Open source · Apache-2.0
agent-toolkit: small open-source tools for people building AI agents
agent-toolkit is TeamShift's free, open-source collection of small developer tools for people building AI agents and business automations: it lints workflows before they run, verifies and debugs webhook signatures, and plans least-privilege OAuth scopes with human-approval policies.
Who it is for
Anyone shipping an agent or automation that writes to real systems: developers wiring n8n flows or custom agents, platform teams reviewing them, and consultants who set them up for clients. Each tool answers a question that usually gets skipped until something breaks.
The three tools
- workflow-lint (
@teamshift/workflow-lint) is a preflight linter for n8n exports and a small YAML or JSON workflow spec. Nine rules catch missing error handling, retries without idempotency keys, unapproved money, delete or send steps, missing timeouts, hardcoded secrets, unbounded loops, unverified webhooks and personal data sent to an LLM. Output goes to the terminal, JSON or SARIF. - webhook-inspect (
@teamshift/webhook-inspect) verifies Stripe, GitHub, Shopify, Slack, Twilio and generic HMAC signatures with WebCrypto, explains each event, and diagnoses why a signature fails. The CLI adds a local capture server and a replay command. - permission-planner (
@teamshift/permission-planner) turns intended agent actions into the minimum OAuth scopes and API permissions for Google Workspace, Microsoft Graph, Slack, HubSpot, QuickBooks Online, Stripe and Shopify, plus a risk tier and an approval policy. Every scope links to the provider's documentation.
How it works
Each tool has three parts: a pure TypeScript core with no Node.js built-ins, a CLI you run with npx, and a test suite. Because the cores are browser-safe, the same code powers the free pages on this site, where nothing you paste is sent anywhere. The only runtime dependency in the whole toolkit is the yaml parser, used by the two tools that read YAML.
They target the three places agents and automations tend to fail: the workflow itself (a retried payment, an unapproved customer email), the inbound edge (a webhook that fails its signature check for an invisible reason), and the permission boundary (an agent with far broader OAuth scopes than it needs).
Quickstart
npx @teamshift/workflow-lint my-n8n-workflow.json
npx @teamshift/webhook-inspect verify --provider stripe --secret whsec_... --header 't=...,v1=...' --body-file body.json
npx @teamshift/permission-planner plan --actions gmail.send,hubspot.write_deals,stripe.refund
Example
Run permission-planner on an accounts-receivable agent that reads Gmail, sends reminders, writes HubSpot deals and issues Stripe refunds, and it reports the highest risk tier as money, lists gmail.readonly as a Google restricted scope, warns that a requested https://mail.google.com/ is broader than needed, and recommends that refunds always wait for a person.
Limitations
- workflow-lint reads n8n exports and its own generic spec. Other tools need their workflow described in that spec.
- Some n8n checks are heuristics, for example how it recognizes a completion check. Treat a clean report as a floor, not proof.
- webhook-inspect covers six signature schemes. Providers outside that list need the generic HMAC mode.
- The permission catalog covers 89 actions. Stripe restricted-key labels are marked unverified, and an action outside the catalog is reported as unknown rather than guessed.
FAQ
What is agent-toolkit?
agent-toolkit is an open-source, Apache-2.0 collection of three developer tools from TeamShift: workflow-lint, webhook-inspect and permission-planner. Each has a browser-safe TypeScript core, a CLI and a test suite.
Do the browser versions send my data anywhere?
No. The pages at teamshift.io/tools run the same pure cores client-side. Workflows, webhook secrets and bodies you paste stay in your browser tab.
Can I run the tools in CI?
Yes. workflow-lint can write SARIF for GitHub code scanning or JSON for custom gates, and exits non-zero on error-severity findings. permission-planner exits non-zero when an action is not in its catalog, and webhook-inspect verify exits non-zero when a signature fails.
How do I add a rule, provider or catalog entry?
Open a pull request on GitHub. Every lint rule needs a good and a bad fixture, and every permission-catalog entry needs an official source URL, or an explicit unverified status when it cannot be confirmed.