Agent skill

Verdaccio Change Implementation

by verdaccio in verdaccio/verdaccio

A workflow for implementing a Verdaccio bug fix, feature or refactor: pick the release lines, check existing options, edit the owning layer, test and add a changeset.

MITAuto-check passedDevelopment

Install Verdaccio Change Implementation

skills CLI
$ npx skills add verdaccio/verdaccio --skill implement-change -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install verdaccio/verdaccio implement-change --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/implement-change .claude/skills/implement-change && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implement-change
GitHub stars
18k
Token cost
~1.3k tokens
SKILL.md length
702 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

A workflow for implementing a Verdaccio bug fix, feature or refactor: pick the release lines, check existing options, edit the owning layer, test and add a changeset.

  • Fixing a bug in the Verdaccio registry
  • SKILL.md covers Understand the problem before…, Put it in the owning layer, Reuse before you write and Implement and validate
  • Calls pnpm and npm
  • Adding a feature to Verdaccio, or deciding whether existing config already covers it

What it does

The skill starts with understanding rather than coding. The agent establishes success criteria from the request, issue or reproduction, and for a bug reproduces it first by building with `pnpm build`, starting a registry and running the reporter's client command against it. It then decides which release lines are involved: a feature lands on `master` only, while a bug fix goes to `master` first and then to `6.x` or `8.x` where the code path exists, with any pending port noted in the PR.

Before adding code it checks whether configuration, package-access rules, uplink options, bundled plugins, middleware, filter plugins or web UI settings already solve the problem, in which case the deliverable may be an explanation or a docs change. Anything a package manager observes counts as a contract, so status codes, headers, packument fields, tarball URLs and auth flows are compared with registry.npmjs.org and the npm CLI, with an end-to-end matrix covering npm, pnpm, yarn, bun and deno. Changes go into the layer that owns them, reuse existing helpers, and finish with tests and a changeset, tied to the repository's testing-changes, review-code and pull-requests skills.

When your agent uses it

  • Fixing a bug in the Verdaccio registry
  • Adding a feature to Verdaccio, or deciding whether existing config already covers it
  • Deciding which release lines a fix should be ported to
  • Changing registry status codes, headers or auth behavior that npm clients depend on

Example prompts

  • “Fix the uplink timeout bug from this issue and port it to the supported release lines.”
  • “A user wants per-group publish limits; check whether Verdaccio's access rules already cover it.”
  • “Refactor the store's uplink merge logic and add tests and a changeset.”

Requirements

  • A checkout of the verdaccio repository
  • pnpm to build and start a test registry

What it can do on your machine

Read from SKILL.md and the folder at commit 2d3bcca. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verdaccio Change Implementation loads about 1.3k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 702 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from verdaccio/verdaccio at commit 2d3bcca, republished under its MIT licence (© verdaccio). 702 words, ~1,345 tokens.

Download SKILL.mdSave it as .claude/skills/implement-change/SKILL.md (or your agent's skills folder).
name
implement-change
description
Implement a verdaccio bug fix, feature, or refactor — establish the affected release lines, check whether existing configuration, package-access rules, plugins, or uplink options already solve it, put the change in the layer that owns it, reuse existing helpers, add tests and a changeset, and validate. Use when asked to implement a change in this repository.

Implement a change

Apply AGENTS.md. Keep repository policy there; this skill connects implementation to the testing-changes, review-code, and pull-requests workflows.

Understand the problem before adding code

Establish the intended behaviour and concrete success criteria from the request, the issue, or the reproduction. For a bug, reproduce it first when practical: pnpm build, start a registry (pnpm start, or node packages/verdaccio/bin/verdaccio --config <yaml> --listen 4873), and run the client command from the report against it. A reporter's npm install symptom is a registry route plus a client expectation; find both.

Decide which release lines the work concerns:

  • A feature lands on master only.
  • A bug fix lands on every supported line that has the bug: master first, then a port to 6.x (binary) and/or 8.x (internal modules 6.x consumes). Check whether the code path exists there before promising a port, and say in the PR when it is pending.

Check whether Verdaccio can already do it. Configuration (packages/config/src/conf/default.yaml documents the keys), package-access rules (access/publish/unpublish with groups), uplink options (maxage, timeout, fail_timeout, cache, auth), bundled plugins, middleware and filter plugins, and the web UI settings cover a lot. If an existing capability fully solves the request, the deliverable is an explanation and possibly a documentation change; if it partly solves it, extend the owning feature rather than adding a parallel one. Respect an explicitly requested behaviour that nothing existing provides.

Anything a package manager observes is a contract. Before changing a status code, header, packument field, tarball URL, or auth flow, check what registry.npmjs.org and the npm CLI (npm/cli) do, and remember the e2e matrix runs npm, pnpm, yarn modern (3 and 4), bun, and deno.

Put it in the owning layer

Trace the request through the layers before editing: api/web (routing, status, response shape) → store (local versus uplink merge, filters, stage) → local-storage or the storage plugin (files) and proxy (uplink HTTP); auth for identity and access; config for parsing and defaults; core for pure helpers.

Ask where the behaviour belongs, which abstraction it extends, and what else observes it: a validation added only in an api route leaves the web UI and every plugin exposed; a change in store affects every storage plugin. Changes to interfaces in @verdaccio/types break third-party plugins and are major. Prefer a coherent extension over a local workaround, and keep refactoring bounded to the change.

Show full SKILL.md (314 more words)Show less

Reuse before you write

Search packages/core/core/src/*-utils.ts, @verdaccio/config, the store lib helpers, and @verdaccio/test-helper before writing a helper. If the logic exists but is not exported, export or move it and update the callers. Preserve meaningful differences; do not force unrelated behaviour into one generic function because it looks similar. Prefer a maintained package to a hand-rolled parser or escaper, added to the narrowest package that needs it (and older than the workspace's seven-day release-age rule).

Implement and validate

Implement the smallest cohesive change that meets the success criteria. Follow the conventions in AGENTS.md: errorUtils and HTTP_STATUS for errors, the package logger instead of console, streams for tarballs, import.meta.dirname, minimal comments, no swallowed errors.

Add tests that prove the observable contract at the right level: a unit test for a helper, a packages/api integration test for a route, a nocked uplink for store and proxy behaviour, and an e2e scenario only for client wiring. A bug fix ships with a regression test that fails without it.

Add one changeset for the PR, naming every published package it touches (patch for fixes, minor for features, major for breaking config, plugin, or HTTP contract changes), written as a release note without exploit detail. Update docs/migrations-guide.md for breaking changes and docs/warnings.md for a new warning code.

Rebuild the packages you touched, then use testing-changes to run their tests, their dependents' tests, and the client-facing suites the change can affect. Investigate every failure. Then review the complete diff with review-code, fix the verified findings, and rerun the checks the fixes touch.

Report what changed, what existing capability was considered and why it was not enough, the reuse or extraction chosen, the release lines covered and the ports still pending, and exactly what was validated. Commit, push, or open a PR only when the user or the calling workflow authorises it; use pull-requests when taking the change through a PR.

© verdaccio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/implement-change of verdaccio/verdaccio.

Open the folder on GitHubat commit 2d3bcca

Compare with similar skills

Verdaccio Change Implementation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verdaccio Change Implementation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verdaccio Change Implementation this skillverdaccio/verdaccio18k—~1.3kAutomated safety check: PassMIT
Qwen Code ClawQwenLM/qwen-code28k—~2kAutomated safety check: PassApache-2.0
Update Depsviclafouch/meme-studio110—~2.6kAutomated safety check: PassNone
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
Link Workspace Packagesnomcopter/react-mosaic4.8k5 repos~760Automated safety check: PassCustom licence
AO Desktop App LauncherOrchestratorInc/agent-orchestrator13k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Qwen Code Claw

    QwenLM/qwen-code

    Hands coding work such as codebase questions, bug fixes, refactors and PR reviews to the Qwen Code CLI, driven through acpx instead of scraped terminal sessions.

    28k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Update Deps

    viclafouch/meme-studio

    Audit all outdated dependencies with detailed research on changelogs, breaking changes, bug fixes, and deprecations.

    110 GitHub stars~2.6k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 5 repos~760 tokens
    DevelopmentAuto-check passed
  • AO Desktop App Launcher

    OrchestratorInc/agent-orchestrator

    Launches, restarts and troubleshoots the real AO Electron desktop app from a checkout, with isolated or real local data and checks for stale processes.

    13k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Run the tests that cover a change in the pnpm repository, in the Rust workspace (pnpm/, pnpr/) or the TypeScript CLI (pnpm11/), and recognize the cases where a scoped run passes without testing…

    37k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed

More from verdaccio/verdaccio

All 8 skills in this repo
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Verdaccio PR Review

    verdaccio/verdaccio

    Reviews an existing verdaccio/verdaccio pull request end to end, verifies each finding and reports whether it is mergeable, optionally fixing it on the PR branch.

    18k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Verdaccio Issue Triage

    verdaccio/verdaccio

    Triages an incoming verdaccio/verdaccio issue against the code, the affected release line and related issues, and picks labels from the repository's existing taxonomy.

    18k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated today
    Auto-check passed
  • Figures out which rebuild and test suites actually cover a change in the verdaccio monorepo, instead of a scoped run that passes untested.

    18k GitHub stars~1.6k tokensUpdated today
    Auto-check: warnings
  • Verdaccio Plugin Maintenance

    verdaccio/verdaccio

    Maintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems.

    18k GitHub stars~3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Verdaccio Change Implementation

What does Verdaccio Change Implementation do?

A workflow for implementing a Verdaccio bug fix, feature or refactor: pick the release lines, check existing options, edit the owning layer, test and add a changeset. The skill starts with understanding rather than coding. The agent establishes success criteria from the request, issue or reproduction, and for a bug reproduces it first by building with `pnpm build`, starting a registry and running the reporter's client command against it.

When should I use Verdaccio Change Implementation?

Verdaccio Change Implementation fits situations like: fixing a bug in the Verdaccio registry; adding a feature to Verdaccio, or deciding whether existing config already covers it; deciding which release lines a fix should be ported to; changing registry status codes, headers or auth behavior that npm clients depend on.

How do I install Verdaccio Change Implementation in Claude Code?

Run `npx skills add verdaccio/verdaccio --skill implement-change -a claude-code`. Or copy the skill folder (.agents/skills/implement-change in verdaccio/verdaccio) into .claude/skills/implement-change in your project. Claude Code loads it when a task matches its description.

How do I install Verdaccio Change Implementation in Codex?

Run `npx skills add verdaccio/verdaccio --skill implement-change -a codex`. Or copy the skill folder (.agents/skills/implement-change in verdaccio/verdaccio) into .agents/skills/implement-change in your project. Codex loads it when a task matches its description.

Can I use Verdaccio Change Implementation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add verdaccio/verdaccio --skill implement-change -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implement-change, .gemini/skills/implement-change, .github/skills/implement-change and .opencode/skills/implement-change in your project.

What does Verdaccio Change Implementation need to run?

Going by SKILL.md and its folder, Verdaccio Change Implementation needs the command-line tools its instructions call (pnpm and npm). Our summary lists: A checkout of the verdaccio repository; pnpm to build and start a test registry.

Does Verdaccio Change Implementation access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Verdaccio Change Implementation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verdaccio Change Implementation use?

Verdaccio Change Implementation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verdaccio Change Implementation use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verdaccio Change Implementation?

Skills that share tags, products or a category with Verdaccio Change Implementation: Qwen Code Claw (QwenLM/qwen-code, 28k stars), Update Deps (viclafouch/meme-studio, 110 stars), Devcontainer Dev (stacklok/toolhive-studio, 170 stars) and Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verdaccio Change Implementation?

verdaccio (a GitHub organization) maintains it in verdaccio/verdaccio, which has 17,913 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: verdaccio/verdaccio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.