npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@harness-gui/mcp

v0.2.3

Published

MCP server for harness-gui — let an agent notify, show, confirm, select and ask a human, out of band.

Readme

@harness-gui/mcp

MCP server that lets an agent reach the human — out of band.

Five tools: notify, show, confirm, select, form. The answer comes from a person on a separate surface (a terminal, a browser tab, or a native window), so it is not something the model can fill in for itself.

npx @harness-gui/mcp        # stdio transport

Register it with your host:

{
  "mcpServers": {
    "harness-gui": {
      "command": "npx",
      "args": ["@harness-gui/mcp"],
      "env": { "HARNESS_GUI": "on" }
    }
  }
}

Tools

| Tool | For | |---|---| | gui_notify | "the long job finished" — one-way, returns immediately | | gui_show | put a table / summary / document in front of them to read | | gui_confirm | gate anything irreversible or outward-facing before doing it | | gui_select | let them pick when a wrong guess would be costly | | gui_form | collect several fields at once |

gui_show is also the right place for long or richly formatted output: it renders properly and does not consume your context.

HARNESS_GUI must be set

Without HARNESS_GUI=on (or strict) every tool returns a plain refusal instead of reaching anyone. It defaults to off because a server cannot tell whether anyone is watching: under stdio transport stdin is the protocol channel, not a terminal, so TTY detection is meaningless — and the daemon channel is always nominally "available", so it would spin up an unwatched window and wait out the timeout. In a headless environment that is not degrading, it is hanging.

Why a confirm: true parameter is not a guardrail

The model can fill that in itself, and the rejection message usually teaches it how ("pass confirm=true if that is what you want"). A model can construct a request; it cannot construct a human's approval. gui_confirm exists to make that distinction real.

Treat anything other than action: "accept" as "do not proceed". timeout and cancel are reported separately on purpose — "nobody is there" and "the answer is no" are different facts.

One deliberate limitation: no password fields

The SDK's form supports password fields so a human can type something that never enters a model's context — a verification code, say — and the value goes straight to the calling process.

An MCP tool result, by definition, goes into your context. Collecting a secret here would write it into the transcript, which is the exact thing the feature exists to prevent. So gui_form rejects password fields and says why. A program that needs a secret should use the harness-gui SDK directly.

Also in this project

  • harness-gui — the SDK, for any Node program. Zero runtime dependencies.

Architecture, design rules and platform matrix: https://github.com/Morphicai/harness-gui

License

MIT