Skip to main content

aker-build

Build SaaS with AI agents without losing architecture control.

Aker Build scans a repository, runs SaaS gates over what it finds, derives a queue, and routes the one next-safest task — along with the exact files that task may touch. It reports; it never mutates your code, commits, merges, or executes an agent.

The package is aker-build; the command it installs is aker.

pip install aker-build
aker check .

Requirements

Node.js 22.13 or newer must be on your PATH.

This wheel carries the compiled JavaScript engine — there is no separate download — but it does not bundle a Node runtime. Install it from nodejs.org. If Node is missing or too old, aker says so in one sentence and exits non-zero; it never prints a traceback for a prerequisite you can fix.

Python 3.9+. The wheel is pure-Python and platform-independent: there is nothing to compile, and no Python dependencies are added to your environment.

Why a Python package wraps a JavaScript engine

The engine is TypeScript and stays the single source of truth; nothing is reimplemented here. This package exists so Python-first toolchains can install the CLI through the dependency path they already use. The launcher locates Node, checks the version floor, executes the bundled engine, and forwards your arguments and its exit code verbatim.

The same version is published on npm — both channels read one version constant, so pip and npm cannot diverge.

What one pass produces

.aker-build/
├── project-map.json         what is in the repo, and what the scanner understands
├── risks.json               gate findings, each with file:line evidence + confidence
├── queue.json               derived work items
├── route.json               the one next-safest task, with the reason it won
├── aker-build-report.json
└── aker-build-report.md

The set is written as one transaction. A failed stage preserves the previous complete set.

Routing, which is the point

$ aker route . --stdout --format json
{
  "next": {
    "id": "Q-002",
    "title": "Fix: API route without an auth guard",
    "reason": [
      "highest score (0.86)",
      "status=ready",
      "tier=confirmed",
      "validation available"
    ]
  },
  "blocked": [
    { "id": "Q-001", "reason": "insufficient evidence to scope a safe action (needs verification)" }
  ]
}

Items are blocked rather than guessed at when evidence is too thin to scope a safe change. confirmed findings can drive action; suspected findings advise and never block.

Scope your scan before the first real run

Detectors read code that looks like a vulnerability, and a security-adjacent test suite is full of deliberately-unsafe examples. On Aker Build's own repository, 76% of findings land in its own test fixtures — each locally correct, most not useful. Create aker-build.config.json at your repo root:

{
  "version": 1,
  "paths": {
    "exclude": ["**/tests/**", "**/*.test.ts", "fixtures/**", "examples/**"]
  }
}

Commands

aker check [path]              # scan → gates → queue → route → report, one read-only pass
aker scan [path]               # produce project-map.json
aker map                       # show / re-emit the produced map
aker gates [path]              # run the gate set (or --gates <ids>), produce risks.json
aker queue [path]              # derive queue.json
aker route [path]              # select one next-safest task + list blocked items
aker prompt <id>               # compile a scoped agent prompt (--agent claude|codex|generic)
aker review-pr [path] --local-diff   # review a local diff → Ready / Not Ready / Needs Verification
aker report [path]             # summarize produced artifacts (--format json|yaml|md)

Common flags: --config <path>, --out <dir>, --stdout, --format json|yaml.

Exit codes: 0 completed · 1 missing prerequisite or not a Git repository · 2 bad input/config or refused scope · 3 internal error. Findings alone never fail a command.

What it will not do

Local-first and read-only on the source it scans. It does not execute AI agents, commit, push, open pull requests, auto-fix, auto-merge, or require GitHub credentials for --local-diff. Secret-like content is flagged without copying the value into any report.

Honest limitations

Detection is regex-based, not parsed. ORM idioms outside the recognised database-handle allow-list and the PascalCase-model convention go unseen, and window-based classifications stay in the suspected tier on purpose.

The scanner reports what it does understand — project-map.coverage.covered and .uncovered — so "no findings" always reads as "no findings in covered frameworks". Covered today: express, prisma, mongoose, knex, sequelize, typeorm, drizzle. Detected but not understood, and reported as such: nextjs, nestjs, fastify, and UI frameworks. An unrecognised stack produces silence, and silence is not safety.

Aker Build analyses TypeScript application-layer query code. For database-layer RLS analysis it complements, rather than replaces, tools such as pgrls.

Detection quality is measured against a labeled corpus that ships in the repository (19 cases) and gated in CI. The scorecard reports absolute counts next to percentages, because those rates rest on 10 true positives.

Links

MIT licensed.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aker_build-0.1.2.tar.gz (131.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aker_build-0.1.2-py3-none-any.whl (129.4 kB view details)

Uploaded Python 3

File details

Details for the file aker_build-0.1.2.tar.gz.

File metadata

  • Download URL: aker_build-0.1.2.tar.gz
  • Upload date:
  • Size: 131.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for aker_build-0.1.2.tar.gz
Algorithm Hash digest
SHA256 8bfb89cb43a709fa83b3f0364aa7ce1a6a035a4745bb3f71aeb819fc5371670d
MD5 11a412697fb9f7d6af1ac3ecef5d4a0a
BLAKE2b-256 8dd646910c4248ace7e8f5a02a39c38a2db8ee9f1d9fec032f8ea7de9a4482dd

See more details on using hashes here.

Provenance

The following attestation bundles were made for aker_build-0.1.2.tar.gz:

Publisher: pypi-release.yml on Kemetra/Aker-Build

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file aker_build-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: aker_build-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 129.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for aker_build-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 b2da1cf4c9f29f5556b50bdd8a33fff449b640e957d3f132e7ed69b3c06f1261
MD5 f627e1e2bd38c2411b11bf9239bc49f3
BLAKE2b-256 e4e9155f5861b9e56508dc75e3c8cc27a2a7d71f934160a47e042bb444ff745c

See more details on using hashes here.

Provenance

The following attestation bundles were made for aker_build-0.1.2-py3-none-any.whl:

Publisher: pypi-release.yml on Kemetra/Aker-Build

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page