Component · for humans & their agents
Source Connector SDK
verified · first-partyactively maintained$0 during beta (was $79)
A provider-neutral SDK for building safe, evidence-backed data connectors. The connector contract, extraction ladder, tamper-evident evidence records and the SSRF, rate-limit and anti-stealth guardrails a real collection pipeline needs -- zero runtime dependencies.
by Code Recycle
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 205 tests
Most scraping code starts as a pile of fetch() calls and regexes and turns into an incident three months later -- a redirect that leaks past an allowlist into a private IP, a price parser that turns 'from $9.99' into a confident $9.99, a debug log that quietly persists a session cookie. This SDK is the connector layer built to make those failure modes structurally hard to reach, extracted so you do not have to re-discover them.
Most scraping code starts as a pile of fetch() calls and regexes and turns into an incident three months later -- a redirect that leaks past an allowlist into a private IP, a price parser that turns 'from $9.99' into a confident $9.99, a debug log that quietly persists a session cookie. This SDK is the connector layer built to make those failure modes structurally hard to reach, extracted so you do not have to re-discover them.
WHAT SHIPS: a SourceConnector contract (implement only the capabilities your source actually has); a DefaultFetcher that cannot be constructed without an explicit policy admission -- exact-host allowlisting, SSRF refusal including the IPv6 transition ranges that embed a private IPv4 address, a body-size cap enforced while streaming, and a fixed truthful User-Agent with zero stealth, fingerprint or proxy surface (enforced by a test that scans the whole source tree for evasion-shaped identifiers); a JSON-LD / embedded-JSON / static-HTML extraction ladder; a price parser that returns integer minor units or null with a stated reason, never a guessed float; evidence records that are scoped, then redacted, then hashed, in that fixed order, so the checksum always covers the redacted bytes; token bucket, backoff with jitter, circuit breaker, kill switch and idempotency keys; and field-coverage drift detection.
You bring your own policy/admission store (a working reference implementation ships in the tests) and your own serving layer if you do not want the built-in fetcher. Ships as compiled ESM plus .d.ts, zero runtime dependencies. Illustrative hosts in comments and tests are RFC 2606 example domains.
VERIFIED: 205 tests, measured by running the suite.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
01Capabilities
Does
- + Rate limits
- + Input validation
- + SSRF prevention
- + Retry and backoff policy
- + Web scraping
- + Web data extraction
- + Circuit breaker
- + Data quality monitoring
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 205/205 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 33 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Sep 19, 2026 | First public release. |