npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

tribunal-kit

v9.2.8

Published

Tribunal Kit is the governance layer for AI coding agents that stops AI hallucinations and npm ghost packages before they hit disk. Works with Cursor, Windsurf, Claude Code, and Aider.

Readme

🛡️ Value Proposition

AI coding assistants frequently hallucinate dependencies, deprecated framework hooks, and incorrect database columns. Linters and typecheckers catch these errors only after the code is written, failing to understand semantic intent during generation.

Tribunal Kit acts as a neurosymbolic verification envelope. It intercepts AI output locally in < 10ms, validates it against your live repository AST, and prevents hallucinated code and phantom packages from ever touching your disk.


⚡ What's New in v9.2.7

  • Skill Intelligence Engine (tk skill-intel): Autonomous discovery, composition, and gating across 234+ engineering skills with concept extraction, DAG pipeline compilation, and 11-point creation gate.
  • System-1 Expansion Core: Added specialized processing modules including browser intelligence, deterministic decision & evidence engines, and adaptive evolution pipeline.
  • Cross-Domain & Outcome Optimization: Real-time second-order effect detection, emergent failure prediction, and non-downgrade monotonic security invariants.
  • Backend Intelligence Trust Boundary: Strict validation engine output isolation. LLMs can no longer self-authorize findings; evidence requires verifiable provenance hashes and terminal command records.
  • Universal 18-Section Governance Standard: All 234 modular skills enforce Tri-State Evidence classification ([OBSERVED], [INFERRED], [UNVERIFIED]) and non-negotiable Verification-Before-Completion (VBC) gates.

⚡ Core Capabilities

  • Parallel Review Pipeline: 31 domain-specific reviewers analyze generated code simultaneously across 3 waves (Logic, Security, Domain) before writing to disk.
  • Compiled Rust Core: Sub-10ms AST parsing, semantic graph extraction, and file synchronization using SHA-256 diffs.
  • Phantom Package Guardrails: Blocks "slopsquatting" and non-existent npm package imports during code generation.
  • Cross-Session Memory: "Supreme Court Case Law" (tk case) and key-value memory (tk memory) record past AI mistake precedents.
  • Subagent-Driven Development (SDD): Orchestrates multi-agent fan-out and synthesis, strictly isolating context windows to prevent token bloat.
  • Minimal Dependencies: The production CLI runtime requires zero heavy dependencies, protecting your supply chain.
  • Native MCP Server: Exposes real-time repository AST and team contract rules to Model Context Protocol compatible clients.

🏗️ Architecture Overview

Tribunal Kit operates as a fast, intercepting middleware layer between the AI generation event and the local filesystem.

graph LR
    A[User Request] --> B[Context Broker]
    B --> C[Compiled Rust Core<br/>AST / Graph Extraction]
    C --> D[31 Parallel Reviewers<br/>Waves 1, 2 & 3]
    D -->|Violation| E[Inner-Loop Auto-Correct]
    E -.-> B
    D -->|Passed| F[Human Gate]
    F --> G[Safe Commit to Disk]

    style C fill:#ff3300,stroke:#fff,stroke-width:1px,color:#fff
    style D fill:#111,stroke:#444,stroke-width:1px,color:#fff

Data Flow

  1. Input: An LLM agent generates a code change proposal (or triggers a workflow like /generate or /sdd).
  2. Processing: The Rust Core extracts the current AST and validates semantic bounds. The proposal is dispatched to parallel Reviewers (e.g., logic-reviewer, security-auditor, anti-slop-auditor).
  3. Output: If valid, it passes to the Human Gate or writes directly to disk. If invalid, the process is halted, and structured feedback is fed back into the agent's context loop.

🚀 Installation & Quick Start

Install Tribunal Kit in your project directory. Node.js >= 18.0.0 is required.

# 1. Initialize Tribunal Kit in your repository
npx tribunal-kit init

# 2. Sync rules with your local IDE (Cursor, Windsurf, VS Code)
npx tribunal-kit sync

# 3. Verify repository health and active rules
npx tribunal-kit status

Using a CLI Agent? Install the native adapter for Claude Code or Aider:

npx tribunal-kit tk-adapt claude
# or
npx tribunal-kit tk-adapt aider

💻 Usage Guide & CLI Reference

Tribunal Kit CLI operations are routed through the compiled Rust binary when supported, falling back to the JavaScript engine gracefully.

| Command | Arguments | Description | | :---------- | :---------------------------------------------------- | :---------------------------------------------------------------- | | init | [--force] | Initializes the .agent/ configuration payload. | | sync | — | Syncs rules with IDEs (.cursorrules, .windsurfrules). | | status | — | Evaluates workspace rules and checks for violations. | | validate | [--file <path>] | Validates .agent/ payload structure with live reviewer swarm. | | guardrail | [--file <path>] | Scans changes for phantom packages and // VERIFY tags. | | arch | map \| verify \| impact \| diff \| audit \| project | Verifiable Architecture Intelligence & Blast Radius engine. | | system1 | enable \| disable \| status | Manages local ONNX neural tier assessment and model weights. | | sdd | run \| status | Subagent-Driven Development execution with reviewer waves. | | minimal | [--prompt <text>] | Analyzes change requests for minimal viable diffs (Decision 0-7). | | contract | init \| verify \| list | AI agent behavioral contract validation and trace replay. | | memory | store \| recall \| gc | Manages persistent cross-session AI memory. | | case | add \| search <q> | Records or searches for AI mistake precedents. | | tk-adapt | [claude\|aider\|--global] | Installs universal CLI agent adapters. | | hook | — | Installs the automated Git pre-push governance hook. |

(For workflow execution, Tribunal Kit monitors for slash commands like /orchestrate, /audit, /sdd, or /deploy inside your AI context).


⚙️ Configuration Reference

Tribunal Kit is largely zero-config, driven by the .agent/ directory, but exposes settings via mcp_config.json and package.json.

Example MCP Configuration (mcp_config.json)

{
  "mcpServers": {
    "tribunal-kit": {
      "command": "node",
      "args": [".agent/scripts/mcp_server.js"],
      "env": { "NODE_ENV": "production" }
    }
  }
}

📂 Project Structure

tribunal-kit/
├── .agent/              # Active AI governance rules and workflows
│   ├── agents/          # Specialist agent definitions
│   ├── scripts/         # Verification and build scripts
│   ├── skills/          # Reusable AI knowledge packs
│   └── workflows/       # Slash command executions (e.g., /orchestrate)
├── bin/                 # CLI entry points (wrapper.js)
├── crates/core/         # Compiled Rust semantic engine
├── src/                # JS Fallback CLI runtime
├── docs/                # Project documentation and assets
└── AGENTS.md            # Master Fabel protocol and rule registry

🔗 Integrations

| Environment / Tool | Integration Type | Status | | :------------------------ | :-------------------------------------------- | :-------- | | Cursor IDE | Plugin & .cursorrules bridge | Supported | | Anthropic Claude Code | Native Marketplace Plugin (.claude-plugin/) | Supported | | Windsurf | Native .windsurfrules sync | Supported | | Cognition Devin | Native Plugin (.devin-plugin/) | Supported | | Aider CLI | Conventions Bridge (tk-adapt) | Supported | | Google Gemini CLI | Extension Manifest (gemini-extension.json) | Supported |


🔒 Security and Reliability

  • Strict Sandboxing: Tribunal Kit executes entirely locally. It does not phone home, exfiltrate data, or execute arbitrary remote binaries.
  • Zero Dependencies: The production NPM distribution is meticulously engineered to have zero external dependencies, entirely neutralizing downstream supply-chain attacks.
  • Memory Boundaries: Context provided to agents is strictly bounded by the context_broker, preventing context overflow and reducing token hallucination vectors.

🧪 Testing and Quality

Tribunal Kit employs rigorous continuous integration.

# Run payload validation and the full test suite
npm test

# Run the full 7-gate verification suite (Secret scan, Types, Lint, Tests, Build, Audit, Rust)
node .agent/scripts/verify_all.js

# Run the Rust core test suite
npm run test:rust

The validation pipeline enforces validate-payload.js and integrity_manifest.js checks to ensure every specialist agent, workflow, and skill definition conforms to the strict schema before compilation.


⚡ Performance

By offloading AST evaluation and file hashing to the tribunal-core Rust binary, Tribunal Kit achieves:

  • Sub-10ms execution overhead for the guardrail and sync commands.
  • Up to 95% faster context validation compared to standard Node.js implementations traversing large monorepos.

(Benchmarks available via npm run benchmark:rust locally).


🤝 Contributing

We welcome community-authored agents, skills, and Rust core optimizations.

  1. Ensure Node.js 18+ and Rust/Cargo are installed.
  2. Build the Rust core: npm run build:rust
  3. Run tests: npm run test:all
  4. Review CONTRIBUTING.md and DESIGN.md before submitting pull requests.

📄 License

This project is open-source and licensed under the MIT License. See the LICENSE file for details.