Skip to content
Code Recycle

Component · for humans & their agents

Source Connector SDK

verified · first-partyactively maintained$0 during beta (was $79)

A provider-neutral SDK for building safe, evidence-backed data connectors. The connector contract, extraction ladder, tamper-evident evidence records and the SSRF, rate-limit and anti-stealth guardrails a real collection pipeline needs -- zero runtime dependencies.

by Code Recycle

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 205 tests

Most scraping code starts as a pile of fetch() calls and regexes and turns into an incident three months later -- a redirect that leaks past an allowlist into a private IP, a price parser that turns 'from $9.99' into a confident $9.99, a debug log that quietly persists a session cookie. This SDK is the connector layer built to make those failure modes structurally hard to reach, extracted so you do not have to re-discover them.

Most scraping code starts as a pile of fetch() calls and regexes and turns into an incident three months later -- a redirect that leaks past an allowlist into a private IP, a price parser that turns 'from $9.99' into a confident $9.99, a debug log that quietly persists a session cookie. This SDK is the connector layer built to make those failure modes structurally hard to reach, extracted so you do not have to re-discover them.

WHAT SHIPS: a SourceConnector contract (implement only the capabilities your source actually has); a DefaultFetcher that cannot be constructed without an explicit policy admission -- exact-host allowlisting, SSRF refusal including the IPv6 transition ranges that embed a private IPv4 address, a body-size cap enforced while streaming, and a fixed truthful User-Agent with zero stealth, fingerprint or proxy surface (enforced by a test that scans the whole source tree for evasion-shaped identifiers); a JSON-LD / embedded-JSON / static-HTML extraction ladder; a price parser that returns integer minor units or null with a stated reason, never a guessed float; evidence records that are scoped, then redacted, then hashed, in that fixed order, so the checksum always covers the redacted bytes; token bucket, backoff with jitter, circuit breaker, kill switch and idempotency keys; and field-coverage drift detection.

You bring your own policy/admission store (a working reference implementation ships in the tests) and your own serving layer if you do not want the built-in fetcher. Ships as compiled ESM plus .d.ts, zero runtime dependencies. Illustrative hosts in comments and tests are RFC 2606 example domains.

VERIFIED: 205 tests, measured by running the suite.

DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.

01Capabilities

Does

  • + Rate limits
  • + Input validation
  • + SSRF prevention
  • + Retry and backoff policy
  • + Web scraping
  • + Web data extraction
  • + Circuit breaker
  • + Data quality monitoring

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

typescript node

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 33 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableSep 19, 2026First public release.