diff --git a/README.md b/README.md index a6e44af..905704e 100644 --- a/README.md +++ b/README.md @@ -29,6 +29,10 @@ node dist/cli.js --help Windows is not supported in v1. +## Official package attribution + +`@agentcommunity/cli` is the official umbrella command-line client published by [Agent Community](https://agentcommunity.org/developers) from [github.com/agentcommunity/cli](https://github.com/agentcommunity/cli). It is a CLI application and does not expose a public JavaScript SDK. For code-level agent discovery, use the AID SDKs listed on the [Agent Community developer resources page](https://agentcommunity.org/developers). + ## Commands ```text diff --git a/package-lock.json b/package-lock.json index 4efc5d9..89c43f7 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@agentcommunity/cli", - "version": "0.1.2", + "version": "0.1.3", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@agentcommunity/cli", - "version": "0.1.2", + "version": "0.1.3", "license": "MIT", "os": [ "darwin", diff --git a/package.json b/package.json index 7407b57..0f07d04 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,15 @@ { "name": "@agentcommunity/cli", - "version": "0.1.2", - "description": "Official command-line client for Agent Community public data and user-claimed authorization", + "version": "0.1.3", + "description": "Official Agent Community CLI for public MCP, content, NLWeb, batch, and user-claimed authorization interfaces", + "keywords": [ + "agentcommunity", + "agent-community", + "cli", + "ai-agents", + "mcp", + "model-context-protocol" + ], "type": "module", "bin": { "agentcommunity": "dist/cli.js" diff --git a/scripts/audit-package.ts b/scripts/audit-package.ts index 865681a..7f25863 100644 --- a/scripts/audit-package.ts +++ b/scripts/audit-package.ts @@ -8,6 +8,16 @@ import { normalizeNpmPackResult } from "./npm-pack-result.js"; const expectedFiles = ["LICENSE", "README.md", "SECURITY.md", "dist/cli.js", "package.json"]; const expectedBin = { agentcommunity: "dist/cli.js" }; +const expectedKeywords = [ + "agentcommunity", + "agent-community", + "cli", + "ai-agents", + "mcp", + "model-context-protocol", +]; +const expectedDescription = + "Official Agent Community CLI for public MCP, content, NLWeb, batch, and user-claimed authorization interfaces"; const installedBinRelativePath = "node_modules/.bin/agentcommunity"; const secretPatterns = [ /-----BEGIN (?:RSA |EC |OPENSSH )?PRIVATE KEY-----/, @@ -40,6 +50,12 @@ async function main(): Promise { const repositoryRoot = new URL("../", import.meta.url).pathname; const packageJson = JSON.parse(await readFile(join(repositoryRoot, "package.json"), "utf8")); assertExactBin(packageJson, "Source"); + if (packageJson.description !== expectedDescription) { + throw new Error("Official CLI description drift detected."); + } + if (JSON.stringify(packageJson.keywords) !== JSON.stringify(expectedKeywords)) { + throw new Error("Official CLI keyword drift detected."); + } if (packageJson.name !== "@agentcommunity/cli" || packageJson.exports !== undefined) { throw new Error("Package metadata is outside the CLI-only boundary."); } @@ -58,6 +74,12 @@ async function main(): Promise { if (JSON.stringify(inventory) !== JSON.stringify(expectedFiles)) throw new Error(`Unexpected package inventory: ${inventory.join(", ")}`); const tarballPath = join(destination, basename(result.filename)); const packedManifest = JSON.parse(command("tar", ["-xOf", tarballPath, "package/package.json"], repositoryRoot)); + if (packedManifest.description !== expectedDescription) { + throw new Error("Packed CLI description drift detected."); + } + if (JSON.stringify(packedManifest.keywords) !== JSON.stringify(expectedKeywords)) { + throw new Error("Packed CLI keyword drift detected."); + } assertExactBin(packedManifest, "Packed tarball"); const tarball = await readFile(tarballPath); const tarballSha256 = createHash("sha256").update(tarball).digest("hex"); diff --git a/src/__tests__/package-boundary.test.ts b/src/__tests__/package-boundary.test.ts index e7db4bf..96568cd 100644 --- a/src/__tests__/package-boundary.test.ts +++ b/src/__tests__/package-boundary.test.ts @@ -1,9 +1,10 @@ import { spawnSync } from "node:child_process"; +import { readFileSync } from "node:fs"; import { chmod, lstat, mkdir, mkdtemp, readFile, realpath, rm, writeFile } from "node:fs/promises"; import { tmpdir } from "node:os"; import { basename, join } from "node:path"; import { fileURLToPath } from "node:url"; -import { describe, expect, test } from "vitest"; +import { describe, expect, it, test } from "vitest"; import { normalizeNpmPackResult } from "../../scripts/npm-pack-result.js"; @@ -17,6 +18,16 @@ function command(commandName: string, args: Array, cwd: string): string } describe("package and CI boundaries", () => { + it("states official ownership and keeps the CLI distinct from SDK packages", function () { + const readme = readFileSync(new URL("../../README.md", import.meta.url), "utf8"); + + expect(readme).toContain("Official package attribution"); + expect(readme).toContain("@agentcommunity/cli"); + expect(readme).toContain("https://github.com/agentcommunity/cli"); + expect(readme).toContain("https://agentcommunity.org/developers"); + expect(readme).toContain("does not expose a public JavaScript SDK"); + }); + test("declares a CLI-only package for the maintained Node and OS matrix", async () => { const packageJson = JSON.parse(await readFile(new URL("package.json", root), "utf8")); expect(packageJson).toMatchObject({