npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@aefree/pi-package-references

v0.1.1

Published

Bounded package-relative public reference reader for independently installed Pi packages.

Readme

pi-package-references

@aefree/pi-package-references provides the single read_package_reference Pi tool for bounded text owned by independently installed packages.

Installation

Install it in the package that owns the public reference files:

npm install @aefree/pi-package-references

The package has a normal runtime dependency on @aefree/pi-capability-registry; npm resolves that publicly available prerequisite transitively.

Use it from an owner package

  1. Add @aefree/pi-package-references as a normal runtime dependency of the package that owns the reference files.
  2. Ensure both that package's extension and this package's extensions/index.ts are active in Pi. The reader extension registers the single read_package_reference tool; importing contracts/v1 or runtime/v1 has no Pi-resource registration side effects.
  3. During each session_start, register only the directory prefixes the owner intends to publish. During the matching session_shutdown, unregister that registration.
  4. In prompts or agents, call the tool with an exact package name and public path. Do not use project-relative file reads as a substitute.

For example, @example/review-policy, an extension package containing references/review/delivery-policy.md, can register that directory as follows:

import { readFileSync } from "node:fs";
import { dirname, resolve } from "node:path";
import { fileURLToPath } from "node:url";
import type { ExtensionAPI } from "@earendil-works/pi-coding-agent";
import type { RegistrationToken } from "@aefree/pi-capability-registry";
import {
  registerPackageReferenceOwnerV1,
  unregisterPackageReferenceOwnerV1,
} from "@aefree/pi-package-references/runtime/v1";

export default function registerOwner(pi: ExtensionAPI): void {
  const packageRoot = resolve(dirname(fileURLToPath(import.meta.url)), "..");
  const manifest = JSON.parse(readFileSync(resolve(packageRoot, "package.json"), "utf8")) as {
    name: string;
    version: string;
  };
  let activeScope: object | undefined;
  let token: RegistrationToken | undefined;

  pi.on("session_start", async (_event, ctx) => {
    unregisterPackageReferenceOwnerV1(token);
    activeScope = ctx.sessionManager;
    token = await registerPackageReferenceOwnerV1(ctx.sessionManager, {
      contractVersion: 1,
      packageName: manifest.name,
      packageVersion: manifest.version,
      packageRoot,
      registeredBy: "extensions/index.ts",
      publicMounts: [{
        prefix: "references/review/",
        directory: "references/review",
        extensions: [".md"],
      }],
    });
  });

  pi.on("session_shutdown", async (_event, ctx) => {
    if (ctx.sessionManager !== activeScope) return; // stale shutdown
    unregisterPackageReferenceOwnerV1(token);
    token = undefined;
    activeScope = undefined;
  });
}

A prompt or agent then reads an exact package-qualified reference:

{"packageName":"@example/review-policy","path":"references/review/delivery-policy.md"}

The result is tool output, so callers should handle a failed read explicitly: state that mandatory guidance is unavailable and do not claim to have applied unread guidance.

Paths are normalized POSIX-relative, mounts and extensions are explicit, reads are capped at 50 KiB and 2,000 lines, and results expose package/version/mount provenance without installation paths. Missing, private, malformed, ambiguous, incompatible, escaping, changed, and oversized resources fail with sanitized codes.

This is a correctness boundary for trusted installed packages, not a filesystem sandbox. On Windows Node runtimes without O_NOFOLLOW, guarantees are canonical containment plus post-open identity/change detection; adversarial race prevention is not claimed.

The reader must be installed and active as a Pi resource package in addition to any owner package's code dependency. Activate it explicitly with pi install npm:@aefree/pi-package-references, and install/activate the owner package separately. A code dependency alone does not activate Pi extensions. If package resources are filtered in Pi settings, ensure this package's extensions/index.ts and the owner's extension are enabled, then start a new Pi session.

The supported validation baseline is Pi 0.99.1 on Node.js >=22.19.0. The npm artifact contains compiled runtime code, public declarations, and the Pi entry point; authored source, source maps, tests, fixtures, and evals remain repository-only. Build and test scripts are maintainer commands for a repository checkout, not consumer installation steps.