npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@spotpatch/agent

v1.6.0

Published

Node-only provider, tool, worktree, and validation engine for SpotPatch.

Readme

English

The Node-only Agent engine used by SpotPatch framework adapters. It owns OpenAI-compatible provider sessions, explicit and inline capability proof, bounded project-convention context and file tools, isolated Git worktrees, deduplicated validation checks, Diff review, Apply, and conflict-safe Revert.

Applications should enable this capability through a framework adapter such as @spotpatch/vite. This package is public so the adapter dependency graph can be installed and versioned; it is not a standalone UI integration.

Security boundaries:

  • no model-controlled arbitrary shell;
  • no browser-side API keys;
  • bounded paths, reads, writes, Diff sizes, turns, and tool calls;
  • rejected read paths stay unread and unmodified while the bounded Agent loop can recover through allowed discovery results;
  • no implicit stash, reset, commit, push, publish, or deployment;
  • review is the default apply mode.

Requires Node.js >=20.19.0.

Managed validation recognizes fixed, non-emitting TypeScript and Astro diagnostic commands. Installed dependency views are exposed only after the Agent turn and removed after validation, including failures. Arbitrary commands do not receive this exception. These checks trust installed tools; they are not an OS sandbox. See the Astro validation boundary.

简体中文

这是 SpotPatch 框架适配器使用的 Node-only Agent 引擎,负责 OpenAI-compatible Provider 会话、显式/内联能力证明、有界项目规范上下文与文件工具、隔离 Git worktree、去重后的项目检查、Diff 审阅、Apply 和冲突安全的 Revert。

业务应用应通过 @spotpatch/vite 等框架适配器启用该能力。本包公开发布是为了形成可安装、可版本化的依赖图,不是独立 UI 接入入口。

安全边界包括:不向模型开放任意 Shell、不把 API Key 放入浏览器、限制路径/读写/Diff/轮次/工具调用;只读路径被拒绝时保持零读取、零修改,并允许 Agent 在既有边界内改用合法发现结果继续执行;不隐式执行 stash、reset、commit、push、发包或部署。默认应用模式必须经过审阅。

要求 Node.js >=20.19.0。

Links / 链接