Package: @bangdao-ai/acw-tools
Maintainer: bangdao-ai (Bangdao Technology)
Homepage: https://www.npmjs.com/package/@bangdao-ai/acw-tools

## Dual-use declaration

This package is published with contentPolicy.class = "dual-use" because it includes
security-relevant capabilities that automated scanners may confuse with malware.
All capabilities below are used only for the legitimate ACW (AI Collaborative
Workbench) MCP integration described in README.md.

## Code obfuscation

Published artifacts are bundled and obfuscated with javascript-obfuscator to protect
proprietary business logic. Obfuscation is applied only to this first-party MCP code;
it is not used to hide malicious behavior. Source is maintained privately by the
maintainer team.

## Local system access (user-initiated)

- Read local IDE conversation databases (Cursor state.vscdb / similar) when the user
  runs the MCP server, to upload AI collaboration records to their own ACW account.
- Read non-credential Cursor account metadata (cached email, sign-up type, and
  membership type). The package does not read Cursor login or access tokens.
- Execute limited local commands (git remote lookup, node child processes for parsing)
  required for repository detection and conversation parsing.
- Read and write files under the user's workspace or configured agent directories
  (.agents/skills, .agents/rules, .agents/knowledge, etc.) when the user invokes
  download/upload tools.

## Network access (authenticated)

- HTTPS requests to ACW_BASE_URL (default https://acw.bangdao-tech.com) using the
  user-provided ACW_TOKEN for rules, skills, knowledge, and conversation sync.
- The package does not download, replace, or rebuild native binaries during
  installation or runtime. Older Node versions use only the normally installed
  optional better-sqlite3 dependency.

## Intended legitimate use

Enterprise developers use this MCP server inside Cursor or Codex to:

1. Download company rules, skills, and knowledge into a project workspace.
2. Upload skills and knowledge to the ACW platform.
3. Sync AI conversation metadata to ACW for team collaboration analytics.

While the MCP process is running, authenticated conversation sync and host telemetry
may run on a background schedule. The package uses only the user-provided ACW_TOKEN
for authentication and does not modify system files outside user-invoked workspace
paths.

## Contact

Issues: https://github.com/bangdao-ai/acw-tools/issues
