npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@pi-harness/plugin-skill-catalog

v0.1.33

Published

List loaded Agent Skills and safely inspect one through a bounded untrusted-data boundary, plus managed MCP status.

Readme

@pi-harness/plugin-skill-catalog

Skills Catalog — List loaded Agent Skills and safely inspect one through a bounded untrusted-data boundary, plus managed MCP status.

Install

npm install --save-exact @pi-harness/plugin-skill-catalog

Enable

Add the entry to the Cordis profile the harness starts from:

- id: skill-catalog
  name: "@pi-harness/plugin-skill-catalog"
  config: {}

Skills Catalog requires the core resource loader, but MCP Client is optional. Without the piMcp service, skill listing and reading still work; action: "mcp" reports available: false and the panel shows MCP as unavailable rather than claiming zero configured servers. To inspect MCP status, separately install and enable @pi-harness/plugin-mcp-client; reuse an existing instance instead of adding a duplicate. An empty servers: [] configuration provides the service without starting external processes.

The Pi Harness plugin marketplace installs and enables this package for you; the steps above are the manual equivalent.

Tool contract

skill_catalog supports { action: "list", query?: string }, { action: "read", name: string }, and { action: "mcp" }. Unknown actions, fields and fields belonging to other actions are rejected. Queries contain at most 120 characters; names contain 1–64 characters. NUL and accessor properties are rejected.

list reads the current resource loader snapshot each time. It returns full matching and loaded counts, up to 200 skills and 100 diagnostics, and a truncation flag. Fields are bounded (name 64, description/diagnostic message 2,000, path 4,096 characters). modelInvocationDisabled means the loaded skill is excluded from automatic model invocation; explicit inspection remains available. This flag does not mean the skill failed to load.

read finds an exact loaded skill name independently of the list display limit and reads at most 128 KiB of valid UTF-8 from a regular nonsymlink file. It returns permitted content as untrusted data; review/blocked findings withhold the source. These are heuristic checks, not proof of safety or an instruction execution boundary. The tool does not activate skills. Cancellation, disposal or replacement/removal of the loaded skill during the read rejects the result; an in-flight bounded filesystem read completes before cancellation is observed. File contents are read at execution time, not frozen when the loader indexed metadata.

mcp returns service availability, up to 100 server IDs, statuses and start times, with full count and truncation. Startup commands and arguments are omitted. It does not start servers or change configuration. The panel reads current snapshots and displays at most eight skills and six server states. All bounded metadata is model-visible and no legacy aliases are retained.