{"slug": "i-named-three-developer-tools-all-three-names-were-taken-on-npm", "title": "I named three developer tools. All three names were taken on npm.", "summary": "A developer who shipped three small CLI tools — Bridle, Interlock and Slopguard — discovered that all three names were already owned on npm, and that six install commands in his own READMEs would have caused npx to fetch and run strangers' packages on any clean machine. He now recommends checking the registry with a single curl during naming, installing explicitly from the GitHub repo rather than the bare package name, and testing install instructions in a clean container or temp directory.", "body_md": "I shipped three small tools over about a week. [Bridle](https://singhlabs.dev/bridle/), [Interlock](https://singhlabs.dev/interlock/), [Slopguard](https://singhlabs.dev/slopguard/). I was pleased with the names — short, metaphors that explain the mechanism, not a vowel-dropped startup pun among them.\n\nThen, quite late, I checked the npm registry.\n\n``` bash\n$ for p in bridle interlock slopguard; do\n    curl -s -o /dev/null -w \"%{http_code} $p\\n\" https://registry.npmjs.org/$p\n  done\n200 bridle\n200 interlock\n200 slopguard\n```\n\nAll three taken. Not squatted — real packages, by real people:\n\n**bridle** — \"Javascript black magic RPC over websockets\"\n\n**interlock** — interlockjs, a module bundler\n\n**slopguard** — \"Don't let AI slop past your gate. Detect AI-generated code patterns\"\n\nThat last one is doing roughly what mine does.\n\nLosing a name is annoying. That wasn't the problem.\n\nThe problem was already sitting in my README, in the install instructions:\n\n```\nnpx github:manpreet171/bridle init   # correct\nnpx bridle lint                      # ...not correct\n```\n\nThe first line is fine — explicit about the source. The second was copied from muscle memory, and it does something quite different.\n\n`npx github:user/repo` fetches and runs from GitHub. It **does not install anything**. So by the second command there is no local `bridle` binary, and npx does what npx does: goes to the public registry, finds the package literally named `bridle`, downloads it, and runs it.\n\n**Six commands in that README would have run a stranger's websocket library on the machine of anyone following my own documentation.**\n\nNobody was attacking me. I wrote the instructions myself, and they were wrong in a way that's invisible when you read them and obvious when you run them on a clean machine.\n\nBecause it works fine on *your* machine.\n\nYou've been developing the tool. You've got it linked, or installed globally, or you're in the repo where `node_modules/.bin` has it. `npx bridle lint` resolves locally and does exactly what you expect.\n\nIt's only on a machine that has never seen your project that npx falls through to the registry. Which is every machine except yours.\n\nInstall explicitly from the repo, then use the short command:\n\n```\nnpm install -g github:manpreet171/bridle\nbridle lint\n```\n\nInstalling from a GitHub source skips the npm namespace entirely, so it doesn't matter who owns the bare name. Verify it links a real binary before you publish the instruction:\n\n``` bash\n$ cd /tmp/check && npm init -y && npm install github:manpreet171/bridle\nadded 1 package\n$ ls node_modules/.bin/\nbridle  bridle.cmd  bridle.ps1\n$ ./node_modules/.bin/bridle --version\nbridle — Harness Script Engineering CLI\n```\n\nThat last line is the whole test. It's the binary I wrote, not the one someone else published under the same word.\n\n**Check the registry during naming, not after.** It's one curl. I checked the domain and the GitHub org and skipped the one namespace my install instructions actually resolve against.\n\n```\ncurl -s -o /dev/null -w \"%{http_code}\\n\" https://registry.npmjs.org/<name>\n```\n\n`404` is free. `200` means somebody owns it and your README needs to be explicit forever.\n\n**Test install instructions on a machine that isn't yours.** A clean container, or at minimum a temp directory outside the project. Docs that only work where the code already exists aren't docs.\n\n**Assume the good names are gone.** Every short English noun that describes a mechanism is taken. Either accept a scoped or suffixed package name, or accept that you install from source and say so clearly.\n\nI kept the names. They're good names and they're right for the tools. But the install line in all three READMEs now goes through the repo, and the pages on this site say plainly that the bare npm name belongs to someone else.\n\nThat felt like an admission when I wrote it. It's just accurate.\n\nThe tools: [singhlabs.dev](https://singhlabs.dev/). All MIT, all zero-dependency, all installed from the repo rather than a bare npm name.\n\nAnyone else been bitten by npx falling through to the registry? I suspect it's more common in READMEs than anyone realises, precisely because it never fails for the author. [Tell me](https://singhlabs.dev/contact/).\n\nRead next: [The models are a point apart. The harnesses are on fire.](https://singhlabs.dev/blog/capability-is-not-authority/) · [I researched loop engineering to build a product. I built nothing.](https://singhlabs.dev/blog/loop-engineering-map/)\n\n*Originally published at [singhlabs.dev](https://singhlabs.dev/blog/npm-names-taken/).*", "url": "https://wpnews.pro/news/i-named-three-developer-tools-all-three-names-were-taken-on-npm", "canonical_source": "https://dev.to/manpreet171/i-named-three-developer-tools-all-three-names-were-taken-on-npm-3f6h", "published_at": "2026-10-05 10:41:41+00:00", "updated_at": "2026-10-05 10:49:26.469997+00:00", "lang": "en", "topics": ["developer-tools"], "entities": ["npm", "Bridle", "Interlock", "Slopguard", "singhlabs.dev", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/i-named-three-developer-tools-all-three-names-were-taken-on-npm", "markdown": "https://wpnews.pro/news/i-named-three-developer-tools-all-three-names-were-taken-on-npm.md", "text": "https://wpnews.pro/news/i-named-three-developer-tools-all-three-names-were-taken-on-npm.txt", "jsonld": "https://wpnews.pro/news/i-named-three-developer-tools-all-three-names-were-taken-on-npm.jsonld"}}