Agent skill

Package Health

by mohitagw15856 in mohitagw15856/pm-claude-skills

Check a package's health before you depend on it — npm and PyPI registry APIs via keyless curl: downloads, release recency, maintenance signals, and the dependency-decision read.

MITAuto-check passed

Install Package Health

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill package-health -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills package-health --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/package-health .claude/skills/package-health && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
package-health
GitHub stars
1.4k
Token cost
~1.3k tokens
SKILL.md length
623 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Check a package's health before you depend on it — npm and PyPI registry APIs via keyless curl: downloads, release recency, maintenance signals, and the dependency-decision read.

  • Works in 5 steps: npm calls: latest: curl -s… → PyPI calls: curl -s… → Interpret age against purpose:… → …
  • Asked is this npm package maintained
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: The Signals and the… and Output Format, plus 3 more sections
  • Calls curl; reaches registry.npmjs.org and api.npmjs.org

What it does

Package Health is an agent skill from mohitagw15856/pm-claude-skills. Check a package's health before you depend on it — npm and PyPI registry APIs via keyless curl: downloads, release recency, maintenance signals, and the dependency-decision read. Use when asked is this npm package maintained, check this PyPI library before we adopt it, compare these two packages, or is this dependency abandoned. Produces the health read with the signals interpreted (not just listed), the numbers with their commands, and the adopt/avoid/vendor recommendation framing.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked is this npm package maintained
  • Check this PyPI library before we adopt it
  • Compare these two packages
  • Is this dependency abandoned

Example prompts

  • “/package-health”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. npm calls: latest: curl -s "https://registry.npmjs.org/express/latest" (version, dependencies, deprecation notices) · full metadata: curl…
  2. PyPI calls: curl -s "https://pypi.org/pypi/requests/json" — info (version, requires_python, project_urls, yanked flags), releases (the…
  3. Interpret age against purpose: no-release-in-3-years = abandoned for an API client (upstream APIs moved), plausibly finished for a pure…
  4. The signal cluster beats any single number: healthy = recent releases + steady cadence + real downloads + active repo (chain to…
  5. The decision framing, not the decision: adopt / adopt-and-monitor / vendor-the-function (for one-function utilities, fifty lines beats a…

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org
    • api.npmjs.org
    • pypi.org
    • pypistats.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Package Health loads about 1.3k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 623 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 623 words, ~1,328 tokens.

Download SKILL.mdSave it as .claude/skills/package-health/SKILL.md (or your agent's skills folder).
name
package-health
description
Check a package's health before you depend on it — npm and PyPI registry APIs via keyless curl: downloads, release recency, maintenance signals, and the dependency-decision read. Use when asked is this npm package maintained, check this PyPI library before we adopt it, compare these two packages, or is this dependency abandoned. Produces the health read with the signals interpreted (not just listed), the numbers with their commands, and the adopt/avoid/vendor recommendation framing.

Package Health Skill

Adding a dependency is hiring code you'll never interview — and the registries publish the résumé keylessly: last release date, download trajectory, version cadence, maintainer count. This skill pulls the signals for npm and PyPI over plain curl and does the part the raw numbers don't: interpretation. A package with no release in three years is abandoned or finished — and which one it is depends on what the package does. The output is a read, not a dashboard.

What This Skill Produces

  • The health read — maintained / stable-and-done / drifting / abandoned — with the reasoning
  • The signals table — latest version + date, download scale, release cadence, deprecation flags
  • The comparison — for adoption decisions between candidates, same signals side by side
  • The commands — every number's curl, rerunnable

Required Inputs

Ask for these if not provided:

  • The package(s) and ecosystem — npm or PyPI; exact names (typosquats are a real hazard — the exact-name check is part of the job, and a near-miss name is a 🔴 finding, not a typo to auto-correct)
  • The role it would play — a core dependency, a dev tool, a one-function utility: the stakes calibrate the read ("finished" is fine for a slugify; concerning for a crypto library)
  • The runtime context — versions/platforms that matter for compatibility checking

Framework: The Signals and the Reads

  1. npm calls: latest: curl -s "https://registry.npmjs.org/express/latest" (version, dependencies, deprecation notices) · full metadata: curl -s "https://registry.npmjs.org/express" (time object = the whole release history — cadence lives here; maintainers) · downloads: curl -s "https://api.npmjs.org/downloads/point/last-month/express".
  2. PyPI calls: curl -s "https://pypi.org/pypi/requests/json" — info (version, requires_python, project_urls, yanked flags), releases (the dated history). Downloads for PyPI live at https://pypistats.org/api/packages/<name>/recent (keyless).
  3. Interpret age against purpose: no-release-in-3-years = abandoned for an API client (upstream APIs moved), plausibly finished for a pure algorithm. The read must say which and why — this rule is the skill's whole value over a stats page.
  4. The signal cluster beats any single number: healthy = recent releases + steady cadence + real downloads + active repo (chain to github-repo-vitals via the metadata's repository URL). Warning shapes: downloads huge but releases stopped (the ecosystem is riding a corpse — someone will fork; watch which), single maintainer + critical role (bus-factor flag, not a disqualifier), deprecation notice in the registry (the maintainer's own verdict — believe them).
  5. The decision framing, not the decision: adopt / adopt-and-monitor / vendor-the-function (for one-function utilities, fifty lines beats a dependency) / avoid — recommended with reasoning, stakes-calibrated; security auditing is its own discipline and gets named as out of scope rather than faked.
Show full SKILL.md (219 more words)Show less

Output Format

Package Health: [name] ([ecosystem])

The read: [maintained / stable-and-done / drifting / abandoned] — [two sentences of reasoning].

SignalValueRead
[Version + date · release cadence · downloads/month · maintainers · deprecation/yank flags]

[Comparison mode: candidates × signals, same table, verdict per role]

Recommendation frame: [adopt / monitor / vendor / avoid — with the stakes reasoning] Source: [registry] APIs · as of [date] · rerun: [the curls] Registry signals, not a security audit — that's a separate discipline.

Quality Checks

  • The exact package name was verified — near-miss names flagged, never auto-corrected
  • The read interprets age against the package's purpose, not against a universal freshness bar
  • Warning shapes (riding-a-corpse, bus-factor, registry deprecation) are checked
  • The repo-vitals chain is offered when the registry signals are ambiguous
  • Security audit is scoped out explicitly, not implied

Anti-Patterns

  • Do not present a stats dump as a health check — the read is the product
  • Do not treat "old" as "dead" without the purpose test — finished software exists
  • Do not auto-correct package names — typosquats are the attack this check can catch
  • Do not extrapolate download counts into quality — popularity is a signal about forks and eyes, not correctness
  • Do not answer from memory — versions and deprecations are live facts; fetch or hand over the commands

Example Trigger Phrases

  • "Is this npm package maintained?"
  • "Check this PyPI library before we adopt it."
  • "Compare these two packages."
  • "Is this dependency abandoned?"

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/package-health of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Package Health next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Package Health compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Package Health this skillmohitagw15856/pm-claude-skills1.4k—~1.3kAutomated safety check: PassMIT
Defuddlekepano/obsidian-skills49k11 repos~208Automated safety check: PassMIT
Vercel Deploybytedance/deer-flow84k10 repos~797Automated safety check: PassMIT
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
Nx Run Tasksnomcopter/react-mosaic4.8k8 repos~613Automated safety check: PassCustom licence

Similar skills

  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 11 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    84k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 8 repos~613 tokens
    DevelopmentAuto-check passed
  • Validates OpenHarness features by running real multi-turn agent loops with live LLM calls against an unfamiliar codebase, checking actual tool execution.

    16k GitHub starsUsed in 1 repo~2.1k tokens
    Testing & QAAuto-check: notes

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Package Health

What does Package Health do?

Check a package's health before you depend on it — npm and PyPI registry APIs via keyless curl: downloads, release recency, maintenance signals, and the dependency-decision read. Package Health is an agent skill from mohitagw15856/pm-claude-skills. Check a package's health before you depend on it — npm and PyPI registry APIs via keyless curl: downloads, release recency, maintenance signals, and the dependency-decision read.

When should I use Package Health?

Package Health fits situations like: asked is this npm package maintained; check this PyPI library before we adopt it; compare these two packages; is this dependency abandoned.

How do I install Package Health in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill package-health -a claude-code`. Or copy the skill folder (skills/package-health in mohitagw15856/pm-claude-skills) into .claude/skills/package-health in your project. Claude Code loads it when a task matches its description.

How do I install Package Health in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill package-health -a codex`. Or copy the skill folder (skills/package-health in mohitagw15856/pm-claude-skills) into .agents/skills/package-health in your project. Codex loads it when a task matches its description.

Can I use Package Health in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill package-health -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/package-health, .gemini/skills/package-health, .github/skills/package-health and .opencode/skills/package-health in your project.

What does Package Health need to run?

Going by SKILL.md and its folder, Package Health needs the command-line tools its instructions call (curl).

Does Package Health access the network?

SKILL.md names 4 domains. In commands or code: registry.npmjs.org, api.npmjs.org, pypi.org and pypistats.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Package Health safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Package Health use?

Package Health is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Package Health use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Package Health?

Skills that share tags, products or a category with Package Health: Defuddle (kepano/obsidian-skills, 49k stars), Vercel Deploy (bytedance/deer-flow, 84k stars), Knap Markdown Templates (kepano/obsidian-skills, 49k stars) and MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Package Health?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.