npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@qmxme/pi-rottweiler

v0.1.3

Published

Command guard extension for pi - blocks destructive git ops, ssh, and whole-filesystem find

Readme

@qmxme/pi-rottweiler

Command guard extension for pi that blocks destructive or dangerous shell commands before they run.

Features

Blocks the following before execution:

  • Pushes to protected branches: git push targeting master or main (including git push / git push <remote> while on master or main). Pushes to any other branch are allowed.
  • Other destructive git operations: git push --tags, git update-ref, git tag -d, git reset --hard
  • Release / version bumps: npm version
  • System / environment switches: nixos-rebuild switch, home-manager switch
  • The ssh family: ssh, ssh-add, ssh-agent, ssh-copy-id, sshd, sftp, scp, slogin
  • Whole-filesystem scans: find / (find on the entire filesystem)

How it works

Rather than regex-matching raw text (which both over-blocks words inside commit messages/strings and under-blocks wrapped invocations), rottweiler tokenizes the shell command and inspects the actual command words (argv[0]) — after shell separators and common wrapper commands (sudo, timeout, xargs, env, nohup, ...). Quoted text is treated as data, not commands, so words like ssh in a commit message or echoed string don't trigger a block.

It also recurses into shell -c '<command>' forms to catch commands nested inside a shell invocation.

Installation

pi install npm:@qmxme/pi-rottweiler

With a pinned version:

pi install npm:@qmxme/[email protected]

Project-local installation:

pi install npm:@qmxme/pi-rottweiler -l

Try without installing:

pi -e npm:@qmxme/pi-rottweiler

Development

npm install      # install type-checking dependencies
npm run typecheck  # type-check the extension
npm test         # run the regression test suite
npm run dev      # watch mode

License

MIT