Agent skill

npm

by espennilsen in espennilsen/pi

Manage npm packages — install, publish, version bump, audit, and run scripts using the npm tool.

MITAuto-check passed

Install npm

skills CLI
$ npx skills add espennilsen/pi --skill npm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install espennilsen/pi npm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/espennilsen/pi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/npm .claude/skills/npm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
npm
GitHub stars
122
Token cost
~372 tokens
SKILL.md length
111 words
Files
1
Skills in repo
36
Repo updated
First seen
Licence
MIT

At a glance

Manage npm packages — install, publish, version bump, audit, and run scripts using the npm tool.

  • Works in 5 steps: Before publishing, always read… → Use dry_run: true for publish, pack, and… → Check npm outdated before updating to… → …
  • SKILL.md covers Common workflows and Guidelines
  • Calls npm

What it does

npm is an agent skill from espennilsen/pi. Manage npm packages — install, publish, version bump, audit, and run scripts using the npm tool.

Its SKILL.md is about 370 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm. The licence is MIT.

Example prompts

  • “/npm”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Before publishing, always read package.json to verify name, version, files, and registry config.
  2. Use dry_run: true for publish, pack, and version to preview before committing.
  3. Check npm outdated before updating to understand what will change.
  4. Run npm audit after installing new dependencies.
  5. When working in a monorepo, use the path parameter to target specific packages.

What it can do on your machine

Read from SKILL.md and the folder at commit 79d019b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

npm loads about 372 tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 111 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~372

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from espennilsen/pi at commit 79d019b, republished under its MIT licence (© espennilsen). 111 words, ~372 tokens.

Download SKILL.mdSave it as .claude/skills/npm/SKILL.md (or your agent's skills folder).
name
npm
description
Manage npm packages — install, publish, version bump, audit, and run scripts using the npm tool.

NPM Skill

Use the npm tool to manage Node.js packages and run npm workflows.

Common workflows

Install dependencies
npm tool: action=install
npm tool: action=install, args="express @types/express --save-dev"
Run scripts
npm tool: action=run, args="dev"
npm tool: action=test
npm tool: action=build
Publish a package

Always do a dry run first to verify what will be published:

npm tool: action=publish, dry_run=true

Then publish for real:

npm tool: action=publish
npm tool: action=publish, args="--tag beta"
Version bumps

Preview first, then apply:

npm tool: action=version, args="patch", dry_run=true
npm tool: action=version, args="minor"
Check for issues
npm tool: action=outdated
npm tool: action=audit
npm tool: action=audit, args="--fix"
Inspect packages
npm tool: action=info, args="react"
npm tool: action=list, args="--depth=0"

Guidelines

  1. Before publishing, always read package.json to verify name, version, files, and registry config.
  2. Use dry_run: true for publish, pack, and version to preview before committing.
  3. Check npm outdated before updating to understand what will change.
  4. Run npm audit after installing new dependencies.
  5. When working in a monorepo, use the path parameter to target specific packages.

© espennilsen, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/npm of espennilsen/pi.

Open the folder on GitHubat commit 79d019b

Compare with similar skills

npm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

npm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
npm this skillespennilsen/pi122—~372Automated safety check: PassMIT
Defuddlekepano/obsidian-skills49k12 repos~208Automated safety check: PassMIT
Vercel Deploybytedance/deer-flow83k10 repos~797Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k1 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 12 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    83k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 8 repos~613 tokens
    DevelopmentAuto-check passed

More from espennilsen/pi

All 36 skills in this repo
  • GitHub

    espennilsen/pi

    Interact with GitHub repos, PRs, issues, CI, and notifications via the pi-github extension commands and gh CLI.

    122 GitHub stars~1k tokensUpdated 17 days ago
    Auto-check passed
  • Skill Creator

    espennilsen/pi

    Create, review, and improve skills for Pi agents. An agent skill from espennilsen/pi.

    122 GitHub stars~2.1k tokensUpdated 17 days ago
    Auto-check passed
  • Dry Code Review

    espennilsen/pi

    Perform a comprehensive DRY (Don't Repeat Yourself) code review on a codebase.

    122 GitHub stars~1.7k tokensUpdated 17 days ago
    Auto-check passed
  • Extract Design System

    espennilsen/pi

    Reverse-engineer a design system from a live website (public URL or localhost).

    122 GitHub stars~2k tokensUpdated 17 days ago
    Auto-check passed
  • Herdr Operations

    espennilsen/pi

    A skill your agent uses when inspecting or operating Herdr sessions, workspaces, tabs, panes, agents, terminal output, agent messaging, or waits.

    122 GitHub starsUsed in 1 repo~525 tokens
    Auto-check passed
  • PDF Reader

    espennilsen/pi

    Read and extract content from PDF files — text, tables, metadata, and images.

    122 GitHub stars~1.6k tokensUpdated 17 days ago
    Auto-check passed

Works with

Questions about npm

What does npm do?

Manage npm packages — install, publish, version bump, audit, and run scripts using the npm tool. npm is an agent skill from espennilsen/pi. Manage npm packages — install, publish, version bump, audit, and run scripts using the npm tool.

How do I install npm in Claude Code?

Run `npx skills add espennilsen/pi --skill npm -a claude-code`. Or copy the skill folder (skills/npm in espennilsen/pi) into .claude/skills/npm in your project. Claude Code loads it when a task matches its description.

How do I install npm in Codex?

Run `npx skills add espennilsen/pi --skill npm -a codex`. Or copy the skill folder (skills/npm in espennilsen/pi) into .agents/skills/npm in your project. Codex loads it when a task matches its description.

Can I use npm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add espennilsen/pi --skill npm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm, .gemini/skills/npm, .github/skills/npm and .opencode/skills/npm in your project.

What does npm need to run?

Going by SKILL.md and its folder, npm needs the command-line tools its instructions call (npm). Our summary lists: Node.js.

Does npm access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is npm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does npm use?

npm is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does npm use?

About 372 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to npm?

Skills that share tags, products or a category with npm: Defuddle (kepano/obsidian-skills, 49k stars), Vercel Deploy (bytedance/deer-flow, 83k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars) and Knap Markdown Templates (kepano/obsidian-skills, 49k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains npm?

espennilsen (a GitHub user) maintains it in espennilsen/pi, which has 122 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on September 21, 2026.

Source: espennilsen/pi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.