Files
deepagentsjs/libs/providers/quickjs
github-actions[bot] bed2d344bc chore: version packages (#712)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents@1.12.0

### Minor Changes

- [#703](https://github.com/langchain-ai/deepagentsjs/pull/703)
[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): adopt
more minimal prompting

We've observed that current models don't need as verbose of prompting
guidance, so we're reducing the amount of perscriptive guidance that
deepagents has. This is reflected in the generic system prompt (which is
now blank), and in the tool descriptions (which have been simplified).

- [#708](https://github.com/langchain-ai/deepagentsjs/pull/708)
[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): make todo
middleware opt-in

- [#674](https://github.com/langchain-ai/deepagentsjs/pull/674)
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)
Thanks [@hntrl](https://github.com/hntrl)! - feat(filesystem): allow
`write_file` to create missing files or completely replace existing
files
## deepagents-acp@0.1.21

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0
## @langchain/node-vfs@1.0.0

### Patch Changes

- [#674](https://github.com/langchain-ai/deepagentsjs/pull/674)
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)
Thanks [@hntrl](https://github.com/hntrl)! - fix: allow
`VfsBackend.write` to overwrite existing files while continuing to
reject symlinks
## @langchain/daytona@1.0.0


## @langchain/deno@1.0.0


## @langchain/modal@1.0.0


## @langchain/quickjs@1.0.0


## @langchain/sandbox-standard-tests@2.0.0


## @deepagents/evals@0.0.20

### Patch Changes

- Updated dependencies
[[`d25097f`](https://github.com/langchain-ai/deepagentsjs/commit/d25097f78d0e66741da34e1d74551f3c19991126),
[`1225a7f`](https://github.com/langchain-ai/deepagentsjs/commit/1225a7ff8673686c2a3c0411636a9511b7d8d0d0),
[`dd142fe`](https://github.com/langchain-ai/deepagentsjs/commit/dd142fe4fc54c986d5bcf51211d9a839a427e931)]:
  - deepagents@1.12.0

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-29 09:47:28 -07:00
..
2026-03-06 08:49:17 +00:00
2026-07-29 09:47:28 -07:00
2026-03-06 08:49:17 +00:00
2026-07-29 09:47:28 -07:00

@langchain/quickjs

Sandboxed JavaScript/TypeScript REPL for deepagents, powered by QuickJS-NG through QuickJS-Emscripten

npm version License: MIT

Installation

npm install @langchain/quickjs deepagents

Quick Start

import { createDeepAgent } from "deepagents";
import { createQuickJSMiddleware } from "@langchain/quickjs";

const agent = createDeepAgent({
  model: "claude-sonnet-4-5",
  middleware: [createQuickJSMiddleware()],
});

const result = await agent.invoke({
  messages: [
    { role: "user", content: "Calculate the first 20 Fibonacci numbers" },
  ],
});

The agent now has a js_eval tool. It can write and execute JavaScript/TypeScript in a sandboxed REPL where variables persist across calls:

// Call 1: the agent writes
var fibs = [0, 1];
for (let i = 2; i < 20; i++) fibs.push(fibs[i - 1] + fibs[i - 2]);
console.log(fibs);

// Call 2: state persists — `fibs` is still available
console.log(`Sum: ${fibs.reduce((a, b) => a + b, 0)}`);

Features

WASM Sandbox

All code runs inside a QuickJS WASM interpreter. There is no require, no import, no fetch, no filesystem access — only the explicitly bridged helpers (readFile, writeFile, and optionally tools.*).

TypeScript Support

LLMs naturally produce TypeScript. An AST-based transform pipeline strips type annotations, interfaces, and generics before evaluation — the model doesn't need to write pure JavaScript.

Virtual Filesystem

The REPL has readFile(path) and writeFile(path, content) functions that read from and write to the agent's backend (LangGraph state by default):

const raw = await readFile("/data.json");
const data = JSON.parse(raw);
const summary = { total: data.items.length };
await writeFile("/summary.json", JSON.stringify(summary, null, 2));

Programmatic Tool Calling (PTC)

Any agent tool can be exposed inside the REPL as a typed async function. Instead of the LLM emitting tool calls one at a time, it writes code that calls tools directly — loops, conditionals, parallel execution, and result transformation all happen in code:

const agent = createDeepAgent({
  model: "claude-sonnet-4-5-20250929",
  middleware: [
    createQuickJSMiddleware({
      ptc: true, // expose all agent tools inside the REPL
    }),
  ],
});

Inside the REPL, the agent can then write:

const urls = ["/users", "/orders", "/products"];
const results = await Promise.all(
  urls.map((u) => tools.httpRequest({ url: "https://api.example.com" + u })),
);
const parsed = results.map((r) => JSON.parse(r));
console.log(`Users: ${parsed[0].length}, Orders: ${parsed[1].length}`);

PTC configuration is progressive:

Value Behavior
false Disabled (default)
true All agent tools except VFS builtins
string[] Only these tools
{ include: string[] } Only these tools
{ exclude: string[] } All tools except these

Recursive Language Model (RLM)

When the agent has subagents configured, a task() global is available inside the REPL (no PTC needed), so the agent can spawn sub-agents in parallel from within the REPL:

const agent = createDeepAgent({
  model: "claude-sonnet-4-5-20250929",
  subagents: [
    {
      name: "general-purpose",
      description: "Research agent",
      systemPrompt: "...",
    },
  ],
  middleware: [createQuickJSMiddleware()],
});

The agent then writes code like:

const topics = ["quantum computing", "fusion energy", "CRISPR"];
const results = await Promise.all(
  topics.map((topic) =>
    task({
      description: `Research ${topic} in depth`,
      subagentType: "general-purpose",
    }),
  ),
);
// Aggregate and return the report from the eval; the agent then writes it to a
// file with its own write_file tool.
const report = topics.map((t, i) => `## ${t}\n${results[i]}`).join("\n\n");
report;

task cannot be exposed via ptc — it is reserved for the task() global, so passing ptc: ["task"] throws.

API

createQuickJSMiddleware(options?)

Creates a middleware that adds the js_eval tool to your agent.

interface QuickJSMiddlewareOptions {
  backend?: BackendProtocol | BackendFactory; // File I/O backend (default: StateBackend)
  ptc?: boolean | string[] | { include: string[] } | { exclude: string[] }; // PTC config
  memoryLimitBytes?: number; // Default: 50MB
  maxStackSizeBytes?: number; // Default: 320KB
  executionTimeoutMs?: number; // Default: 30s (-1 to disable)
  systemPrompt?: string | null; // Override the built-in REPL system prompt
}

ReplSession

The underlying session class. Usually you don't interact with this directly — the middleware manages sessions per thread.

ReplSession.getOrCreate(id, options?)  // Get or create a session
ReplSession.get(id)                    // Look up existing session
session.eval(code, timeoutMs)          // Execute code
session.flushWrites(backend)           // Persist buffered file writes
session.toJSON() / ReplSession.fromJSON(data)  // Serialization

License

MIT — see LICENSE.