Agent skill

Update npm Packages

by PowerShell in PowerShell/vscode-powershell

Guide for updating NPM dependencies in vscode-powershell. An agent skill from PowerShell/vscode-powershell.

MITAuto-check: warningsDevelopment

Install Update npm Packages

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add PowerShell/vscode-powershell --skill update-npm-packages -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PowerShell/vscode-powershell update-npm-packages --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PowerShell/vscode-powershell.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/update-npm-packages .claude/skills/update-npm-packages && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-npm-packages
GitHub stars
1.9k
Token cost
~350 tokens
SKILL.md length
141 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Guide for updating NPM dependencies in vscode-powershell. An agent skill from PowerShell/vscode-powershell.

  • Asked to update packages
  • Calls npm
  • Fix vulnerabilities
  • Bump dependency versions

What it does

Update npm Packages is an agent skill from PowerShell/vscode-powershell. Guide for updating NPM dependencies in vscode-powershell. Use when asked to update packages, fix vulnerabilities, or bump dependency versions.

Its SKILL.md is about 350 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Linting and formatting. It works with npm, PowerShell, Visual Studio Code and ESLint. The repository describes itself as: Provides PowerShell language and debugging support for Visual Studio Code. The licence is MIT.

When your agent uses it

  • Asked to update packages
  • Fix vulnerabilities
  • Bump dependency versions

Example prompts

  • “/update-npm-packages”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 9c59338. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update npm Packages loads about 350 tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~350

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:20
    - The `.npmrc` uses an Azure Artifacts mirror; read its comments for authentication instructions.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PowerShell/vscode-powershell at commit 9c59338, republished under its MIT licence (© PowerShell). 141 words, ~350 tokens.

Download SKILL.mdSave it as .claude/skills/update-npm-packages/SKILL.md (or your agent's skills folder).
name
update-npm-packages
description
Guide for updating NPM dependencies in vscode-powershell. Use when asked to update packages, fix vulnerabilities, or bump dependency versions.

Updating NPM Packages

Read docs/development.md "Tracking Upstream Dependencies" section for full context.

Rules

  • Dependencies are split into three groups:
    • dependencies — runtime packages bundled into the extension
    • devDependencies — build tools only (minimum for Azure DevOps pipeline)
    • optionalDependencies — lint, type-checking, and test tools (for development and GitHub Actions)
  • Always use npm install --include=optional to get all three groups.
  • The .npmrc uses an Azure Artifacts mirror; read its comments for authentication instructions.
  • When updating engines.vscode follow the "Tracking Upstream Dependencies" section of docs/development.md.
  • Update the ESLint packages (eslint, @eslint/js, typescript-eslint, eslint-config-prettier) together and fix any new lint warnings.
  • After updating, verify: npm run compile, npm run lint, npm audit.
  • For vulnerabilities in transitive dependencies identified by npm audit, add an overrides entry in package.json rather than using npm audit fix --force which may downgrade our packages.
  • Check that each overrides entry is still necessary.

© PowerShell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/update-npm-packages of PowerShell/vscode-powershell.

Open the folder on GitHubat commit 9c59338

Compare with similar skills

Update npm Packages next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update npm Packages compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update npm Packages this skillPowerShell/vscode-powershell1.9k—~350Automated safety check: WarnMIT
Create Saleor Packagesaleor/apps162—~608Automated safety check: PassCustom licence
Prepare Rslint npm Releaseweb-infra-dev/rslint460—~1.5kAutomated safety check: PassMIT
Igniteui Angular LintingIgniteUI/igniteui-angular599—~614Automated safety check: PassCustom licence
Antfuoyjt/uniapp-vue3-template627—~1.3kAutomated safety check: PassMIT
TypescriptLiberatedPixelCup/Universal-LPC-Spritesheet-Character-Generator1.8k—~1.5kAutomated safety check: PassGPL-3.0

Similar skills

  • Scaffold a new shared package in the saleor-apps monorepo under ./packages/.

    162 GitHub stars~608 tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Prepare Rslint npm Release

    web-infra-dev/rslint

    Prepare a stable release PR for the unified rslint npm packages by updating package versions and rule/TypeScript release metadata.

    460 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Igniteui Angular Linting

    IgniteUI/igniteui-angular

    Quick-reference for linting the core Ignite UI for Angular library.

    599 GitHub stars~614 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Antfu

    oyjt/uniapp-vue3-template

    Anthony Fu's {Opinionated} preferences and best practices for web development

    627 GitHub stars~1.3k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Typescript

    LiberatedPixelCup/Universal-LPC-Spritesheet-Character-Generator

    Write TypeScript that satisfies this repo's lint and tsconfig rules, and convert an existing .js file to .ts without breaking its call sites.

    1.8k GitHub stars~1.5k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Typescript Style

    tjx666/vscode-mcp

    TypeScript code style and repo conventions for VSCode MCP — inference vs explicit types, ESM import suffixes, zod schema contracts, async VSCode/Node APIs, JSON-safe IPC results, JSDoc for public…

    106 GitHub stars~961 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from PowerShell/vscode-powershell

  • Interactive Extension Testing

    PowerShell/vscode-powershell

    Guide for setting up the multi-root PowerShell VS Code extension/PSES dev workspace.

    1.9k GitHub stars~824 tokensUpdated 1 mo ago
    Auto-check passed
  • Release

    PowerShell/vscode-powershell

    Guide for preparing a release of the PowerShell VS Code extension.

    1.9k GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Update npm Packages

What does Update npm Packages do?

Guide for updating NPM dependencies in vscode-powershell. An agent skill from PowerShell/vscode-powershell. Update npm Packages is an agent skill from PowerShell/vscode-powershell. Guide for updating NPM dependencies in vscode-powershell.

When should I use Update npm Packages?

Update npm Packages fits situations like: asked to update packages; fix vulnerabilities; bump dependency versions.

How do I install Update npm Packages in Claude Code?

Run `npx skills add PowerShell/vscode-powershell --skill update-npm-packages -a claude-code`. Or copy the skill folder (.github/skills/update-npm-packages in PowerShell/vscode-powershell) into .claude/skills/update-npm-packages in your project. Claude Code loads it when a task matches its description.

How do I install Update npm Packages in Codex?

Run `npx skills add PowerShell/vscode-powershell --skill update-npm-packages -a codex`. Or copy the skill folder (.github/skills/update-npm-packages in PowerShell/vscode-powershell) into .agents/skills/update-npm-packages in your project. Codex loads it when a task matches its description.

Can I use Update npm Packages in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PowerShell/vscode-powershell --skill update-npm-packages -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-npm-packages, .gemini/skills/update-npm-packages, .github/skills/update-npm-packages and .opencode/skills/update-npm-packages in your project.

What does Update npm Packages need to run?

Going by SKILL.md and its folder, Update npm Packages needs the command-line tools its instructions call (npm). Our summary lists: Node.js.

Does Update npm Packages access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update npm Packages safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Update npm Packages use?

Update npm Packages is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update npm Packages use?

About 350 tokens (SKILL.md is roughly 1.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update npm Packages?

Skills that share tags, products or a category with Update npm Packages: Create Saleor Package (saleor/apps, 162 stars), Prepare Rslint npm Release (web-infra-dev/rslint, 460 stars), Igniteui Angular Linting (IgniteUI/igniteui-angular, 599 stars) and Antfu (oyjt/uniapp-vue3-template, 627 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update npm Packages?

PowerShell (a GitHub organization) maintains it in PowerShell/vscode-powershell, which has 1,912 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on August 21, 2026.

Source: PowerShell/vscode-powershell on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.