What Dependencies Does the Kimi Code Agent-Core Package Have? A Complete Breakdown
The @moonshot-ai/agent-core package depends on 27 runtime dependencies including workspace-local packages, image processing libraries, HTTP clients, validators, and utilities defined in its package.json.
The agent-core package forms the heart of MoonshotAI's Kimi Code, powering agent orchestration, session management, and tool execution. Understanding its dependency tree reveals the architectural priorities: Type-safe validation, fast HTTP communication, robust file handling, and seamless image processing. All dependencies are declared in packages/agent-core/package.json and implemented throughout src/.
Runtime Dependencies in Agent-Core
The package splits its requirements into runtime dependencies (shipped with production builds) and development dependencies (build/test only). Below are the production-critical packages.
Core Framework and Internal Packages
Four workspace-local packages provide Kimi Code's foundational layers:
| Package | Purpose |
|---|---|
| @moonshot-ai/kaos | Internal "kaos" library for core abstractions |
| @moonshot-ai/kimi-code-oauth | OAuth authentication flow helpers |
| @moonshot-ai/kosong | Provider-abstraction layer for model routing |
| @moonshot-ai/protocol | Core protocol definitions for agent communication |
These use workspace:^ versioning, ensuring consistent internal API contracts across the monorepo.
HTTP, Networking and Protocol
- undici (
^7.27.1) — Fast HTTP client optimized for Node.js ≥18, used for all outbound model API calls - socks (
^2.8.9) — SOCKS proxy client for network tunneling - @modelcontextprotocol/sdk (
^1.29.0) — Official SDK implementing the Model Context Protocol standard
Validation and Schema
- zod (
^4.3.6) — Runtime schema validation with TypeScript type inference - ajv (
^8.18.0) — JSON Schema validator for configuration files - ajv-formats (
^3.0.1) — Extended format validators (email, URI, date-time) for AJV
Image and Media Processing
- jimp (
^1.6.1) — Pure-JavaScript image manipulation (resize, crop, format conversion) - @jsquash/webp (
^1.5.0) — WebP encoding/decoding for efficient model-compatible images
File System and I/O Utilities
- chokidar (
^4.0.3) — File-watcher enabling hot-reload during development - ignore (
^5.3.2) —.gitignore-style pattern matching for file filtering - pathe (
^2.0.3) — Cross-platform path utilities (POSIX/Windows normalization) - picomatch (
^4.0.4) — Fast glob pattern matcher - proper-lockfile (
^4.1.2) — Process-safe file locking - tar (
^7.5.13) — TAR archive creation and extraction - yauzl (
^3.3.0) — ZIP file reader for archive inspection
Data Parsing and Templating
- js-yaml (
^4.1.1) — YAML parsing and stringifying - smol-toml (
^1.6.1) — Lightweight TOML parser - nunjucks (
^3.2.4) — Jinja-style templating engine for dynamic prompts
Terminal, Browser and Misc
- node-pty (
^1.1.0) — Pseudo-terminal handling for shell command execution - linkedom (
^0.18.12) — Fast DOM implementation for server-side HTML parsing - @mozilla/readability (
^0.6.0) — Extracts article content from web pages - open (
^10.2.0) — Cross-platform file/URL opener - ulid (
^3.0.1) — Universally-unique lexicographically-sortable identifiers - retry (
0.13.1) — Resilient retry logic with exponential backoff - regexp.escape (
^2.0.1) — Escapes special RegExp characters - @antfu/utils (
^9.3.0) — General-purpose utility functions
How Agent-Core Uses Its Dependencies
HTTP Client: Undici in ProviderManager
In packages/agent-core/package.json, undici provides the HTTP foundation. The provider system in src/session/provider-manager.ts leverages it for model API communication:
// packages/agent-core/src/session/provider-manager.ts pattern
import { fetch } from 'undici';
class RemoteProvider implements ModelProvider {
async generate(prompt: string) {
const response = await fetch(this.endpoint, {
method: 'POST',
headers: { 'Authorization': `Bearer ${this.key}` },
body: JSON.stringify({ prompt })
});
return response.json();
}
}
Schema Validation: Zod and AJV
zod handles runtime type safety for external data, while ajv validates JSON configuration files. From src/config/index.ts:
import { z } from 'zod';
export const AgentConfigSchema = z.object({
name: z.string(),
maxTurns: z.number().int().positive(),
provider: z.string()
});
// Type inference from schema
export type AgentConfig = z.infer<typeof AgentConfigSchema>;
Image Compression: Jimp and WebP
The src/tools/support/image-compress.ts module combines jimp and @jsquash/webp to prepare images for vision models:
import { Jimp } from 'jimp';
import { encode } from '@jsquash/webp`;
export async function compressImageForModel(
buffer: Buffer,
options: { maxEdgePx: number }
): Promise<Uint8Array> {
// Resize with Jimp, encode to WebP for efficiency
const image = await Jimp.read(buffer);
const resized = image.resize({ w: options.maxEdgePx });
const raw = new Uint8Array(resized.bitmap.data);
return encode(raw, { quality: 85 });
}
File Watching: Chokidar
Hot-reload functionality uses chokidar to monitor configuration changes:
import { watch } from 'chokidar';
const watcher = watch('./config/**/*.{json,yaml}', {
ignoreInitial: true,
persistent: true
});
watcher.on('change', (path) => reloadConfig(path));
Development-Only Dependencies
The devDependencies section includes type definitions (@types/*), testing utilities (sinon), and build tools. Notable entries:
- sinon — Spies, stubs, and mocks for unit testing
- yazl — ZIP file creation (complementing yauzl for reading)
- TypeScript declaration files for untyped packages
These are excluded from production builds via proper package.json scoping.
Dependency Architecture Summary
The agent-core dependency design follows three principles visible in packages/agent-core/package.json:
| Principle | Implementation |
|---|---|
| Monorepo cohesion | Workspace-local packages (@moonshot-ai/*) share protocol definitions |
| Performance | Native-speed libraries (undici, jimp with WASM WebP) for I/O-heavy paths |
| Reliability | Validation at boundaries (zod, ajv) and resilience patterns (retry, proper-lockfile) |
Summary
- The @moonshot-ai/agent-core package declares 27 runtime dependencies in
packages/agent-core/package.json - Four workspace-local packages (
kaos,kosong,protocol,kimi-code-oauth) provide internal integration - undici serves as the primary HTTP client, replacing Node's native fetch for performance
- zod and ajv form a dual-layer validation strategy: Zod for TypeScript-native schemas, AJV for JSON Schema compliance
- jimp and @jsquash/webp enable browser-free image processing for multimodal agents
- chokidar, proper-lockfile, and retry support resilient, watchable, concurrent-safe operations
Frequently Asked Questions
What HTTP client does agent-core use and why?
undici (^7.27.1). It outperforms Node's native fetch with connection pooling, interceptors, and lower overhead—critical for high-throughput model API calls in src/session/provider-manager.ts.
How does agent-core validate configuration files?
Dual validation: zod for TypeScript-first runtime types with inference, ajv for strict JSON Schema compliance on external config files. This pattern appears in src/config/index.ts across the codebase.
Why does agent-core need both jimp and @jsquash/webp?
jimp handles general image manipulation (resize, crop, format detection) in pure JavaScript, while @jsquash/webp provides optimized WebP encoding via WASM. Together they compress images for vision models without external binary dependencies.
What's the difference between yauzl and the devDependency yazl?
yauzl (runtime) reads ZIP archives for tool inspection and extraction. yazl (dev-only) creates ZIP files for packaging tests and build artifacts. This read/write separation keeps production bundles smaller.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →