npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@flowrail/hook

v0.0.24

Published

FlowRail PreToolUse hook dispatcher for Claude Code. Pre-write secret scan + LLM-backed code verifier; pre-bash supply-chain check via the FlowRail MCP server.

Readme

@flowrail/hook

FlowRail's hook dispatcher for Claude Code. It intercepts every Write/Edit/MultiEdit and Bash call your coding agent makes and routes it through FlowRail's security verification pipeline before the change lands.

Sub-commands:

  • flowrail-hook pre-write — reconstructs the post-edit file content (plain Write, Edit with replace_all: false / true, and MultiEdit composition), runs a local secret scan and lockfile diff, and verifies code files against your active design review's guardrails via the FlowRail server's flowrail_verify_code MCP tool.
  • flowrail-hook pre-bash — inspects tool_input.command, resolves the dependency tree with npm install --dry-run on package-install patterns, and runs FlowRail's 4-signal supply-chain check via the flowrail_check_dep_install MCP tool.
  • flowrail-hook stop / session-start — turn-batched whole-app composition review (the cross-file authN/authZ pass no per-file verify can see) and its session-start coverage catch-up.
  • flowrail-hook capabilities — prints {name, version, subcommands} for version-skew checks.

Configuration

  • FLOWRAIL_MCP_URL — FlowRail server base URL (default http://localhost:8787; the hosted service is https://api.flowrail.ai).
  • FLOWRAIL_API_KEY — your API key. Sign up and mint one at flowrail.ai/settings/keys.

The installer (@flowrail/init) bakes the server URL into the hook command line in .claude/settings.json (tracked, no credential), but it never writes your API key to a tracked file — the key lives only in your shell environment. The hook inherits FLOWRAIL_API_KEY from whatever shell launched Claude Code, so keep it exported (e.g. via ~/.zshrc) so every session picks it up.

Install

You normally don't install or invoke this package directly — the one-shot installer wires everything up:

npx @flowrail/init@latest

Links