Lerd
liberusoftware/real-estate-laravel
Manage the lerd local PHP development environment via MCP tools: run framework console commands (artisan, bin/console, etc.), manage services, start/stop queue workers, run composer, manage Node.js…
Maintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems.
$ npx skills add verdaccio/verdaccio --skill plugins -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install verdaccio/verdaccio plugins --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/plugins .claude/skills/plugins && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "plugins" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/plugins into .claude/skills/plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugins", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pluginsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add verdaccio/verdaccio --skill plugins -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install verdaccio/verdaccio plugins --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/plugins .agents/skills/plugins && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "plugins" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/plugins into .agents/skills/plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugins", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add verdaccio/verdaccio --skill plugins -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install verdaccio/verdaccio plugins --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/plugins .cursor/skills/plugins && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "plugins" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/plugins into .cursor/skills/plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugins", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/verdaccio/verdaccio.git --path .agents/skills/plugins--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add verdaccio/verdaccio --skill plugins -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install verdaccio/verdaccio plugins --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/plugins .gemini/skills/plugins && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "plugins" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/plugins into .gemini/skills/plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugins", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install verdaccio/verdaccio pluginsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add verdaccio/verdaccio --skill plugins -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/plugins .github/skills/plugins && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "plugins" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/plugins into .github/skills/plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugins", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add verdaccio/verdaccio --skill plugins -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install verdaccio/verdaccio plugins --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/plugins .opencode/skills/plugins && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "plugins" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/plugins into .opencode/skills/plugins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "plugins", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pluginsMaintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems.
The repository ships a small set of bundled plugins (htpasswd, local-storage, auth-memory, memory, audit, package-filter and ui-theme) and owns the contracts that third-party plugins implement. The work is maintenance: fixing bundled plugins, keeping the `pluginUtils` interfaces stable, making sure plugins load and verifying them with `@verdaccio/plugin-verifier`. A table lists each package with its path, category and role, such as htpasswd as the default auth and local-storage as the default storage.
New bundled plugins are not accepted without an accepted discussion thread in the repository's GitHub Discussions, Ideas category. The agent looks for that discussion first, and without one it reports what the thread should argue: the problem, why configuration and existing plugins fall short, and the maintenance cost. New third-party plugins live in their own repositories, and the skill points people to the website docs for the auth, storage, middleware, filter and theme plugin types. The excerpt is cut off in the plugin table.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2d3bcca. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmnpmnodeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
verdaccio.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
BAD_USERNAME_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verdaccio Plugin Maintenance loads about 3k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,295 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from verdaccio/verdaccio at commit 2d3bcca, republished under its MIT licence (© verdaccio). 1,295 words, ~3,004 tokens.
.claude/skills/plugins/SKILL.md (or your agent's skills folder).This repository ships a small set of bundled plugins and owns the contracts every third-party plugin implements. The work here is maintenance: fixing the bundled plugins, keeping the contracts stable, and making sure plugins load. Writing a new plugin is not repository work.
A PR that adds a new bundled plugin under packages/plugins is not accepted unless
an accepted discussion thread exists for it in the repository's GitHub Discussions
(https://github.com/verdaccio/verdaccio/discussions, category Ideas). The
discussion settles whether the capability belongs in core, in a bundled plugin, or in
an external package, and who maintains it. When asked to add a bundled plugin:
New third-party plugins live in their own repositories, outside this one. Point
people to the website docs (https://verdaccio.org/docs/plugins and the plugin-auth,
plugin-storage, plugin-middleware, plugin-filter, plugin-theme pages); the
contracts below are the same, and @verdaccio/plugin-verifier checks the result. The
scaffolding tools for external plugins are not used in this repository.
| Package | Path | Category | Notes |
|---|---|---|---|
verdaccio-htpasswd | packages/plugins/htpasswd | authentication | Default auth in default.yaml; file resolved relative to configPath |
@verdaccio/local-storage | packages/plugins/local-storage | storage | Default storage; the production reference for StorageHandler |
verdaccio-auth-memory | packages/plugins/auth-memory | authentication | Smallest complete auth plugin; the reference for the auth chain |
verdaccio-memory | packages/plugins/memory | storage | In-memory storage used by tests; smallest complete storage plugin |
verdaccio-audit | packages/plugins/audit | middleware | npm audit proxy; loaded by default when no middleware is configured |
@verdaccio/package-filter | packages/plugins/package-filter | filter | Registered under its scoped name in filters: |
@verdaccio/ui-theme | packages/plugins/ui-theme | theme | The default web UI; consumed as a published dependency by every line |
packages/tools/verdaccio-*-fake-plugin are test fixtures for the loader, not plugins
to maintain.
The interfaces live in packages/core/core/src/plugin-utils.ts (pluginUtils), the
shared types in @verdaccio/types. Every plugin extends pluginUtils.Plugin<Config>
and is constructed as (pluginConfig, { config, logger }).
| Category | Config section | Interface | Sanity check (loader refuses the plugin without it) |
|---|---|---|---|
| authentication | auth: | Auth<Config> | one of authenticate, allow_access, allow_publish |
| storage | store: | Storage<Config> + StorageHandler | getPackageStorage |
| middleware | middlewares: | ExpressMiddleware<Config, Storage, Auth> | register_middlewares |
| filter | filters: | ManifestFilter<Config> | filter_metadata |
| theme | theme: | object with staticPath, manifest, manifestFiles | all three properties |
Changing a contract is a breaking change for every third-party plugin. Adding an
optional method (as allow_stage was added) is backwards compatible; renaming,
removing, changing a signature, or turning a callback into a promise is major: it needs
a major changeset, an entry in docs/migrations-guide.md, the bundled plugins updated
in the same PR, and a look at the external plugins the organisation maintains
(verdaccio-aws-s3-storage, verdaccio-google-cloud, verdaccio-azure,
verdaccio-auth-ldap, ...) so they can be ported. The loader's sanity checks in
plugin-utils.ts are part of the contract too.
Semantics the bundled plugins rely on and that a fix must preserve:
authenticate answers cb(null, groups)
on success, cb(null, false) to let the next plugin try, and a VerdaccioError
(errorUtils.getUnauthorized(API_ERROR.BAD_USERNAME_PASSWORD)) to stop. The
allow_* methods honour $all, $anonymous, $authenticated, and the user's
groups exactly as auth-memory does; a change there alters package-access rules for
every deployment.StorageHandler is promise-based; readTarball/writeTarball return
Node streams and receive an AbortSignal; writes are atomic and fail-safe;
updatePackage(name, async manifest => manifest) serialises concurrent updates to
the same manifest; a failed writeTarball leaves nothing behind. Only one storage
plugin is used (the first loaded, with a warning).register_middlewares(app, auth, storage) mounts routes on the
Express app; protect them with auth.apiJWTmiddleware() rather than parsing tokens.
audit is the default when middlewares: is empty.filter_metadata(manifest) returns a new manifest and runs on every
packument read; package-filter shows the versions/time/dist-tags/_distfiles
cleanup that must stay consistent.{ staticPath, manifest, manifestFiles: { js, css } };
only the first theme is used.asyncLoadPlugin in packages/loaders/src/plugin-async-loader.ts is the only loader,
used by auth, store (storage and filters), server/express (middleware) and web
(theme), and by @verdaccio/plugin-verifier:
foo resolves to package verdaccio-foo (verdaccio-theme-foo for themes);
server.pluginPrefix replaces the prefix. A scoped key is used verbatim.plugins: ./plugins in the config, <plugins dir>/<package name> is tried
first (relative to the config file, so configPath must be set), then Node resolution
from node_modules.default class (new plugin.default(config, options)) or a CJS
factory function. require() is tried first, import() second; the entry point for a
folder is read from exports['.'], then module, then main.plugins: folder (that path wraps executePlugin in
a try/catch); the npm-resolved (node_modules) path calls executePlugin
unguarded, so a throwing constructor there currently propagates out of
asyncLoadPlugin instead of being skipped — a known loader gap, not a guarantee.Loader changes are tested in packages/loaders/test and through every bundled plugin's
plugin-load.spec.ts; run both.
Run the verifier first: verdaccio-plugin-verifier <key> --category <category> [--plugins-folder <abs path>] [--prefix <prefix>], or verifyPlugin({ pluginPath, category, pluginsFolder, prefix, pluginConfig, configPath }) from
@verdaccio/plugin-verifier. Its diagnostics name the failing phase: resolve, export,
instantiate, or sanity-check. Then check, in order: the key-to-name mapping and
pluginPrefix, the plugins: folder versus node_modules resolution, the export
shape, a throwing constructor or a missing dependency of the plugin, and the sanity
check. The loader logs package not found for resolution problems, error loading plugin for constructor and dependency errors, and doesn't look like a valid plugin
for a sanity failure; DEBUG=verdaccio:plugin:* verdaccio prints every step.
A "plugin not loaded" report from a user is usually one of these, not a loader bug; triage it against this list before opening the loader.
pnpm --filter <pkg> test) or a config that
registers it, started with node packages/verdaccio/bin/verdaccio --config <yaml>.store, auth, or server: a bundled
plugin gets no privilege a third-party plugin cannot have.packages/plugins/auth-memory/test/index.spec.ts; new Config(getDefaultConfig())
from @verdaccio/config for the app config), and every bundled plugin keeps a
plugin-load.spec.ts through verifyPlugin. Auth and middleware changes get an
integration test through initializeServer from @verdaccio/test-helper; storage
changes run the store tests and the e2e CLI battery
(./scripts/e2e-cli-local.sh npm@11).build/ is what other
packages import), then follow the testing-changes
skill.@verdaccio/core when a
contract moved).
htpasswd, audit, and package-filter are dependencies of the verdaccio package
and ship with every release; ui-theme is in the fixed version group.6.x/8.x when the bug exists there; the plugin sources differ between
lines, so re-run that line's tests rather than cherry-picking blindly.Plugin configuration is not validated by core: a plugin validates its own section in
the constructor and fails there with a clear message, never on the first request, and
it does not read process.env for what belongs in the YAML. Never log credentials,
debug output included.
Mirror packages/plugins/auth-memory: vite.config.mjs calling createLibConfig from
the root vite.lib.config.mjs, tsconfig.json and tsconfig.build.json extending the
base, package.json with build/watch/test/clean scripts and exports pointing
at build/, @verdaccio/core as a workspace: dependency, a types.ts for the
plugin's config, a README with the config snippet. Then add the folder to
pnpm-workspace.yaml, pnpm install, build it, register it where the discussion
decided (default.yaml, packages/verdaccio/package.json), add the unit and
plugin-load.spec.ts tests, a minor changeset for the new package, and link the
discussion from the PR body.
© verdaccio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/plugins of verdaccio/verdaccio.
Open the folder on GitHubat commit 2d3bcca
Verdaccio Plugin Maintenance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verdaccio Plugin Maintenance this skillverdaccio/verdaccio | 18k | — | ~3k | Automated safety check: Pass | MIT | |
| Lerdliberusoftware/real-estate-laravel | 112 | — | ~7.8k | Automated safety check: Warn | MIT | |
| EasyEDA Pro API Bridgeeasyeda/easyeda-api-skill | 855 | — | ~7.8k | Automated safety check: Pass | MIT | |
| Aube Package Manager Helperaubepkg/aube | 2k | — | ~1.1k | Automated safety check: Warn | MIT | |
| Nodejs CLI Best Practiceslirantal/nodejs-cli-apps-best-practices | 4.1k | — | ~2k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 877 | — | ~895 | Automated safety check: Pass | MIT |
liberusoftware/real-estate-laravel
Manage the lerd local PHP development environment via MCP tools: run framework console commands (artisan, bin/console, etc.), manage services, start/stop queue workers, run composer, manage Node.js…
easyeda/easyeda-api-skill
Gives an agent the EasyEDA Pro API reference and a WebSocket bridge to run code in a live EasyEDA client, for PCB, schematic and library work and extension development.
aubepkg/aube
Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.
lirantal/nodejs-cli-apps-best-practices
Guide and audit Node.js CLI application development against 41 established best practices covering UX, distribution, interoperability, accessibility, testing, error handling, development setup…
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
deinsoftware/swpm
Automated code review bash script for SWPM. An agent skill from deinsoftware/swpm.
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
verdaccio/verdaccio
Reviews an existing verdaccio/verdaccio pull request end to end, verifies each finding and reports whether it is mergeable, optionally fixing it on the PR branch.
verdaccio/verdaccio
Triages an incoming verdaccio/verdaccio issue against the code, the affected release line and related issues, and picks labels from the repository's existing taxonomy.
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
verdaccio/verdaccio
Figures out which rebuild and test suites actually cover a change in the verdaccio monorepo, instead of a scoped run that passes untested.
verdaccio/verdaccio
A workflow for implementing a Verdaccio bug fix, feature or refactor: pick the release lines, check existing options, edit the owning layer, test and add a changeset.
Categories
Maintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems. The repository ships a small set of bundled plugins (htpasswd, local-storage, auth-memory, memory, audit, package-filter and ui-theme) and owns the contracts that third-party plugins implement. The work is maintenance: fixing bundled plugins, keeping the `pluginUtils` interfaces stable, making sure plugins load and verifying them with `@verdaccio/plugin-verifier`.
Verdaccio Plugin Maintenance fits situations like: fixing a bug in a bundled Verdaccio plugin; changing a pluginUtils interface without breaking plugins; diagnosing why a plugin does not load; handling a request to add a new bundled plugin.
Run `npx skills add verdaccio/verdaccio --skill plugins -a claude-code`. Or copy the skill folder (.agents/skills/plugins in verdaccio/verdaccio) into .claude/skills/plugins in your project. Claude Code loads it when a task matches its description.
Run `npx skills add verdaccio/verdaccio --skill plugins -a codex`. Or copy the skill folder (.agents/skills/plugins in verdaccio/verdaccio) into .agents/skills/plugins in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add verdaccio/verdaccio --skill plugins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugins, .gemini/skills/plugins, .github/skills/plugins and .opencode/skills/plugins in your project.
Going by SKILL.md and its folder, Verdaccio Plugin Maintenance needs the command-line tools its instructions call (pnpm, npm and node) and credentials named BAD_USERNAME_PASSWORD. Our summary lists: A checkout of the Verdaccio repository; `@verdaccio/plugin-verifier` for verifying plugins.
SKILL.md names 1 domain. As links in the text: verdaccio.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verdaccio Plugin Maintenance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verdaccio Plugin Maintenance: Lerd (liberusoftware/real-estate-laravel, 112 stars), EasyEDA Pro API Bridge (easyeda/easyeda-api-skill, 855 stars), Aube Package Manager Helper (aubepkg/aube, 2k stars) and Nodejs CLI Best Practices (lirantal/nodejs-cli-apps-best-practices, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
verdaccio (a GitHub organization) maintains it in verdaccio/verdaccio, which has 17,913 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.
Source: verdaccio/verdaccio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.