Open-core packages (this repo is Vantio Optics):
packages/vantio-cli— CLI runner (@vantio/cli). Install the current release from npm:npm install -g @vantio/clipackages/vantio-agent-sdk-py— Python agent SDK (vantio-agent-sdk). Install the current release from PyPI:pip install vantio-agent-sdkpackages/vantio-agent-sdk— Node.js agent SDK (@vantio/agent-sdk). Install the current release from npm.packages/vantio-optics-mcp— Optics MCP (@vantio/optics-mcp) — observe only
Phantom Engine (Linux host protection) lives outside this repository. Do not add it here. The product page is https://vantio.ai/phantom.
# Install dependencies (pnpm only — see Dependency Governance below)
pnpm install
# Build all packages
pnpm build
# Run CLI directly from source
node packages/vantio-cli/bin/vantio.js
# Type-check the Node SDK
cd packages/vantio-agent-sdk && pnpm exec tsc --noEmitType Safety
The any keyword is banned across the entire TypeScript codebase. Use unknown with strict type guards. PRs containing any will not be merged.
Payload Quarantine No raw user prompts, LLM responses, or PII may be passed to the SDK telemetry payload. Strip all linguistic content at the API boundary before ingestion.
Dependency Governance
pnpm is the only authorized package manager. npm install and yarn are banned to prevent phantom dependency vectors. Do not commit package-lock.json or yarn.lock.
This repository is strictly Ring-3 user-space. Do not submit PRs that introduce:
- eBPF programs, kernel probes, or any Ring-0 logic
- References to
/sys/fs/bpf/,bpf_*helpers, oraya-ebpf - Imports from or dependencies on the proprietary
vantio-phantom-enginerepository
Violations are automatically rejected by CI.
| ✅ In scope | ❌ Out of scope |
|---|---|
@vantio/agent-sdk improvements |
eBPF / kernel code |
vantio CLI enhancements |
Modifications to the Phantom Engine loader |
| Python SDK improvements | Raw syscall hooks or IDS-style telemetry |