Markbind Typescript Migration
MarkBind/markbind
Complete guide for migrating JavaScript files to TypeScript in the MarkBind project, including the two-commit strategy, import/export syntax conversion, and best practices.
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add grafana/skills --skill check-npm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install grafana/skills check-npm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-plugins/check-npm .claude/skills/check-npm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "check-npm" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-plugins/check-npm into .claude/skills/check-npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check-npm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/grafana/skills/tree/main/skills/grafana-plugins/check-npmType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add grafana/skills --skill check-npm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install grafana/skills check-npm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/grafana-plugins/check-npm .agents/skills/check-npm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "check-npm" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-plugins/check-npm into .agents/skills/check-npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check-npm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/skills --skill check-npm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install grafana/skills check-npm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/grafana-plugins/check-npm .cursor/skills/check-npm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "check-npm" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-plugins/check-npm into .cursor/skills/check-npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check-npm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/grafana/skills.git --path skills/grafana-plugins/check-npm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add grafana/skills --skill check-npm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install grafana/skills check-npm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/grafana-plugins/check-npm .gemini/skills/check-npm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "check-npm" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-plugins/check-npm into .gemini/skills/check-npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check-npm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install grafana/skills check-npmInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add grafana/skills --skill check-npm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/grafana-plugins/check-npm .github/skills/check-npm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "check-npm" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-plugins/check-npm into .github/skills/check-npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check-npm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add grafana/skills --skill check-npm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install grafana/skills check-npm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/grafana-plugins/check-npm .opencode/skills/check-npm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "check-npm" agent skill from https://github.com/grafana/skills/tree/main/skills/grafana-plugins/check-npm into .opencode/skills/check-npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check-npm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
check-npmAudit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.
Check npm is an agent skill from grafana/skills, published by the product's own GitHub organization. Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/fix-snippets.md`, `references/managers.md` and `references/protocols.md`).
It sits in DevOps & Cloud, covering Monitoring and alerting, Supply chain security and Git workflow. It works with npm, Grafana, pnpm and Git. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqnpmyarnpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, yarn and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Check npm loads about 1.3k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 362 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
grep -E '^ignore-scripts=' .npmrc 2>/dev/null| npm | `.npmrc` has `ignore-scripts=true` | missing or `false` || pnpm 10 | `.npmrc` `ignore-scripts=true` OR `strictDepBuilds: true` | neither |pnpm 11+ ignores script settings in `.npmrc` and `package.json#pnpm`. pnpm 10 / yarn edge cases: [references/managers.mdgrep -E '^allow-git=' .npmrc 2>/dev/nullgrep -E '^min(imum)?-release-age=' .npmrc 2>/dev/null# npm — .npmrcAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 362 words, ~1,295 tokens.
.claude/skills/check-npm/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Read-only audit of the workspace root. Do not modify any files.
test -f package.json || { echo "STOP: no package.json at workspace root"; exit 1; }
jq -r '.packageManager // "unset"' package.json
ls -1 yarn.lock package-lock.json pnpm-lock.yaml 2>/dev/null || trueIf no package.json, stop. Priority: packageManager → lockfile → default npm.
npm --version # required ≥ 11.15.0
yarn --version # required ≥ 4.14.0
pnpm --version # required ≥ 11.0.0Use semver comparison. Verify pinned packageManager meets threshold.
| Manager | Minimum |
|---|---|
| npm | 11.15.0 |
| yarn | 4.14.0 |
| pnpm | 11.0.0 |
grep -E '^ignore-scripts=' .npmrc 2>/dev/null
grep -E 'enableScripts:' .yarnrc.yml 2>/dev/null
grep -E 'strictDepBuilds:|dangerouslyAllowAllBuilds:|allowBuilds:' pnpm-workspace.yaml 2>/dev/null| Manager | PASS | FAIL |
|---|---|---|
| npm | .npmrc has ignore-scripts=true | missing or false |
| yarn | enableScripts: false or key absent | enableScripts: true |
| pnpm ≥ 11 | strictDepBuilds unset/true, dangerouslyAllowAllBuilds unset/false, and allowBuilds unset/[] | strictDepBuilds: false, dangerouslyAllowAllBuilds: true, or allowBuilds non-empty |
| pnpm 10 | .npmrc ignore-scripts=true OR strictDepBuilds: true | neither |
pnpm 11+ ignores script settings in .npmrc and package.json#pnpm. pnpm 10 / yarn edge cases: references/managers.md.
Registry:
grep -E '^allow-git=' .npmrc 2>/dev/null
grep -E 'approvedGitRepositories:' .yarnrc.yml 2>/dev/null
grep -E 'blockExoticSubdeps:' pnpm-workspace.yaml 2>/dev/nullScan workspace package.json files (dependencies, devDependencies, optionalDependencies, peerDependencies). Prefer workspace-member discovery (pnpm-workspace.yaml / root workspaces / lerna / rush) per references/protocols.md, then scan only those manifests. Fallback (may overmatch non-workspace manifests):
find . -name package.json -not -path '*/node_modules/*'Safe values only: semver range, workspace:, patch:, npm: alias to semver. Flag everything else (git URLs, tarballs, user/repo shorthand, file:, link:, exec:, …) as path → name → value (protocol).
| Manager | PASS | FAIL |
|---|---|---|
| npm | allow-git=none or root | missing or all |
| yarn | approvedGitRepositories: [] or grafana-scoped list, or omitted with policy comment + clean scan | unsafe entries or broad allow-list |
| pnpm ≥ 11 | blockExoticSubdeps unset/true | false |
| pnpm 10.x | blockExoticSubdeps: true | unset (default false) or false |
Protocol detection order and yarn posture details: references/protocols.md.
3 days = 4320 minutes. npm uses days; yarn and pnpm use minutes.
grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/null
grep -E 'npmMinimalAgeGate:' .yarnrc.yml 2>/dev/null
grep -E 'minimumReleaseAge:|minimumReleaseAgeStrict:' pnpm-workspace.yaml 2>/dev/null| Manager | PASS | FAIL |
|---|---|---|
| npm | min-release-age ≥ 3 | missing |
| yarn | npmMinimalAgeGate ≥ 4320 min | missing or below |
| pnpm ≥ 11 | minimumReleaseAge ≥ 4320 | unset (default 1440) or below |
| pnpm 10 | minimum-release-age / minimumReleaseAge ≥ 4320 | missing |
Flag minimumReleaseAgeStrict: false on pnpm 11.
| # | Check | Status | Detail |
|---|---|---|---|
| 0 | Package manager | (npm / yarn / pnpm) | version: x.y.z (pinned: y.y.y if set) |
| 1 | Tool version ≥ threshold | PASS / FAIL | actual vs required |
| 2 | Scripts disabled | PASS / FAIL | config line or "missing" |
| 3 | Unsafe dep protocols | PASS / FAIL | registry state + flagged entries |
| 4 | Min release age ≥ 3 days | PASS / FAIL | config + value |
Use PASS / FAIL only — no emojis.
For each FAIL, one paste-ready fix:
# npm — .npmrc
ignore-scripts=true
allow-git=none
min-release-age=3# pnpm 11 — pnpm-workspace.yaml
strictDepBuilds: true
dangerouslyAllowAllBuilds: false
allowBuilds: []
minimumReleaseAge: 4320
blockExoticSubdeps: true# yarn — .yarnrc.yml
npmMinimalAgeGate: 4320More fixes (tool upgrades, yarn git allow-list, pnpm 10): references/fix-snippets.md.
If all PASS: "All checks passed." and stop.
© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/grafana-plugins/check-npm of grafana/skills.
Open the folder on GitHubat commit 1ccacf2
Check npm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Check npm this skillgrafana/skills | 282 | — | ~1.3k | Automated safety check: Warn | Apache-2.0 | |
| Markbind Typescript MigrationMarkBind/markbind | 158 | — | ~2k | Automated safety check: Pass | MIT | |
| npm Supply Chain Securitybodadotsh/npm-security-best-practices | 858 | — | ~1k | Automated safety check: Warn | MIT | |
| ZCF Release AutomationUfoMiao/zcf | 6.1k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| Logseq Plugin SDKlogseq/logseq | 45k | — | ~2.3k | Automated safety check: Pass | AGPL-3.0 |
MarkBind/markbind
Complete guide for migrating JavaScript files to TypeScript in the MarkBind project, including the two-commit strategy, import/export syntax conversion, and best practices.
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
logseq/logseq
Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).
TryGhost/Ghost
Moves a legacy internal Ghost package from JavaScript and CommonJS to TypeScript and ESM in three focused commits that keep git file history intact.
grafana/skills
Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).
grafana/skills
Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…
grafana/skills
Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…
grafana/skills
A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.
grafana/skills
Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.
grafana/skills
Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…
Works with
Categories
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Check npm is an agent skill from grafana/skills, published by the product's own GitHub organization. Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days.
Check npm fits situations like: the user invokes /check-npm; asks to audit package manager security; lifecycle scripts; Git dependencies.
Run `npx skills add grafana/skills --skill check-npm -a claude-code`. Or copy the skill folder (skills/grafana-plugins/check-npm in grafana/skills) into .claude/skills/check-npm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add grafana/skills --skill check-npm -a codex`. Or copy the skill folder (skills/grafana-plugins/check-npm in grafana/skills) into .agents/skills/check-npm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill check-npm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/check-npm, .gemini/skills/check-npm, .github/skills/check-npm and .opencode/skills/check-npm in your project.
Going by SKILL.md and its folder, Check npm needs the command-line tools its instructions call (jq, npm, yarn and pnpm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 7 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Check npm is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Check npm: Markbind Typescript Migration (MarkBind/markbind, 158 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars) and Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 282 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.
Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.