npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@nx-devkit/skillspector

v0.1.19

Published

Nx plugin for SkillSpector security scanning: any SKILL.md gets a scan target reporting vulnerabilities, secrets, and risky patterns — with SARIF output and CI annotations.

Downloads

6,215

Readme

@nx-devkit/skillspector

Nx plugin for SkillSpector security scanning: any directory containing SKILL.md becomes a project with a scan target that analyzes skill code for vulnerabilities, secrets, and risky patterns. No project.json needed.

Part of nx-devkit.

Install

bun add -D @nx-devkit/skillspector

Depends on @nx/devkit ^22 || ^23 (installed automatically) and a skillspector binary reachable on PATH — or point the skillspectorBin option at any install.

Register

nx add @nx-devkit/skillspector   # runs the init generator — registers the plugin in nx.json

Or manually:

// nx.json
{ "plugins": ["@nx-devkit/skillspector"] }

What it infers

| Trigger | Target | Executor | |---|---|---| | SKILL.md | scan | @nx-devkit/skillspector:scan — spawns the skillspector binary via execFile, no shell |

Inspect

npx nx show projects
npx nx show project <name>
npx nx run <name>:scan

Options

{
  "plugins": [
    ["@nx-devkit/skillspector", {
      "scanTargetName": "scan",
      "noLlm": true,
      "annotations": true,
      "failOnError": true,
      "skillspectorBin": "skillspector",
      "sarif": "reports/skillspector.sarif",
      "baseline": ".skillspector-baseline.json"
    }]
  ]
}

| Option | Default | Effect | |---|---|---| | scanTargetName | scan | Name of the inferred scan target. | | noLlm | true | Disable LLM-based analysis (static checks only). | | annotations | true | Write annotations-<projectName>.txt with ::error workflow-command lines for code findings (skipped on a clean scan). | | failOnError | true | Fail the target when HIGH or CRITICAL findings are present. | | skillspectorBin | skillspector | Binary to invoke — override for local dev or vendored installs. | | sarif | — | Path prefix for the SARIF 2.1.0 report — -<projectName>.sarif is appended (any .sarif suffix is stripped first), so reports/scan.sarif produces reports/scan-<name>.sarif. | | baseline | — | Path to a baseline file suppressing known findings. |

CI integration

  • Annotations — with annotations: true (default) and at least one code finding, the executor writes annotations-<projectName>.txt at the workspace root containing ::error file=…,line=…:: workflow-command lines (findings-only; the file is not created on a clean scan). Surface them in CI by cating the files into the step output or uploading them as an artifact — they are not emitted to stdout automatically.
  • SARIF — set sarif to a path and upload it with github/codeql-action/upload-sarif, or convert to annotations with a SARIF-to-annotations step.
  • Gating — failOnError fails CI on HIGH/CRITICAL; use baseline to ratchet down existing debt.

Skip rules

  • SKILL.md inside node_modules is skipped.
  • SKILL.md at the workspace root is skipped.
  • SKILL.md escaping the workspace root is skipped.

Project naming

Like @nx-devkit/skill, project names are slug + a 12-hex-char SHA-256 suffix of the project root — collision-resistant in practice (birthday bound applies, not a guarantee).

License

MIT