npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@peepsick/usb-cli

v1.0.1

Published

Universal Skill Bridge CLI — install, search, inspect and security-scan (secscan) AI agent skills from your terminal.

Readme

@peepsick/usb-cli

The Universal Skill Bridge command line.

Install 529 original agent skills (65 hand-researched domains × 8 workflows, plus 9 core skills) into Claude Code, Hermes, LeoSIS, Cursor, OpenAI, Anthropic, LangChain, MCP, OpenRouter, Groq, Mistral, Ollama, LM Studio, vLLM, or any custom path — with one command.

Install

npm install -g @peepsick/usb-cli

Or skip the package and grab the standalone bash script:

curl -fsSL https://usb.peepsicklabs.com/usb -o /usr/local/bin/usb && chmod +x /usr/local/bin/usb

Usage

# Interactive picker — pick what to install
usb

# Install the whole pack (auto-detects runtime)
usb install

# Install one skill by slug
usb install intent-router

# Install one domain (8 workflows)
usb install react-state

# Install a curated preset
usb install web-dev
usb install backend
usb install security

# Just the 9 core orchestration skills
usb install core-only

# Search the catalog
usb search oauth

# Show details about one skill
usb info intent-router

# Show pack version
usb version

# Security-scan skills before trusting them (Skill Contract Verifier)
usb secscan                        # project-local skills (.claude/skills, skills, .cursor/rules)
usb secscan --system               # installed skill locations on this machine
usb secscan --repo owner/repo      # fetch a git/GitHub repo read-only and scan it
usb secscan ./some/skills --json   # machine-readable report
usb secscan --write-baseline .     # snapshot findings; then gate CI:
usb secscan --baseline .usb-secscan-baseline.json   # only NEW findings block

Security scanning

usb secscan verifies each skill's contract: does the body only do what the frontmatter declares? Undeclared capabilities (credential access, pipe-to-shell network egress, destructive deletion, persistence hooks) are findings; vague or silent-agency phrasing is reported as advisory signals and never blocks on its own. Deterministic output, --json for CI, exit 1 when a contract is violated. Requires python3. See the repository README ("Security scanning skills") for the rule catalog.

How it works

The CLI is a thin bash wrapper (~6 KB, zero dependencies beyond curl and bash) that talks to the public USB catalog. No local state, no API keys, no telemetry by default.

Python dependencies (optional)

usb secscan and usb mcprobe require only Python 3 (no pip packages). usb mcp (MCP stdio server) additionally requires the mcp Python package:

pip install mcp
# or
pip install -r $(npm root -g)/@peepsick/usb-cli/requirements.txt

License

MIT — part of the USB open-source project.