What Are the Dependencies for the Kimi-Code Applications?
Kimi-code distributes its runtime dependencies across a TypeScript monorepo where each package under packages/ declares specific libraries like zod, openai, and chokidar in individual package.json files, while maintaining some packages such as minidb and protocol with zero external dependencies.
The MoonshotAI/kimi-code repository is organized as a modular TypeScript monorepo where functional boundaries determine dependency scopes. Understanding the kimi-code dependencies requires examining each package's manifest, as the architecture intentionally isolates runtime requirements to prevent version conflicts and unnecessary bloat.
Core Agent Engine Dependencies
The agent execution layer resides in two primary packages that share foundational utilities while diverging in LLM provider support.
@moonshot-ai/agent-core (v1) located in packages/agent-core/package.json provides the unified agent engine with dependencies including @modelcontextprotocol/sdk for MCP integration, zod for schema validation, and system utilities like chokidar for file watching, node-pty for terminal emulation, and js-yaml for configuration parsing. Additional libraries such as jimp for image processing, linkedom for DOM manipulation, and tar/yauzl for archive handling support diverse agent workflows.
@moonshot-ai/agent-core-v2 in packages/agent-core-v2/package.json extends the core engine with dependency injection capabilities and directly integrates LLM provider SDKs. Beyond the v1 foundation, it adds @anthropic-ai/sdk, @google/genai, and openai for native multi-provider support, plus @moonshot-ai/minidb for embedded document storage and @moonshot-ai/tree-sitter-bash for parsing Bash scripts.
LLM Provider Abstraction Layer
The @moonshot-ai/kosong package (located in packages/kosong/package.json) serves as the normalization layer between disparate LLM APIs. Its runtime dependencies include @anthropic-ai/sdk, @google/genai, and openai for provider endpoints, alongside zod and zod-to-json-schema for type-safe request/response validation and schema generation. This architecture allows agent-core packages to switch between OpenAI, Anthropic, and Google models without vendor-specific code changes.
SDK and Protocol Dependencies
Client-facing packages maintain lean dependency trees focused on specific developer workflows.
@moonshot-ai/kimi-code-sdk (the Node.js SDK in packages/node-sdk/package.json) depends on @antfu/utils for utility functions, smol-toml for TOML configuration parsing, yazl for ZIP archive creation, and zod for runtime type safety. These dependencies enable SDK consumers to bundle and validate agent configurations without pulling in the full engine weight.
@moonshot-ai/transcript (in packages/transcript/package.json) maintains a minimal footprint with only zod as a runtime dependency, providing isomorphic transcript data validation used across both server and browser contexts.
Infrastructure and Utility Packages
Supporting libraries handle specialized rendering, authentication, and execution tasks with targeted dependencies.
@moonshot-ai/pi-tui (in packages/pi-tui/package.json) powers terminal user interfaces using get-east-asian-width for correct CJK character display and marked for Markdown rendering in terminal environments.
@moonshot-ai/kaos (in packages/kaos/package.json) abstracts execution environments with pathe for cross-platform path handling and ssh2 for remote SSH execution capabilities.
@moonshot-ai/kimi-code-oauth (in packages/oauth/package.json) relies on proper-lockfile to manage filesystem-based token persistence and prevent race conditions during authentication flows.
Zero-Dependency Packages
Two architectural packages operate without external runtime dependencies, reducing supply chain attack surfaces.
@moonshot-ai/minidb (in packages/minidb/package.json) implements an embedded JSON document store used by the global search index using only native TypeScript/JavaScript APIs.
@moonshot-ai/protocol (in packages/protocol/package.json) contains shared REST and WebSocket API type definitions as pure TypeScript interfaces, requiring no third-party libraries at runtime.
Usage Examples
The following snippets demonstrate how these dependencies surface in actual code:
// Using Agent-Core v2 with OpenAI and Anthropic providers
import { Agent } from '@moonshot-ai/agent-core-v2';
import { OpenAIProvider } from '@moonshot-ai/kosong/openai';
import { AnthropicProvider } from '@moonshot-ai/kosong/anthropic';
const agent = new Agent({
provider: new OpenAIProvider({ apiKey: process.env.OPENAI_API_KEY! }),
});
// Runtime validation via zod (dependency of agent-core)
import { z } from 'zod';
agent.addTool({
name: 'summarize',
description: 'Summarize a text block',
schema: z.object({ text: z.string() }),
});
// Rendering Terminal UI with marked (pulled in via pi-tui)
import { render } from '@moonshot-ai/pi-tui';
import { marked } from 'marked';
const markdown = '# Hello\nThis is a **Kimi** TUI demo.';
render(marked(markdown));
// Using the SDK with yazl and smol-toml dependencies
import { createClient } from '@moonshot-ai/kimi-code-sdk';
const client = createClient({ url: 'http://localhost:58627' });
await client.sessions.create({ name: 'demo' });
Summary
- Kimi-code organizes dependencies per-package in a TypeScript monorepo structure under
packages/. - The agent-core packages rely on system utilities (
chokidar,node-pty), validation libraries (zod,ajv), and v2 specifically adds LLM provider SDKs (openai,@anthropic-ai/sdk). @moonshot-ai/kosongnormalizes multiple LLM APIs while handling schema conversion viazod-to-json-schema.minidbandprotocolmaintain zero external runtime dependencies, functioning as pure TypeScript implementations.- Package manifests at paths like
packages/agent-core/package.jsonandpackages/kosong/package.jsonserve as the source of truth for version pinning.
Frequently Asked Questions
How do I install dependencies for a specific kimi-code package?
Install individual packages using your package manager with the scoped name, such as npm install @moonshot-ai/agent-core, which will automatically resolve the specific versions of zod, chokidar, and other dependencies declared in that package's package.json as implemented in the MoonshotAI/kimi-code repository.
Which kimi-code packages have no external dependencies?
Both @moonshot-ai/minidb and @moonshot-ai/protocol operate with zero external runtime dependencies, relying solely on native Node.js APIs and TypeScript type definitions, making them suitable for security-sensitive environments where supply chain minimization is critical.
Why does agent-core-v2 include LLM SDKs directly while agent-core does not?
The v2 engine adopts a dependency-injection scope architecture that requires direct provider instantiation, whereas v1 relies on the @moonshot-ai/kosong abstraction layer; consequently, v2 declares @anthropic-ai/sdk, @google/genai, and openai as direct dependencies while v1 keeps these in the separate kosong package.
Can I use the kimi-code SDK without installing the agent engine?
Yes, the @moonshot-ai/kimi-code-sdk (located in packages/node-sdk/package.json) maintains independent dependencies including @antfu/utils, smol-toml, yazl, and zod, allowing you to interact with Kimi agents via the REST API without pulling in the heavy system dependencies like node-pty or chokidar required by the full engine.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →