npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

hawkeye-review

v0.11.1

Published

Code review on your own Claude or Codex plan.

Readme

Hawkeye is a code reviewer that belongs to you, not to a repository. Open a pull request, and a runner on your machine reads every push with the coding agent you already pay for, under your own login, then posts one verdict as hawkeye-review[bot].

  • What it costs: nothing beyond that plan. No seat, no token bill.
  • Why it is different: every other AI reviewer is bought per seat and wired into a repository by an admin. This one runs on your subscription, on your hardware. Your plan credential and your repository never reach a server of ours; only the findings do.
  • What it needs today: a Claude Code or Codex login on the machine that runs the reviews.

Sign in with GitHub to review every push, or try one review with no account:

npx hawkeye-review check <pr-url>

What a review gives you

  • A verdict that follows the findings. Blocked only when something must be fixed, Changes needed when something should be. The model's own opinion never sets it.
  • Every finding says what breaks and what to do. Pinned to the changed line when there is one, with a one-line replacement when that alone fixes it. No praise, no hedging, and silence where the code is fine.
  • Held to your repository's rules. It reads AGENTS.md, CLAUDE.md and CONTRIBUTING.md, then looks at intent, behavior, blast radius, verification, fit and hygiene.
  • It follows up on every push. One comment, updated in place. Fixed findings resolve, only new ones are raised, and problems older than your change are marked Inherited and never block it.

What it caught on its own pull requests

Three findings from Hawkeye's reviews of Hawkeye, each fixed before merge. Every review is public.

  • Must fix · #260 · The new fallback lets a user arm a pull request they did not author.
  • Should fix · #262 · Concurrent claims can invalidate the replacement run they just handed out.
  • Should fix · #238 · event.currentTarget is null once await navigator.clipboard.writeText has rejected, so the refused branch throws.

A real review

The first round on this repository's own pull request #87 is a review the bot posted: a verdict, one line per finding with the file and line, the lenses behind a disclosure, and the round in the footer. The landing page replays it from open to posted.

What happens when you open a pull request

  1. Every push queues one job for its head. Pushes collapse to the latest head, so a busy branch never piles up reviews. The hosted control plane holds only the queue, webhooks and findings.
  2. Your runner claims it and clones the branch. One process on hardware you own. The control plane never sees a plan credential and never proxies model traffic.
  3. Your coding agent reviews it under your login. Only the validated findings leave the machine; the checkout and your login stay there.
  4. The comment lands as hawkeye-review[bot]. A comment and a passing commit status that carries the verdict, never a block. Merging stays your call.

Your plan's limits are the budget, and the dashboard shows what each review took in turns and minutes.

What the runner can reach

A review runs a coding agent on your machine, as you, over code you did not write. Know what that means before you connect a runner.

  • What it can reach. The agent runs shell commands to read and test the checkout, with your environment and your files in reach, not only the pull request. Anything your own terminal can read, change or run, a command it runs could too.
  • What it is denied. Its file-editing, web-fetch and web-search tools are removed. The shell stays, so the first point holds in full: a command can still write a file or start a program. The checkout's own agent configuration (CLAUDE.md, .claude/) is removed before it starts and the repository's settings are never loaded, so a pull request cannot change the reviewer's tools or settings. The branch's AGENTS.md, CLAUDE.md and CONTRIBUTING.md are still read into the prompt as repository rules, fenced as untrusted text. The token that cloned the branch is never written into the checkout.
  • What bounds the risk today. The runner reviews pull requests you open, in repositories you chose, so the exposure is code from the people who can push to your branches. prepare reviews whatever pull request URL you hand it, inside your own agent session and with that session's permissions: the tool and settings denials above stop at the runner, while the removed agent configuration and the clone token kept out of the checkout apply there too. Hand it code you would be willing to run. Reviewing strangers' pull requests waits for a sandbox around the shell (#160).

Run the runner on a machine, or under a user, whose files you are willing to have read by a program reviewing that code.

Start with one pull request

You need a machine with Node 22 or newer, git 2.31 or newer, and Claude Code or Codex installed and signed in (run claude or codex once and check it answers). Nothing else is installed; npx fetches the runner each time.

  1. Sign in with GitHub at hawkeye.reviews.

  2. Install the GitHub App on a repository you admin: open github.com/apps/hawkeye-review, choose Install, and pick the repositories. The App is how the review gets posted: it reads the repository, its issues and its pull requests, and writes review comments and commit statuses. Signing in also shares the email address on your GitHub account.

  3. Start the runner on that machine and leave it running:

    npx hawkeye-review runner

    The first run connects the machine: it opens the Connect page and prints a code. Type the code there and approve it; the terminal says it is connected, saves its token and starts. The Runners page shows it online within a minute. If the machine sleeps or the terminal closes, reviews wait in the queue and run when it is back.

  4. Open a pull request of your own, not a draft, in a repository you installed the App on. A draft is reviewed once you mark it ready, unless you turn on "Review drafts too" in Settings. Within a minute its checks show hawkeye as "Reviewing on ", and a few minutes later the review is posted as a comment. Every later push is reviewed again, and the same comment is updated in place.

To stop: open the pull request's page from the Pull requests list and press Pause reviews; Turn reviews on brings it back. Settings turns automatic review off for the pull requests you open from then on; ones already being reviewed keep going until you pause them. Closing the terminal stops the runner, and queued reviews wait for it.

If nothing happens, the Runners page says whether your runner is online, and each pull request's page on the dashboard lists its runs with the reason when one failed.

Try one review with no account

npx hawkeye-review check <pr-url> reviews the pull request with Claude Code or Codex on your machine and prints the review in the terminal: the verdict, then each finding with its file, line and what to do. Nothing is posted anywhere. Run it again after a new push and it reviews what changed since. It needs Node 22, git, Claude Code or Codex signed in, and a GitHub token (gh auth token is enough).

To have your own agent session do the review instead, npx hawkeye-review prepare <pr-url> writes the review prompt, and the show command it prints reads the result.

Open source, yours to run

  • MIT licensed, and every pull request to this repository is reviewed by Hawkeye itself before a maintainer reads it.
  • Run your own instance: the self-hosting guide covers a Vercel deployment on Neon Postgres, the way the hosted instance runs. Docker Compose is there for development.
  • Read how it works and why, the contributing guide, and the security policy.