A new JavaScript package manager named jpm has appeared on Hacker News, claiming to be a production-grade tool where every single line of code was written by an AI agent. Developed using Claude Opus 5.5 and directed by veteran engineer JT Turner, the Rust-based binary weighs in at just 2 MB and boasts installation speeds up to 15x faster than npm. The project represents a significant shift in how we view AI-assisted development, moving beyond autocomplete to full architectural implementation under human supervision.

Performance Benchmarks and Architecture

According to data published on getjpm.sh, jpm completed a cold install of the Nuxt framework with 591 packages in 1.22 seconds on GitHub CI, compared to npm’s 18.54 seconds. The tool utilizes a content-addressed store to hardlink files, ensuring each package is built only once per machine. While jpm excels in wall-clock time and peak memory usageβ€”using only 34 MB for the Nuxt install versus npm’s 387 MBβ€”it does have larger disk footprint requirements for its unpacked store, a trade-off the developers accept for speed.

Security Model and AI Verification

The security architecture is notably aggressive for an AI-generated codebase. jpm implements a secure by default policy where install scripts are disabled until explicitly approved by the developer, mitigating common npm malware vectors. The project also enforces a one-day delay on new package releases to prevent hijacked updates from propagating instantly. To validate the AI's work, Turner subjected the code to rigorous testing against Project Wycheproof for TLS, RFC vectors, and the existing test suites of npm, pnpm, yarn, and bun. This multi-layered verification process was deemed necessary because, as the documentation notes, Perfect doesn't exist. There's good enough, there's great, and there's tested enough to know which one you have.

Key Takeaways

  • Full AI Generation: Claude Opus 5.5 wrote every line of code, including custom TLS and crypto implementations, under the direction of JT Turner.
  • Significant Speed Gains: jpm is the fastest in 9 of 12 benchmark cells, with a 15x speedup over npm for cold installs of large dependencies.
  • Strict Security Defaults: Features include mandatory script approval, a 24-hour release age buffer, and refusal of non-standard dependency sources.
  • Compatibility Focus: The tool imports existing lockfiles from npm, pnpm, yarn, and bun, allowing for seamless migration without breaking CI pipelines.

The Bottom Line

jpm proves that AI agents can now handle complex systems programming tasks, provided there is a human architect enforcing strict verification protocols. If these benchmarks hold up under broader scrutiny, we are looking at the end of the era where human-written code is inherently trusted over AI-generated code in critical infrastructure.