From 0c50d05594ceb0021a16dc627375ae4fd287cb07 Mon Sep 17 00:00:00 2001 From: InTheta <17220028+InTheta@users.noreply.github.com> Date: Mon, 3 Aug 2026 11:28:10 +0100 Subject: [PATCH] Release cross-platform SDK preview 23 --- .github/workflows/ci.yml | 12 ++++++++++ AGENTS.md | 2 ++ README.md | 16 +++++++------ docs/design-partner-checklist.md | 4 ++-- docs/examples.md | 6 ++--- docs/getting-started.md | 14 +++++------ docs/omni-agent-recipes.md | 2 +- docs/releases/v0.1.0-preview.23.md | 38 ++++++++++++++++++++++++++++++ docs/sdk-api.md | 2 +- docs/user-seller-agent.md | 2 +- docs/x402-integration.md | 4 ++-- package-lock.json | 4 ++-- package.json | 6 ++--- scripts/clean-dist.mjs | 4 ++++ scripts/fresh-dev-setup.mjs | 16 +++++++++++-- scripts/smoke-package.mjs | 37 +++++++++++++---------------- 16 files changed, 117 insertions(+), 52 deletions(-) create mode 100644 docs/releases/v0.1.0-preview.23.md create mode 100644 scripts/clean-dist.mjs diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 542712d..853ac96 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -23,3 +23,15 @@ jobs: - run: npm ci - run: npm run verify - run: npm run artifact:check + + windows-package: + runs-on: windows-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22 + cache: npm + - run: npm ci + - run: npm run package:smoke + - run: npm run artifact:check diff --git a/AGENTS.md b/AGENTS.md index d736481..5811c30 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -36,6 +36,8 @@ - Run `npm run verify` (or `pnpm run verify`) for source, consumer typecheck, tests, package smoke, quickstart, and the clean-room packed install. Keep scripts package-manager neutral. +- Keep package lifecycle and clean-room scripts OS-neutral. Use Node filesystem APIs for cleanup and + invoke installed bins through the active package manager; do not assume Unix `rm` or bin shims. - Keep the clean-room `example:fresh-dev` in `verify`; it must install the packed artifact into a new temporary project, use an unmistakably mock receipt, and perform no external request or spend. - Keep installed `acm partner-check` no-spend by default. Its funded path must require both a diff --git a/README.md b/README.md index d021c54..58cb2dd 100644 --- a/README.md +++ b/README.md @@ -6,12 +6,14 @@ Give an AI agent permission to buy **one exact x402 resource** under a bounded g > Developer preview. The protected buyer flow is implemented and tested on Base Sepolia. Seller and data-exchange helpers are experimental local previews; they do not settle payments or prove buyer demand. +Current release: [`v0.1.0-preview.23`](docs/releases/v0.1.0-preview.23.md). + ## 60-second no-spend check Requirements: Node.js 20+ and internet access. No clone, account, wallet, or private key is required. ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz doctor \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz doctor \ > acm-no-spend-report.json ``` @@ -32,7 +34,7 @@ The check reads Coinbase's public x402 Bazaar catalog, confirms all nine canonic ## Five-minute local demo ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo buyer +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo buyer ``` The deterministic demo creates a bounded grant, validates a fresh synthetic result, revokes the grant, and proves the next request is denied. Any `0xmock_...` receipt is deliberately not a chain transaction. @@ -40,7 +42,7 @@ The deterministic demo creates a bounded grant, validates a fresh synthetic resu ## Install as a dependency ```bash -npm install github:InTheta/agent-capability-middleware#v0.1.0-preview.22 +npm install github:InTheta/agent-capability-middleware#v0.1.0-preview.23 ``` ```ts @@ -75,7 +77,7 @@ After an ACM operator provides a protected gateway URL and confirms its dedicate ```bash export ACM_GATEWAY_URL='https://provided-gateway.example' export ACM_CONFIRM_TESTNET_SPEND=yes -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz partner-check \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz partner-check \ > acm-paid-report.json unset ACM_API_KEY ACM_CONFIRM_TESTNET_SPEND ``` @@ -126,9 +128,9 @@ MCP can carry tool calls, OAuth/OIDC can identify workloads and users, verifiabl ACM also explores the other side of the market: a developer can describe a paid API, and a user can offer a confirmed, minimized capability under **Free, Paid, Ask, or Deny** policy. These helpers are useful for product design and local testing, but they are not yet hosted settlement, fulfilment, an auction, or a production data marketplace. ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo developer-seller -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo user-seller -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo exchange +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo developer-seller +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo user-seller +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo exchange ``` See [runnable examples](docs/examples.md) and the [user seller preview](docs/user-seller-agent.md). diff --git a/docs/design-partner-checklist.md b/docs/design-partner-checklist.md index 596494b..9fe441f 100644 --- a/docs/design-partner-checklist.md +++ b/docs/design-partner-checklist.md @@ -22,7 +22,7 @@ No clone, Git installation, account, environment file, or wallet is required: ```bash node --version -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz doctor \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz doctor \ > acm-no-spend-report.json ``` @@ -60,7 +60,7 @@ Enter the credential through a hidden prompt: ```bash export ACM_GATEWAY_URL='https://provided-gateway.example' export ACM_CONFIRM_TESTNET_SPEND=yes -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz partner-check \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz partner-check \ > acm-paid-report.json unset ACM_API_KEY ACM_CONFIRM_TESTNET_SPEND ``` diff --git a/docs/examples.md b/docs/examples.md index ec15de7..71ce4af 100644 --- a/docs/examples.md +++ b/docs/examples.md @@ -7,7 +7,7 @@ Start with the buyer path. Seller and exchange examples are clearly separated be From any empty directory with Node.js 20+: ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz partner-check \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz partner-check \ > acm-no-spend-report.json ``` @@ -27,7 +27,7 @@ Expected fields: ## 2. Deterministic buyer demo — no spend ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo buyer +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo buyer ``` This demonstrates the policy lifecycle without a chain transaction: @@ -45,7 +45,7 @@ Run only after an ACM operator provides a protected gateway URL and confirms its ```bash export ACM_GATEWAY_URL='https://provided-gateway.example' export ACM_CONFIRM_TESTNET_SPEND=yes -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz partner-check \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz partner-check \ > acm-paid-report.json unset ACM_API_KEY ACM_CONFIRM_TESTNET_SPEND ``` diff --git a/docs/getting-started.md b/docs/getting-started.md index 12afb3e..de78181 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -9,7 +9,7 @@ Requirements: Node.js 20+ and npm. The first two steps require no account, walle Run the pinned preview from any empty directory: ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz doctor \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz doctor \ > acm-no-spend-report.json ``` @@ -30,7 +30,7 @@ This checks Coinbase's public x402 Bazaar catalog, the nine canonical Omni route ## 2. Run the buyer lifecycle locally ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo buyer +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo buyer ``` Expected outcome: @@ -47,7 +47,7 @@ The local `0xmock_...` receipt is not a blockchain transaction. ```bash mkdir acm-example && cd acm-example npm init -y -npm install github:InTheta/agent-capability-middleware#v0.1.0-preview.22 +npm install github:InTheta/agent-capability-middleware#v0.1.0-preview.23 ``` Create `buy-market-risk.mjs`: @@ -86,7 +86,7 @@ Stop until an ACM operator provides a protected gateway URL and confirms its ded ```bash export ACM_GATEWAY_URL='https://provided-gateway.example' export ACM_CONFIRM_TESTNET_SPEND=yes -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz partner-check \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz partner-check \ > acm-paid-report.json unset ACM_API_KEY ACM_CONFIRM_TESTNET_SPEND ``` @@ -121,9 +121,9 @@ The paid report must show a public receipt, an ACM audit event, fresh `market_ri These are local offer-policy helpers, not live settlement or marketplace claims: ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo developer-seller -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo user-seller -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo exchange +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo developer-seller +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo user-seller +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo exchange ``` See [runnable examples](examples.md) for their exact boundaries. diff --git a/docs/omni-agent-recipes.md b/docs/omni-agent-recipes.md index fbade47..03edb76 100644 --- a/docs/omni-agent-recipes.md +++ b/docs/omni-agent-recipes.md @@ -5,7 +5,7 @@ into exact URLs, expected schemas, prices, and Base Sepolia payment constraints wallet key in agent code. ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz recipes +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz recipes ``` This command plans requests only. It does not create a grant, sign, or pay. diff --git a/docs/releases/v0.1.0-preview.23.md b/docs/releases/v0.1.0-preview.23.md new file mode 100644 index 0000000..366aaf0 --- /dev/null +++ b/docs/releases/v0.1.0-preview.23.md @@ -0,0 +1,38 @@ +# ACM SDK v0.1.0-preview.23 + +Release date: 3 August 2026 + +`preview.23` is the first preview whose packed-install verification is enforced on both Linux and +Windows. It preserves the `preview.22` public API and fixes the package lifecycle scripts so a +Windows developer can build and pack the SDK without a Unix `rm` executable. + +## Public entry points + +Run the live, read-only readiness check without cloning the repository or creating a payment: + +```bash +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz doctor +``` + +Install the SDK as a pinned dependency: + +```bash +npm install github:InTheta/agent-capability-middleware#v0.1.0-preview.23 +``` + +## Verified scope + +- nine canonical Omni HTTP x402 route templates; +- four bounded paid Omni MCP tools plus the free catalog tool; +- exact grant, resource, network, asset, amount and payee binding; +- protected gateway custody—the public SDK accepts no payer private key; +- no-spend doctor and deterministic buyer demo; +- explicitly armed Base Sepolia partner acceptance; +- clean packed installation, consumer type checking and CLI execution; +- Windows and Linux packaging. + +## Boundaries + +This remains a developer preview. It does not provide a public hosted ACM gateway, tenant +isolation, autonomous mainnet spending, or a live user-data marketplace. Mainnet use remains a +separate operator-controlled gateway capability and is not enabled by installing this package. diff --git a/docs/sdk-api.md b/docs/sdk-api.md index b85a87a..e966e5e 100644 --- a/docs/sdk-api.md +++ b/docs/sdk-api.md @@ -20,7 +20,7 @@ This is the complete reference. New integrations should begin with the Until npm publication, run the CLI directly from GitHub: ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz inspect +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz inspect ``` All `demo` commands are local, keyless, and non-settling. diff --git a/docs/user-seller-agent.md b/docs/user-seller-agent.md index d4741a2..b8d8ca9 100644 --- a/docs/user-seller-agent.md +++ b/docs/user-seller-agent.md @@ -5,7 +5,7 @@ The public SDK now includes a local, keyless preview of **Sell one capability**. ## Try it ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz demo user-seller +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz demo user-seller ``` The example creates one user-confirmed running-shoe purchase intent and evaluates a fixed-price request. It does not settle payment. diff --git a/docs/x402-integration.md b/docs/x402-integration.md index 15e1690..2dc6d7f 100644 --- a/docs/x402-integration.md +++ b/docs/x402-integration.md @@ -89,7 +89,7 @@ The installed acceptance runner creates a 15-minute grant restricted to `x402.pa phase first: ```bash -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz partner-check \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz partner-check \ > acm-no-spend-report.json ``` @@ -99,7 +99,7 @@ payer is ready, explicitly arm one paid acceptance: ```bash export ACM_GATEWAY_URL='https://provided-gateway.example' export ACM_CONFIRM_TESTNET_SPEND=yes -npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.22.tar.gz partner-check \ +npx --yes https://github.com/InTheta/agent-capability-middleware/archive/refs/tags/v0.1.0-preview.23.tar.gz partner-check \ > acm-paid-report.json unset ACM_API_KEY ACM_CONFIRM_TESTNET_SPEND ``` diff --git a/package-lock.json b/package-lock.json index 2869e80..a9f833a 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@agent-capability-middleware/sdk", - "version": "0.1.0-preview.22", + "version": "0.1.0-preview.23", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@agent-capability-middleware/sdk", - "version": "0.1.0-preview.22", + "version": "0.1.0-preview.23", "license": "Apache-2.0", "bin": { "acm": "dist/cli.js" diff --git a/package.json b/package.json index aa02cd0..29eed2c 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@agent-capability-middleware/sdk", - "version": "0.1.0-preview.22", + "version": "0.1.0-preview.23", "description": "TypeScript SDK for policy-bound x402 buying and experimental capability offers", "type": "module", "license": "Apache-2.0", @@ -39,7 +39,7 @@ } }, "scripts": { - "build": "rm -rf dist && tsc -p tsconfig.json", + "build": "node scripts/clean-dist.mjs && tsc -p tsconfig.json", "typecheck": "tsc --noEmit -p tsconfig.json", "typecheck:consumer": "tsc -p tsconfig.json && tsc --noEmit --strict --target ES2022 --module NodeNext --moduleResolution NodeNext examples/typecheck.ts", "test": "tsc -p tsconfig.json && node --test tests/*.test.mjs", @@ -57,7 +57,7 @@ "artifact:check": "npm run build && git diff --exit-code -- dist", "cli:smoke": "tsc -p tsconfig.json && node dist/cli.js doctor --local && node dist/cli.js help", "verify": "tsc --noEmit -p tsconfig.json && tsc -p tsconfig.json && tsc --noEmit --strict --target ES2022 --module NodeNext --moduleResolution NodeNext examples/typecheck.ts && node --test tests/*.test.mjs && node scripts/verify-offers.mjs && node scripts/verify-partner-check.mjs && node examples/developer-sells-api.mjs && node examples/user-sells-capability.mjs && node examples/data-exchange.mjs && node examples/omni-agent-recipes.mjs && node scripts/smoke-package.mjs && node scripts/run-quickstart.mjs && node scripts/fresh-dev-setup.mjs && node dist/cli.js doctor --local && node dist/cli.js recipes && node dist/cli.js demo exchange && node dist/cli.js help", - "prepack": "rm -rf dist && tsc -p tsconfig.json" + "prepack": "node scripts/clean-dist.mjs && tsc -p tsconfig.json" }, "engines": { "node": ">=20" diff --git a/scripts/clean-dist.mjs b/scripts/clean-dist.mjs new file mode 100644 index 0000000..e6f9b19 --- /dev/null +++ b/scripts/clean-dist.mjs @@ -0,0 +1,4 @@ +import { rmSync } from "node:fs"; +import { resolve } from "node:path"; + +rmSync(resolve("dist"), { recursive: true, force: true }); diff --git a/scripts/fresh-dev-setup.mjs b/scripts/fresh-dev-setup.mjs index 574c785..6e57256 100644 --- a/scripts/fresh-dev-setup.mjs +++ b/scripts/fresh-dev-setup.mjs @@ -49,8 +49,20 @@ try { if (consumer.status !== 0) throw new Error(`Fresh consumer exited ${consumer.status ?? "unknown"}`); if (!consumer.stdout?.includes("FRESH_DEV_MOCK_OK")) throw new Error("Fresh consumer omitted success marker"); } finally { - gateway?.kill("SIGTERM"); - await rm(temporaryDirectory, { recursive: true, force: true }); + if (gateway?.exitCode === null) { + const exited = new Promise((resolveExit) => gateway.once("exit", resolveExit)); + gateway.kill("SIGTERM"); + await Promise.race([ + exited, + new Promise((resolveWait) => setTimeout(resolveWait, 5_000)), + ]); + } + await rm(temporaryDirectory, { + recursive: true, + force: true, + maxRetries: 5, + retryDelay: 100, + }); } function runNpm(arguments_, cwd = process.cwd()) { diff --git a/scripts/smoke-package.mjs b/scripts/smoke-package.mjs index 3fbd189..b0d30a3 100644 --- a/scripts/smoke-package.mjs +++ b/scripts/smoke-package.mjs @@ -65,12 +65,8 @@ try { if (smoke.status !== 0) throw new Error(smoke.stderr || smoke.stdout); process.stdout.write(smoke.stdout); - const cli = spawnSync(join(temporaryDirectory, "node_modules", ".bin", "acm"), ["doctor", "--local"], { - cwd: temporaryDirectory, - encoding: "utf8", - }); - if (cli.status !== 0) throw new Error(cli.stderr || cli.stdout); - const doctorReport = JSON.parse(cli.stdout); + const cliOutput = runInstalledCli(["doctor", "--local"]); + const doctorReport = JSON.parse(cliOutput); if ( doctorReport.ok !== true || doctorReport.mode !== "local" @@ -78,33 +74,25 @@ try { || doctorReport.networkRequestCreated !== false || doctorReport.spent !== false ) { - throw new Error(`Installed ACM CLI did not preserve the key boundary: ${cli.stdout}`); + throw new Error(`Installed ACM CLI did not preserve the key boundary: ${cliOutput}`); } process.stdout.write("EXTERNAL_CLI_SMOKE_OK\n"); - const recipes = spawnSync(join(temporaryDirectory, "node_modules", ".bin", "acm"), ["recipes"], { - cwd: temporaryDirectory, - encoding: "utf8", - }); - if (recipes.status !== 0) throw new Error(recipes.stderr || recipes.stdout); - const recipeReport = JSON.parse(recipes.stdout); + const recipesOutput = runInstalledCli(["recipes"]); + const recipeReport = JSON.parse(recipesOutput); if ( recipeReport.canonicalRouteTemplates !== 9 || recipeReport.catalogedRouteTemplates !== 9 || recipeReport.recipes?.length !== 25 || recipeReport.spent !== false ) { - throw new Error(`Installed ACM CLI returned an invalid recipe plan: ${recipes.stdout}`); + throw new Error(`Installed ACM CLI returned an invalid recipe plan: ${recipesOutput}`); } process.stdout.write("EXTERNAL_RECIPES_CLI_SMOKE_OK\n"); - const exchange = spawnSync(join(temporaryDirectory, "node_modules", ".bin", "acm"), ["demo", "exchange"], { - cwd: temporaryDirectory, - encoding: "utf8", - }); - if (exchange.status !== 0) throw new Error(exchange.stderr || exchange.stdout); - if (!exchange.stdout.includes("ACM_EXCHANGE_DEMO_OK")) { - throw new Error(`Installed ACM CLI could not run the exchange demo: ${exchange.stdout}`); + const exchangeOutput = runInstalledCli(["demo", "exchange"]); + if (!exchangeOutput.includes("ACM_EXCHANGE_DEMO_OK")) { + throw new Error(`Installed ACM CLI could not run the exchange demo: ${exchangeOutput}`); } process.stdout.write("EXTERNAL_EXCHANGE_CLI_SMOKE_OK\n"); } finally { @@ -116,3 +104,10 @@ function runNpm(arguments_, cwd = process.cwd()) { if (result.status !== 0) throw new Error(result.stderr || result.stdout); return result.stdout; } + +function runInstalledCli(arguments_) { + const execArguments = npmCli.includes("pnpm") + ? ["exec", "acm", ...arguments_] + : ["exec", "--", "acm", ...arguments_]; + return runNpm(execArguments, temporaryDirectory); +}