@ghostops/sdk
Typed authenticated requests, timeout and cancellation support, correlation IDs, and explicit authentication, policy, containment, and transport failures.
DEVELOPER INTERFACE / LOCAL-FIRST
TypeScript SDK + tools-only MCP stdio integration. Packages are locally installable—not published to npm.
git clone https://github.com/Muzzy5150/ghost-ops.git
cd ghost-ops
npm ci
npm run setup
npm run sdk:build
npm run dev -- --port 3210Source is private; repository access is required. Run setup only in a fresh clone with isolated local state. Do not reset an existing database. Start with scripts/server.ts; direct next start is not an authorized admin transport.
import { GhostOpsClient } from "@ghostops/sdk";
const ghost = new GhostOpsClient({
endpoint: process.env.GHOSTOPS_URL!,
agentId: process.env.GHOSTOPS_AGENT_ID!,
sessionId: process.env.GHOSTOPS_SESSION_ID!,
credential: process.env.GHOSTOPS_AGENT_TOKEN!,
});
const result = await ghost.callTool({
tool: "read_document", arguments: { resource: "docs/research" },
});
await ghost.close();Provision restricted identities through the authorized local operator CLI. Credentials belong in the operator-controlled environment, never frontend code or tool descriptions. Never cache permission decisions or retry effects blindly.
Typed authenticated requests, timeout and cancellation support, correlation IDs, and explicit authentication, policy, containment, and transport failures.
Local stdio initialization, tool discovery, and invocation. It forwards operations to the loopback gateway; it does not introduce a second execution path.
npm run test:external
npm run test:runtime
npm run evidence:verify -- /path/to/approved-evidence.zipThese workflows use bounded synthetic resources. HMAC verification authenticates evidence only under the local signing-key and host trust assumptions. Web Sentinel publication requires separate approval of the exact repository and content.
Authorization is enforced on guarded requests. Unintegrated shell commands, browser actions, direct filesystem operations, and unrelated agent runtimes are outside that boundary. No paid model or sponsor service is required for the offline local demonstration.