npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@schava09/slopgate

v0.1.0

Published

The verification gate for AI-generated code. Catches the failure modes coding agents introduce — hallucinated APIs, silent logic drift, weakened tests, security regressions — and blocks the merge until they're addressed.

Readme

slopgate

The verification gate for AI-generated code.

Coding agents ship code faster than humans can review it. The bottleneck in 2026 isn't writing code — it's verifying it. slopgate is the gate that runs on a diff and catches the specific failure modes agents introduce, so bad changes stop at the door instead of in production.

npx @schava09/slopgate

It reviews your current diff and exits non-zero if it finds a blocking problem — drop it in CI and it gates every PR.


What it catches

Not style. Not nits. The things that actually pass human review under volume and break the build (or the business):

| | | |---|---| | 🧩 Hallucinated APIs | Calls to functions, imports, config keys, or flags that look real but don't exist. | | 🔀 Silent logic drift | An inverted condition, a changed default, a dropped edge case in a "no-behavior-change" refactor. | | 🧪 Weakened / missing tests | New logic with no test; an assertion loosened or changed to match wrong behavior. | | 🚧 Stubs masquerading as done | TODOs, mock return values, empty catch blocks, functions that return early without doing the work. | | 🔓 Security regressions | Injected SQL/command/path, committed secrets, removed auth checks, unsafe deserialization. | | 🐛 Agent-blind correctness bugs | Missing awaits, null derefs, resource leaks, races, broken error handling. |

Every finding cites a real line, quotes the offending code, carries a confidence level, and gives a concrete fix — no "consider reviewing this."


What it looks like

Run against a 4-line diff that inverts a + into a -, adds a raw-SQL checkout, and leaves a TODO:

## slopgate — verification gate

Verdict: This diff is not mergeable: it inverts the summation in `total`
(now returns a negative total), adds a `checkout` function that concatenates
user input into raw SQL against an undefined `db` reference, and leaves a
TODO in place with no tests.

6 finding(s): 2 critical, 2 high, 2 medium

🟥 Summation operator flipped from + to -, total is now negative
   cart.js:3 · critical · logic-drift · confidence: high
   `return items.reduce((a,b)=>a-b.price,0)` — starting from 0 and subtracting
   each price yields the negation of the cart total. Nothing in the diff
   justifies this.
   Fix: Restore `a+b.price`.

🟥 SQL injection via string-concatenated user id in checkout
   cart.js:5 · critical · security · confidence: high
   Fix: Use a parameterized query, `db.execute('... id = ?', [u.id])`.

🟧 `db` is undefined — no import or parameter provides it
   cart.js:5 · high · hallucinated-api · confidence: high
   Throws ReferenceError at call time.

…plus the missing-tests, un-awaited-promise, and TODO-stub findings. Exit code 1 → CI fails.


Install & run

Requires Node 18+ and an Anthropic API key.

export ANTHROPIC_API_KEY=sk-ant-...

# Review your branch against origin/main
npx @schava09/slopgate

# Review only what's staged (great as a pre-commit hook)
npx @schava09/slopgate --staged

# Diff against a specific ref, block only on high+ severity
npx @schava09/slopgate --base origin/develop --fail-on high

Options

--staged              Review staged changes instead of a branch diff
--base <ref>          Diff against this ref (default: merge-base with origin/main)
--fail-on <severity>  Block at/above: critical|high|medium|low|never   (default: high)
--format <fmt>        markdown | json                                   (default: markdown)
--context <text>      Extra repo context to hand the reviewer
--context-file <path> Read that context from a file
--model <id>          Model override (default: claude-opus-5)

Exit code is 1 when something at or above --fail-on is found, 0 otherwise — so CI fails loudly and pre-commit hooks block the commit.


Gate your PRs (GitHub Action)

Add .github/workflows/slopgate.yml:

name: slopgate
on: pull_request
jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      - uses: sharanya09/slopgate@v0
        with:
          anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
          base: ${{ github.event.pull_request.base.sha }}
          fail_on: high

The findings render into the job summary, and the check fails when a blocking issue is found.

Pre-commit hook

echo 'npx --yes @schava09/slopgate --staged --fail-on high' > .git/hooks/pre-commit
chmod +x .git/hooks/pre-commit

Cost

slopgate makes one model call per run over your diff. Defaults to claude-opus-5 for the sharpest review. For high-volume repos, --model claude-sonnet-5 is meaningfully cheaper and still strong on this task.

Tune what it catches

The entire rubric lives in src/prompt.js. Fork it, add the failure patterns your team keeps hitting, and it becomes your team's institutional review knowledge in one file.

License

MIT