Agent skill

Generate Package Skill

by skilld-dev in skilld-dev/skilld

Generate or update an Agent Skill that teaches consumers one npm or local package the user maintains, including framework modules and wrappers.

MITAuto-check passedDevelopment

Install Generate Package Skill

skills CLI
$ npx skills add skilld-dev/skilld --skill generate-package-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install skilld-dev/skilld generate-package-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/skilld-dev/skilld.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/generate-package-skill .claude/skills/generate-package-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
generate-package-skill
GitHub stars
315
Token cost
~3.2k tokens
SKILL.md length
1,829 words
Files
4 (incl. scripts, assets)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Generate or update an Agent Skill that teaches consumers one npm or local package the user maintains, including framework modules and wrappers.

  • Works in 4 steps: Research → Test the examples → Write → …
  • A maintainer asks for a package Skill
  • SKILL.md covers Inputs, 1. Research, 2. Test the examples and 3. Write, plus 1 more section
  • Runs JavaScript scripts from its folder; calls npm, node and pnpm; reaches skilld.dev

What it does

Generate Package Skill is an agent skill from skilld-dev/skilld. Generate or update an Agent Skill that teaches consumers one npm or local package the user maintains, including framework modules and wrappers. Tests each example against the installed version. Use when a maintainer asks for a package Skill, a SKILL.md for their library, or a Skill update after a release.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and assets (for example `assets/harness-request.md`).

It sits in Development. It works with npm. The repository describes itself as: Open-source, privacy friendly skills.sh alternative for humans and agents. The licence is MIT.

When your agent uses it

  • A maintainer asks for a package Skill
  • A SKILL.md for their library
  • A Skill update after a release

Example prompts

  • “/generate-package-skill”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Research
  2. Test the examples
  3. Write
  4. Check and report

What it can do on your machine

Read from SKILL.md and the folder at commit 5797f37. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • node
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • skilld.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Generate Package Skill loads about 3.2k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 1,829 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from skilld-dev/skilld at commit 5797f37, republished under its MIT licence (© skilld-dev). 1,829 words, ~3,188 tokens.

Download SKILL.mdSave it as .claude/skills/generate-package-skill/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
generate-package-skill
description
Generate or update an Agent Skill that teaches consumers one npm or local package the user maintains, including framework modules and wrappers. Tests each example against the installed version. Use when a maintainer asks for a package Skill, a SKILL.md for their library, or a Skill update after a release.

Generate a package Skill

Write a short Skill that stops an Agent from misusing one package version. The reader knows the language, the framework, and the domain. Write only what it would get wrong.

Inputs

Take a package name, directory, or prepared source. Ask for the destination only when it is missing. In a monorepo, put the Skill in the published package directory. Write one Skill per installed package, unless a second package has distinct users. Skip an internal package, whose users are the repository's own packages, such as a shared engine or types package. Report why, and write nothing. assets/ holds the Harness request. A direct run ignores it.

1. Research

  1. Record the exact version the destination branch publishes: its package.json version and the npm dist-tag that carries it. If npm latest is an older major, test the branch's version. If the branch is ahead of its last release, read source at that release tag and report the unreleased changes.
  2. Read the manifest, every exported entry point, and the public types. For many sibling integrations, read the shared runtime and the most used few, and report which you sampled.
  3. For a framework module, read what setup registers: auto-imports, components, the config key and defaults, hooks, server routes.
  4. If the package wraps, re-exports, or peers on another package, read the types or tagged source of the version the consumer gets, never a default branch.
  5. Read the current official docs and examples, and release notes only for breaking changes and removed APIs. When docs cover several frameworks, read the consumer's framework pages first, then the core pages they link.

To update an existing Skill after a release, use update-package-skill. It tests only what the release changed.

2. Test the examples

Observed behaviour beats documentation.

  1. Create a minimal consumer fixture outside the package source. Install the recorded version, or link the local build. Before packing, build the package and its native code (NAPI, WASM); prepack can need them. Pack with the repository's package manager: npm pack leaves pnpm catalog: versions. Give the fixture its own pnpm-workspace.yaml, so a parent workspace cannot satisfy its imports. Install only the package, documented peers, and check tools such as typescript. A resolution error is a finding. Install each peer at npm latest. If latest is outside the peer range, test both versions.
  2. Use consumer defaults. The package repository's config and fixtures can turn them off. In Nuxt, keep test modules out of modules/; Nuxt registers every module there. One fixture page can exercise many examples.
  3. Run each example you include. Compare output with the claim: HTML, return values, type errors, build logs, exit codes, report files. Each concrete claim in prose is an example too: a value, count, default, result shape, error text, exit code, or bundle effect. Run it, or report it read from source. Run each example with one failure input as well, such as an unreachable URL, a bad token, or a stalled request. Run each example under each global setting the Skill describes, such as a staging environment or a site-wide switch. For each claim that a setting or dependency is required, run once without it and record what fails. Test each mode the package declares: framework modes (SSR, SPA, streaming, dev, build), each condition in exports, the oldest runtime in engines, and each CLI binary with a config file and with flags. Report other modes untested. Wrap every run in timeout 120. Grep the package for agent and CI detection, such as CLAUDECODE or CI; unset each variable it reads with env -u VAR. Read dev warnings in the dev log, prerender results in build output, and runtime results from the production server. If a trap says nothing happens, run it and confirm the silence. To fetch from a server, run scripts/serve-fixture.mjs in the fixture: node SKILL_DIR/scripts/serve-fixture.mjs --fetch / -- node .output/server/index.mjs. Quote '{port}' in a server argument, since some shells expand it. --header 'User-Agent: Googlebot/2.1' sends a header, Host included. For a binary, use --fetch-raw PATH --out DIR. DIR/responses.json lists each status, content type, and response headers. For an HTTP client package, start a fake target on port 0 inside the test, and assert on the requests it receives. Without --fetch, it holds the server until SIGTERM. Background it with your tool's option; & and nohup die with the shell call. Start servers from your own test script and record each process ID you start; stop only those. Never kill by port or with pkill -f: another Agent can own that process. In a browser, set a desktop user agent; a package can treat HeadlessChrome as a bot.
  4. If documentation and behaviour disagree, write the behaviour and report the mismatch.
  5. Keep an unrunnable example only when the types prove it; report it untested.

Do not fix the package or its docs in the Skill change.

3. Write

Include:

  • Setup that differs from the framework default, such as a required config key.
  • What the package does automatically, and how to turn it off.
  • Traps: silent failures, plausible wrong calls, documentation mismatches, version limits.
  • One small example per common task the types do not make obvious.
  • Breaking changes an Agent trained on an older version would repeat: old call, new call.
  • A deploy section, such as CI cache or Cloudflare, when most traps live there.

Cut:

  • Self-explanatory config options; link the config reference. Keep a table when values are the API, such as priorities.
  • Internals the consumer cannot act on, such as tree shaking.
  • Changelog paraphrase, fixed bugs, release history.
  • Generic debug advice, such as "view source" or public validators.
  • path:line citations. Put evidence in the report.
  • Any second copy of content, such as a list repeating inline reference links.

Shape:

  • Name the package and tested version in the first paragraph, not the frontmatter.
  • Order, dropping empty sections: setup, automatic behaviour, common tasks, integrations, traps, version limits, config, debug.
  • A config example that is a common task goes there; the config section only lists options.
  • Write each code block as a complete file with the imports the framework accepts. Start it with a path comment, such as // server/api/search.ts, so it can be extracted.
  • Write the tested version once, in the first paragraph. Other version literals, such as a User-Agent string, go stale.
  • A trap detailed in a reference gets one linking line in traps.
  • Aim for 150 lines and about 2,000 tokens in SKILL.md. Never exceed 500 lines. Past the aim, keep silent failures before loud ones and common-path traps before rare ones. Merge traps that share a fix. Cut a common-task example before a trap.
  • Keep one file. Move a topic to references/<topic>.md only past about 40 lines and when under a third of tasks need it.
  • Link each reference from SKILL.md, one level deep. A reference over 100 lines starts with contents.
  • Write at most eight reference files. Add scripts/ only when running code beats reading it.
  • Skillgen maintains only SKILL.md and Markdown under references/: at most 9 files and 64 KiB in total. It never updates scripts/.
  • Never include credentials, caches, build output, or dependency directories.

The frontmatter contains only name and description. The name uses lowercase letters, numbers, and single hyphens, at most 64 characters, and matches the directory. For a scoped package, drop the @ and replace / with a hyphen: @nuxtjs/seo becomes nuxtjs-seo. The description, at most 1024 characters in third person, says what the Skill does, then when to use it, in the words a user types: package name, main exports, config key, error symptoms. Write it as one plain line of 300 to 450 characters. Skill loaders parse frontmatter with different YAML parsers, so use no double quotes, backticks, or %. Name an error symptom in plain words, never as a quoted message. Good: Adds and debugs Schema.org JSON-LD in Nuxt with nuxt-schema-org. Use when a task mentions structured data, rich results, useSchemaOrg, defineArticle, or the schemaOrg config key.

Show full SKILL.md (510 more words)Show less

4. Check and report

Cross-Agent portability

Keep one source Skill for compatible Agents. Keep their discovery paths outside the generated Skill. Use capability descriptions instead of provider-specific tool names. Ask for inputs explicitly; do not depend on $ARGUMENTS, hooks, or dynamic context injection. Resolve bundled files from the Skill directory and consumer commands from the consumer project root. Name script runtimes, binaries, network access, and credential requirements beside their use. If a required capability is unavailable, report it and stop that dependent step. Never invent evidence or silently skip a required check.

Check a matching task, an unrelated task, and a missing-input task. When available, use a fresh session in each Agent the user asks to support. If the user names no Agent, validate the format with skilld run SKILL_DIR --json and expect _tag: Success. Test the current Agent if it can start a fresh session. Record its version, model, task, output, and required permissions. Distinguish format validation, discovery, activation, and task completion. Report unavailable Agent paths untested. Package example checks do not prove cross-Agent execution.

Before finishing, extract every block with scripts/extract-blocks.mjs: node SKILL_DIR/scripts/extract-blocks.mjs SKILL.md DIR. Copy each block into the fixture and run it unchanged. Never test a copy you edited by hand. Repeat after each edit. --replace https://example.com=http://localhost:PORT swaps a placeholder. DIR/blocks.json maps each block to its line.

Confirm:

  • Each example ran against the recorded version, or is reported untested.
  • Each reference is linked. Delete stale files from an earlier Skill.
  • The frontmatter follows the rules above, parses with a strict YAML parser, and skilld run SKILL_DIR --json returns _tag: Success. Fix each failure before you finish.

Report to the user:

  • The files and the tested version.
  • Each untested example, and each mismatch: example, documented result, observed result. These are package bugs. Draft them as one issue for the package Repository, ordered by impact: silent wrong results, crashes, doc mismatches, cleanups. Give each item expected, observed, a minimal repro with its output, and a source link at the release tag. File it only if asked.
  • The source path or documentation URL behind each version-specific rule.
  • If the Skill sits inside the published package directory, add its directory to files in package.json. After one build, list packed files with npm pack --dry-run --ignore-scripts; pnpm pack rejects that flag.
  • Edit the README beside the Skill's package.json. If it already links the skilld.dev page, keep that link. Else add the badge below after the others. Replace a skilld add tip that names this package in place with the tip below. Else add the tip after the install command. Replace OWNER, REPOSITORY, and PACKAGE. Count every SKILL.md in the Repository, hidden Agent folders included; the skilld.dev indexer skips test and fixture folders. If it holds several Skills, append /SKILL_NAME to the page and badge paths. The README omits the run command; the page shows it.
html
<a href="https://skilld.dev/gh/OWNER/REPOSITORY">
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://skilld.dev/b/OWNER/REPOSITORY?theme=dark">
    <source media="(prefers-color-scheme: light)" srcset="https://skilld.dev/b/OWNER/REPOSITORY?theme=light">
    <img alt="Skill repository on skilld.dev" src="https://skilld.dev/b/OWNER/REPOSITORY?theme=light">
  </picture>
</a>
md
> [!TIP]
> Using an AI agent? Get the PACKAGE Skill on [skilld.dev/gh/OWNER/REPOSITORY](https://skilld.dev/gh/OWNER/REPOSITORY).

For a direct run, show the files for review, or open a pull request if asked. Replace an existing Skill only with user approval. A direct run has no Harness checks; never claim it passed them.

© skilld-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, assets) in skills/generate-package-skill of skilld-dev/skilld.

  • SKILL.md
  • assets/harness-request.md
  • scripts/extract-blocks.mjs
  • scripts/serve-fixture.mjs

Open the folder on GitHubat commit 5797f37

Compare with similar skills

Generate Package Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Generate Package Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Generate Package Skill this skillskilld-dev/skilld315—~3.2kAutomated safety check: PassMIT
Nx Run Tasksnomcopter/react-mosaic4.8k7 repos~613Automated safety check: PassCustom licence
Get API Docs with chubandrewyng/context-hub14k2 repos~775Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0

Similar skills

  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 7 repos~613 tokens
    DevelopmentAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 2 repos~775 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Looks up current documentation and code examples for any library, framework, SDK or CLI with the Context7 ctx7 command instead of relying on training data.

    1.5k GitHub starsUsed in 3 repos~1.6k tokens
    DevelopmentAuto-check passed

More from skilld-dev/skilld

  • Update Package Skill

    skilld-dev/skilld

    Updates an existing package Skill for a new release of its npm or local package by testing only what changed since the version the Skill names.

    315 GitHub stars~992 tokensUpdated today
    Auto-check passed
  • Skilld

    skilld-dev/skilld

    Operate skilld CLI for Skill discovery, use, installation, inspection, updates, authentication, configuration, restoration, and removal, including Repository, curator, and collection refs.

    315 GitHub stars~5.3k tokensUpdated today
    Auto-check passed
  • Review Skill

    skilld-dev/skilld

    Review an Agent Skill for valid structure, clear triggers, usable instructions, current evidence, and risky or unclear actions.

    315 GitHub stars~648 tokensUpdated today
    Auto-check passed
  • Generate Project Skill

    skilld-dev/skilld

    Generate or update an Agent Skill from the observed workflows, boundaries, and conventions of one software project.

    315 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Generate Package Skill

What does Generate Package Skill do?

Generate or update an Agent Skill that teaches consumers one npm or local package the user maintains, including framework modules and wrappers. Generate Package Skill is an agent skill from skilld-dev/skilld. Generate or update an Agent Skill that teaches consumers one npm or local package the user maintains, including framework modules and wrappers.

When should I use Generate Package Skill?

Generate Package Skill fits situations like: A maintainer asks for a package Skill; A SKILL.md for their library; A Skill update after a release.

How do I install Generate Package Skill in Claude Code?

Run `npx skills add skilld-dev/skilld --skill generate-package-skill -a claude-code`. Or copy the skill folder (skills/generate-package-skill in skilld-dev/skilld) into .claude/skills/generate-package-skill in your project. Claude Code loads it when a task matches its description.

How do I install Generate Package Skill in Codex?

Run `npx skills add skilld-dev/skilld --skill generate-package-skill -a codex`. Or copy the skill folder (skills/generate-package-skill in skilld-dev/skilld) into .agents/skills/generate-package-skill in your project. Codex loads it when a task matches its description.

Can I use Generate Package Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add skilld-dev/skilld --skill generate-package-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generate-package-skill, .gemini/skills/generate-package-skill, .github/skills/generate-package-skill and .opencode/skills/generate-package-skill in your project.

What does Generate Package Skill need to run?

Going by SKILL.md and its folder, Generate Package Skill needs JavaScript for the scripts in its folder and the command-line tools its instructions call (npm, node and pnpm). Our summary lists: Node.js.

Does Generate Package Skill access the network?

SKILL.md names 1 domain. In commands or code: skilld.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Generate Package Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Generate Package Skill use?

Generate Package Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Generate Package Skill use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Generate Package Skill?

Skills that share tags, products or a category with Generate Package Skill: Nx Run Tasks (nomcopter/react-mosaic, 4.8k stars), Get API Docs with chub (andrewyng/context-hub, 14k stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars) and Open Code Review CLI (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Generate Package Skill?

skilld-dev (a GitHub organization) maintains it in skilld-dev/skilld, which has 315 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 7, 2026.

Source: skilld-dev/skilld on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.