npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@openlibing/openlibing-cli

v0.1.9

Published

OpenLibing MCP 本地 CLI:把 ops 报告等只读能力包装为 MCP 工具(stdio 传输)

Readme

@openlibing/openlibing-cli

OpenLibing MCP 本地 CLI:把 ops 报告等只读能力包装为 MCP 工具(stdio 传输),供 Trae / OpenCode 等 AI 客户端直接调用。

特性

  • MCP 工具(stdio):report_listTemplates / report_queryData / auth_login
  • 连接即授权:mcp start 启动时自动续期凭证;凭证失效自动弹出浏览器授权,点一次即完成
  • 平台选择:登录时弹出平台选择页(GitCode / Gitee / GitHub / UniPortal / OpenUBMC),点选后跳转对应平台授权
  • 凭证安全:token/refresh/csrf 本地 AES-256-GCM 加密存储(~/.openlibing-cli/auth.{env}.json,按环境分文件,beta/prod 互不覆盖),不落服务端
  • 401 自愈:工具调用遇 401 自动 refresh 续期重试;续期失败返回明确引导(不依赖外部 cookie)

安装

# 直接通过 npx 使用(推荐,AI 客户端配置方式)
npx -y @openlibing/openlibing-cli --version

# 或全局安装
npm install -g @openlibing/openlibing-cli

客户端配置

Trae(手动添加 MCP)

{
  "mcpServers": {
    "openlibing-report": {
      "command": "npx",
      "args": ["-y", "@openlibing/openlibing-cli", "mcp", "start"],
      "env": {
        "OPENLIBING_ENV": "beta",
        "START_MCP_TIMEOUT_MS": "300000"
      }
    }
  }
}

START_MCP_TIMEOUT_MS 建议 ≥ 300000(5 分钟),给首次授权留足时间,避免 60 秒默认超时误判失败。

OpenCode(opencode.jsonc)

{
  "mcp": {
    "openlibing-report": {
      "type": "local",
      "command": ["npx", "-y", "@openlibing/openlibing-cli", "mcp", "start"],
      "environment": { "OPENLIBING_ENV": "beta" },
      "enabled": true
    }
  }
}

登录(点一次授权)

MCP 连接时若本地无有效凭证,会自动弹出浏览器:

  1. 平台选择页 → 点选登录平台(默认 GitCode)
  2. 跳转该平台授权页 → 点一次"授权"(首次可能需要先登录平台账号)
  3. 浏览器自动关闭,凭证加密保存,MCP 开始提供工具

命令行方式:

# 自动登录(弹平台选择页,点一次授权)
npx -y @openlibing/openlibing-cli auth login

# 强制手动粘贴 URL 方式(无浏览器/特殊场景)
npx -y @openlibing/openlibing-cli auth login --manual

# 查看登录状态 / 续期 / 退出
npx -y @openlibing/openlibing-cli auth status
npx -y @openlibing/openlibing-cli auth refresh
npx -y @openlibing/openlibing-cli auth logout

自动登录依赖本机 Chrome 或 Edge(优先 Chrome,失败回退 Edge)。两者都没有时回退手动粘贴方式。

环境变量

| 变量 | 默认 | 说明 | | --- | --- | --- | | OPENLIBING_ENV | beta | 环境:beta / prod / gamma / local,决定网关与 ops 地址 | | OPENLIBING_PLATFORM | gitcode | 默认登录平台(手动模式兜底用;自动模式弹选择页) | | OPENLIBING_GATEWAY_URL | 按 env | 覆盖网关地址 | | OPENLIBING_OPS_URL | 按 env | 覆盖 ops 报告接口地址 | | OPENLIBING_PLUGIN_CLIENT | agent_arena | 插件登录 client(须在网关白名单) | | OPENLIBING_PLUGIN_ID | openlibing-cli | 插件标识 | | OPENLIBING_AUTH_FILE | ~/.openlibing-cli/auth.{env}.json | 覆盖凭证文件路径(测试隔离用) |

凭证与安全

  • 凭证文件:~/.openlibing-cli/auth.{env}.json(如 auth.prod.json / auth.beta.json;AES-256-GCM,密钥由本机标识派生,换机器/用户不可解密)
  • 环境隔离:各环境独立登录、独立凭证文件;切换 OPENLIBING_ENV 自动读写对应环境凭证,不再互相覆盖
  • token / csrf 有效期约 30 分钟:mcp start 启动和 401 时自动用 refresh token 续期,无需手动干预
  • refresh token 失效后需重新授权(自动弹浏览器,点一次即可)
  • 401 错误信息明确指引运行 auth login / auth refresh,不会引导获取网关 cookie

发布与维护

  • 版本发布走项目级 npm-manage skill(publish.py 解密 npm token 发布,token 不落明文)
  • 版本:0.1.8(登录平台选择 / 连接即授权 / 401 自愈 / Playwright 自动登录 / 登录态持久化 / 字段命名同步 workflow 与 job 级时间)
  • 包名:@openlibing/openlibing-cli(原 @openlibing/mcp-cli 已 deprecated,迁移说明见下)

迁移说明(mcp-cli → openlibing-cli)

  • npm 包:@openlibing/mcp-cli → @openlibing/openlibing-cli,安装/调用命令同步替换
  • bin 命令:mcp-cli → openlibing-cli
  • 插件 ID:openlibing-mcp-cli → openlibing-cli(gateway 插件授权白名单需同步)
  • 凭证目录:~/.openlibing-mcp-cli/ → ~/.openlibing-cli/(旧凭证失效,需重新授权一次)
  • 源码仓:openlibing-mcp-cli → openlibing-cli(git 历史已完整迁移)

开发

npm install
npm run build      # tsc 编译到 dist/
npm test           # vitest(握手/凭证/工具注册)

关键源码:

| 模块 | 说明 | | --- | --- | | src/auth/browser.ts | 系统浏览器启动(chrome→edge 回退)、平台选择页、回调捕获 | | src/auth/login.ts | 插件登录 / 自动授权 / 凭证续期 / MCP 启动鉴权 | | src/auth/store.ts | 凭证 AES-256-GCM 本地加密存储 | | src/client/reportApi.ts | 报告接口客户端(401 自动续期 + 引导错误) | | src/mcp/server.ts | MCP stdio server 组装 |