Agent skill

npm Trusted Publishing

by pr-pm in pr-pm/prpm

A skill your agent uses when setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC, provenance attestations, and monorepo configuration

MITAuto-check passedDevOps & Cloud

Install npm Trusted Publishing

skills CLI
$ npx skills add pr-pm/prpm --skill npm-trusted-publishing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pr-pm/prpm npm-trusted-publishing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pr-pm/prpm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/npm-trusted-publishing .claude/skills/npm-trusted-publishing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
npm-trusted-publishing
GitHub stars
122
Token cost
~781 tokens
SKILL.md length
207 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC, provenance attestations, and monorepo configuration

  • Works in 3 steps: GitHub Actions Workflow → package.json Repository Field → npmjs.com Configuration
  • Setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC
  • SKILL.md covers Overview, When to Use, Quick Reference and Implementation, plus 3 more sections
  • Calls npm; reaches github.com and registry.npmjs.org; needs NPM_TOKEN and NODE_AUTH_TOKEN

What it does

npm Trusted Publishing is an agent skill from pr-pm/prpm. Use when setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC, provenance attestations, and monorepo configuration

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD, OAuth and OpenID Connect and Monorepo tooling. It works with npm and GitHub Actions. The repository describes itself as: The universal registry for AI coding tools. The licence is MIT.

When your agent uses it

  • Setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC
  • Provenance attestations
  • Monorepo configuration

Example prompts

  • “/npm-trusted-publishing”

Requirements

  • Node.js
  • A credential in NPM_TOKEN
  • A credential in NODE_AUTH_TOKEN

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. GitHub Actions Workflow
  2. package.json Repository Field
  3. npmjs.com Configuration

What it can do on your machine

Read from SKILL.md and the folder at commit 5f993e6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • registry.npmjs.org

    Also links to:

    • docs.npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN
    • NODE_AUTH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

npm Trusted Publishing loads about 781 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 207 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~781

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pr-pm/prpm at commit 5f993e6, republished under its MIT licence (© pr-pm). 207 words, ~781 tokens.

Download SKILL.mdSave it as .claude/skills/npm-trusted-publishing/SKILL.md (or your agent's skills folder).
name
npm-trusted-publishing
description
Use when setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC, provenance attestations, and monorepo configuration

NPM Trusted Publishing

Overview

Set up secure npm publishing from GitHub Actions using OIDC trusted publishing instead of long-lived NPM_TOKEN secrets.

When to Use

  • Setting up npm publish workflow in GitHub Actions
  • Migrating from NPM_TOKEN to trusted publishing
  • Adding provenance attestations to packages
  • Publishing monorepo packages

Quick Reference

RequirementImplementation
GitHub Actions permissionid-token: write
package.json fieldrepository.url matching GitHub repo
npm publish flag--provenance
npmjs.com setupConfigure trusted publisher per package

Implementation

1. GitHub Actions Workflow
yaml
permissions:
  contents: write
  id-token: write  # Required for OIDC

jobs:
  publish:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - uses: actions/setup-node@v4
        with:
          node-version: "20"
          registry-url: "https://registry.npmjs.org"

      - run: npm ci
      - run: npm run build

      # No NODE_AUTH_TOKEN needed - uses OIDC
      - run: npm publish --access public --provenance
2. package.json Repository Field
json
{
  "name": "@scope/package",
  "repository": {
    "type": "git",
    "url": "git+https://github.com/owner/repo.git",
    "directory": "packages/subpackage"
  }
}

Monorepo note: Include directory field for packages not at repo root.

3. npmjs.com Configuration

For each package, go to Settings > Publishing access and add:

  • Repository: owner/repo
  • Workflow: publish.yml (or your workflow filename)
  • Environment: (optional)

Common Mistakes

MistakeFix
Missing --provenance flagAdd to npm publish command
Wrong URL formatUse git+https://github.com/...
Missing id-token: writeAdd to workflow permissions
Forgot npmjs.com setupConfigure trusted publisher in package settings
Using NODE_AUTH_TOKENRemove - OIDC handles auth
Outdated npm versionAdd npm install -g npm@latest step (see below)

npm Version Requirement

GitHub Actions runners may have an outdated npm version that doesn't properly support OIDC trusted publishing. This causes a confusing error:

npm notice Access token expired or revoked. Please try logging in again.
npm error code E404
npm error 404 Not Found - PUT https://registry.npmjs.org/@scope%2fpackage - Not found

Solution: Update npm to latest before publishing:

yaml
- uses: actions/setup-node@v4
  with:
    node-version: "20"
    registry-url: "https://registry.npmjs.org"

- name: Update npm to latest
  run: npm install -g npm@latest

- run: npm publish --access public --provenance

See GitHub Community Discussion #173102 for details.

Reference

© pr-pm, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/npm-trusted-publishing of pr-pm/prpm.

Open the folder on GitHubat commit 5f993e6

Compare with similar skills

npm Trusted Publishing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

npm Trusted Publishing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
npm Trusted Publishing this skillpr-pm/prpm122—~781Automated safety check: PassMIT
Automate npm Releasejd-solanki/slidev-theme-dracula161—~626Automated safety check: PassNone
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
ReleaseWebMCP-org/npm-packages104—~1.6kAutomated safety check: NotesMIT
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
npm Release Via GitHub Actionsjmfederico/pi-web869—~2.9kAutomated safety check: PassMIT

Similar skills

  • Automate npm Release

    jd-solanki/slidev-theme-dracula

    Automate npm package publishing via GitHub Actions for single-package repos and independent monorepo packages, including bumpp version tags, GitHub release notes, trusted publishing, provenance, and…

    161 GitHub stars~626 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Release

    WebMCP-org/npm-packages

    Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

    104 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…

    869 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Publish

    code-yeongyu/oh-my-openagent

    Publish oh-my-opencode to npm by triggering the GitHub Actions publish workflow and verifying its artifacts.

    70k GitHub stars~5.5k tokensUpdated today
    DevOps & CloudAuto-check: warnings

More from pr-pm/prpm

All 35 skills in this repo
  • Reference for writing Claude Code agent files: location, frontmatter fields, validation limits, tool and model choices, and the required content format.

    122 GitHub starsUsed in 2 repos~4k tokens
    Auto-check passed
  • Covers how to build, configure and publish Claude Code hooks: event types, exit codes, JSON I/O, and PRPM packaging.

    122 GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check: notes
  • Shows how to write .claude/rules/ files correctly: paths frontmatter instead of globs, quoted glob patterns, global rules and conversion of Cursor rules.

    122 GitHub starsUsed in 2 repos~551 tokens
    Auto-check passed
  • Reference for writing portable Agent Skills packages, covering SKILL.md frontmatter limits, name rules, directory layout and where Codex CLI, GitHub Copilot and Amp look for skills.

    122 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • A skill your agent uses when implementing Stripe webhook endpoints and getting 'Raw body not available' or signature verification errors - provides raw body parsing solutions and subscription period…

    122 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Guides writing an agents.md project-context file: plain markdown with no frontmatter, focused on what an AI coding assistant cannot already know.

    122 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed

Questions about npm Trusted Publishing

What does npm Trusted Publishing do?

A skill your agent uses when setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC, provenance attestations, and monorepo configuration. npm Trusted Publishing is an agent skill from pr-pm/prpm.

When should I use npm Trusted Publishing?

npm Trusted Publishing fits situations like: setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC; provenance attestations; monorepo configuration.

How do I install npm Trusted Publishing in Claude Code?

Run `npx skills add pr-pm/prpm --skill npm-trusted-publishing -a claude-code`. Or copy the skill folder (.claude/skills/npm-trusted-publishing in pr-pm/prpm) into .claude/skills/npm-trusted-publishing in your project. Claude Code loads it when a task matches its description.

How do I install npm Trusted Publishing in Codex?

Run `npx skills add pr-pm/prpm --skill npm-trusted-publishing -a codex`. Or copy the skill folder (.claude/skills/npm-trusted-publishing in pr-pm/prpm) into .agents/skills/npm-trusted-publishing in your project. Codex loads it when a task matches its description.

Can I use npm Trusted Publishing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pr-pm/prpm --skill npm-trusted-publishing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm-trusted-publishing, .gemini/skills/npm-trusted-publishing, .github/skills/npm-trusted-publishing and .opencode/skills/npm-trusted-publishing in your project.

What does npm Trusted Publishing need to run?

Going by SKILL.md and its folder, npm Trusted Publishing needs the command-line tools its instructions call (npm) and credentials named NPM_TOKEN and NODE_AUTH_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN; A credential in NODE_AUTH_TOKEN.

Does npm Trusted Publishing access the network?

SKILL.md names 3 domains. In commands or code: github.com and registry.npmjs.org; the agent is likely to contact these when it follows the instructions. As links in the text: docs.npmjs.com. This is read from the text; nothing was executed.

Is npm Trusted Publishing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does npm Trusted Publishing use?

npm Trusted Publishing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does npm Trusted Publishing use?

About 781 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to npm Trusted Publishing?

Skills that share tags, products or a category with npm Trusted Publishing: Automate npm Release (jd-solanki/slidev-theme-dracula, 161 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Release (WebMCP-org/npm-packages, 104 stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains npm Trusted Publishing?

pr-pm (a GitHub organization) maintains it in pr-pm/prpm, which has 122 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 6, 2026.

Source: pr-pm/prpm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.