Official agent skill

npm

by github in github/gh-aw

Troubleshoot npm registry, proxy, and certificate failures on the Microsoft corporate network or VPN using the 1ES public npm feed.

OfficialMITAuto-check passed

Install npm

skills CLI
$ npx skills add github/gh-aw --skill npm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw npm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/npm .claude/skills/npm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
npm
GitHub stars
5.4k
Token cost
~911 tokens
SKILL.md length
433 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Troubleshoot npm registry, proxy, and certificate failures on the Microsoft corporate network or VPN using the 1ES public npm feed.

  • SKILL.md covers Use the 1ES public npm feed, Proxy and certificate failures and Stop on unresolved network…
  • Calls npm and curl; reaches ms-feed-25.pkgs.visualstudio.com

What it does

npm is an agent skill from github/gh-aw, published by the product's own GitHub organization. Troubleshoot npm registry, proxy, and certificate failures on the Microsoft corporate network or VPN using the 1ES public npm feed.

Its SKILL.md is about 910 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

Example prompts

  • “/npm”

What it can do on your machine

Read from SKILL.md and the folder at commit a4ca9f2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ms-feed-25.pkgs.visualstudio.com

    Also links to:

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

npm loads about 911 tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~911

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit a4ca9f2, republished under its MIT licence (© github). 433 words, ~911 tokens.

Download SKILL.mdSave it as .claude/skills/npm/SKILL.md (or your agent's skills folder).
name
npm
description
Troubleshoot npm registry, proxy, and certificate failures on the Microsoft corporate network or VPN using the 1ES public npm feed.

npm on the Microsoft network or VPN

Use this skill when npm downloads are blocked by the Microsoft corporate network or VPN. Run commands in the affected package directory. Prefer npm ci with the existing lockfile and default registry when access works; do not change dependency versions to solve a network failure.

Use the 1ES public npm feed

When access to npmjs is blocked, retry through the Microsoft 1ES public feed with command-scoped settings:

sh
registry=https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/
npm ci --registry="$registry" --replace-registry-host=npmjs

--replace-registry-host=npmjs routes npmjs lockfile downloads through the selected registry without rewriting the lockfile. Private registries and lifecycle scripts that download from other hosts still need their own approved network access. Do not edit manifests, lockfile URLs, or committed npm configuration just to work around the local VPN.

To diagnose feed access, query an actual package and exact version from the lockfile. For example, substitute the project's pinned package and version in:

sh
npm view yaml@2.9.0 version --registry="$registry" \
  --fetch-retries=0 --fetch-timeout=15000

Use npm view, not npm ping: the feed may not implement the ping endpoint. A successful metadata query checks that package's availability, not tarball or postinstall access. Retry the original install to verify recovery.

If the feed returns an authentication error or lacks the pinned package, report the blocker rather than guessing credentials or trying arbitrary mirrors. Caching an upstream package can require feed permissions.

Show full SKILL.md (223 more words)Show less

Proxy and certificate failures

The feed is an npm registry, not an HTTP proxy. Never set HTTPS_PROXY or HTTP_PROXY to the feed URL. If a forward proxy is required, use only an IT-approved proxy URL in the current shell and check NO_PROXY for unintended bypasses. Do not expose proxy credentials or copy machine-specific configuration into the repository or logs.

For certificate-chain errors, use the approved corporate CA rather than disabling TLS verification:

  • On Node versions that support it, retry with NODE_USE_SYSTEM_CA=1 so Node uses the system trust store.
  • Otherwise, set NODE_EXTRA_CA_CERTS to the path of an IT-provided PEM certificate bundle before starting npm.
  • Check whether an npm cafile override is selecting a different CA bundle.

Keep HTTPS and TLS verification enabled. Never use strict-ssl=false, NODE_TLS_REJECT_UNAUTHORIZED=0, curl -k, or an HTTP registry, and do not disconnect the VPN or bypass corporate network controls.

Stop on unresolved network failures

For ENOTCONN, connection resets, timeouts, or firewall denials, report the failing hostname and error with secrets redacted. Distinguish registry metadata, package tarball, and lifecycle-script failures. Stop repeated installs once the network blocker is confirmed; do not delete the lockfile or clear caches as a network fix. Escalate to IT for approved HTTPS access to the failing host, including ms-feed-25.pkgs.visualstudio.com when the feed itself is blocked.

Based on the githubnext/gh-aw-cao npm skill, under the repository's MIT license.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/npm of github/gh-aw.

Open the folder on GitHubat commit a4ca9f2

Compare with similar skills

npm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

npm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
npm this skillgithub/gh-aw5.4k—~911Automated safety check: PassMIT
Defuddlekepano/obsidian-skills49k12 repos~208Automated safety check: PassMIT
Vercel Deploybytedance/deer-flow83k10 repos~797Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k1 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 12 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    83k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 8 repos~613 tokens
    DevelopmentAuto-check passed

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.4k GitHub starsUsed in 24 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.4k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.4k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.4k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.4k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.4k GitHub stars~736 tokensUpdated today
    Auto-check passed

Works with

Questions about npm

What does npm do?

Troubleshoot npm registry, proxy, and certificate failures on the Microsoft corporate network or VPN using the 1ES public npm feed. npm is an agent skill from github/gh-aw, published by the product's own GitHub organization. Troubleshoot npm registry, proxy, and certificate failures on the Microsoft corporate network or VPN using the 1ES public npm feed.

How do I install npm in Claude Code?

Run `npx skills add github/gh-aw --skill npm -a claude-code`. Or copy the skill folder (.github/skills/npm in github/gh-aw) into .claude/skills/npm in your project. Claude Code loads it when a task matches its description.

How do I install npm in Codex?

Run `npx skills add github/gh-aw --skill npm -a codex`. Or copy the skill folder (.github/skills/npm in github/gh-aw) into .agents/skills/npm in your project. Codex loads it when a task matches its description.

Can I use npm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill npm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm, .gemini/skills/npm, .github/skills/npm and .opencode/skills/npm in your project.

What does npm need to run?

Going by SKILL.md and its folder, npm needs the command-line tools its instructions call (npm and curl).

Does npm access the network?

SKILL.md names 3 domains. In commands or code: ms-feed-25.pkgs.visualstudio.com; the agent is likely to contact it when it follows the instructions. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is npm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does npm use?

npm is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does npm use?

About 911 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to npm?

Skills that share tags, products or a category with npm: Defuddle (kepano/obsidian-skills, 49k stars), Vercel Deploy (bytedance/deer-flow, 83k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars) and Knap Markdown Templates (kepano/obsidian-skills, 49k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains npm?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,359 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 8, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.