the tools every command on this site assumes you already have · updated 2026-10-06
Start here · nothing on the pages below works until this one is done
Then take what you came for · each of these hands you a command to paste
Read only if you want to · nothing above needs anything on these
Behind a password · ask me for one; each page has its own
Every command below is typed into a terminal. macOS already has one, Terminal.app, and all of this would run in it — iTerm2 is the better one, and it comes first so you set your terminal up once: a window you can split into panes, a scrollback you can search, and sessions that come back after a restart.
Take the stable build — it needs macOS 12.4 or later:
iterm2.com/downloads.html · Stable ReleasesUnzip it, drag iTerm.app into /Applications, then open it:
⌘Space, type iterm, return. macOS asks you to confirm an app that did not come from
the App Store — that prompt is normal. Everything below is typed at the prompt it opens.
The guard, pnpm and the Codex cask below all arrive through it, as do three of the
four projects on Bundles and the binaries listed on
Skills.
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
It is not done when it exits. On Apple Silicon it prints a Next steps block adding
eval "$(/opt/homebrew/bin/brew shellenv)" to your profile — until you paste that,
brew is command not found in the next shell.
This route keeps itself updated; the claude-code cask is the other supported one
and moves only on brew upgrade.
curl -fsSL https://claude.ai/install.sh | bash
macOS 13 or later, and a paid plan — Pro, Max, Team, Enterprise or a Console account. The free claude.ai tier does not include Claude Code, and that is the one prerequisite on this page no command can install.
Everything from here on pulls packages off a registry. pmg checks them against
known-malicious data first, so it wants to be in place before the Skills
script, not after. The second half writes the shell aliases that put it in front of
npm, npx, pnpm and uv.
brew install safedep/tap/pmg && pmg setup install
From nvm rather than brew install node, for the reasons in the
Runtimes table below.
curl -fsSL https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.6/install.sh | bash
Now restart the shell, then install a node. This cannot be chained onto the line above:
nvm is a shell function sourced from your rc, so it does not exist yet in the shell
that ran the installer.
nvm install --lts
Skipping this second line fails silently — the nvm installer installs
nvm, not node. Until it runs, node is
command not found and every npx route on this site dies at the first
source. Check with node -v before moving on.
pnpm is what the projects on Bundles are built with, so have
it before you clone one. uv provides uvx, which runs a Python CLI without
installing it — how the YouTube transcript and yt-dlp routes work. It is not on
Homebrew, hence the second line.
brew install pnpm
curl -LsSf https://astral.sh/uv/install.sh | sh
The Claude Code side of every page here needs nothing else. This one is for the ten plugins on
Plugins that install with codex plugin add, and for
gpt-image-2 on Skills, which drives your ChatGPT plan through
the local CLI rather than an API key.
brew install --cask codex
Everything above is a CLI that talks to the internet as its ordinary behaviour, and the firewall macOS ships only screens what comes in. This is the one thing on the machine that can say which program is contacting what, and stop it. Last because it prompts the first time each process connects: install it earlier and you spend the rest of the run answering dialogs about Homebrew.
brew install --cask lulu
It watches nothing until macOS is told to let it — approve the system extension and the network filter in System Settings when it asks. Then expect a first week of prompts for every updater on the machine, and an agent that stops mid-run until you answer one. That is the cost, it is why this step is optional, and the guards table below is what you get for paying it.
| brew Homebrew | Not itself named by a rule — but the guard, pnpm and the Codex cask all come
out of it here, as do three of the four projects on
Bundles and every binary the skills on Skills
reach for. On a fresh Mac this is the first thing to run — step 2 above, behind only the window you run it in. Apple Silicon unpacks it into /opt/homebrew, a prefix
nothing has on PATH — the brew shellenv line the installer prints is
what makes the command exist in the next shell. |
| claude installer, or a caskSubscription | Claude Code itself. The installer in step 3 above keeps itself updated;
brew install --cask claude-code is the other supported route and tracks the stable
channel, about a week behind, moving only on brew upgrade — which is why it is in
none of the brew lines here.
macOS 13 or later, and a paid plan: Pro, Max, Team, Enterprise or a Console account — the free claude.ai tier does not include Claude Code. That plan is the one prerequisite on this page no command can install. |
| node nvm — not Homebrew | Node 18+. Every route here that is not brew is npx, so nothing on
the other pages runs without it.
From nvm rather than brew install node: Homebrew gives you one version,
moves it on any bare brew upgrade, and ignores a repo's .nvmrc. It
also installs its own copy anyway, as a dependency of something unrelated — so asking for a
second on purpose only makes it ambiguous which node a script gets. If you end up
cloning this site's repo, its deploy.sh resolves
~/.nvm/versions/node by path and will not run without one there. |
| pnpm brew, or install script | The odd one out: nothing on this site installs through it. It is what the projects
themselves are built with, so have it before you clone one — npm install in a
pnpm repo resolves a tree the lockfile never described, and that surfaces later as a build
failing only on your machine.
brew install pnpm, or
curl -fsSL https://get.pnpm.io/install.sh | sh - |
| uv not on Homebrew | Provides uvx, which runs a published Python CLI without installing it — how
anything on YouTube gets read here (uvx --from youtube-transcript-api …,
uvx yt-dlp), so neither of those tools has to be on the machine at all. Install it with
curl -LsSf https://astral.sh/uv/install.sh | sh. |
| codex a caskSubscription | Only for the Codex half of Plugins — ten plugins listed there install
with codex plugin add, and a further block ships inside this binary — plus
gpt-image-2 on Skills, which drives your ChatGPT plan
through the local CLI rather than an API key. Skip it and both simply do not apply; the
Claude Code side of every page needs nothing installed.
The binary is free and signing in is not: it wants a ChatGPT plan, Plus or above, or an API key billed per use instead. |
| cargo rustup | Only for the herdr half of Plugins: some of those plugins ship as Rust
source and are compiled the moment they are installed. Nothing else here needs a toolchain —
herdr itself is a brew binary, and the Claude Code and Codex halves download
plugins already built.
Worth having before the plugins script rather than after. Without it those installs fail on cargo build --release with
failed to start: No such file or directory, which names neither
cargo nor the fix; the script now warns first, and the rest of the herdr plugins
install fine without one. Install it with
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh. |
| pmg safedep/tap | Sits in front of npm, npx, pnpm, uv,
pip, yarn, poetry and bun, and checks
what a command is about to pull against SafeDep's malicious-package data before it runs.
It also holds a dependency cooldown — the window in which a compromised release is usually
caught and pulled; five days is the setting these pages assume. Worth having in place before
the Skills script, not after: that script installs from 35 sources in
one go.
brew install safedep/tap/pmg then pmg setup install, which
writes ~/.pmg.rc and sources it from your shell rc
(pmg setup remove undoes it, pmg setup doctor checks it).
Know what it does not cover: those aliases live in your interactive shell, and no PATH shim is installed alongside them. A script piped to sh —
including this site's own install.sh — never reads your rc, so the
npx calls inside it run unguarded. Type the command yourself and you are behind
the guard; paste a pipeline and you are not. |
| LuLu a cask | The other direction, and the later moment. pmg decides what reaches the disk;
this decides what the things already on it may reach. The firewall macOS ships screens
inbound connections and says nothing about outbound, so a package that passed the guard at
install time has nothing between it and the network afterwards — and everything the steps
above install is a CLI that talks to the internet as its ordinary behaviour. LuLu asks, per
process, the first time, and remembers the answer.
brew install --cask lulu is step 8 above, and last there on purpose: it
prompts per process, so a machine still installing spends the rest of the run answering for
Homebrew. Approve the system extension and the network filter in System Settings — it watches
nothing until macOS is told to let it. Free and open source, from Objective-See; macOS 10.15 or
later.
The cost arrives immediately and is why that step is the optional one: the first week is a prompt for every updater and telemetry ping on the machine, and an agent mid-run stops at one until you answer. Deny something it needed and what you get back is a network error, several steps from the decision that caused it. |
Everything above is macOS with Homebrew. Linux and Windows are on each project's own page — the links in the left column go there, not to a search result.