npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

pi-getpass

v0.1.0

Published

Pi package providing a secure getpass tool for temporary secret environment variables

Readme

pi-getpass

A pi package that adds a getpass tool for collecting secrets safely from the user.

When the agent needs an API key, token, password, or other secret, it calls getpass with an exact env var name like OPENAI_API_KEY. The package temporarily replaces the normal pi input UI with a masked secret input, stores the secret in process.env for the current pi process, and returns only the env var name to the model. The secret value is not written to chat/session history.

What this is / is not

pi-getpass is a convenience tool for getting a secret from you without asking you to paste it into chat or manually write it into an .env file first.

It is not a secret-leakage guard or sandbox:

  • It offers no passive protection after the secret is captured.
  • It does not stop the agent, shell commands, other extensions, or child processes from reading or printing the env var.
  • It does not redact outputs from tools like env, printenv, set -x, logs, or config files.
  • It only provides a cleaner input path: masked TUI input → temporary env var → agent can use the env var name.

Use normal secret hygiene: do not echo secrets, avoid tracing, unset secrets when done, and review commands that consume them.

Install

pi install git:github.com/Microwave-WYB/pi-getpass

For local development from a clone:

git clone https://github.com/Microwave-WYB/pi-getpass.git
cd pi-getpass
pi install .
# or for one run only:
pi -e .

Tools

getpass

Collect a secret and store it in a temporary env var.

Parameters:

  • envVar — exact env var name to populate, e.g. OPENAI_API_KEY, GITHUB_TOKEN, DATABASE_URL
  • overwrite — allow replacing an existing env var of the same name; default false
  • prompt — text shown to the user
  • allowEmpty — allow an empty secret

Example agent flow:

  1. Call getpass with { "envVar": "OPENAI_API_KEY", "prompt": "Enter your OpenAI API key" }.
  2. Use $OPENAI_API_KEY in later bash calls, for example:
printf 'OPENAI_API_KEY=%s\n' "$OPENAI_API_KEY" >> .env

Do not echo or print the secret.

getpass_list

List env var names populated by getpass in the current pi runtime. Returns names only, never values.

getpass_unset

Unset a getpass env var from the current pi process:

{ "envVar": "OPENAI_API_KEY" }

Commands

/getpass OPENAI_API_KEY
/getpass-list
/getpass-unset OPENAI_API_KEY

Variables are temporary and last only for the current pi process/session runtime, unless explicitly written somewhere by a later command.