npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

guardrail-local

v0.1.9

Published

CLI local para orquestrar auditorias de segurança de código com a sua IA.

Readme

GuardRail local

A CLI do GuardRail não escolhe nem hospeda a IA do cliente. Ela apenas prepara o playbook, executa o comando local configurado e valida as evidências antes de gerar o relatório.

Instalação para desenvolvimento

Na pasta deste projeto, execute npm link. Depois, em qualquer repositório local, execute guardrail init.

Configuração do executor

Execute uma vez guardrail connect --command "sua-ia --prompt {prompt}". O comando pode usar {workspace}, {prompt} e {output}. Para integrações automáticas, a IA pode gravar no {output} um JSON com findings. No modo universal, ela apenas executa o prompt e gera o PDF padrão em docs/security-audit/; o GuardRail reconhece esse resultado ao executar guardrail finalize.

Auditoria

No repositório que será auditado: use guardrail audit para integração por CLI, ou guardrail prepare, execute sua IA normalmente e termine com guardrail finalize.

Os resultados são gravados em docs/security-audit/relatorio-auditoria-seguranca.pdf e docs/security-audit/achados-verificados.json.

OpenCode

Dentro do repositório que será auditado, conecte uma única vez com guardrail connect opencode. Depois use apenas guardrail audit. O GuardRail usa opencode run no diretório do projeto e reconhece o PDF que o OpenCode gerar.

Codex

No repositório auditado, configure a integração local uma vez:

guardrail init
guardrail connect codex

Reinicie o Codex e peça, por exemplo: Execute uma auditoria GuardRail com o perfil full neste projeto. A integração MCP expõe todos os perfis atuais (full, api, frontend, secrets e infra), além de validar e gerar os relatórios ao fim da análise.

Instalação pelo npm

Depois da publicação, instale a CLI sem usar npm link:

npm install --global guardrail-local

Ou execute-a sem instalação global:

npx guardrail-local init
npx guardrail-local connect opencode
npx guardrail-local audit

Para usá-la como dependência de desenvolvimento de um projeto:

npm install --save-dev guardrail-local
npx guardrail init

Consulte o guia completo da CLI para todos os comandos, o contrato do JSON de saída, o fluxo manual e a solução de problemas.