npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@galaxy-foundry/gxwf-pi-harness

v0.4.1

Published

Pi-backed isolated worker runner and extension for testing Galaxy Workflow Foundry skills.

Readme

@galaxy-foundry/gxwf-pi-harness

Pi-backed worker isolation for evaluating published Galaxy Workflow Foundry skills.

The package has two surfaces:

  • runPiSkill() starts one ephemeral Pi RPC worker with one explicitly loaded skill, a fresh configuration directory, staged declared inputs, and ambient resource discovery disabled.
  • @galaxy-foundry/gxwf-pi-harness/extension registers the constrained foundry_subagent tool used by a top-level Pipeline skill.

The extension derives the worker's expected artifacts exclusively from the selected published cast's _provenance.json. The parent agent can choose the skill, task, and declared inputs, but cannot replace or suppress that artifact contract.

Local mode is process and context isolation, not a security boundary. The trace CLI defaults each local run to a unique directory under the operating system's temporary directory, and both local and container workers load a dereferenced staged copy of the selected skill rather than its checkout path. An explicit --run-dir still overrides that diagnostic default.

The runner hashes that frozen copy once and supplies cast_bundle_sha256 as runtime metadata in the worker prompt, outside the hashed bundle. It records the same value as run.json.invocation.skill_sha256. For a declared galaxy-tool-provenance artifact, it checks that generated.cast_artifact_sha equals this value; missing, malformed, or mismatched provenance is a skill failure. This identifies the whole loaded bundle, not _provenance.json.mold.content_hash (the Mold source hash).

OpenAI subscription-backed diagnostics can opt into the Foundry-specific pi-test-auth store. Login, refresh, and logout use Pi's public authentication API; Foundry does not interpret or copy tokens. For each local run, the fresh Pi configuration temporarily links to the store's auth.json, then removes that link before retaining the run directory. Run records contain only the label pi-test-auth, never the store path or credential values.

Container mode runs the whole Pi RPC worker inside a disposable Docker container. It mounts the staged skill bundle and copied declared inputs read-only, mounts only the run's output directory read-write, and uses tmpfs for Pi configuration and temporary files. The checkout itself is never mounted.

Build the default image from the repository root:

npm run gxwf-pi-harness:container-build

The image pins Pi 0.84.4, the @galaxy-foundry/gxwf-foundry CLI 0.1.0, Python, and Planemo 0.75.47. This supports both the summarize-nextflow pilot and skills such as convert-nfcore-module-to-galaxy-tool that lint and test Galaxy artifacts. It carries compatibility labels for Pi, the Foundry CLI, Planemo, and the RPC contract; all four are checked before every run. A caller may use --sandbox-image <ref> for another locally available image with the same labels. The runner resolves the ref to an immutable image ID before launch and records that ID, any repository digests, every mount, the network policy, and the names—not values—of forwarded credential variables.

Container provider access is explicit. Use --sandbox-network bridge and repeat --credential-env <NAME> for only the variables the provider needs. Use --sandbox-network none for credential-free probes. Run the Docker boundary test with npm run gxwf-pi-harness:container-test.

The OAuth store is intentionally rejected in container mode. A whole-process container would require putting the refresh credential inside that worker boundary; use an allowlisted API-key environment variable there until the planned host-agent/tool-sandbox split is available.

Extension configuration

  • FOUNDRY_SKILLS_DIR — required path to the installed Foundry skills root.
  • FOUNDRY_RUNS_DIR — directory for child run records; defaults to a temporary directory.
  • FOUNDRY_WORKER_TIMEOUT_MS — child wall timeout; defaults to ten minutes.
  • FOUNDRY_SANDBOX — local (default) or container.
  • FOUNDRY_SANDBOX_IMAGE — optional compatible container image ref.
  • FOUNDRY_SANDBOX_NETWORK — bridge (default) or none.
  • FOUNDRY_SANDBOX_CREDENTIAL_ENV — comma-separated environment-variable allowlist.

The trace-mode CLI also accepts --thinking <level> when an evaluation should pin Pi's reasoning level rather than use the model default.

The extension accepts skill names, never arbitrary skill paths. It resolves each name as one direct child of FOUNDRY_SKILLS_DIR and starts the child through the same runner used by trace-mode callers.

License

MIT.