What Dependencies Does the Kimi Code Agent-Core Package Have? A Complete Breakdown

The @moonshot-ai/agent-core package depends on 27 runtime dependencies including workspace-local packages, image processing libraries, HTTP clients, validators, and utilities defined in its package.json.

The agent-core package forms the heart of MoonshotAI's Kimi Code, powering agent orchestration, session management, and tool execution. Understanding its dependency tree reveals the architectural priorities: Type-safe validation, fast HTTP communication, robust file handling, and seamless image processing. All dependencies are declared in packages/agent-core/package.json and implemented throughout src/.

Runtime Dependencies in Agent-Core

The package splits its requirements into runtime dependencies (shipped with production builds) and development dependencies (build/test only). Below are the production-critical packages.

Core Framework and Internal Packages

Four workspace-local packages provide Kimi Code's foundational layers:

Package Purpose
@moonshot-ai/kaos Internal "kaos" library for core abstractions
@moonshot-ai/kimi-code-oauth OAuth authentication flow helpers
@moonshot-ai/kosong Provider-abstraction layer for model routing
@moonshot-ai/protocol Core protocol definitions for agent communication

These use workspace:^ versioning, ensuring consistent internal API contracts across the monorepo.

HTTP, Networking and Protocol

  • undici (^7.27.1) — Fast HTTP client optimized for Node.js ≥18, used for all outbound model API calls
  • socks (^2.8.9) — SOCKS proxy client for network tunneling
  • @modelcontextprotocol/sdk (^1.29.0) — Official SDK implementing the Model Context Protocol standard

Validation and Schema

  • zod (^4.3.6) — Runtime schema validation with TypeScript type inference
  • ajv (^8.18.0) — JSON Schema validator for configuration files
  • ajv-formats (^3.0.1) — Extended format validators (email, URI, date-time) for AJV

Image and Media Processing

  • jimp (^1.6.1) — Pure-JavaScript image manipulation (resize, crop, format conversion)
  • @jsquash/webp (^1.5.0) — WebP encoding/decoding for efficient model-compatible images

File System and I/O Utilities

  • chokidar (^4.0.3) — File-watcher enabling hot-reload during development
  • ignore (^5.3.2) — .gitignore-style pattern matching for file filtering
  • pathe (^2.0.3) — Cross-platform path utilities (POSIX/Windows normalization)
  • picomatch (^4.0.4) — Fast glob pattern matcher
  • proper-lockfile (^4.1.2) — Process-safe file locking
  • tar (^7.5.13) — TAR archive creation and extraction
  • yauzl (^3.3.0) — ZIP file reader for archive inspection

Data Parsing and Templating

  • js-yaml (^4.1.1) — YAML parsing and stringifying
  • smol-toml (^1.6.1) — Lightweight TOML parser
  • nunjucks (^3.2.4) — Jinja-style templating engine for dynamic prompts

Terminal, Browser and Misc

  • node-pty (^1.1.0) — Pseudo-terminal handling for shell command execution
  • linkedom (^0.18.12) — Fast DOM implementation for server-side HTML parsing
  • @mozilla/readability (^0.6.0) — Extracts article content from web pages
  • open (^10.2.0) — Cross-platform file/URL opener
  • ulid (^3.0.1) — Universally-unique lexicographically-sortable identifiers
  • retry (0.13.1) — Resilient retry logic with exponential backoff
  • regexp.escape (^2.0.1) — Escapes special RegExp characters
  • @antfu/utils (^9.3.0) — General-purpose utility functions

How Agent-Core Uses Its Dependencies

HTTP Client: Undici in ProviderManager

In packages/agent-core/package.json, undici provides the HTTP foundation. The provider system in src/session/provider-manager.ts leverages it for model API communication:

// packages/agent-core/src/session/provider-manager.ts pattern
import { fetch } from 'undici';

class RemoteProvider implements ModelProvider {
  async generate(prompt: string) {
    const response = await fetch(this.endpoint, {
      method: 'POST',
      headers: { 'Authorization': `Bearer ${this.key}` },
      body: JSON.stringify({ prompt })
    });
    return response.json();
  }
}

Schema Validation: Zod and AJV

zod handles runtime type safety for external data, while ajv validates JSON configuration files. From src/config/index.ts:

import { z } from 'zod';

export const AgentConfigSchema = z.object({
  name: z.string(),
  maxTurns: z.number().int().positive(),
  provider: z.string()
});

// Type inference from schema
export type AgentConfig = z.infer<typeof AgentConfigSchema>;

Image Compression: Jimp and WebP

The src/tools/support/image-compress.ts module combines jimp and @jsquash/webp to prepare images for vision models:

import { Jimp } from 'jimp';
import { encode } from '@jsquash/webp`;

export async function compressImageForModel(
  buffer: Buffer,
  options: { maxEdgePx: number }
): Promise<Uint8Array> {
  // Resize with Jimp, encode to WebP for efficiency
  const image = await Jimp.read(buffer);
  const resized = image.resize({ w: options.maxEdgePx });
  const raw = new Uint8Array(resized.bitmap.data);
  return encode(raw, { quality: 85 });
}

File Watching: Chokidar

Hot-reload functionality uses chokidar to monitor configuration changes:

import { watch } from 'chokidar';

const watcher = watch('./config/**/*.{json,yaml}', {
  ignoreInitial: true,
  persistent: true
});

watcher.on('change', (path) => reloadConfig(path));

Development-Only Dependencies

The devDependencies section includes type definitions (@types/*), testing utilities (sinon), and build tools. Notable entries:

  • sinon — Spies, stubs, and mocks for unit testing
  • yazl — ZIP file creation (complementing yauzl for reading)
  • TypeScript declaration files for untyped packages

These are excluded from production builds via proper package.json scoping.

Dependency Architecture Summary

The agent-core dependency design follows three principles visible in packages/agent-core/package.json:

Principle Implementation
Monorepo cohesion Workspace-local packages (@moonshot-ai/*) share protocol definitions
Performance Native-speed libraries (undici, jimp with WASM WebP) for I/O-heavy paths
Reliability Validation at boundaries (zod, ajv) and resilience patterns (retry, proper-lockfile)

Summary

  • The @moonshot-ai/agent-core package declares 27 runtime dependencies in packages/agent-core/package.json
  • Four workspace-local packages (kaos, kosong, protocol, kimi-code-oauth) provide internal integration
  • undici serves as the primary HTTP client, replacing Node's native fetch for performance
  • zod and ajv form a dual-layer validation strategy: Zod for TypeScript-native schemas, AJV for JSON Schema compliance
  • jimp and @jsquash/webp enable browser-free image processing for multimodal agents
  • chokidar, proper-lockfile, and retry support resilient, watchable, concurrent-safe operations

Frequently Asked Questions

What HTTP client does agent-core use and why?

undici (^7.27.1). It outperforms Node's native fetch with connection pooling, interceptors, and lower overhead—critical for high-throughput model API calls in src/session/provider-manager.ts.

How does agent-core validate configuration files?

Dual validation: zod for TypeScript-first runtime types with inference, ajv for strict JSON Schema compliance on external config files. This pattern appears in src/config/index.ts across the codebase.

Why does agent-core need both jimp and @jsquash/webp?

jimp handles general image manipulation (resize, crop, format detection) in pure JavaScript, while @jsquash/webp provides optimized WebP encoding via WASM. Together they compress images for vision models without external binary dependencies.

What's the difference between yauzl and the devDependency yazl?

yauzl (runtime) reads ZIP archives for tool inspection and extraction. yazl (dev-only) creates ZIP files for packaging tests and build artifacts. This read/write separation keeps production bundles smaller.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →