npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@agenticprimitives/edge-runtime

v0.0.0-alpha.7

Published

Vendor-neutral edge ADMISSION layer: the EdgeAdapter interface, trusted-header hygiene, the GatewayAssertion verification port, and the admission pipeline (route resolution + size/depth/envelope + Stage-1 abuse limit). Owns admission only, never authority

Readme

@agenticprimitives/edge-runtime

The vendor-neutral edge admission layer. The edge is the only public surface; it admits or rejects requests cheaply, then forwards to the A2A/MCP origin behind a Service Binding. It owns admission only — it never owns authority (delegation, revocation, entitlement, KAS, signing, decryption all run behind the binding, never imported here — ADR-0043).

See spec 288 §4.

What's in the box (W1)

  • EdgeAdapter — the interface Cloudflare / Zuplo / API Shield implement. The admission protocol doesn't change when the gateway does.
  • Trusted-header hygieneTRUSTED_HEADERS + sanitizeTrustedHeaders(headers, { authenticated }) strip internal headers (x-agent-subdomain, x-agentic-principal, …) from an unauthenticated caller so they can't be spoofed.
  • GatewayAssertion verification portverifyGatewayAssertion(...) proves, issuer-agnostically, that a gateway admitted these exact bytes for this route. It proves admission only — never SA authorization (the native pipeline still does that). The signature check is injected, so the default issuer and a future Zuplo lane are the same code path.
  • Admission pipelinerunAdmission(req, opts): resolve route (from a surface-catalog) → sanitize headers → body-size / JSON-depth / envelope checks → Stage-1 abuse limit (an injected rate-control SoftRateLimiter, fail-soft) → correlation id.
import { runAdmission } from '@agenticprimitives/edge-runtime';

const result = await runAdmission(extractedRequest, {
  resolveRoute: (r) => registry.get(routeToId(r.path)),
  softLimiter,                       // from @agenticprimitives/rate-control (fail-soft)
  authenticated: false,              // direct public caller → strip trusted headers
});
if (!result.ok) return reject(result.status);   // single generic error; reason is internal-only
forwardToOrigin(result.descriptor, result.headers, result.correlationId);  // origin still validates authoritatively

Not in the core

  • The Cloudflare adapter (Worker rate-limiter binding, Service-Binding dispatch, cf-connecting-ip) and the deployed agentic-edge Worker — ship separately (spec 288 §5); the production edge is external (ADR-0037).
  • Any authority logic — forbidden imports; reached via Service Binding.

License

MIT