npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

redshift-security-harness

v0.1.1

Published

Scoped, source-aware red-team security harness for local repositories.

Readme

What Is Redshift?

Redshift is a security harness for focused, source-aware red-team work. Give it a local target and a clear objective. It coordinates specialist agents to inspect the relevant code, challenge assumptions, and return one prioritized report in your terminal.

This is not a chat workspace or a general-purpose autonomous agent. Every assessment begins with an explicit target, stays within the requested repository scope, and ends with evidence-backed findings you can act on.

How It Works

  1. Define the component or path you want assessed.
  2. State the security question you want answered.
  3. Redshift maps the attack surface and assigns focused review work across trust boundaries, data flows, and supply-chain exposure.
  4. Findings are reconciled into a single report with evidence, impact, and recommended next actions.

Quick Start

npm start -- configure

npm start -- scan `
  --target src `
  --objective "Find authorization and untrusted-input paths"

Check the proposed assessment scope before using a model:

npm start -- scan --target src --objective "Review the public API" --dry-run

Run npm start -- scan --help for command options.

Bring Your Own Key

Run redshift configure once to choose a provider and save its model settings locally. Redshift supports OpenAI, Google Gemini, OpenCode Zen and Go, and local Ollama. OpenCode Zen and Go use the same OpenCode API key for Go subscribers. API-key entry is hidden in the terminal. Choose a model supported by your selected provider.

Your configuration is saved outside the repository in your user configuration directory. It is never committed with the project. Environment variables and command flags can still override saved settings for a single run.

What Redshift Reviews

  • Entry points and exposed attack surfaces
  • Authentication, authorization, tenancy, and privilege boundaries
  • Untrusted data flowing into sensitive operations
  • Dependencies, build paths, configuration, and release assumptions
  • Candidate issues that benefit from a safe local validation step

Assessment Boundaries

Redshift is designed for authorized work against local source code.

  • Targets must remain inside the selected repository root.
  • Agents operate read-only and do not modify the source tree.
  • Assessments do not probe external systems, use real credentials, or report secret values.
  • Findings distinguish confirmed issues from likely risks, open questions, and hardening opportunities.

Using a remote model means the source excerpts it requests are sent to that provider. Configuration asks for explicit approval first. Configure only providers you trust with the repository under assessment.

Agent Roles

Redshift uses a small, purpose-built crew rather than a single general reviewer:

  • Recon maps reachable surfaces and trust boundaries.
  • Trust investigates identity, authorization, and privilege controls.
  • Dataflow traces attacker-controlled input toward sensitive operations.
  • Supply Chain examines dependency, configuration, and delivery risks.
  • Validator performs narrow, safe local validation when needed.
  • Reporter turns the collected evidence into the final terminal report.

The definitions are kept in agents/. The agent-to-agent coordination reference is available in blueprints/A2A_PORTABLE_PLAYBOOK.md.

License

Redshift is available under the MIT License.