Before anything else

the tools every command on this site assumes you already have · updated 2026-10-06

The map · 10 pages, in the order they are meant to be met

Start here · nothing on the pages below works until this one is done

Then take what you came for · each of these hands you a command to paste

Read only if you want to · nothing above needs anything on these

Behind a password · ask me for one; each page has its own

The install eight steps · the last two are optional

1 · iTerm2 · the window every step after this is typed into

Every command below is typed into a terminal. macOS already has one, Terminal.app, and all of this would run in it — iTerm2 is the better one, and it comes first so you set your terminal up once: a window you can split into panes, a scrollback you can search, and sessions that come back after a restart.

Take the stable build — it needs macOS 12.4 or later:

iterm2.com/downloads.html · Stable Releases

Unzip it, drag iTerm.app into /Applications, then open it: ⌘Space, type iterm, return. macOS asks you to confirm an app that did not come from the App Store — that prompt is normal. Everything below is typed at the prompt it opens.

2 · Homebrew · four of the six steps after this arrive through it

The guard, pnpm and the Codex cask below all arrive through it, as do three of the four projects on Bundles and the binaries listed on Skills.

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"

It is not done when it exits. On Apple Silicon it prints a Next steps block adding eval "$(/opt/homebrew/bin/brew shellenv)" to your profile — until you paste that, brew is command not found in the next shell.

3 · Claude Code · the agent everything here is for

This route keeps itself updated; the claude-code cask is the other supported one and moves only on brew upgrade.

curl -fsSL https://claude.ai/install.sh | bash

macOS 13 or later, and a paid plan — Pro, Max, Team, Enterprise or a Console account. The free claude.ai tier does not include Claude Code, and that is the one prerequisite on this page no command can install.

4 · The guard, before anything it guards · two commands, one paste

Everything from here on pulls packages off a registry. pmg checks them against known-malicious data first, so it wants to be in place before the Skills script, not after. The second half writes the shell aliases that put it in front of npm, npx, pnpm and uv.

brew install safedep/tap/pmg && pmg setup install

5 · Node, in two commands and not one · the step people get wrong

From nvm rather than brew install node, for the reasons in the Runtimes table below.

curl -fsSL https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.6/install.sh | bash

Now restart the shell, then install a node. This cannot be chained onto the line above: nvm is a shell function sourced from your rc, so it does not exist yet in the shell that ran the installer.

nvm install --lts

Skipping this second line fails silently — the nvm installer installs nvm, not node. Until it runs, node is command not found and every npx route on this site dies at the first source. Check with node -v before moving on.

6 · pnpm and uv · the two package managers that are not npm

pnpm is what the projects on Bundles are built with, so have it before you clone one. uv provides uvx, which runs a Python CLI without installing it — how the YouTube transcript and yt-dlp routes work. It is not on Homebrew, hence the second line.

brew install pnpm curl -LsSf https://astral.sh/uv/install.sh | sh

7 · Codex · only if you use it

The Claude Code side of every page here needs nothing else. This one is for the ten plugins on Plugins that install with codex plugin add, and for gpt-image-2 on Skills, which drives your ChatGPT plan through the local CLI rather than an API key.

brew install --cask codex

8 · LuLu, and last on purpose · the step that keeps asking

Everything above is a CLI that talks to the internet as its ordinary behaviour, and the firewall macOS ships only screens what comes in. This is the one thing on the machine that can say which program is contacting what, and stop it. Last because it prompts the first time each process connects: install it earlier and you spend the rest of the run answering dialogs about Homebrew.

brew install --cask lulu

It watches nothing until macOS is told to let it — approve the system extension and the network filter in System Settings when it asks. Then expect a first week of prompts for every updater on the machine, and an agent that stops mid-run until you answer one. That is the cost, it is why this step is optional, and the guards table below is what you get for paying it.

Runtimes everything else runs on these

brew
Homebrew
Not itself named by a rule — but the guard, pnpm and the Codex cask all come out of it here, as do three of the four projects on Bundles and every binary the skills on Skills reach for. On a fresh Mac this is the first thing to run — step 2 above, behind only the window you run it in. Apple Silicon unpacks it into /opt/homebrew, a prefix nothing has on PATH — the brew shellenv line the installer prints is what makes the command exist in the next shell.
claude
installer, or a caskSubscription
Claude Code itself. The installer in step 3 above keeps itself updated; brew install --cask claude-code is the other supported route and tracks the stable channel, about a week behind, moving only on brew upgrade — which is why it is in none of the brew lines here.

macOS 13 or later, and a paid plan: Pro, Max, Team, Enterprise or a Console account — the free claude.ai tier does not include Claude Code. That plan is the one prerequisite on this page no command can install.
node
nvm — not Homebrew
Node 18+. Every route here that is not brew is npx, so nothing on the other pages runs without it.

From nvm rather than brew install node: Homebrew gives you one version, moves it on any bare brew upgrade, and ignores a repo's .nvmrc. It also installs its own copy anyway, as a dependency of something unrelated — so asking for a second on purpose only makes it ambiguous which node a script gets. If you end up cloning this site's repo, its deploy.sh resolves ~/.nvm/versions/node by path and will not run without one there.
pnpm
brew, or install script
The odd one out: nothing on this site installs through it. It is what the projects themselves are built with, so have it before you clone one — npm install in a pnpm repo resolves a tree the lockfile never described, and that surfaces later as a build failing only on your machine.
brew install pnpm, or curl -fsSL https://get.pnpm.io/install.sh | sh -
uv
not on Homebrew
Provides uvx, which runs a published Python CLI without installing it — how anything on YouTube gets read here (uvx --from youtube-transcript-api …, uvx yt-dlp), so neither of those tools has to be on the machine at all. Install it with curl -LsSf https://astral.sh/uv/install.sh | sh.
codex
a caskSubscription
Only for the Codex half of Plugins — ten plugins listed there install with codex plugin add, and a further block ships inside this binary — plus gpt-image-2 on Skills, which drives your ChatGPT plan through the local CLI rather than an API key. Skip it and both simply do not apply; the Claude Code side of every page needs nothing installed.

The binary is free and signing in is not: it wants a ChatGPT plan, Plus or above, or an API key billed per use instead.
cargo
rustup
Only for the herdr half of Plugins: some of those plugins ship as Rust source and are compiled the moment they are installed. Nothing else here needs a toolchain — herdr itself is a brew binary, and the Claude Code and Codex halves download plugins already built.

Worth having before the plugins script rather than after. Without it those installs fail on cargo build --release with failed to start: No such file or directory, which names neither cargo nor the fix; the script now warns first, and the rest of the herdr plugins install fine without one. Install it with curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh.

The guards one checks what you install · one watches what it does afterwards

pmg
safedep/tap
Sits in front of npm, npx, pnpm, uv, pip, yarn, poetry and bun, and checks what a command is about to pull against SafeDep's malicious-package data before it runs. It also holds a dependency cooldown — the window in which a compromised release is usually caught and pulled; five days is the setting these pages assume. Worth having in place before the Skills script, not after: that script installs from 35 sources in one go.
brew install safedep/tap/pmg then pmg setup install, which writes ~/.pmg.rc and sources it from your shell rc (pmg setup remove undoes it, pmg setup doctor checks it).

Know what it does not cover: those aliases live in your interactive shell, and no PATH shim is installed alongside them. A script piped to sh — including this site's own install.sh — never reads your rc, so the npx calls inside it run unguarded. Type the command yourself and you are behind the guard; paste a pipeline and you are not.
LuLu
a cask
The other direction, and the later moment. pmg decides what reaches the disk; this decides what the things already on it may reach. The firewall macOS ships screens inbound connections and says nothing about outbound, so a package that passed the guard at install time has nothing between it and the network afterwards — and everything the steps above install is a CLI that talks to the internet as its ordinary behaviour. LuLu asks, per process, the first time, and remembers the answer.
brew install --cask lulu is step 8 above, and last there on purpose: it prompts per process, so a machine still installing spends the rest of the run answering for Homebrew. Approve the system extension and the network filter in System Settings — it watches nothing until macOS is told to let it. Free and open source, from Objective-See; macOS 10.15 or later.

The cost arrives immediately and is why that step is the optional one: the first week is a prompt for every updater and telemetry ping on the machine, and an agent mid-run stops at one until you answer. Deny something it needed and what you get back is a network error, several steps from the decision that caused it.

Everything above is macOS with Homebrew. Linux and Windows are on each project's own page — the links in the left column go there, not to a search result.