@niooon/github
v1.5.2
Published
Self-contained, direct GitHub, Vercel & Supabase Automation SDK & CLI with Permission-First Agent Rules. Directly manages GitHub repositories/workflows, Vercel deployments/projects, and Supabase database/functions/policies.
Maintainers
Readme
@niooon/github - Standalone GitHub, Vercel & Supabase Automation SDK & CLI (@niooon/github)
Self-contained, direct GitHub, Vercel & Supabase Automation SDK & CLI with Permission-First Agent Rules. Directly manages GitHub repositories/workflows, Vercel deployments/projects, and Supabase database/functions/policies.
✨ 100% Self-Contained Automation SDK & CLI:
- GitHub Module: Communicates directly with official GitHub REST API (
https://api.github.com). - Vercel Module: Communicates directly with official Vercel REST API (
https://api.vercel.com). - Supabase Module: Communicates directly with official Supabase Management API (
https://api.supabase.com/v1). - Zero-Retention Vault Key Sourcing: Use a single
NIOOON_PLATFORM_KEYto dynamically fetch scoped credentials on-demand and wipe them from memory immediately after each call. - Permission-First Agent Protocol: Baked-in permission rules (
AGENT_RULES.md) requiring explicit user confirmation before executing any Supabase mutating operations. - Isolated Token Security: Separate environment variables (
GITHUB_TOKEN,VERCEL_TOKEN,SUPABASE_ACCESS_TOKEN). Zero token mixing.
📦 Installation
# Global CLI installation
npm install -g @niooon/github
# Local project installation
npm install @niooon/github⚡ Quick Start: Authentication
🔑 Method 1: Single Unified Platform Key (Zero-Retention Sourcing)
export NIOOON_PLATFORM_KEY="sk_live_your_niooon_platform_key"
# GitHub, Vercel, and Supabase operations are now all unlocked with zero disk exposure!🔐 Method 2: Direct Service Tokens (Backwards-Compatible)
# 1. GitHub PAT
export GITHUB_TOKEN="ghp_yourGitHubPAT"
# 2. Vercel Token
export VERCEL_TOKEN="your_vercel_api_token"
# 3. Supabase Token & Ref
export SUPABASE_ACCESS_TOKEN="sbp_yourSupabaseAccessToken"
export SUPABASE_PROJECT_REF="your_project_ref"🔒 Supabase Permission-First Agent Rule
⚠️ MANDATORY FOR ALL AI AGENTS: Before executing ANY mutating Supabase operation (database query, table creation, function deployment, policy modification), the agent MUST explicitly prompt the user for confirmation detailing the target and impact.
🚀 Programmatic SDK Usage
import { NexusGitHub, NexusVercel, NexusSupabase, NexusVault } from "@niooon/github";
// 1. GitHub Direct Operations (using platform key or GITHUB_TOKEN)
const github = new NexusGitHub({ platformKey: process.env.NIOOON_PLATFORM_KEY });
const repo = await github.repos.get("my-repo");
// 2. Vercel Direct Deployments (using platform key or VERCEL_TOKEN)
const vercel = new NexusVercel({ platformKey: process.env.NIOOON_PLATFORM_KEY });
const deploy = await vercel.deploy.create({ name: "my-frontend" });
// 3. Supabase Management with Baked-in Permissions
const supabase = new NexusSupabase({
platformKey: process.env.NIOOON_PLATFORM_KEY,
});
// Read-only project check
const whoami = await supabase.auth.whoami();
console.log("Supabase Authenticated:", whoami.tokenMasked);
// List database tables
const tables = await supabase.database.listTables();
console.log("Existing Tables:", tables.map(t => t.name));
// Mutating action requiring user confirmation:
// const res = await supabase.database.createTable({
// name: "profiles",
// columns: [{ name: "id", type: "uuid", isPrimary: true }, { name: "email", type: "text" }],
// confirmed: true // Required confirmation flag
// });📄 License
MIT © niooon
