Agent skill

npm Registry Operations

by steipete in steipete/agent-scripts

Handles npm registry tasks such as whoami checks, package name availability, name reservation and publishing, with credentials pulled from 1Password.

MITAuto-check passedDevOps & Cloud

Install npm Registry Operations

skills CLI
$ npx skills add steipete/agent-scripts --skill npm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install steipete/agent-scripts npm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/npm .claude/skills/npm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
npm
GitHub stars
7.3k
Token cost
~1.1k tokens
SKILL.md length
532 words
Files
11 (incl. scripts)
Skills in repo
45
Repo updated
First seen
Licence
MIT

At a glance

Handles npm registry tasks such as whoami checks, package name availability, name reservation and publishing, with credentials pulled from 1Password.

  • Confirming which npm account the agent is logged in as
  • SKILL.md covers Auth, Package Publishing, Package Reservation and Offline Regression Tests
  • Runs JavaScript and Shell scripts from its folder; calls npm; needs OP_SERVICE_ACCOUNT_TOKEN
  • Checking whether a package name is available, or reserving it

What it does

The skill covers account and registry work: checking who is logged in, seeing whether a package name is free, reserving names, publishing, checking organizations and debugging authentication. It ships shell and Node helpers, including npm-auth.sh, npm-auth-login.mjs, npm-service.sh for ad-hoc authenticated npm commands, publish-package.sh for a local package and reserve-packages.sh.

Credentials come from 1Password, and the agent is told never to run op directly in the shell tool. A stored registry session is tried first, with a registry login using a fresh one-time code as the fallback, and successful fallback sessions are cached back to the same item. Work happens in a shared tmux window with a temporary npmrc that is deleted afterward. The agent stops and asks if the item is missing, the vault is ambiguous or npm denies access.

The excerpt names a specific 1Password item and vault belonging to the author, so you would point it at your own item. It also relies on a separate one-password skill for secret handling.

When your agent uses it

  • Confirming which npm account the agent is logged in as
  • Checking whether a package name is available, or reserving it
  • Publishing a local package to the npm registry with stored credentials
  • Debugging a failed npm login or denied package access

Example prompts

  • “Check whether the package name fastgrid is free on npm and reserve it if so.”
  • “Publish the package in ./packages/cli to npm using the stored registry session.”
  • “npm publish says I have no access to this package, so debug the auth.”

Requirements

  • npm and Node.js
  • A 1Password service account token (OP_SERVICE_ACCOUNT_TOKEN)
  • tmux
  • The one-password skill

What it can do on your machine

Read from SKILL.md and the folder at commit 79150cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 10 files in scripts/ (JavaScript and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OP_SERVICE_ACCOUNT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

npm Registry Operations loads about 1.1k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 532 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from steipete/agent-scripts at commit 79150cf, republished under its MIT licence (© steipete). 532 words, ~1,132 tokens.

Download SKILL.mdSave it as .claude/skills/npm/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
npm
description
npm registry ops: login, whoami, names, publish; 1Password tmux.

npm

Use for npm registry/account tasks: npm whoami, package availability, package reservation, publish, org checks, and auth debugging.

Auth

  • Use one-password first for secret rules.
  • Never run op directly in the shell tool.
  • Primary item: npm Registry - steipete - Release Automation in Molty.
  • Default to OP_SERVICE_ACCOUNT_TOKEN; no desktop unlock. The item carries the working registry session (registry_token) plus username/password/TOTP fallback.
  • Desktop npmjs fallback is explicit only: pass --account my.1password.com when Molty is unavailable and the user wants the fallback. Explicit release/publish requests are consent for its unlock prompt.
  • Stop and ask if the item is missing, the account/vault is ambiguous, credentials are malformed, npm denies package access, or the requested package/version does not match the repo release target.
  • Run npm auth work inside one task window of the shared op-work tmux session (clawdbot-op.sock; see one-password). Reuse the window on failure; kill it when the npm task is done. Never mint an npm-specific socket or session.
  • Keep npm auth in a temp npmrc; delete it after the command.
  • All helpers share scripts/npm-auth.sh: stored registry_token session first, then scripts/npm-auth-login.mjs registry login with a fresh six-digit OTP; successful fallback sessions are cached back to the same item. Do not hand-roll field extraction, registry login, or cache writes.
  • Installed skill directory symlinks are supported. Shell entrypoints resolve physical siblings; sourced npm-auth.sh owns NPM_AUTH_SCRIPT_DIR without changing the caller's SCRIPT_DIR or working directory. Node helpers also support file symlinks, including --preserve-symlinks-main.
  • Credential selection prefers canonical field id, then purpose, then a unique label; duplicate label-only matches are rejected (legacy npmjs may retain same-label fields).
  • For ad-hoc authenticated registry commands, use scripts/npm-service.sh -- <npm args...>; use publish-package.sh for a local package.
  • npm 11 prompt piping is brittle; avoid printf ... | npm login --auth-type=legacy.
  • Avoid expect for npm login unless necessary; logs can echo prompts and are easy to get wrong.
  • Prefer the helper's registry API login path (npm-profile loginCouch) for automation.
  • If auth shape is ambiguous or npm whoami fails, stop and ask for the exact field label / credential fix. Do not probe more 1Password items or open another tmux window/session.
Show full SKILL.md (191 more words)Show less

Package Publishing

From the package root, inside the same auth tmux window:

bash
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/publish-package.sh

The helper verifies identity, refuses an existing package version, publishes with a fresh OTP, retries one expired OTP, verifies registry visibility, and cleans auth files.

Package Reservation

Use scripts/reserve-packages.sh from inside the same tmux window:

bash
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/reserve-packages.sh package-one package-two

What it does:

  • reads the Molty release-automation item once via op
  • reuses the stored registry session or creates one from username/password/TOTP
  • publishes 0.0.0 placeholder packages with a generic README
  • continues after per-package publish failures
  • redacts tokens/OTP in logs
  • cleans temp npmrc/work dirs

Notes:

  • npm may reject names as too similar to already-published names. Treat that as a registry policy result, not an auth failure.
  • npm CLI prompt piping is brittle on npm 11. Prefer the helper’s registry API login path over scripted npm login.
  • For scoped packages, npm view can lag/404 even when the package exists. Check npm access get status <pkg>; public or a publish failure saying previously published versions means the name is reserved.

Offline Regression Tests

From the repo root; synthetic fixtures only, no real 1Password/npm auth. Always use an empty environment (the shell mock checks its environment for token leaks):

bash
test_home="$(mktemp -d)"
(
  set -e
  trap 'rm -rf "$test_home"' EXIT
  env -i HOME="$test_home" PATH="$PATH" node --test skills/npm/scripts/*.test.mjs </dev/null
  env -i HOME="$test_home" PATH="$PATH" /bin/bash skills/npm/scripts/npm-auth.test.sh </dev/null
)

© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts) in skills/npm of steipete/agent-scripts.

  • SKILL.md
  • scripts/npm-auth-cache.mjs
  • scripts/npm-auth-cache.test.mjs
  • scripts/npm-auth-login.mjs
  • scripts/npm-auth-login.test.mjs
  • scripts/npm-auth.sh
  • scripts/npm-auth.test.sh
  • scripts/npm-cli-test-helpers.mjs
  • scripts/npm-service.sh
  • scripts/publish-package.sh
  • scripts/reserve-packages.sh

Open the folder on GitHubat commit 79150cf

Compare with similar skills

npm Registry Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

npm Registry Operations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
npm Registry Operations this skillsteipete/agent-scripts7.3k—~1.1kAutomated safety check: PassMIT
Publish UI Package Releasecline/cline70k—~1.4kAutomated safety check: PassApache-2.0
Releasepaperclipai/paperclip99k—~2.4kAutomated safety check: PassMIT
ClickUp CLI Release Processkrodak/clickup-cli121—~906Automated safety check: WarnMIT
Azure Data FactoryMicrosoftDocs/Agent-Skills7771 repos~16kAutomated safety check: PassCC-BY-4.0
Azure Data Science VmMicrosoftDocs/Agent-Skills777—~1.8kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Validates and publishes the standalone @cline/ui npm package through its own release workflow, separate from the Cline SDK runtime packages.

    70k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release

    paperclipai/paperclip

    Coordinate a full Paperclip release across engineering verification, npm, GitHub, smoke testing, and announcement follow-up.

    99k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • ClickUp CLI Release Process

    krodak/clickup-cli

    Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.

    121 GitHub stars~906 tokensUpdated 2 days ago
    DevOps & CloudAuto-check: warnings
  • Azure Data Factory

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Data Factory development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations…

    777 GitHub starsUsed in 1 repo~16k tokens
    DevOps & CloudAuto-check passed
  • Azure Data Science Vm

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Data Science Virtual Machines development including troubleshooting, decision making, architecture & design patterns, security, configuration, integrations & coding…

    777 GitHub stars~1.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Azure Devtest Labs

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure DevTest Labs development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations…

    777 GitHub stars~3.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from steipete/agent-scripts

All 45 skills in this repo
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated 4 days ago
    Auto-check passed
  • Agent Transcript for PRs

    steipete/agent-scripts

    Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.

    7.3k GitHub starsUsed in 1 repo~698 tokens
    Auto-check passed
  • Parallels macOS VM Lab

    steipete/agent-scripts

    Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.

    7.3k GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • ClawSweeper Status

    steipete/agent-scripts

    Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.

    7.3k GitHub stars~972 tokensUpdated 4 days ago
    Auto-check passed
  • GitHub Project Triage

    steipete/agent-scripts

    Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.

    7.3k GitHub stars~4k tokensUpdated 4 days ago
    Auto-check passed
  • Nano Banana Image Generation

    steipete/agent-scripts

    Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.

    7.3k GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about npm Registry Operations

What does npm Registry Operations do?

Handles npm registry tasks such as whoami checks, package name availability, name reservation and publishing, with credentials pulled from 1Password. The skill covers account and registry work: checking who is logged in, seeing whether a package name is free, reserving names, publishing, checking organizations and debugging authentication.sh.

When should I use npm Registry Operations?

npm Registry Operations fits situations like: confirming which npm account the agent is logged in as; checking whether a package name is available, or reserving it; publishing a local package to the npm registry with stored credentials; debugging a failed npm login or denied package access.

How do I install npm Registry Operations in Claude Code?

Run `npx skills add steipete/agent-scripts --skill npm -a claude-code`. Or copy the skill folder (skills/npm in steipete/agent-scripts) into .claude/skills/npm in your project. Claude Code loads it when a task matches its description.

How do I install npm Registry Operations in Codex?

Run `npx skills add steipete/agent-scripts --skill npm -a codex`. Or copy the skill folder (skills/npm in steipete/agent-scripts) into .agents/skills/npm in your project. Codex loads it when a task matches its description.

Can I use npm Registry Operations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill npm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm, .gemini/skills/npm, .github/skills/npm and .opencode/skills/npm in your project.

What does npm Registry Operations need to run?

Going by SKILL.md and its folder, npm Registry Operations needs JavaScript and a shell for the scripts in its folder, the command-line tools its instructions call (npm) and credentials named OP_SERVICE_ACCOUNT_TOKEN. Our summary lists: npm and Node.js; A 1Password service account token (OP_SERVICE_ACCOUNT_TOKEN); tmux; The one-password skill.

Does npm Registry Operations access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is npm Registry Operations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does npm Registry Operations use?

npm Registry Operations is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does npm Registry Operations use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to npm Registry Operations?

Skills that share tags, products or a category with npm Registry Operations: Publish UI Package Release (cline/cline, 70k stars), Release (paperclipai/paperclip, 99k stars), ClickUp CLI Release Process (krodak/clickup-cli, 121 stars) and Azure Data Factory (MicrosoftDocs/Agent-Skills, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains npm Registry Operations?

steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,273 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 4, 2026.

Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.