.com/Elnora-AI/knowledge-vault) — an Obsidian-compatible knowledge base for agent teams — search and save your work to any vault\n<!-- ELNORA-FAMILY:END -->\n\n## Contributing\n\nIssues and PRs are welcome at [github.com/Elnora-AI/elnora-vanta](https://github.com/Elnora-AI/elnora-vanta)\n\nKeep the safety grading intact. A new mutating operation has to be classified `write` or `destructive` and go through the same gate, and a change that lets a write execute without `--confirm` will be sent back. Questions: opensource@elnora.ai\n\n## Security\n\nReport a vulnerability to security@elnora.ai rather than opening a public issue. [SAFETY.md](SAFETY.md) has the threat model.\n\n## License\n\n[Apache-2.0](LICENSE) © Elnora AI\n","readmeFilename":"README.md"}