Agent skill

Node Modules Inspector

by antfu in antfu/node-modules-inspector

Inspects a project's installed nodemodules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade…

MITAuto-check passed

Install Node Modules Inspector

skills CLI
$ npx skills add antfu/node-modules-inspector --skill node-modules-inspector -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install antfu/node-modules-inspector node-modules-inspector --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/antfu/node-modules-inspector.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/node-modules-inspector .claude/skills/node-modules-inspector && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
node-modules-inspector
GitHub stars
3k
Token cost
~2.2k tokens
SKILL.md length
834 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Inspects a project's installed nodemodules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade…

  • The user wants to audit dependencies
  • SKILL.md covers When to reach for this, CLI mode, MCP mode and Flags the agent should know, plus 2 more sections
  • Calls npx, npm and pnpm
  • Find duplicate packages

What it does

Node Modules Inspector is an agent skill from antfu/node-modules-inspector. Inspects a project's installed nodemodules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade opportunities + publint findings, grouped by consumer/author). Use when the user wants to audit dependencies, find duplicate packages, check what's taking up disk space in nodemodules, identify outdated peer/prod dependencies that newer dependents could upgrade past, or list publint problems. Available as a CLI (npx…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Model Context Protocol, npm and pnpm. The repository describes itself as: Interactive UI for local node modules inspection. The licence is MIT.

When your agent uses it

  • The user wants to audit dependencies
  • Find duplicate packages
  • Check whats taking up disk space in nodemodules
  • Identify outdated peer/prod dependencies that newer dependents could upgrade past

Example prompts

  • “Use the node-modules-inspector skill to inspect a project's installed nodemodules and produces three reports: duplicated packages (installed in…”
  • “/node-modules-inspector”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 602140f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, npm and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Node Modules Inspector loads about 2.2k tokens when it runs. Until then it costs about 187 tokens; SKILL.md has 834 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~187
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from antfu/node-modules-inspector at commit 602140f, republished under its MIT licence (© antfu). 834 words, ~2,164 tokens.

Download SKILL.mdSave it as .claude/skills/node-modules-inspector/SKILL.md (or your agent's skills folder).
name
node-modules-inspector
description
Inspects a project's installed node_modules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade opportunities + publint findings, grouped by consumer/author). Use when the user wants to audit dependencies, find duplicate packages, check what's taking up disk space in node_modules, identify outdated peer/prod dependencies that newer dependents could upgrade past, or list publint problems. Available as a CLI (`npx node-modules-inspector report <duplicates|sizes|maintainers> [--json]`) or an MCP stdio server (`npx node-modules-inspector mcp`) exposing the same three reports as agent tools. Works with pnpm, npm, and bun.

node-modules-inspector

node-modules-inspector is a CLI + MCP server that inspects the installed node_modules of the current project and produces structured reports. Three reports, same underlying analysis pipeline:

ReportAnswers
duplicatesWhich packages are installed in multiple versions?
sizesWhich packages take up the most disk space?
maintainersWhich consumers have dep-upgrade opportunities or publint issues, grouped by package and author?

Reports run against the real on-disk node_modules — no registry calls are required for the basic shape; npm metadata is fetched only to enrich the maintainers report (gated by config).

Works with pnpm, npm, and bun. The default npx node-modules-inspector (with no subcommand) opens a Vue web UI for humans; agents should use the report and mcp subcommands below.

When to reach for this

Trigger on any of:

  • "audit my dependencies", "find duplicate packages", "node_modules cleanup"
  • "what's taking up disk space in node_modules"
  • "which deps are outdated" / "what dep-upgrade opportunities are there"
  • "show me publint issues across my deps"
  • "who maintains my dependencies"

Don't reach for it for: registry-only questions (use fast-npm-meta), bundle-size analysis of a single package (use a bundler-specific tool), security audits (use npm audit / osv-scanner).

CLI mode

All subcommands share these options:

  • --root <dir> — project root (default: cwd)
  • --config <file> — config file (default: node-modules-inspector.config.{ts,js,json})
  • --depth <n> — max dependency depth to traverse (default: 8)
  • --json — emit JSON to stdout; pretty ANSI table otherwise

Progress logs always go to stderr, so ... --json is pipe-safe.

duplicates
sh
npx node-modules-inspector report duplicates --json

Options:

  • --min-versions <n> — only include packages installed at this many versions or more (default: 2)
  • --limit <n> — cap result count

Output shape:

json
[
  {
    "name": "@typescript-eslint/scope-manager",
    "versions": ["8.56.1", "8.59.1", "8.59.2", "8.59.4"],
    "specs": ["@typescript-eslint/scope-manager@8.56.1", "..."]
  }
]

Versions are sorted ascending by semver. Entries are sorted by version-count descending. Use this to find dedupe targets — pnpm dedupe / npm dedupe resolves these where ranges overlap.

sizes
sh
npx node-modules-inspector report sizes --json --limit 20

Options:

  • --limit <n> — cap result count (default: 50)
  • --include-workspace — include workspace packages (default: excluded; they have no meaningful install size)

Output shape:

json
[
  {
    "spec": "typescript@6.0.3",
    "name": "typescript",
    "version": "6.0.3",
    "workspace": false,
    "bytes": 24346827,
    "categories": {
      "js": { "bytes": 15344521, "count": 200 },
      "dts": { "bytes": 7002306, "count": 150 }
    }
  }
]

categories keys come from a fixed set: js, ts, dts, json, bin, wasm, map, image, css, html, comp, doc, test, flow, other. Entries are sorted by bytes descending.

maintainers
sh
npx node-modules-inspector report maintainers --json

Options:

  • --sort <depth|migration|latest> — sort by consumer depth, max migration ratio, or latest release time (default: depth)
  • --author <handle> — filter to consumers maintained by this author; repeatable
  • --no-publint — exclude publint findings
  • --no-latest-only — include consumer packages that are not on their latest major
  • --limit <n> — cap result count

Output shape:

json
[
  {
    "consumer": { "spec": "rollup-plugin-esbuild@6.2.1", "name": "rollup-plugin-esbuild", "version": "6.2.1", "depth": 1 },
    "authors": [{ "type": "github", "github": "egoist", "avatar": "..." }],
    "items": [
      {
        "kind": "dep-upgrade",
        "depName": "unplugin-utils",
        "depType": "prod",
        "declaredRange": "^0.2.4",
        "rawRange": "catalog:deps",
        "catalogName": "deps",
        "installedHighestVersion": "0.3.1",
        "installedHighestSpec": "unplugin-utils@0.3.1",
        "installedVersions": ["0.2.4", "0.3.1"],
        "migratedCount": 10,
        "totalCount": 11,
        "migrationRatio": 0.909
      },
      {
        "kind": "publint",
        "messages": [/* publint Message objects */],
        "counts": { "error": 0, "warning": 1, "suggestion": 2 }
      }
    ],
    "maxMigrationRatio": 0.909,
    "latestReleasedAt": 1739000000000
  }
]

How to read this:

  • A dep-upgrade item means: this consumer declares depName at declaredRange, but there's a newer installed version (installedHighestVersion) that the range does not satisfy. migrationRatio is the fraction of consumers in the same cohort that already migrated — a high ratio (e.g. 0.9) means most other consumers already moved on, so this one is lagging.
  • rawRange differs from declaredRange only when the consumer used a pnpm catalog reference (catalog:deps); declaredRange is the resolved range.
  • A publint item carries the raw publint messages, partitioned by severity in counts.
  • authors come from the consumer's package.json author/maintainers fields, with GitHub-handle detection.

Publint findings only appear when pkg.resolved.publint was populated. Enable that by adding publint: true to node-modules-inspector.config.ts (or by using the project's web UI which runs publint async).

Show full SKILL.md (324 more words)Show less

MCP mode

sh
npx node-modules-inspector mcp

Starts an MCP stdio server. Exposes three tools, identical surface to the CLI:

  • nmi:report-duplicates
  • nmi:report-sizes
  • nmi:report-maintainers

When configured in an MCP client (e.g. Claude Code) under server name node-modules-inspector, address them as node-modules-inspector:nmi:report-duplicates, etc.

Tool input schemas mirror the CLI options. Tool output is JSON in the exact shape shown above for each report.

Prefer MCP when:

  • Multiple queries are expected in one session — the dependency tree is read once and cached across tool calls.
  • The agent needs structured output schemas to drive validation.

Prefer the CLI (report ... --json) when shell-pipelining (jq, redirect, etc.) is more convenient.

Flags the agent should know

  • The first run reads node_modules end-to-end and caches npm metadata on disk (under ~/.node-modules-inspector or similar). Subsequent runs are much faster.
  • Workspace packages are excluded from sizes by default — pass --include-workspace if you actually want them.
  • --depth 8 is enough for almost all real projects. Increase only if the user explicitly asks about deeply-nested transitive dependencies.
  • For very large monorepos, running against a single workspace package via --root packages/<name> is faster than the whole repo.

Failure modes

  • "No package manager detected" — the project has no node_modules directory, or none of pnpm/npm/bun lockfiles. Suggest the user run install first.
  • Empty duplicates result — fine, it means everything is deduped (mention pnpm dedupe etc. only if user wants to verify).
  • Empty maintainers result — usually means there are no dep-upgrade opportunities AND publint: true is not set in the config; if the user expected publint output, point them at the config.

Web UI (skip for agent tasks)

npx node-modules-inspector (no subcommand) starts a Vue dev server on port 9999 with a full visual explorer (graph view, filters, multi-version compare, maintainer-action dashboard). It's for humans; don't suggest it for an agent task. The report CLI and mcp server above cover the same data programmatically.

npx node-modules-inspector build produces a static SPA of the analysis into dist/__node-modules-inspector/ — useful for CI artifacts but not for agent consumption.

© antfu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/node-modules-inspector of antfu/node-modules-inspector.

Open the folder on GitHubat commit 602140f

Compare with similar skills

Node Modules Inspector next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Node Modules Inspector compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Node Modules Inspector this skillantfu/node-modules-inspector3k—~2.2kAutomated safety check: PassMIT
Okx Cex Marketdex-original/okx-agent-trade-kit1091 repos~2.7kAutomated safety check: PassMIT
Okx Sentiment Trackerdex-original/okx-agent-trade-kit1091 repos~3.8kAutomated safety check: PassMIT
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
ReleaseWebMCP-org/npm-packages103—~1.6kAutomated safety check: NotesMIT
Security Vuln Remediationstacklok/toolhive-studio170—~2.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Okx Cex Market

    dex-original/okx-agent-trade-kit

    A skill your agent uses when the user asks for: price of any asset, ticker, order book, candles, OHLCV, funding rate, open interest, OI change scanner, market screener (top movers, high-volume…

    109 GitHub starsUsed in 1 repo~2.7k tokens
    Business, Finance & HRAuto-check passed
  • Okx Sentiment Tracker

    dex-original/okx-agent-trade-kit

    A skill your agent uses when the user asks about: 'any crypto news', 'latest news', 'market update', 'daily briefing', 'BTC news', 'ETH news', 'news on SOL', 'search SEC ETF', 'regulation news'…

    109 GitHub starsUsed in 1 repo~3.8k tokens
    Business, Finance & HRAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Release

    WebMCP-org/npm-packages

    Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

    103 GitHub stars~1.6k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes
  • Security Vuln Remediation

    stacklok/toolhive-studio

    Remediate security vulnerabilities found by Grype or pnpm audit.

    170 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check: notes
  • MCP Security Audit

    github/awesome-copilot

    Official

    Audit MCP (Model Context Protocol) server configurations for security issues.

    40k GitHub stars~3.1k tokensUpdated today
    SecurityAuto-check passed

Questions about Node Modules Inspector

What does Node Modules Inspector do?

Inspects a project's installed nodemodules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade…. Node Modules Inspector is an agent skill from antfu/node-modules-inspector. Inspects a project's installed nodemodules and produces three reports: duplicated packages (installed in multiple versions), packages sorted by install size, and maintenance actions (dep-upgrade opportunities + publint findings, grouped by consumer/author).

When should I use Node Modules Inspector?

Node Modules Inspector fits situations like: the user wants to audit dependencies; find duplicate packages; check whats taking up disk space in nodemodules; identify outdated peer/prod dependencies that newer dependents could upgrade past.

How do I install Node Modules Inspector in Claude Code?

Run `npx skills add antfu/node-modules-inspector --skill node-modules-inspector -a claude-code`. Or copy the skill folder (skills/node-modules-inspector in antfu/node-modules-inspector) into .claude/skills/node-modules-inspector in your project. Claude Code loads it when a task matches its description.

How do I install Node Modules Inspector in Codex?

Run `npx skills add antfu/node-modules-inspector --skill node-modules-inspector -a codex`. Or copy the skill folder (skills/node-modules-inspector in antfu/node-modules-inspector) into .agents/skills/node-modules-inspector in your project. Codex loads it when a task matches its description.

Can I use Node Modules Inspector in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add antfu/node-modules-inspector --skill node-modules-inspector -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/node-modules-inspector, .gemini/skills/node-modules-inspector, .github/skills/node-modules-inspector and .opencode/skills/node-modules-inspector in your project.

What does Node Modules Inspector need to run?

Going by SKILL.md and its folder, Node Modules Inspector needs the command-line tools its instructions call (npx, npm and pnpm). Our summary lists: Node.js.

Does Node Modules Inspector access the network?

SKILL.md contains no URLs. Its commands use npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Node Modules Inspector safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Node Modules Inspector use?

Node Modules Inspector is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Node Modules Inspector use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Node Modules Inspector?

Skills that share tags, products or a category with Node Modules Inspector: Okx Cex Market (dex-original/okx-agent-trade-kit, 109 stars), Okx Sentiment Tracker (dex-original/okx-agent-trade-kit, 109 stars), Devcontainer Dev (stacklok/toolhive-studio, 170 stars) and Release (WebMCP-org/npm-packages, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Node Modules Inspector?

antfu (a GitHub user) maintains it in antfu/node-modules-inspector, which has 2,957 GitHub stars. The repository was last updated on September 16, 2026.

Source: antfu/node-modules-inspector on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.