npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

wicked-installer

v0.4.3

Published

Interactive installer for the wicked-* ecosystem — registry-driven, dependency-aware, cross-CLI.

Readme

 _      _            _ 
 __      _(_) ___| | _____  __| |
 \ \ /\ / / |/ __| |/ / _ \/ _` |
  \ V  V /| | (__|   <  __/ (_| |
   \_/\_/ |_|\___|_|\_\___|\__,_|

  _           _        _ _           
 (_)_ __  ___| |_ __ _| | | ___ _ __ 
 | | '_ \/ __| __/ _` | | |/ _ \ '__|
 | | | | \__ \ || (_| | | |  __/ |   
 |_|_| |_|___/\__\__,_|_|_|\___|_|

Registry-driven installer for the wicked-* AI developer ecosystem.

npm version license


Quick start

npx wicked-installer

Interactive TUI — pick a bundle or select products individually. Detects which AI coding CLIs you have installed and guides you from there.


CLI

npx wicked-installer                 Interactive install
npx wicked-installer list            List available products
npx wicked-installer install <ids>   Install specific products (space-separated)
npx wicked-installer pack <verb>     Third-party skill packs (add/remove/list/check)
npx wicked-installer status          Show detected CLIs, installed products, and
                                     wicked-garden's Claude Code registration
npx wicked-installer --version

Flags:
  --dry-run              Print the exact plan (target dirs, commands) and write nothing
                         into any target — no npm/npx/cargo/git installs, no downloads,
                         no copies (per-CLI scripts may stage into the OS temp dir, §13)
  --claude-home <dir>    Claude Code config dir to register wicked-garden into
                         (repeatable; default: $CLAUDE_CONFIG_DIR, else ~/.claude)
  --source-root <dir>    Register wicked-garden from the local checkout
                         <dir>/wicked-garden instead of the published marketplace
  --force                Passed through to the per-CLI install scripts (interactive)

install <ids> resolves required dependencies first (garden pulls in wicked-vault), installs each product directly, and exits 1 if any of them failed. With --dry-run every product type prints its plan and nothing is installed or written — the only process a dry run may start is the read-only claude --version probe the Claude plugin plan is derived from.


wicked-garden is a registered Claude Code plugin

Claude Code only loads plugins it has registered — a marketplace entry plus an install record whose payload lives in <configDir>/plugins/cache/<marketplace>/<plugin>/<version>/. That cache is also the only place wicked-crew's skills discovery reads. A bare copy under ~/.claude/plugins/wicked-garden/ (what npx wicked-garden install produces, always into ~/.claude whatever CLAUDE_CONFIG_DIR says) is loaded by nothing.

So when the claude CLI is present, every garden install path — install wicked-garden, the interactive path with Claude Code selected (the picker hands install-claude.js the other products, then registers garden itself), and the interactive zero-CLI path — resolves the active config dir(s) the same way: --claude-home flags, else CLAUDE_CONFIG_DIR (a list split on : or ,; on Windows on ; or ,; authoritative when set — a set-but-empty value is an error, not a fall-through), else ~/.claude. For each dir it probes (claude --version, plus the on-disk registration state) and then runs only what that state calls for, with CLAUDE_CONFIG_DIR=<target>:

claude plugin marketplace add mikeparcewski/wicked-garden   # only when the marketplace is absent
claude plugin install wicked-garden@wicked-garden           # or `update` when a healthy install exists

then re-derives from disk that the marketplace entry, the install record (with a real version) and the payload under <target>/plugins/cache/wicked-garden/wicked-garden/<version>/ (with a matching plugin.json version) all exist. If the run added the marketplace and the install then fails, the add is rolled back (claude plugin marketplace remove wicked-garden); with several config dirs each is registered in order and reported — a failure in a later dir leaves earlier dirs registered. A marketplace already registered from another source (say, a local checkout) is kept as-is. --source-root <dir> registers <dir>/wicked-garden as the marketplace instead of GitHub. --dry-run prints the same probes (probe: lines) and exactly the commands a live run would execute (dry-run: lines); the only thing it spawns is claude --version.

Legacy copies are left in place. A bare ~/.claude/plugins/wicked-garden/ (from npx wicked-garden install) or a skills/hooks copy an earlier install-claude.js recorded in its marker is detected and reported — legacy wicked-garden copy detected at — left in place; removal will ship separately — never removed by this version. Their removal is tracked in issue #20.

State is read from plugins/known_marketplaces.json / plugins/installed_plugins.json (what claude plugin marketplace list --json / claude plugin list --json print) rather than by running those commands, because they initialise <configDir>/.claude.json as a side effect. Nothing is written into skills/, settings.json or .claude.json for garden — those writes remain only for products that need them (wicked-estate's MCP block).

When no Claude Code CLI is present the direct path (install wicked-garden) falls back to npx wicked-garden install and says so: copied to ~/.claude/plugins/wicked-garden; not registered — Claude Code not detected. On the interactive path, where you chose Claude Code as the target, garden is instead reported as a manual step and nothing is copied — a copy Claude Code never loads is not an install of what you selected. A Claude Code that is present but fails claude --version is an error, never a fallback. Per-product results stay independent — a garden failure never uninstalls estate or bus, and the run exits non-zero if any product failed; with several config dirs a failure in a later dir leaves earlier dirs registered (reported, not undone). Legacy copies are never removed by this version (see issue #20). --source-root never falls back either: the bare copy would install the published package, not your checkout. install-claude.js itself never installs a plugin (handed one directly, it reports a manual step and writes nothing) and imports nothing outside node: builtins.

status prints, per active config dir, the marketplace (and its source), the installed version/scope, the cached versions, the enable switch, and a verdict: registered only when the marketplace entry, the install record (every selected record carrying a real version) and a payload whose plugin.json version matches the record all exist; partially registered (…) naming what is missing; copy only (unregistered) for a bare plugins/wicked-garden copy; not installed; unreadable (…) when a state file — or any path component below the config dir — is a symlink, resolves outside the config dir, or cannot be read. The overall line is the worst state across the active dirs (unreadable > not installed > copy only > partial > registered) and status exits 1 unless wicked-garden is registered in every active dir; the product list's "installed" for wicked-garden means exactly that. status runs no claude plugin … command. Its CLI detection is read-only: the claude --version probe (verified to write nothing) plus the pre-existing product-status probes (<cli> --version for the other detected CLIs) — no install, no write.


Skill packs (the wicked-garden extension contract)

Third parties extend the wicked-garden catalog with packs — a wicked-pack.json manifest plus a skills/ tree following the {vendor}-{domain} router / {vendor}-{domain}-{role} worker contract. This command is the single acquisition path (garden's own npx wicked-garden pack install delegates here):

npx wicked-installer pack add acme-seo-pack        # npm package spec
npx wicked-installer pack add ./acme-seo-pack      # local directory
npx wicked-installer pack remove acme-seo          # the MANIFEST name (wicked-pack.json "name"),
                                                   # not the npm spec — see `pack list`
npx wicked-installer pack list                     # what garden's runtime discovers
npx wicked-installer pack check ./acme-seo-pack    # conformance gate only

pack add fetches the source, runs wicked-garden's shipped conformance gate (fail-closed; --force to override), copies the pack to ~/.something-wicked/wicked-garden/packs/installed/<name>, makes its skills visible to Claude Code (~/.claude/skills/ — or skips the copy when the pack ships as a Claude Code plugin), and registers it with the garden runtime (catalog + crew specialist routing + peer-floor probe). Validation and registration are wicked-garden's own tooling — this command never re-implements them.

Honest scope note: skill visibility for the other supported CLIs (Codex, Antigravity, OpenCode, Pi) is not wired for packs yet; the per-CLI install-script seam (INTERFACE.md) is where that lands. Provenance is recorded (source URL + content hashes) but packs are not signed — install only from sources you trust, as with any npm dependency.

Pack authoring guide: wicked-garden's docs/extending.md.


Bundles

| Bundle | What it installs | Best for | |---|---|---| | quick-start | wicked-bus + wicked-crew | Fastest path to a governed multi-agent session — daemon up, Studio console open, first run in under five minutes | | garden | wicked-bus + wicked-garden | Recommended starting point for Claude Code users — evidence-gated work, graph-aware refactoring, and the full 40-specialist QE domain | | knowledge | wicked-bus + wicked-estate | Persistent memory, knowledge, and code-graph layer — everything else queries it | | creative | wicked-interactive + wicked-crew | The document & render engine (HTML/PDF/PPTX), driven through Crew + the AI workflow console (Studio ships inside Crew) | | full | wicked-bus + wicked-estate + wicked-garden + wicked-interactive + wicked-crew | The complete wicked-* experience |

Required dependencies resolve automatically: wicked-garden requires wicked-vault (the evidence backend its gate re-derives against), so any selection containing garden also installs it.


Products

| Product | Status | What it does | |---|---|---| | wicked-estate | stable | MCP server: code graph + memory + knowledge in one binary. 29 tools across 3 domains. 103 languages. | | wicked-bus | stable | Durable event fabric for agents — restart-durable at-least-once delivery with dead-lettering and replay. Zero infra (embedded SQLite), single-host. | | wicked-garden | active | Curated toolkit for what coding agents can't do alone. Claude Code plugin. Includes the 40-specialist QE domain (acceptance testing, evidence-gated, no self-grading). | | wicked-interactive | stable | Foundation-plane document & render engine (HTML/PDF/PPTX + version lineage) that wicked-crew spawns and proxies — surfaced through studio, not visited directly. | | wicked-studio | active | Browser console for wicked-crew — launch/steer governed runs, answer HITL gates, live event streams. Ships bundled inside wicked-crew. | | wicked-core | active | The execution engine + governance hook binary behind wicked-crew. Ships inside the wicked-core-ts platform package wicked-crew pins (core-ts >= 0.7.26); nothing to install separately. | | wicked-crew | active | Governed multi-agent execution — drives coding-agent CLIs through durable workflows with deny-dominates dual gates and evidence-re-derived "done". Includes the Studio console. |

Dependency, not a product: wicked-vault (npm) is in the registry only so dependency resolution can install it — it is wicked-garden's required evidence backend, not a standalone pick.

Retired products — do not install:

  • wicked-testing (retired 2026-08, v0.11.0 final): QE capabilities moved to wicked-garden's qe domain; acceptance gate is now wicked-crew.
  • wicked-brain (retired 2026-08): memory + knowledge absorbed into wicked-estate. npm package deprecated.

Supported CLIs

Claude Code · Cursor · Codex · Kiro · OpenCode · GitHub Copilot · Antigravity · Pi


License

MIT