# What Dependencies Does the Kimi Code Agent-Core Package Have? A Complete Breakdown

> Discover the complete list of runtime dependencies for the Kimi Code agent-core package. Understand its dependencies including image processing, HTTP clients, and utilities.

- Repository: [Moonshot AI/kimi-code](https://github.com/MoonshotAI/kimi-code)
- Tags: api-reference
- Published: 2026-08-14

---

**The `@moonshot-ai/agent-core` package depends on 27 runtime dependencies including workspace-local packages, image processing libraries, HTTP clients, validators, and utilities defined in its [`package.json`](https://github.com/MoonshotAI/kimi-code/blob/main/package.json).**

The agent-core package forms the heart of MoonshotAI's Kimi Code, powering agent orchestration, session management, and tool execution. Understanding its dependency tree reveals the architectural priorities: Type-safe validation, fast HTTP communication, robust file handling, and seamless image processing. All dependencies are declared in [`packages/agent-core/package.json`](https://github.com/MoonshotAI/kimi-code/blob/main/packages/agent-core/package.json) and implemented throughout `src/`.

## Runtime Dependencies in Agent-Core

The package splits its requirements into runtime dependencies (shipped with production builds) and development dependencies (build/test only). Below are the production-critical packages.

### Core Framework and Internal Packages

Four **workspace-local packages** provide Kimi Code's foundational layers:

| Package | Purpose |
|---------|---------|
| **@moonshot-ai/kaos** | Internal "kaos" library for core abstractions |
| **@moonshot-ai/kimi-code-oauth** | OAuth authentication flow helpers |
| **@moonshot-ai/kosong** | Provider-abstraction layer for model routing |
| **@moonshot-ai/protocol** | Core protocol definitions for agent communication |

These use `workspace:^` versioning, ensuring consistent internal API contracts across the monorepo.

### HTTP, Networking and Protocol

- **undici** (`^7.27.1`) — Fast HTTP client optimized for Node.js ≥18, used for all outbound model API calls
- **socks** (`^2.8.9`) — SOCKS proxy client for network tunneling
- **@modelcontextprotocol/sdk** (`^1.29.0`) — Official SDK implementing the Model Context Protocol standard

### Validation and Schema

- **zod** (`^4.3.6`) — Runtime schema validation with TypeScript type inference
- **ajv** (`^8.18.0`) — JSON Schema validator for configuration files
- **ajv-formats** (`^3.0.1`) — Extended format validators (email, URI, date-time) for AJV

### Image and Media Processing

- **jimp** (`^1.6.1`) — Pure-JavaScript image manipulation (resize, crop, format conversion)
- **@jsquash/webp** (`^1.5.0`) — WebP encoding/decoding for efficient model-compatible images

### File System and I/O Utilities

- **chokidar** (`^4.0.3`) — File-watcher enabling hot-reload during development
- **ignore** (`^5.3.2`) — `.gitignore`-style pattern matching for file filtering
- **pathe** (`^2.0.3`) — Cross-platform path utilities (POSIX/Windows normalization)
- **picomatch** (`^4.0.4`) — Fast glob pattern matcher
- **proper-lockfile** (`^4.1.2`) — Process-safe file locking
- **tar** (`^7.5.13`) — TAR archive creation and extraction
- **yauzl** (`^3.3.0`) — ZIP file reader for archive inspection

### Data Parsing and Templating

- **js-yaml** (`^4.1.1`) — YAML parsing and stringifying
- **smol-toml** (`^1.6.1`) — Lightweight TOML parser
- **nunjucks** (`^3.2.4`) — Jinja-style templating engine for dynamic prompts

### Terminal, Browser and Misc

- **node-pty** (`^1.1.0`) — Pseudo-terminal handling for shell command execution
- **linkedom** (`^0.18.12`) — Fast DOM implementation for server-side HTML parsing
- **@mozilla/readability** (`^0.6.0`) — Extracts article content from web pages
- **open** (`^10.2.0`) — Cross-platform file/URL opener
- **ulid** (`^3.0.1`) — Universally-unique lexicographically-sortable identifiers
- **retry** (`0.13.1`) — Resilient retry logic with exponential backoff
- **regexp.escape** (`^2.0.1`) — Escapes special RegExp characters
- **@antfu/utils** (`^9.3.0`) — General-purpose utility functions

## How Agent-Core Uses Its Dependencies

### HTTP Client: Undici in ProviderManager

In [`packages/agent-core/package.json`](https://github.com/MoonshotAI/kimi-code/blob/main/packages/agent-core/package.json), **undici** provides the HTTP foundation. The provider system in [`src/session/provider-manager.ts`](https://github.com/MoonshotAI/kimi-code/blob/main/src/session/provider-manager.ts) leverages it for model API communication:

```typescript
// packages/agent-core/src/session/provider-manager.ts pattern
import { fetch } from 'undici';

class RemoteProvider implements ModelProvider {
  async generate(prompt: string) {
    const response = await fetch(this.endpoint, {
      method: 'POST',
      headers: { 'Authorization': `Bearer ${this.key}` },
      body: JSON.stringify({ prompt })
    });
    return response.json();
  }
}

```

### Schema Validation: Zod and AJV

**zod** handles runtime type safety for external data, while **ajv** validates JSON configuration files. From [`src/config/index.ts`](https://github.com/MoonshotAI/kimi-code/blob/main/src/config/index.ts):

```typescript
import { z } from 'zod';

export const AgentConfigSchema = z.object({
  name: z.string(),
  maxTurns: z.number().int().positive(),
  provider: z.string()
});

// Type inference from schema
export type AgentConfig = z.infer<typeof AgentConfigSchema>;

```

### Image Compression: Jimp and WebP

The [`src/tools/support/image-compress.ts`](https://github.com/MoonshotAI/kimi-code/blob/main/src/tools/support/image-compress.ts) module combines **jimp** and **@jsquash/webp** to prepare images for vision models:

```typescript
import { Jimp } from 'jimp';
import { encode } from '@jsquash/webp`;

export async function compressImageForModel(
  buffer: Buffer,
  options: { maxEdgePx: number }
): Promise<Uint8Array> {
  // Resize with Jimp, encode to WebP for efficiency
  const image = await Jimp.read(buffer);
  const resized = image.resize({ w: options.maxEdgePx });
  const raw = new Uint8Array(resized.bitmap.data);
  return encode(raw, { quality: 85 });
}

```

### File Watching: Chokidar

Hot-reload functionality uses **chokidar** to monitor configuration changes:

```typescript
import { watch } from 'chokidar';

const watcher = watch('./config/**/*.{json,yaml}', {
  ignoreInitial: true,
  persistent: true
});

watcher.on('change', (path) => reloadConfig(path));

```

## Development-Only Dependencies

The `devDependencies` section includes type definitions (`@types/*`), testing utilities (`sinon`), and build tools. Notable entries:

- **sinon** — Spies, stubs, and mocks for unit testing
- **yazl** — ZIP file creation (complementing **yauzl** for reading)
- TypeScript declaration files for untyped packages

These are excluded from production builds via proper [`package.json`](https://github.com/MoonshotAI/kimi-code/blob/main/package.json) scoping.

## Dependency Architecture Summary

The agent-core dependency design follows three principles visible in [`packages/agent-core/package.json`](https://github.com/MoonshotAI/kimi-code/blob/main/packages/agent-core/package.json):

| Principle | Implementation |
|-----------|----------------|
| **Monorepo cohesion** | Workspace-local packages (`@moonshot-ai/*`) share protocol definitions |
| **Performance** | Native-speed libraries (undici, jimp with WASM WebP) for I/O-heavy paths |
| **Reliability** | Validation at boundaries (zod, ajv) and resilience patterns (retry, proper-lockfile) |

## Summary

- The **@moonshot-ai/agent-core** package declares **27 runtime dependencies** in [`packages/agent-core/package.json`](https://github.com/MoonshotAI/kimi-code/blob/main/packages/agent-core/package.json)
- **Four workspace-local packages** (`kaos`, `kosong`, `protocol`, `kimi-code-oauth`) provide internal integration
- **undici** serves as the primary HTTP client, replacing Node's native fetch for performance
- **zod** and **ajv** form a dual-layer validation strategy: Zod for TypeScript-native schemas, AJV for JSON Schema compliance
- **jimp** and **@jsquash/webp** enable browser-free image processing for multimodal agents
- **chokidar**, **proper-lockfile**, and **retry** support resilient, watchable, concurrent-safe operations

## Frequently Asked Questions

### What HTTP client does agent-core use and why?

**undici** (`^7.27.1`). It outperforms Node's native fetch with connection pooling, interceptors, and lower overhead—critical for high-throughput model API calls in [`src/session/provider-manager.ts`](https://github.com/MoonshotAI/kimi-code/blob/main/src/session/provider-manager.ts).

### How does agent-core validate configuration files?

**Dual validation**: **zod** for TypeScript-first runtime types with inference, **ajv** for strict JSON Schema compliance on external config files. This pattern appears in [`src/config/index.ts`](https://github.com/MoonshotAI/kimi-code/blob/main/src/config/index.ts) across the codebase.

### Why does agent-core need both jimp and @jsquash/webp?

**jimp** handles general image manipulation (resize, crop, format detection) in pure JavaScript, while **@jsquash/webp** provides optimized WebP encoding via WASM. Together they compress images for vision models without external binary dependencies.

### What's the difference between yauzl and the devDependency yazl?

**yauzl** (runtime) reads ZIP archives for tool inspection and extraction. **yazl** (dev-only) creates ZIP files for packaging tests and build artifacts. This read/write separation keeps production bundles smaller.