npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@lmzhen/dsh-tool-skill-manage

v0.7.0

Published

Model-facing skill_manage tool (community build)

Readme

@lmzhen/dsh-tool-skill-manage

Model-facing skill_manage tool: it exposes skill-library mutations to the model and routes them through the evolution approval seam when one is mounted; it owns neither the library nor its lifecycle rules.

Model surface

  • Model-visible: the skill_manage tool schema and its success/validation messages; result tokens scale with what is returned.
  • Prompt prefix / KV cache: the tool schema is prefix-stable, and skill writes do not alter the current request prompt; catalog invalidation affects the next request; family rules: packages/README.md §"Model-visible prompt prefix and the KV cache".
  • Mount it? yes — the tool-skill-manage row, carried by the evolution-all and one-click evolution-preset bundles and the Evolution agent preset delta.

Safety model

Approval seam

Mutations (create/edit/update/patch/delete/write_file/remove_file/restructure) pass through the evolution approval seam when evolution-approval is mounted; approved/staged writes are replayed by the registered runner with the library origin preserved. The missing-required-argument pre-check runs BEFORE that boundary — one shared table and one refusal builder with executeCore, so the stage boundary and the execution check cannot diverge: a write that cannot execute is refused, never staged for approval.

pin/unpin: explicit exception

pin and unpin are deliberately outside the approval seam. Pinning only lifts/restores the curator-lifecycle freeze (a lifecycle flag, never content) and is fully reversible by the same tool. Routing it through policy:'ask' would let a staged-but-never-approved request hold the library in a pinned state invisibly. Tradeoff accepted: no approval on a lifecycle-flag flip; if product policy changes, pin/unpin should be wired into the same staging path as patch.

Configuration

  • maxSkillContentChars / maxSkillFileBytes bound SKILL.md reads and support-file writes on this row.
  • Deprecated name (G0/S0.3): maxSkillContentChars is the legacy spelling of the policy row's skillContentChars (canonical id). The two are not auto-synchronised with it: this row's value is what the write paths use, and since 0.6.0 the user settings layer can override it per user. Reading the legacy name still works; writing it is refused. Removal was planned for 0.7.0 and is deferred: the alias still ships, so no later version is claimed here.

Known limitations

  • No known durable consumer gaps at this time. Runtime contracts are covered by package and boundary tests.

Runtime invariant: No companion is published. The platform auto-assembles nothing and the family mounts no <pkg>/invariant cordis row, so a companion here would never execute (v37 S2.1 / I-3).

Notes and history

  • pin/unpin: explicit exception (0.3.18, E-70)