npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@xaccefy/pi-xpi

v0.9.4

Published

XPI — offensive security tools for Pi Agent. Casefile tracking, web search, library docs, exploit technique search, and todo tracking.

Readme

XPI

Security tooling for the Pi agent — casefile tracking, web search, exploit-technique intelligence, code search, and todos.

npm version npm downloads License: MIT

What it is

XPI turns the Pi agent into a security researcher: a case ledger with enforced gates, real exploit-technique grounding, web lookup, fast code search, and a pipeline that keeps findings honest.

  • Casefile — hypothesis → investigating → confirmed → reported, with gates at every step
  • Machine-owned PoC gates — zero exit is necessary but never proof: direct-response findings require nonce-bound body evidence plus a DNS-pinned, conclusive target_only replay against an operator-approved control; reflection-capable requests can add a harness-generated target-only canary; only the main agent may make the semantic decision and commit phase 2
  • Exploit chainsChainSuggest surfaces combinations the model missed
  • Coverage matrix — machine-checkable "we tested everything" claims
  • Code search — structural AST search (ast-grep) for sinks and call chains, plus built-in grep/find for text

Install

Works on Pi Agent and its fork OMP (@oh-my-pi/pi-coding-agent). One manifest serves both: OMP reads the same pi extension field, the Agent Plugins plugin.json for skills, and the task tool spawns the specialist agents.

./install.sh            # auto-detects pi or omp in PATH
./install.sh --pi       # force Pi  (installs pi-subagents + optional ast-grep structural search)
./install.sh --pi --no-subagents  # minimal Pi install; use /xp lite because swarm dispatch is unavailable
./install.sh --omp      # force OMP (copies agents/*.md to ~/.omp/agent/agents)

Or install the npm package per host:

pi install npm:@xaccefy/pi-xpi     # Pi
omp install npm:@xaccefy/pi-xpi    # OMP

Set PREVIEW_IS_API_KEY for exploit_search (see docs/guide.md).

Quick start

/xp        # toggle bounded swarm XP mode on/off
/xp lite   # explicit single-agent security workflow
/xp swarm  # bounded multi-agent pipeline

Use /xp for the default bounded swarm workflow, or /xp lite for CTFs, focused reviews, and one-target work where dispatch is unnecessary. On Pi, swarm dispatches only auditor, tracer, skeptic, and chain via pi-subagents; on OMP it uses the native task tool with the same four agent names. Validation, patching, reporting, and ConfirmFinding stay with the main agent.

Full tool reference, configuration, and pipeline docs: docs/guide.md.

Packages

| Package | npm | |---------|-----| | Umbrella | @xaccefy/pi-xpi | | Case ledger | @xaccefy/pi-casefile | | Web lookup + exploit search | @xaccefy/pi-webxp | | Todos | @xaccefy/pi-xtodo |

Develop

bun install
bun test --isolate
bun run typecheck