npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@ktlsr/assay-runner

v0.2.0

Published

Sandboxed run execution, host adapter contract and local run store for Assay — a CI test runner for Agent Skills.

Readme

@ktlsr/assay-runner

The execution layer of Assay, a CI test runner for Agent Skills.

core decides what a result means. This package produces the material it decides on: it runs a case set N times against a host adapter, captures what happened, and writes a canonical run record to disk.

npm install @ktlsr/assay-runner

What it does

Runs a suite. runSuite executes every case the configured number of times, collects evidence per attempt, and returns a Run — the canonical record type defined in @ktlsr/assay-core. The repeat count is never 1 by default: a single attempt is an observation, not a measurement.

Provides a workspace per attempt. createWorkspace gives each attempt its own temporary directory. snapshot and envDiff hash the file system before and after so writes can be attributed, and capture reads back the artifacts an assertion needs, within the limits in CAPTURE_LIMITS.

The workspace observes; it does not enforce. File system and network boundaries rest on the host's own permission layer, and a process that opens its own socket is not seen. Where the boundary cannot be observed the run records that fact and the affected assertion becomes unknown — a shell command, for instance, is not readable as a set of writes, so side-effect claims around it are not scored. The ceiling is documented rather than papered over; see sandbox-security.md.

Pins the run. pinsOf and suiteHash record the four pins a later comparison requires, including hashes computed from actual content rather than declared version strings.

Stores runs locally. RunStore writes versioned JSON under .assay/runs/. Records are human-readable and can be uploaded as a CI artifact directly. No database and no hosted service is required for any of this.

Writing an adapter

A host adapter implements HostAdapter from @ktlsr/assay-core. Every method is async, so a synchronous throw still surfaces as a rejected promise and the runner can handle failure in one place. See docs/adapters.md.

@ktlsr/assay-runner/testing exports a MockAdapter. It is a test tool. It is deliberately kept off the main entry point and a repository test fails if any non-test source imports it, because fabricated results must never reach a report.

License

Apache-2.0. See LICENSE and NOTICE.