npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@holmes-lab/holmes-kit

v0.1.18

Published

Holmes-Kit — deterministic Agentic Software Engineering (ASE) harness with causal traceability (spec chain + D-CPG + RTM + phase guardrail)

Readme

🔍 Holmes-Kit

npm version node version license

"No Spec, No Code" — Deterministic Agentic Software Engineering (ASE) harness with causal traceability.


🕵️ Philosophy & Vision: Beyond Code Generation

Holmes-Kit is not merely an AI code generator. Inspired by Sherlock Holmes, Holmes-Kit is built to deduce, track down, and analyze code defects, structural drift, and security vulnerabilities across the full Software Development Life Cycle (SDLC).


🛡️ Currently Supported Features (v0.1.x Production Features)

  • 📋 Requirements & Specification Governance: Strict "No Spec, No Code" enforcement with 4-tier spec chain traceability (REQ ➔ H-SPEC ➔ A-SPEC ➔ T-SPEC) and // @implements A-SPEC-XXX line 1 code anchors.
  • 🐞 Causal Defect Localization & CPG: AST Code Property Graph (CPG) & Dataflow Taint reachability analysis across 7 languages (TS/JS, Python, Go, Rust, Java, C/C++, C#).
  • 🧪 Self-Healing & Diagnostic Doctor: Automated integrity checks and self-healing auto-fix remediation (holmes-kit doctor --fix & spec_remediate).
  • 🚦 CI/CD Governance Gate Runner: Non-interactive headless CI/CD build gate (holmes-kit ci) for GitHub Actions and GitLab CI pipelines.
  • 📊 Automated RTM & Taint Heatmap: Interactive standalone HTML/SVG report generation (generateRtmHeatmap) for spec coverage and security dataflow reachability.
  • 🤖 CLI-First AI Harness Matrix: Native process hook gating for Claude Code, Antigravity CLI (AGY), Codex CLI, and Google Antigravity SDK.

🚀 Full SDLC Vision & Roadmap (Future Goals)

Holmes-Kit strives to expand into a unified enterprise SDLC harness bridging external development tools:

  • 🔌 Enterprise Issue Tracker Connectors: Flexible synchronization with Jira, GitHub Issues, Linear, and Notion.
  • 🌐 Multi-Repository Polyrepo Governance: Multi-repo spec chain synchronization and cross-repository dependency impact analysis (REQ-211).
  • 🛡️ External SAST & Linter Bridge: Deep integration with SonarQube, Semgrep, and ESLint findings.

🤖 Supported AI Coding Tools & Environments (CLI-First Focus)

Holmes-Kit prioritizes CLI-based AI Coding Agents where OS-level process hooks, subshell isolation, and deterministic control plane enforcement are natively guaranteed:

| AI Coding Agent / Framework | Harness Tier | Integration & Enforcement Mechanisms | | :--- | :--- | :--- | | 🤖 Claude Code CLI | 🥇 Tier 1 (Native) | OS PreToolUse & Stop hooks (.claude/settings.local.json), MCP server (.mcp.json) | | 🚀 Antigravity CLI (AGY) | 🥇 Tier 1 (Native) | AGY Hooks (hooks.json), MCP config (.agents/mcp_config.json), Governance Skills | | 💻 Codex CLI / Agentic Shell | 🥇 Tier 1 (Native) | Codex MCP integration (.codex/mcp_config.json), Subshell Isolation Gates | | 🧩 Google Antigravity SDK | 🥇 Tier 1 (Native) | Autonomous Agent SDK bindings and cryptographic provenance verification |

Note: Holmes-Kit focuses strictly on CLI-based autonomous agents to guarantee 100% deterministic OS hook gating (deny enforcement) before file modifications occur.


⚡ Quickstart (3-Minute Setup)

1. Install — find your row first

The same wrong command was run three times by a real adopter before the right one; a table beats prose read top-to-bottom.

Windows (recommended) — a bootstrap installer that runs before npm and fixes what npm cannot: it relocates out of protected folders (an elevated PowerShell opens in C:\WINDOWS\System32, where npm install fails with EPERM), checks the Node.js version, and, if a native module fails to build, prints the one winget command that installs the missing C++ toolchain instead of raw compiler output. Pure Windows PowerShell 5.1; no prompts; nothing persistent is changed.

# From a downloaded copy of the package (e.g. after `npm pack`, or from a checkout):
powershell -NoProfile -ExecutionPolicy Bypass -File scripts\install.ps1

# One-liner (once hosted):
# irm https://<host>/install.ps1 | iex

Add -DryRun to see what it would do without installing. Exit codes: 0 ok / already installed · 2 bad argument · 3 Node.js too old · 4 npm failed (remediation printed) · 5 installed but not on PATH (prefix printed).

| Which situation are you in? | Privileges | Command | |---|---|---| | Using it in one project (most people) | none | npm install --save-dev @holmes-lab/holmes-kit | | Company-managed PC / restricted account | none | same — no system directory is touched | | CI / container | none | same, plus --prefer-online right after a release | | CLI across many projects (-g) | depends | run npm config get prefix first — see below |

Before npm install -g: if npm config get prefix names a protected directory (C:\Program Files\nodejs, /usr/local), -g dies with EPERM before any package file arrives — no package version can fix that, and elevation is the wrong fix (it runs native install scripts with system privileges, and it did not even work in the reported case). Move the prefix to user space instead — one-time setup, exact commands in the Install Guide, along with troubleshooting keyed to the exact error text (EPERM mkdir, notarget, better-sqlite3 build failures).

Prerequisites — Node.js >= 20.0.0. The 8 tree-sitter grammars ship prebuilt binaries for macOS/Linux/Windows and compile nothing; better-sqlite3 downloads a prebuild at install time, falling back to compiling — only that fallback needs a C++ toolchain (VS Build Tools / Xcode CLT / apk add python3 make g++).

2. Initialize in Your Project

cd /path/to/your/project
npx holmes-kit init      # drop the npx prefix if you installed with -g

An interactive prompt will ask which AI agent harnesses to wire into your project:

? Select the AI Agent harnesses to wire into this project:
  [X] 🤖 Claude Code          (.claude/settings.local.json, .mcp.json)
  [X] 🚀 Antigravity CLI (AGY) (.agents/mcp_config.json, hooks.json, skills)
  [ ] 💻 Codex CLI            (.codex/mcp_config.json)

3. Verify Health

npx holmes-kit doctor

If everything is green, your project is governed and ready for AI pair-programming!


🔄 Daily Workflow (How It Works)

Once initialized, your AI agent automatically follows the No Spec, No Code lifecycle:

flowchart LR
    A["1. Spec First<br/>(REQ → A-SPEC)"] --> B["2. Test First<br/>(TDD & T-SPEC)"]
    B --> C["3. Implementation<br/>(// @implements A-SPEC)"]
    C --> D["4. Verified Code<br/>(Provenance Sealed)"]
  1. Spec First: The agent authors requirements and architecture specs via spec_create.
  2. Test First: The agent writes tests and approves T-SPEC before writing implementation code.
  3. Implement: Code files anchor to their architecture spec with // @implements A-SPEC-NNN.
  4. Deterministic Guard: If the agent attempts to write code without approved specs, Holmes-Kit hooks block the action and provide exact next steps.

🧰 Essential CLI Cheatsheet

| Command | Purpose | | :--- | :--- | | holmes-kit init | Interactive agent harness setup (Claude, Antigravity, Codex) | | holmes-kit init --agent all | Non-interactive instant setup for all supported agents | | holmes-kit init --dry-run | Preview files and configuration changes without writing | | holmes-kit doctor | Comprehensive health check of specs, hooks, MCP, and anchors | | holmes-kit doctor --fix | Automatically self-heal and repair broken hooks or missing skills | | holmes-kit ci | Run non-interactive headless governance gate for GitHub Actions / GitLab CI | | holmes-kit ci --json | Run CI gate and emit machine-readable JSON results |


🧩 Optional: Manual MCP Integration (Cursor, Windsurf, Claude Desktop)

Note: If you ran holmes-kit init, this configuration is 100% automated for you.
Use the manual configuration below only if you wish to integrate Holmes-Kit into standalone third-party MCP clients like Cursor, Windsurf, Claude Desktop, or VS Code:

{
  "mcpServers": {
    "holmes-kit": {
      "command": "npx",
      "args": ["-y", "--package=@holmes-lab/holmes-kit", "holmes-mcp"],
      "env": {
        "HOLMES_SPECS": ".ax/specs"
      }
    }
  }
}

🌐 Supported Languages & Environments

Holmes-Kit embeds native AST & Code Property Graph (D-CPG) analyzers to track causal relationships and anchor implementations across diverse technology stacks.

💻 Supported Programming Languages

| Language | CPG Parser | Anchor Syntax | Dataflow Taint & RTM | | :--- | :--- | :--- | :---: | | TypeScript / JavaScript | Tree-sitter TypeScript/JS | // @implements A-SPEC-XXX | ✅ Full Support | | Python | Tree-sitter Python | # @implements A-SPEC-XXX | ✅ Full Support | | Go | Tree-sitter Go | // @implements A-SPEC-XXX | ✅ Full Support | | Rust | Tree-sitter Rust | // @implements A-SPEC-XXX | ✅ Full Support | | Java | Tree-sitter Java | // @implements A-SPEC-XXX | ✅ Full Support | | C / C++ | Tree-sitter C/C++ | // @implements A-SPEC-XXX | ✅ Full Support | | C# (.NET) | Tree-sitter C# | // @implements A-SPEC-XXX | ✅ Full Support |

🖥️ Supported Operating Systems & Runtimes

| OS / Platform | Architecture | Status | Notes | | :--- | :--- | :---: | :--- | | macOS | Apple Silicon (arm64) / Intel (x64) | ✅ Tier 1 | macOS 12+ (Full hook enforcement) | | Linux | x86_64 / arm64 | ✅ Tier 1 | Ubuntu, Debian, Fedora, Arch, RHEL | | Windows (WSL2) | x86_64 | ✅ Tier 1 | WSL2 Ubuntu/Debian recommended | | Windows Native | x86_64 | ✅ Tier 1 | Windows 10/11 (Node.js 20+ with C++ build tools). Gate parity verified from CI — see ADR-015 for the graduation criteria and the residual risks (NTFS 8.3 names, reserved device names, 260-char paths) |

Runtime Requirement: Node.js >= 20.0.0 (LTS recommended)

How a tier is decided: by the verification that actually executes, not by declaration. A platform is Tier 1 only while its gate verdicts are exercised by the suite; if that stops being true it is demoted and the demotion is recorded. See ADR-015.


🔒 Source Code Availability & Distribution Policy

  • Distribution Mode: Holmes-Kit is currently distributed and executable as an official public npm package (@holmes-lab/holmes-kit).
  • Source Code Status: The underlying source code repository is currently private / closed-source.
  • Open Source Consideration: Decisions regarding whether, when, and how to transition to a full open-source codebase will be reviewed and determined in future milestones based on enterprise feedback, security audits, and community governance requirements.

📜 License

Distributed under the MIT License.