Agent skill

Esm Cjs Risk Scan

by logseq in logseq/logseq

Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.

AGPL-3.0Auto-check passedKnowledge Management

Install Esm Cjs Risk Scan

skills CLI
$ npx skills add logseq/logseq --skill esm-cjs-risk-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install logseq/logseq esm-cjs-risk-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/esm-cjs-risk-scan .claude/skills/esm-cjs-risk-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
esm-cjs-risk-scan
GitHub stars
45k
Token cost
~3.3k tokens
SKILL.md length
1,381 words
Files
2 (incl. scripts)
Skills in repo
12
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.

  • Works in 6 steps: Run the scanner. → Check the SUMMARY header for overall… → HIGH: Must fix. Package will crash at… → …
  • Changing Electron/main-process dependencies
  • SKILL.md covers Quick Start, Parameters, What Gets Scanned and Output, plus 4 more sections
  • Runs JavaScript scripts from its folder; calls node and pnpm

What it does

Esm Cjs Risk Scan is an agent skill from logseq/logseq. Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims. Use when changing Electron/main-process dependencies, debugging startup import errors, or auditing packages before dependency upgrades.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.

It sits in Knowledge Management, covering CSV and tabular files. It works with npm. The repository describes itself as: A privacy-first, open-source platform for knowledge management and collaboration. Download link: http://github.com/logseq/logseq/releases. roadmap: https://logseq.io/p/NX4mcggEV. The licence is AGPL-3.0.

When your agent uses it

  • Changing Electron/main-process dependencies
  • Debugging startup import errors
  • Auditing packages before dependency upgrades

Example prompts

  • “/esm-cjs-risk-scan”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Run the scanner.
  2. Check the SUMMARY header for overall risk counts.
  3. HIGH: Must fix. Package will crash at runtime.
  4. MEDIUM: Review. Consider dynamic-import or CJS-compatible alternative.
  5. OK: Verify S:OK-only packages are expected (installed in static/node_modules only).
  6. For Electron code, also verify with runtime test

What it can do on your machine

Read from SKILL.md and the folder at commit 22a29b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Esm Cjs Risk Scan loads about 3.3k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 1,381 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from logseq/logseq at commit 22a29b3, republished under its AGPL-3.0 licence (© logseq). 1,381 words, ~3,261 tokens.

Download SKILL.mdSave it as .claude/skills/esm-cjs-risk-scan/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
esm-cjs-risk-scan
description
Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims. Use when changing Electron/main-process dependencies, debugging startup import errors, or auditing packages before dependency upgrades.

ESM/CJS Risk Scan

Scan Node/Electron ClojureScript code for npm dependencies that may fail at runtime due to ESM/CJS incompatibility. Use when changing Electron dependencies, debugging startup import errors, or auditing before dependency upgrades.

Quick Start

bash
# Default scan (electron scope, human-readable table)
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs

# Scan all Node targets
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --scope all-node

# Machine-readable TSV output
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --format tsv

# JSON output
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --format json

# Show full error details in probe results
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --verbose

Parameters

ParameterValuesDefaultDescription
--scopeelectron, all-nodeelectronWhich source directories and package locations to scan
--formattable, tsv, jsontableOutput format. table is grouped and human-readable; tsv is tab-separated for machine parsing; json for programmatic use
--verbose / -v(flag)offShow full error messages in probe results instead of abbreviated ERR
Scopes
ScopeSource DirectoriesDescription
electronsrc/electron/electronElectron main-process code only
all-nodeSee table belowAll Node/server-side code across the repo

all-node source directories and their basis:

DirectoryBuild target / role
src/electron/electron:electron target — :node-script (Electron main process)
src/test:test / :test-no-worker — :node-test (test runner)
deps/cli/srcCLI tool (nbb Node script, uses fs-extra, path)
deps/db-sync/src, deps/db-sync/testDB sync server / Node adapter
deps/db/script, deps/db/testDB utility scripts
deps/graph-parser/src, test, scriptGraph parser CLI and tests
deps/publishing/script, testPublishing CLI and tests

Browser/Worker builds (:app, :db-worker, :inference-worker, :mobile) are intentionally excluded — their npm deps are resolved at bundle time and never require()-called directly in Node.

What Gets Scanned

The scanner detects three import patterns in .cljs / .cljc / .clj files:

PatternKindExample
["pkg" :as x]npm-import["electron" :as e] — shadow-cljs npm import (compiled to require() for Node targets)
js/require "pkg"js-require(js/require "update-electron-app") — Direct runtime require() call
dynamic-import "pkg"dynamic-import(shadow.esm/dynamic-import "https-proxy-agent") — Async ESM import()

Output

Risk Levels
RiskMeaningAction
HIGHPackage cannot be loaded by any mechanism. js-require with all probes failing; dynamic-import with import probe failing; or npm-import where both require() and import() fail (esm-? mode)Must replace the package — no loading workaround exists
MEDIUMnpm-import where require() fails but import() works (esm-imp mode). Caused by packages whose exports map has only "import" conditionals with no "require" or top-level "default" fallback — Node's module resolver rejects require(). shadow-cljs generates require() which will failSwitch to dynamic-import
OKPackage loads successfully from at least one probe CWD, or is esm-req/esm-edep — safe to use in ns-form requireNo action needed
INFORelative path requires or Node builtins; always safeInformational only
Table Columns (default format)
ColumnDescription
PACKAGEnpm package name as referenced in source code
VERVersion from package.json (- if not installed)
KINDImport mechanism: npm-import, js-require, or dynamic-import
TYPEPackage type field: cjs (CommonJS), esm (ESM type:module), blt (Node builtin), - (unset)
MODEModule load mode (see below). Abbreviated in table; full names in TSV/JSON
REQUIRESimplified require() probe results per CWD (see Probe Results below)
FILESource file containing the import

HIGH/MEDIUM items additionally show: exports and import probe values.

Module Modes
Mode (full)Table abbrevMeaning
cjs-or-nonmodulecjstype is not module. CJS or unspecified — always works with require()
module-require-compatibleesm-reqtype: module but require() still works (Node 22+ or dual-mode package)
module-electron-depesm-edeptype: module; probe fails only because Electron runtime (electron package) is absent. Works fine in actual Electron.
module-import-onlyesm-imptype: module and only loadable via import(). require() will fail
module-unloadableesm-?type: module and both require() and import() fail in current environment
builtinbltNode.js built-in module (fs, path, os, child_process, etc.)
What actually makes require() fail for ESM packages?

Not merely "type": "module". Node 22+ supports require(esm) for ESM modules without top-level await. The real determiner is the exports map structure:

Package exports structurerequire() behaviorExample
No exports field (only main)✅ Works in Node 22+node-fetch@3.3.2
exports has top-level "default" key✅ Works in Node 22+electron-dl@4.0.0 ({"types":…, "default":…})
exports has "require" key✅ Works (explicit CJS path)Most dual-mode packages
exports has only "import" key, no "default"❌ Rejected by Node's module resolverhttps-proxy-agent ({"import":{…}})

The scanner's esmOnly flag (in TSV/JSON output) marks the last case — exports explicitly restricts to import-only. Classification always uses probe results as the authoritative source.

Probe Results

The scanner tests require() and import() from three CWD locations:

AbbreviationDirectoryRole
Sstatic/Primary Electron runtime directory
Rresources/Secondary resources directory
.repository rootDevelopment directory

Compact display (default mode):

DisplayMeaning
ALL:OKLoads from all three CWDs
ALL:ERRFails from all three CWDs
ALL:ERR(e-dep)All failures are electron-runtime errors; package loads fine in Electron
S:OK R:ERR .:ERRLoads from static/ only (normal for Electron packages)
S:ERR(e-dep) R:ERR(e-dep) .:ERRProbe fails because electron runtime is absent; package loads fine in Electron
SKIP(electron)Skipped for electron runtime package
BUILTINNode.js built-in module

Use --verbose (-v) for error details, e.g. S:OK R:ERR(MODULE_NOT_FOUND) .:ERR(MODULE_NOT_FOUND).

TSV Columns (--format=tsv)

All fields tab-separated, one row per usage:

risk, kind, package, version, type, module_mode, exports_require, exports_import, require_probe, import_probe, file

Probe columns contain raw probe strings (e.g. static=OK;resources=ERR:MODULE_NOT_FOUND;.=ERR:MODULE_NOT_FOUND).

Workflow

  1. Run the scanner.
  2. Check the SUMMARY header for overall risk counts.
  3. HIGH: Must fix. Package will crash at runtime.
  4. MEDIUM: Review. Consider dynamic-import or CJS-compatible alternative.
  5. OK: Verify S:OK-only packages are expected (installed in static/node_modules only).
  6. For Electron code, also verify with runtime test:
    bash
    pnpm exec electron static/electron.js

Common Patterns & FAQ

Show full SKILL.md (560 more words)Show less
"S:OK R:ERR .:ERR" — Is this a problem?

No. This is normal for Electron-specific packages (e.g., keytar, update-electron-app, electron-window-state). They are installed in static/node_modules/ (the Electron app directory). The resources/ and root directories don't need them.

"ERR:Electron failed to install correctly..."

This error appears when probing packages that depend on electron at runtime (e.g., update-electron-app) from directories where electron isn't properly available. Not a real issue — the package works fine from static/ (S:OK), which is where Electron actually runs.

Node builtins (fs, path, os, etc.)

Detected automatically and shown with BUILTIN probe status. Always work in Node/Electron targets. Classified as OK.

electron-* package probing

Only the electron package itself (the runtime framework) skips probing. Other electron-* packages (electron-log, electron-window-state, electron-dl, etc.) are regular npm packages and are probed normally.

ESM packages with module-electron-dep mode

Some ESM packages (e.g. electron-dl v4) internally call import { BrowserWindow } from 'electron'. When the scanner probes them with a plain Node.js require(), the call fails — not because the package is unloadable, but because the electron npm package (an installer shim) doesn't expose Electron's named runtime exports.

In the actual Electron runtime, the electron module IS the framework, so BrowserWindow and friends resolve correctly. The generated shadow.js shim (shadow.js.nativeProvides["electron-dl"] = require("electron-dl")) works fine at Electron startup.

How the scanner detects this: If every probe failure contains 'electron' in the error message (the named-export failure pattern), the package is reclassified from module-unloadable → module-electron-dep and from MEDIUM/HIGH → OK. Probe column shows ERR(e-dep) to mark the probe location.

When to verify manually: If a new package shows esm-edep unexpectedly, inspect its source — it should contain import ... from 'electron' or use Electron APIs directly. You can also check the compiled Electron shim cache at .shadow-cljs/builds/electron/dev/goog-js/ (Transit JSON, dev build) or .shadow-cljs/builds/electron/release/closure-inputs/ (plain JS, release build) for shadow.js.shim.module$<package>.js files — their content will show require("pkg") if shadow-cljs successfully resolved the package for the Node/Electron target.

Understanding the plain-Node probe limitation

The scanner runs require() and import() probes in a plain Node.js process (node -e ...), not inside a real Electron runtime. This means:

  • Packages that depend on Electron APIs will fail the probe even if they work fine in the app
  • The scanner uses the module-electron-dep heuristic to handle this case automatically
  • For packages that use Electron APIs in unusual ways (not just import ... from 'electron'), a manual check may be needed

If a build has already been compiled, you can inspect .shadow-cljs/builds/electron/release/closure-inputs/ for shadow.js.shim.module$<package>.js files (plain JS, immediately readable). The presence of require("pkg") in the shim content confirms shadow-cljs successfully resolved the package for the Electron Node target. This is the definitive ground truth; the scanner's probe is a pre-build approximation.

Note: static/js/cljs-runtime/ contains shims for browser worker targets that use :js-provider :external (currently :db-worker and :inference-worker). Those shims use shadow$bridge("pkg") — not require() — delegating actual module loading to the Webpack-bundled worker bundle. The :app target does not use :js-provider :external and its missing modules throw "Module not provided" at runtime instead. Electron (:node-script) shims never appear in this directory either.

For HIGH risk:

  • Use a CJS-compatible subpath of the package if available
  • Switch to (shadow.esm/dynamic-import "pkg") for ESM-only packages
  • Pin a version that provides CJS support
  • Use an alternative CJS-compatible package

For MEDIUM risk:

  • Switch to (shadow.esm/dynamic-import "pkg")
  • Find a CJS-compatible alternative
  • Verify Node 22+ require(esm) covers your case (module-require-compatible mode)

Re-run the scanner after changes to verify fixes.

Script

© logseq, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .agents/skills/esm-cjs-risk-scan of logseq/logseq.

  • SKILL.md
  • scripts/scan_esm_cjs_risk.mjs

Open the folder on GitHubat commit 22a29b3

Compare with similar skills

Esm Cjs Risk Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Esm Cjs Risk Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Esm Cjs Risk Scan this skilllogseq/logseq45k—~3.3kAutomated safety check: PassAGPL-3.0
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
Wellally Techhuifer/WellAlly-health9605 repos~4.8kAutomated safety check: PassMIT
Portaljs Add Datasetdatopian/portaljs2.4k—~1.6kAutomated safety check: PassMIT
Download Statsnubjs/nub4.4k—~2.5kAutomated safety check: PassMIT
Defuddlekepano/obsidian-skills49k11 repos~208Automated safety check: PassMIT

Similar skills

  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • Wellally Tech

    huifer/WellAlly-health

    Integrate digital health data sources (Apple Health, Fitbit, Oura Ring) and connect to WellAlly.tech knowledge base.

    960 GitHub starsUsed in 5 repos~4.8k tokens
    Knowledge ManagementAuto-check passed
  • Portaljs Add Dataset

    datopian/portaljs

    Add a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal.

    2.4k GitHub stars~1.6k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Generate download-stats CSVs and a chart for nub across its distribution channels (npm + GitHub release assets, which subsume Homebrew).

    4.4k GitHub stars~2.5k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 11 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • TeamAI Team Sync

    Tencent/teamai-cli

    Make every team AI native — TeamAI syncs a team's AI skills, rules, docs and env across AI coding tools. Use when the task operates on team-shared AI…

    5.1k GitHub stars~632 tokensUpdated yesterday
    Knowledge ManagementAuto-check passed

More from logseq/logseq

All 12 skills in this repo
  • Compare two revisions of the Logseq logseq-review-workflow skill by running the same review prompt against isolated before and after skill snapshots, collecting both outputs, and producing a…

    45k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Logseq Plugin SDK

    logseq/logseq

    Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).

    45k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Logseq CLI

    logseq/logseq

    Operate the current Logseq command-line interface to inspect or modify graphs, pages, blocks, tasks, tags, and properties; run Datascript queries; show page/block trees; manage graphs; and manage…

    45k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…

    45k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Logseq I18n

    logseq/logseq

    Logseq i18n workflow for adding, renaming, reviewing, or editing translation keys and user-facing strings.

    45k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Answer user questions about the Logseq repository by researching source code, docs, tests, runtime behavior, and local tools.

    45k GitHub stars~1.2k tokensUpdated today
    Auto-check: warnings

Works with

Questions about Esm Cjs Risk Scan

What does Esm Cjs Risk Scan do?

Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims. Esm Cjs Risk Scan is an agent skill from logseq/logseq. Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.

When should I use Esm Cjs Risk Scan?

Esm Cjs Risk Scan fits situations like: changing Electron/main-process dependencies; debugging startup import errors; auditing packages before dependency upgrades.

How do I install Esm Cjs Risk Scan in Claude Code?

Run `npx skills add logseq/logseq --skill esm-cjs-risk-scan -a claude-code`. Or copy the skill folder (.agents/skills/esm-cjs-risk-scan in logseq/logseq) into .claude/skills/esm-cjs-risk-scan in your project. Claude Code loads it when a task matches its description.

How do I install Esm Cjs Risk Scan in Codex?

Run `npx skills add logseq/logseq --skill esm-cjs-risk-scan -a codex`. Or copy the skill folder (.agents/skills/esm-cjs-risk-scan in logseq/logseq) into .agents/skills/esm-cjs-risk-scan in your project. Codex loads it when a task matches its description.

Can I use Esm Cjs Risk Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add logseq/logseq --skill esm-cjs-risk-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/esm-cjs-risk-scan, .gemini/skills/esm-cjs-risk-scan, .github/skills/esm-cjs-risk-scan and .opencode/skills/esm-cjs-risk-scan in your project.

What does Esm Cjs Risk Scan need to run?

Going by SKILL.md and its folder, Esm Cjs Risk Scan needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and pnpm). Our summary lists: Node.js.

Does Esm Cjs Risk Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Esm Cjs Risk Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Esm Cjs Risk Scan use?

Esm Cjs Risk Scan is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Esm Cjs Risk Scan use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Esm Cjs Risk Scan?

Skills that share tags, products or a category with Esm Cjs Risk Scan: Knap Markdown Templates (kepano/obsidian-skills, 49k stars), Wellally Tech (huifer/WellAlly-health, 960 stars), Portaljs Add Dataset (datopian/portaljs, 2.4k stars) and Download Stats (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Esm Cjs Risk Scan?

logseq (a GitHub organization) maintains it in logseq/logseq, which has 45,158 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.

Source: logseq/logseq on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.