Official agent skill

Check npm

by grafana in grafana/skills

Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.

OfficialApache-2.0Auto-check: warningsDevOps & Cloud

Install Check npm

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add grafana/skills --skill check-npm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills check-npm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-plugins/check-npm .claude/skills/check-npm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
check-npm
GitHub stars
282
Token cost
~1.3k tokens
SKILL.md length
362 words
Files
4 (incl. references)
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.

  • Works in 6 steps: Detect package manager → Tool version → Lifecycle scripts disabled → …
  • The user invokes /check-npm
  • SKILL.md covers 0. Detect package manager, 1. Tool version, 2. Lifecycle scripts disabled and 3. Unsafe dependency protocols, plus 2 more sections
  • Calls jq, npm and yarn

What it does

Check npm is an agent skill from grafana/skills, published by the product's own GitHub organization. Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/fix-snippets.md`, `references/managers.md` and `references/protocols.md`).

It sits in DevOps & Cloud, covering Monitoring and alerting, Supply chain security and Git workflow. It works with npm, Grafana, pnpm and Git. The licence is Apache-2.0.

When your agent uses it

  • The user invokes /check-npm
  • Asks to audit package manager security
  • Lifecycle scripts
  • Git dependencies

Example prompts

  • “/check-npm”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect package manager
  2. Tool version
  3. Lifecycle scripts disabled
  4. Unsafe dependency protocols
  5. Minimum release age ≥ 3 days
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq
    • npm
    • yarn
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, yarn and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Check npm loads about 1.3k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 362 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:48
    grep -E '^ignore-scripts=' .npmrc 2>/dev/null
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:55
    | npm | `.npmrc` has `ignore-scripts=true` | missing or `false` |
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:58
    | pnpm 10 | `.npmrc` `ignore-scripts=true` OR `strictDepBuilds: true` | neither |
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:60
    pnpm 11+ ignores script settings in `.npmrc` and `package.json#pnpm`. pnpm 10 / yarn edge cases: [references/managers.md
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:67
    grep -E '^allow-git=' .npmrc 2>/dev/null
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:92
    grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/null
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:121
    # npm — .npmrc

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 362 words, ~1,295 tokens.

Download SKILL.mdSave it as .claude/skills/check-npm/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
check-npm
description
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.
license
Apache-2.0
disable-model-invocation
false

npm / yarn / pnpm supply-chain audit

Read-only audit of the workspace root. Do not modify any files.

0. Detect package manager

bash
test -f package.json || { echo "STOP: no package.json at workspace root"; exit 1; }
jq -r '.packageManager // "unset"' package.json
ls -1 yarn.lock package-lock.json pnpm-lock.yaml 2>/dev/null || true

If no package.json, stop. Priority: packageManager → lockfile → default npm.

1. Tool version

bash
npm --version    # required ≥ 11.15.0
yarn --version   # required ≥ 4.14.0
pnpm --version   # required ≥ 11.0.0

Use semver comparison. Verify pinned packageManager meets threshold.

ManagerMinimum
npm11.15.0
yarn4.14.0
pnpm11.0.0

2. Lifecycle scripts disabled

bash
grep -E '^ignore-scripts=' .npmrc 2>/dev/null
grep -E 'enableScripts:' .yarnrc.yml 2>/dev/null
grep -E 'strictDepBuilds:|dangerouslyAllowAllBuilds:|allowBuilds:' pnpm-workspace.yaml 2>/dev/null
ManagerPASSFAIL
npm.npmrc has ignore-scripts=truemissing or false
yarnenableScripts: false or key absentenableScripts: true
pnpm ≥ 11strictDepBuilds unset/true, dangerouslyAllowAllBuilds unset/false, and allowBuilds unset/[]strictDepBuilds: false, dangerouslyAllowAllBuilds: true, or allowBuilds non-empty
pnpm 10.npmrc ignore-scripts=true OR strictDepBuilds: trueneither

pnpm 11+ ignores script settings in .npmrc and package.json#pnpm. pnpm 10 / yarn edge cases: references/managers.md.

3. Unsafe dependency protocols

Registry:

bash
grep -E '^allow-git=' .npmrc 2>/dev/null
grep -E 'approvedGitRepositories:' .yarnrc.yml 2>/dev/null
grep -E 'blockExoticSubdeps:' pnpm-workspace.yaml 2>/dev/null

Scan workspace package.json files (dependencies, devDependencies, optionalDependencies, peerDependencies). Prefer workspace-member discovery (pnpm-workspace.yaml / root workspaces / lerna / rush) per references/protocols.md, then scan only those manifests. Fallback (may overmatch non-workspace manifests):

find . -name package.json -not -path '*/node_modules/*'

Safe values only: semver range, workspace:, patch:, npm: alias to semver. Flag everything else (git URLs, tarballs, user/repo shorthand, file:, link:, exec:, …) as path → name → value (protocol).

ManagerPASSFAIL
npmallow-git=none or rootmissing or all
yarnapprovedGitRepositories: [] or grafana-scoped list, or omitted with policy comment + clean scanunsafe entries or broad allow-list
pnpm ≥ 11blockExoticSubdeps unset/truefalse
pnpm 10.xblockExoticSubdeps: trueunset (default false) or false

Protocol detection order and yarn posture details: references/protocols.md.

Show full SKILL.md (138 more words)Show less

4. Minimum release age ≥ 3 days

3 days = 4320 minutes. npm uses days; yarn and pnpm use minutes.

bash
grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/null
grep -E 'npmMinimalAgeGate:' .yarnrc.yml 2>/dev/null
grep -E 'minimumReleaseAge:|minimumReleaseAgeStrict:' pnpm-workspace.yaml 2>/dev/null
ManagerPASSFAIL
npmmin-release-age ≥ 3missing
yarnnpmMinimalAgeGate ≥ 4320 minmissing or below
pnpm ≥ 11minimumReleaseAge ≥ 4320unset (default 1440) or below
pnpm 10minimum-release-age / minimumReleaseAge ≥ 4320missing

Flag minimumReleaseAgeStrict: false on pnpm 11.

5. Report

#CheckStatusDetail
0Package manager(npm / yarn / pnpm)version: x.y.z (pinned: y.y.y if set)
1Tool version ≥ thresholdPASS / FAILactual vs required
2Scripts disabledPASS / FAILconfig line or "missing"
3Unsafe dep protocolsPASS / FAILregistry state + flagged entries
4Min release age ≥ 3 daysPASS / FAILconfig + value

Use PASS / FAIL only — no emojis.

For each FAIL, one paste-ready fix:

ini
# npm — .npmrc
ignore-scripts=true
allow-git=none
min-release-age=3
yaml
# pnpm 11 — pnpm-workspace.yaml
strictDepBuilds: true
dangerouslyAllowAllBuilds: false
allowBuilds: []
minimumReleaseAge: 4320
blockExoticSubdeps: true
yaml
# yarn — .yarnrc.yml
npmMinimalAgeGate: 4320

More fixes (tool upgrades, yarn git allow-list, pnpm 10): references/fix-snippets.md.

If all PASS: "All checks passed." and stop.

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/grafana-plugins/check-npm of grafana/skills.

  • SKILL.md
  • references/fix-snippets.md
  • references/managers.md
  • references/protocols.md

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Check npm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Check npm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Check npm this skillgrafana/skills282—~1.3kAutomated safety check: WarnApache-2.0
Markbind Typescript MigrationMarkBind/markbind158—~2kAutomated safety check: PassMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Logseq Plugin SDKlogseq/logseq45k—~2.3kAutomated safety check: PassAGPL-3.0

Similar skills

  • Complete guide for migrating JavaScript files to TypeScript in the MarkBind project, including the two-commit strategy, import/export syntax conversion, and best practices.

    158 GitHub stars~2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 10 days ago
    SecurityAuto-check: warnings
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Logseq Plugin SDK

    logseq/logseq

    Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).

    45k GitHub stars~2.3k tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Moves a legacy internal Ghost package from JavaScript and CommonJS to TypeScript and ESM in three focused commits that keep git file history intact.

    56k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    282 GitHub stars~678 tokensUpdated 2 days ago
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    282 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    282 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    282 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    282 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    282 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Check npm

What does Check npm do?

Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Check npm is an agent skill from grafana/skills, published by the product's own GitHub organization. Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.

When should I use Check npm?

Check npm fits situations like: the user invokes /check-npm; asks to audit package manager security; lifecycle scripts; Git dependencies.

How do I install Check npm in Claude Code?

Run `npx skills add grafana/skills --skill check-npm -a claude-code`. Or copy the skill folder (skills/grafana-plugins/check-npm in grafana/skills) into .claude/skills/check-npm in your project. Claude Code loads it when a task matches its description.

How do I install Check npm in Codex?

Run `npx skills add grafana/skills --skill check-npm -a codex`. Or copy the skill folder (skills/grafana-plugins/check-npm in grafana/skills) into .agents/skills/check-npm in your project. Codex loads it when a task matches its description.

Can I use Check npm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill check-npm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/check-npm, .gemini/skills/check-npm, .github/skills/check-npm and .opencode/skills/check-npm in your project.

What does Check npm need to run?

Going by SKILL.md and its folder, Check npm needs the command-line tools its instructions call (jq, npm, yarn and pnpm).

Does Check npm access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Check npm safe to install?

Our automated static check of SKILL.md flagged 7 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Check npm use?

Check npm is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Check npm use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Check npm?

Skills that share tags, products or a category with Check npm: Markbind Typescript Migration (MarkBind/markbind, 158 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars) and Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Check npm?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 282 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.