npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@akasecurity/ai-tc-claude-code

v0.9.11

Published

AI Traffic Control — inspect and govern AI prompts in Claude Code

Readme

@akasecurity/ai-tc-claude-code — the aka plugin for Claude Code

npm Apache-2.0

AKA Security — We secure agent harnesses at the source.

The Claude Code plugin for AI Traffic Control (ai-tc). It hooks into a Claude Code session and inspects its traffic — prompts, tool calls, tool results, file reads — scanning each event against your rule packs and applying inline warn / redact / block policies. Every event is recorded to a local SQLite store at ~/.aka/data/aka.db.

Detection runs entirely on your machine. Standalone by default — no account and no backend, and nothing is sent anywhere to be scanned.[^egress]

[^egress]: Live detection and enforcement run locally, on every install and whatever else is configured. Two things can send anything off the machine, and both are opt-in. The first is the opt-in /aka:setup calibration below: to rate what an initial history scan finds, its judge step sends those findings to the model API through the claude CLI — the same provider your Claude session already uses, reached with your own credentials. For each finding that means the raw (unmasked) value including any secret, roughly 120 characters of the surrounding transcript text on either side (re-scanned before it goes, so every secret the rules detect in that window is masked, including the finding's own value where it appears there), the finding's rule, category, severity, masked value and confidence, and a sequential counter the model echoes back so its verdict can be matched to the finding. The source file's path is not sent. It takes two separate opt-ins — one to read your history at all, and a second, distinct grant to send what was found — and without the second the judge does not run. It keeps those values out of your local Claude transcript, but a copy of them does leave the machine. Withdrawing either grant stops future scans; it cannot recall what was already sent. The second is attaching this machine to an AKA deployment your organization runs (aka attach), after which the plugin forwards the activity that deployment is entitled to see and enforces the policy it sets — which can raise enforcement beyond your own settings but never lower it. Nothing is forwarded until both an endpoint and an access key are on disk; aka status says what a machine is attached to and aka detach ends it.

The local store keeps your prompts and tool calls verbatim apart from the spans a rule masks, and file permissions — not encryption — are all that protect it. See Data at rest for which files it spans and what holds on Windows.

Install

This package is distributed through the Claude Code plugin marketplace, not npm install. Add the marketplace and install the plugin from inside Claude Code:

/plugin marketplace add akasecurity/marketplace
/plugin install ai-tc@akasecurity

Or let the aka CLI install the plugin for you:

npm install -g @akasecurity/cli
aka plugins install claude-code

Either way, finish onboarding by running /aka:setup from inside Claude Code:

/aka:setup

If you installed via the CLI, aka init scaffolds the local store and aka dashboard views findings.

What it registers

The plugin installs Claude Code hooks that run locally with no node_modules, and fail open (a hook error never breaks your session):

  • SessionStart — snapshot the session context.
  • UserPromptSubmit — scan prompts before they reach the model.
  • PreToolUse — scan tool inputs (Bash, Edit, Write, MultiEdit, NotebookEdit, WebFetch, Agent / Task, and any mcp__* tool) before they run. Sensitive content in text a tool merely stores is masked in place; in text a tool acts on — a shell command, a URL, an MCP argument — masking would change what runs, so the call is blocked instead.
  • PostToolUse — scan tool outputs and file reads (Bash, Read, WebFetch) after they return.
  • Stop — reconcile token usage and finalize the session record.

It also adds slash commands for reports and setup (/aka:health, /aka:findings, /aka:dashboard, and more).

The plugin works standalone, and governs what a session carries: rule packs, findings, policy, and an audit trail. To harden the harness itself — safe-default permissions, structural command guards, and credential deny rules — pair it with claude-tools. They compose: claude-tools hardens the harness, ai-tc governs the traffic.

Docs

Full documentation and the built-in detection catalog live at akasecurity.github.io/ai-tc-docs.

License

Apache-2.0