npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

visp-kit

v0.5.0

Published

Stops AI-written code reaching review without proof. Declares scope before editing, blocks out-of-scope changes, and records evidence a human can check.

Readme

Visp Kit

Stops AI-written code reaching review without proof.

You point an AI coding tool at a task. It edits ten files when you asked for two, writes a test that passes whether or not the fix works, and hands you a diff you now have to fully re-read to trust.

Visp Kit makes the tool declare what it will change before it edits, blocks anything outside that, and records evidence you can check without reading every line.

It never calls an LLM. It runs beside whatever tool you already use.


Install

npm install -g visp-kit

Requires Node 22 or later, and Git.

Compatibility

This package is the Visp engine — it decides what is allowed and what counts as proof. As of 0.4.0 it provides the visp-kit command and no longer provides visp; that top-level command belongs to visp-hyper-agent.

  • With Hyper: visp-hyper-agent >= 0.6.0 drives this engine and presents its decisions; install both for the full surface. Approvals recorded before the rename stay valid — identity hashes no longer contain command wording.
  • With Memory: this package does not talk to visp-memory directly; recall flows through Hyper.
  • With Visp Dev: not required; machine setup and checks live there.

Upgrading from a visp-era install: run visp-kit agent refresh and visp-kit hooks ci --force so generated instruction files and the CI workflow use the new command name. visp-kit doctor names anything stale.

First run

Four commands, in a real project:

visp-kit init .
visp-kit scan .
visp-kit feature "add password reset"
visp-kit next .

visp-kit next is the one to remember. It always tells you the single next command, so you never have to memorise the workflow — run it whenever you are unsure what to do.

What you get

| | | |---|---| | Scope declared up front | The task names the files it may touch. Edits elsewhere are blocked, not flagged later. | | Evidence that means something | A test written by whoever made the change doesn't count as independent proof. Kit tracks the difference. | | A reviewable summary | An assurance case with the risky parts ranked, so review starts where it matters. | | A record of the decision | Who approved what, against which exact code and which policy. | | Told what moved | Come back a week later and Kit says what changed since you approved — not just that something did. |

Honest limits

Read this before adopting it:

  • No productivity claim. Whether Visp makes teams faster or produces better software is unmeasured. An evaluation protocol is frozen, but no study has run. Any claim otherwise is a bug — please report it.
  • Compatibility is proven pair by pair, pinned to exact commits and package hashes. It is not a version-range support window.
  • Conformance is partial. Some areas are proven and some are not; the published report says which. Non-Linux systems are not yet covered.
  • Assurance verdicts are often inconclusive. That is deliberate — it means the evidence did not establish the claim, not that the claim failed.

Where to get help

  • Source, issues, and pull requests: visp-kit
  • Compatibility evidence and conformance reports: visp-dev
  • Security issues: see SECURITY.md. Do not open a public issue.
  • Contributing: see CONTRIBUTING.md.

How it works

Visp Kit does not call an LLM, or Codex, or Claude, or Copilot. It runs beside whichever tool you use.

It writes plain files under .visp/ in your project: what the task is allowed to touch, what evidence exists, and what a reviewer decided. Your AI tool reads those files. Kit checks the result against them.

The user prompt is raw intent only. Nothing typed into a prompt can widen a task's scope, skip a gate, or approve a change — that is the property the whole design rests on.

Documentation

Everything below ships with the package.

| | | |---|---| | Quickstart | Longer walkthrough than the one above | | Commands | Every command and flag | | Workflow | The stages, and why they are in that order | | Policy and gates | Strictness modes and what each blocks | | Enforcement | Git hooks and CI | | Overrides | Recording a deliberate exception | | Agent targets | Codex, Claude Code, Copilot, OpenCode | | Agent-native workflows | Driving Kit from inside an agent | | Artifact reader | Typed, validated reads of .visp/ from visp-kit/artifacts | | Token efficiency | How context is kept small | | Troubleshooting | When something is blocked and you disagree | | Company adoption | Rolling it out to a team | | Development | Building and contributing |

A small working fixture: examples/strict-agent-workflow.

License

Apache-2.0. See LICENSE.