← Home

@mondaydotcomorg/atp-server

Server implementation for Agent Tool Protocol

14
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

yairfeavivdasaarartomramuyonahareljoshpe-mondayalonbehaimsergeyroytantonru92laviomrishanibenaderetmondayvitalimadarmondayaviel_mondayhadaspeshayelmodnaychristopher-nowakvladmondayella-miliorkeomermondayrutikeveshaf8811avihayavcsalomaneran.hubermandanielabmoshikaviv_go_npmdanielb-bladepoporibaoronmelleryglaubachayelet-mondaydanielle.ahidohaynavecohensaharbtombogbarakbeidoyana-mondaylorin-totahoronmondaynik-savchenkotomerfriedmanyosefwigor_budimatanyaw2nirlachmanorrgottlsebastian-curland-mndyyuly-robermanamirbardugobarcohen2illyayutootmoranfreak4pcmateuszwoamit_hanochdorhasongal_libermannoamn3kronachmany-mondayshahafmelamedyuvalbbenpidorshakedmickael_firstitaycohenmayaheilbrunventuramdudidorongoralthshaieturi-shmuelianatkatzshalomsteinbachannasoboazjofirmonsingoshaneeavifreegeliorrabinvirtserssddnodepablo-mdcamitbiranorelhazroyna-devsergeybrofirc-mondaynizansharavashavnerhaidanklingeraxelstdanielkheyfetscarloscr.mondaylorenzo.paaviv_gogiuliofilahav_p_mondayheshamgotaniasilvabenymondaydanielokaninneomi_shavitshaikatzzarielmondayguywatomsap-mondaylukaszf-mondayliranrorlicheran-cohenmaya-assayagrami-mondayalonbrimerethans-mondaywitoldtkerlich75adamfloorlahavpomernave1rankupmondaybuzagloidanjeandavidmeromcoarnonrgodanapoannasolomonikmitzafon-mondayyoavgalueranshiranbirenbaumnicole_kezlikmichalsz-mondaymickey_mondayitamartedor-cohenliranbinasif_mondaylotemkirshorihassid2507itaymndyeyalmuarekze-mondayibmondayvikas-mondayalonmulukaszfiszer-mondaymarszelun-mondayarnongumarekpeharelcohenameerdokamiedekelabehadascoalonsadanrama-rongilby1galor-mondayran-haveshush-mondaymichaelsimkinbarakbsedenhayatrachelikaliorfranyatchernishovnadavavthierryguynirarazi.mondayedenberdugoneilmonalonzirongabbayetgarmonronniemimoshe-samsonadamru-mondaygauravsh-mondayshlomiatmondayandrey-palmanleonidkrtomzohshirsharmonday-grahamlayoni-alaluftomer-gillmorerobertdasaarbatalsofferalonlestasshwataliareidanmondayraneldanbarosenrotemda10vladislavmoyardendvchensaryuvalgrjohhh_mondayandreihryhoryeuinbaldgjosephsamondaykubakolybaczbanueldomoriatmatanlaavivgialonschatzidanordanamumondaymichallorsrdjan-mondayggaallshanmondaytomerzloophirdojohnny-morfilip-daca-mondayurielwasyngchrisbamondayamitmazor37jakubmoflistoded_by_mondaymichaljanovroamitcogalspmondayyaaraweinbaltaorelco2eyallealexjalbaamithadarradva-gonshrotemseaviyaselarichardmaorcomondayronov1shoshanynaamayagalko_mondaynadavshteinbergelenaliyovelnaroteminbarmayanraficalisadanivsatalbe197dave-rosebergernadavguhosannaougregra81bernardpo-mondayeviatharmnoaraposhayalhadarzaronavmondaytaniasigal_finger_mondaylirondolihibmmichaelimasyoavtekanganmarta-mondayarielklmichalbeldyh1213dvirpeshaharshakitomasztarczynskisimonshshalevkemaor-barazanimarcinko-mondaydanielga-mondayeliyaplsapir_baryavgenypaomergrinigorczmayaisyoavsttim-mondaygalbralonagegil_zilbermanleimoniomndadirhgrzegorzrojekorilatomhousmantomkochromkadrialiorshwnivyahyotamhermesroni-ben-aharontomnisimmoro256litalwshirazbehar2cezarylavasilyklaviel_hershkovitzanyakhmayabarkanmatanmamanbenmamondaydoron.brikmanliorl-mondaytalhararitalshetsemachlilotanyuranramhillelidangaadam_scottpiotrdu-mondayephraimgrjakubso2749yevgenilidorsimmmichaelvamondaynettazigioraguatmondayyahorzhshaharzianastasiyakhomrialpolinanadongwhiatmondayjonathanbibasofir-efraimmiloszpi-mondaykarolszmndyyardengavdanielmo-mondayorly_spivaktalketalibl.mondaysandeepkmondayorfriwaseemabnoy-diamantamirkeantonigmashb22neyemaawmeirawislovskyrzmndrangr-mondayyossisaadi.mondayjonathansetheidoguyhadasdoryehudaronco99olegsh_mondayjr-mondayomerradaniel_barashitaimondayirawironapeitamarshsergeiliamichaymondaydord2ronenmoyuvalbatashgiladar-mondaygiladscjonmathewsmondaymiritwodavidgohbergmaor-kaitamarchdanimaniamiteysivansolmagnus_gabornofarmooliviadayuliagoldbergarielgrgalfaalexpoalonaavnuriel_mondaypiotrkoronifischlimyonatanbi-mondaylauremoben_levyehuda_npm2lidornitzanaranweb-mondayhananmaeladna-mondaydorsimm2naorssamwilukaszmichuziabasafswadmonsatalkorv0vs-mondayliran-brimer-mondayj3nn4pavivzafraniyoniho_mnatalyrapinizovickyhitiagopi-mondayomrico100danielepidanmoraladirmonidohatomerganegevmaroeefa88yosia1990rivkaungarnogakrilmaornakasheliyahumanymondayadirhaziz2mikidavidiamichaltori-mondayalongolokinerethanatishshalevhadkuzaleksnatanrolnik_mndkapusjdoronsiavileviliranroorizvidamondayalexpekamalwo-mondayasaf472mondaymia-hohadla-mondaylaurazajdnermeirav_ronnpm-vibeboazanaeviatarsayaairalnoamco-mondaymia_newmannurkiewicznoamst-mondaymichael-azimovnitzanshisaridandavidcoopertomreedeschanlerhilineemanyuvalseidanpedronilaitaykalmoshiko_ben_avimondayshpiglifynoamagoodmandimaalgadshrotemdushirakohavimaxime.mondaydanielvagabriel.amraminbalzitomasz-fijalkowski-mondayalmogrudaniilvomondayjohnbashanyeroni_adarthomasjo25tomaszlamondayeden-eitanitom-katzdoniawaedogr1yonataneleladdolukasz-dudzinskitom_shlomikaitlynloodedsandaknoelia-mondaydinmaaniugbopaulinalaskohodayaiseinatboalexandrzhmichalpl-mondayiradcoziv-shechtmannitzanholmes718eliasgaidoagitaysimjacksnettyoniho_mondayroiatiasraunaq-mondayeladmondaytomasfelderibgudmanneriri14maanumeodedsaran_zarbivitcerbyseanch.mondaytadlamnir1111antonludaniellevertmanartemch-extlglynn13tslilbutamarch.monday.comalonsimondayyaellirachelskneta-nachmias-cohenbrittdalilach.kimhi.rossmanaliciareidyshahargmndamitlisimontakevinmondayronilevitlaurefegatzmonamirmatalon87ramamityoniarvivkrzysztoffimondaycountach88ronbrannapalganadiaddanielwejanbr-ctrlortalgudismelissalmayorasshaipa-uxrmidatafarmarcin-gabalonedelmanmonday1bepomndymulhamhaorromonksushakmaslomonday2sharon-sotalbamakuba_niemiecyoavroofekpintoknadavhachamovnitai-monday-npmnadavkoshirawegrzegorzswcoralinamitbenmorlaver_mondaysimohanounaohad-katzavguykorenmeytalfredavidbr1donia2610nicole_kezlik2awallace327kamieshamischnitzer1galbenoziliomdymortzmondayyonatanlemahmoudna-mondayromanshapransarusiliorla13liors619dh94adamyahidhagaiweyoni-mondayshirlyraomerfoxrivkapelegjakubrohledermaslomaslo5mohamedigtomaszjackowiakshayo-arraphaeloufabiotaatmondayishandua-mondayhadarahtomrezmatthewtoilyamezidozitdamianmarek-mondaysheenananurenbergvovarangr1-mondayandrewlo-mondaynaormondaymaxdv-4016katedubouskayaliortalmondaymaor-karohadargevadominikko-mondaynovrosenamnharveyr-mondayramimonday90ranku_mondayedenbenegevma2eyalmondaychenbeturdorbi_mondayidanpeduiemst_tomerthibaudduavilevi768988tomerstrivkasc2naorsmondayyuval-moshe-mndyyardenlicarmeldahanofekkisagilinshitsjohnnpmman2025shaygrjeremybarneidozibarakzashamilgibukun-mondaysagibarkol89alonsegalofrichenyuvallev-mondayshannon-mondayjoel-mondaymichaelozmondaybenlivniapeslinnaorsolmondaysergeytsibulnik3jonathanadlerliatyaalonmorgenellaportnovadelebemichaelaritamarhileahorlinruthiedaramirferonykrishtalitaypa777reutlevyeithanhollandermondaybenhagiladomyuriisrohyiamirnajjarmohamedig1odedgonuri-mondaynavelelironamzivha-mondayshirzazvimintsasif_d_dromihilakislevtommateran_zidkiyastavraozkamaofirstdordvalonadadvirshtamarshemark-watkin-mondayshimony-urieltzvico-mondayasafbashiriohadleshnoor-mondayaviramashkenazi-monjihyunum-mondaydanielkorichguymarushchenkobruchim_mondaytomda-mondaymiroslawwonickday-mondayyuvalpadanamalpiroeiyaiddoalmichaldayuvalezkerensoyaarmaypazroiemondayhadarlibmannetaezra1guybe-mondayamitsabag1lorengomusayedahamitreedendoron-mondayfranekmondaylinoymargannoam-yehudasergeisamatanmeyoavkularoniavmonadavsofivaprzemyslawbadiknafoalekseiilandreiyubargaldtbreuerweilyanivridelmichalbudziakurasmulayanhamoshe1100moranosssergeym-mondaylevkomondayyonatanc163matkotolegkaplunohad-mondayandreyolnetta-schezkibotwinickwitosguysimaimonday

Keywords

agentprotocolatpserverapiaillm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:new-function-constructor AI (semgrep): Used only to test if a string is a JS keyword by attempting to parse `var <name>;` — not arbitrary code execution. ai
phantom-deps phantom-dep:@types/acorn AI (phantom-deps): Type-only package; not imported at runtime by convention. ai
phantom-deps phantom-dep:@types/js-yaml AI (phantom-deps): Type-only package; not imported at runtime by convention. ai
phantom-deps phantom-dep:@types/escodegen AI (phantom-deps): Type-only package; not imported at runtime by convention. ai
phantom-deps phantom-dep:@types/jsonwebtoken AI (phantom-deps): Type-only package; not imported at runtime by convention. ai
phantom-deps phantom-dep:@types/babel__traverse AI (phantom-deps): Type-only package; not imported at runtime by convention. ai
phantom-deps phantom-dep:@types/babel__generator AI (phantom-deps): Type-only package; not imported at runtime by convention. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern for server packages. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern. ai
phantom-deps phantom-dep:@opentelemetry/sdk-node AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern. ai
phantom-deps phantom-dep:@opentelemetry/resources AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern. ai
phantom-deps phantom-dep:@opentelemetry/semantic-conventions AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern. ai
phantom-deps phantom-dep:@opentelemetry/exporter-trace-otlp-http AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern. ai
phantom-deps phantom-dep:@opentelemetry/auto-instrumentations-node AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern. ai
phantom-deps phantom-dep:@opentelemetry/exporter-metrics-otlp-http AI (phantom-deps): OpenTelemetry packages referenced in config files; standard observability pattern. ai
phantom-deps phantom-dep:rate-limiter-flexible AI (phantom-deps): Referenced in config files; wildcard version range is a minor concern but stable false positive for this package. ai

Versions (showing 14 of 14)

Version Deps Published
0.25.0 29 / 5
0.24.4 29 / 5
0.24.3 29 / 5
0.19.8 30 / 4
0.19.7 30 / 4
0.19.6 30 / 4
0.19.5 31 / 3
0.19.4 31 / 3
0.19.3 31 / 3
0.19.2 31 / 3
0.19.1 31 / 3
0.18.2 30 / 3
0.17.16 30 / 3
0.17.14 22 / 8

v0.25.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.17.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.