npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@vibecodeqa/mcp

v0.5.4

Published

MCP server for VibeCode QA — gives AI coding agents real-time code health context

Readme

@vibecodeqa/mcp

MCP server for VibeCode QA — gives AI coding agents real-time code health context.

When an AI agent writes or modifies code, it can query vcqa to check: "Is this file healthy? What patterns should I follow? Will this change degrade quality?"

Quick start

Claude Code

claude mcp add vcqa -- npx @vibecodeqa/mcp

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "vcqa": {
      "command": "npx",
      "args": ["@vibecodeqa/mcp"]
    }
  }
}

Cursor / other MCP clients

npx @vibecodeqa/mcp

One shared lens

This server is the single interface through which an agent observes a project — so an external agent (Claude Code, Cursor) and the desktop monitor's own Copilot see exactly the same thing. Observe a target project through these tools; if a capability is missing, add a tool here rather than reaching around into the repo or the app's private storage.

The in-app Copilot consumes this server directly: the Tauri app spawns it as a stdio JSON-RPC client (src-tauri/src/mcp_client.rs) and the copilot agent merges the tool list into its own toolbelt, routing every vcqa_* call through tools/call with the watched folder passed as path. It skips the tools that observe/steer the app itself (vcqa_app_state, vcqa_copilot_thread, vcqa_copilot_send) and vcqa_fix. So adding a tool here gives it to Claude Code and the Copilot at once.

Tools

Health (from the cli / .vibe-check/report.json):

| Tool | Description | |------|-------------| | vcqa_score | Quick score + grade + check summary (uses cache) | | vcqa_scan | Full scan — all 34 checks with issues and details | | vcqa_file_health | Issues for a specific file (use before/after editing) | | vcqa_check | Detailed results for one check (e.g., "complexity") | | vcqa_explain | What a check measures, why it matters, how to fix | | vcqa_fix | AI-powered fix for code issues (needs ANTHROPIC_API_KEY) | | vcqa_delta | Compare current scan vs previous — shows fixed/new issues |

Code (read the same source the monitor shows):

| Tool | Description | |------|-------------| | vcqa_read_file | Read a source file with line numbers | | vcqa_list_files | List project files (the Files-view inventory), filter by ext/substring | | vcqa_grep | Regex-search the project's source → file:line: text | | vcqa_graph | Module dependency graph — the Graph view's nodes (module/ui/lib) and import edges |

Structure (React architecture, from a local graphify call graph — uv tool install graphifyy):

| Tool | Description | |------|-------------| | vcqa_architecture | React layers (Routes/Components/Hooks/State/Services/Lib/Data) + inter-layer call flow — the Layers view | | vcqa_callflow | Real function-call tree from an entry symbol; no root → entry points ranked by reach — the Flow view | | vcqa_sequence | Static sequence diagram (Mermaid) for a symbol's call order — the Sequence view |

Live app state (what's on the user's screen — macOS desktop app):

| Tool | Description | |------|-------------| | vcqa_app_state | The running monitor's current project folder + open page + copilot-open | | vcqa_copilot_thread | Read the in-app copilot's per-page conversation (messages + tools it ran) | | vcqa_copilot_send | Post a message to a page's in-app copilot (as the user) and return its reply — also shows in the app UI. Write actions never fire on a sent message. |

Every project tool takes an optional path (defaults to cwd).

How agents use it

Before modifying a file:

→ vcqa_file_health({ file: "src/auth.ts" })
← 3 issues: complexity 28 (max 15), empty catch block, no test file

The agent now knows to simplify the function, add error handling, and write a test.

After generating code:

→ vcqa_score()
← B 78/100 (was B 80 — dropped 2 pts)
→ vcqa_check({ check: "security" })
← 1 new issue: innerHTML assignment in src/dashboard.tsx:42

The agent fixes the security issue before committing.

After a fix session:

→ vcqa_delta()
← Score: C 64 → B 80 (+16)
  Fixed: 89 issues | New: 3 issues
  +73 confusion (0 → 73), +55 lint (45 → 100), +12 standards (36 → 48)

Understanding a check:

→ vcqa_explain({ check: "confusion" })
← Measures naming ambiguity that causes LLMs to edit the wrong file...

Performance

  • Uses cached report.json from previous CLI runs (< 5 min old)
  • Falls back to live scan via npx @vibecodeqa/cli --skip-tests --json
  • In-memory cache with 60s TTL prevents redundant scans
  • Typical response: < 100ms (cached), 3-8s (live scan)

Links