npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@mkaliezz/dsh-context-pack

v0.2.0

Published

Deterministic privacy-aware repository context packs for DeepSeek Harness

Readme

dsh-context-pack

Deterministic, privacy-aware repository context packs for DeepSeek Harness (DSH).

The DSH-native /context-pack [repository path] command performs an explicit, read-only scan, builds a bounded pack, then queues that pack through agent.inject() for the next model step. It does not wake an idle agent, modify source files, or silently include files that exceed privacy/size rules.

Why

DSH makes model-visible context part of the agent/session lifecycle. A repository context plugin should therefore be bounded and inspectable rather than silently dumping an entire repository into every prompt.

v0.1 behavior

  • human-initiated /context-pack command; no model-directed autonomous scan;
  • deterministic path ordering;
  • fixed noisy-directory exclusions;
  • fail-closed sensitive-path exclusions (.env, common credential/secret names, SSH private-key names);
  • text-extension allowlist;
  • per-file, total-byte, file-count, and final injection budgets;
  • full-file inclusion only — no silent truncation;
  • SHA-256 per-file identity and whole-pack digest;
  • lightweight stack detection;
  • no network and no source mutation;
  • context is queued via the documented DSH agent.inject() seam and is therefore consumed at a later admitted model step.

Bundle config

- id: dsh-context-pack
  name: '@mkaliezz/dsh-context-pack'
  config:
    maxFiles: 60
    maxTotalBytes: 120000
    maxFileBytes: 30000
    maxInjectedBytes: 120000

Run:

/context-pack .

The command returns only a compact receipt (pack digest, included-file count, source bytes, exclusion count). The model-visible pack is injected separately through DSH rather than echoed into the command result.

Core API

const pack = await buildContextPack('/path/to/repo', {
  maxFiles: 60,
  maxTotalBytes: 120_000,
  maxFileBytes: 30_000,
})

Non-claims

  • not a secret scanner or DLP system;
  • not a sandbox;
  • no complete .gitignore compatibility yet;
  • no semantic relevance ranking;
  • no guarantee that every sensitive filename pattern is covered;
  • v0.1 does not persist a standalone context-pack lifecycle record beyond DSH's own command/inbox/session facts.

Development

npm test

Because DSH is Developer Preview, compatibility should be proven against a pinned DSH revision before each compatibility claim.

License

MIT