Agent skill

Verdaccio Plugin Maintenance

by verdaccio in verdaccio/verdaccio

Maintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems.

MITAuto-check passedDevelopment

Install Verdaccio Plugin Maintenance

skills CLI
$ npx skills add verdaccio/verdaccio --skill plugins -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install verdaccio/verdaccio plugins --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/plugins .claude/skills/plugins && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugins
GitHub stars
18k
Token cost
~3k tokens
SKILL.md length
1,295 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Maintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems.

  • Works in 6 steps: Reproduce with the plugin's own tests… → Fix in the plugin, not by special-casing… → Tests: unit tests instantiate the class… → …
  • Fixing a bug in a bundled Verdaccio plugin
  • SKILL.md covers New plugins are not accepted…, The bundled plugins, The contracts and How plugins load, plus 3 more sections
  • Calls pnpm, npm and node; needs BAD_USERNAME_PASSWORD

What it does

The repository ships a small set of bundled plugins (htpasswd, local-storage, auth-memory, memory, audit, package-filter and ui-theme) and owns the contracts that third-party plugins implement. The work is maintenance: fixing bundled plugins, keeping the `pluginUtils` interfaces stable, making sure plugins load and verifying them with `@verdaccio/plugin-verifier`. A table lists each package with its path, category and role, such as htpasswd as the default auth and local-storage as the default storage.

New bundled plugins are not accepted without an accepted discussion thread in the repository's GitHub Discussions, Ideas category. The agent looks for that discussion first, and without one it reports what the thread should argue: the problem, why configuration and existing plugins fall short, and the maintenance cost. New third-party plugins live in their own repositories, and the skill points people to the website docs for the auth, storage, middleware, filter and theme plugin types. The excerpt is cut off in the plugin table.

When your agent uses it

  • Fixing a bug in a bundled Verdaccio plugin
  • Changing a pluginUtils interface without breaking plugins
  • Diagnosing why a plugin does not load
  • Handling a request to add a new bundled plugin

Example prompts

  • “The htpasswd plugin rejects valid users after a config change, find and fix the bug.”
  • “Why does my custom auth plugin fail to load? Check it with the plugin verifier.”
  • “Someone asked for a new bundled plugin, so what do I need to tell them?”

Requirements

  • A checkout of the Verdaccio repository
  • `@verdaccio/plugin-verifier` for verifying plugins

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Reproduce with the plugin's own tests (pnpm --filter test) or a config that
  2. Fix in the plugin, not by special-casing it in store, auth, or server: a bundled
  3. Tests: unit tests instantiate the class with a config object and a fake logger (see
  4. Rebuild the plugin before testing anything that consumes it (build/ is what other
  5. One changeset for the PR, naming the plugin package (and @verdaccio/core when a
  6. Port to 6.x/8.x when the bug exists there; the plugin sources differ between

What it can do on your machine

Read from SKILL.md and the folder at commit 2d3bcca. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • verdaccio.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BAD_USERNAME_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verdaccio Plugin Maintenance loads about 3k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,295 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from verdaccio/verdaccio at commit 2d3bcca, republished under its MIT licence (© verdaccio). 1,295 words, ~3,004 tokens.

Download SKILL.mdSave it as .claude/skills/plugins/SKILL.md (or your agent's skills folder).
name
plugins
description
Maintain the plugins bundled in this repository (htpasswd, local-storage, auth-memory, memory, audit, package-filter, ui-theme) and the plugin contracts in @verdaccio/core — fix a bundled plugin, change a pluginUtils interface safely, diagnose why a plugin does not load, or verify a plugin with @verdaccio/plugin-verifier. Use when a task touches packages/plugins, packages/loaders, pluginUtils, or a plugin loading problem. Requests to add a new bundled plugin are gated on an accepted discussion thread; this skill says how to handle them.

Plugins

This repository ships a small set of bundled plugins and owns the contracts every third-party plugin implements. The work here is maintenance: fixing the bundled plugins, keeping the contracts stable, and making sure plugins load. Writing a new plugin is not repository work.

New plugins are not accepted without a discussion first

A PR that adds a new bundled plugin under packages/plugins is not accepted unless an accepted discussion thread exists for it in the repository's GitHub Discussions (https://github.com/verdaccio/verdaccio/discussions, category Ideas). The discussion settles whether the capability belongs in core, in a bundled plugin, or in an external package, and who maintains it. When asked to add a bundled plugin:

  • Look for the discussion and read the maintainers' conclusion. Without one, do not start the PR; report that the change needs a discussion thread first and what it should argue (the problem, why configuration and existing plugins do not cover it, the maintenance cost).
  • With an accepted discussion, link it from the PR body and follow "Adding a bundled plugin" below.

New third-party plugins live in their own repositories, outside this one. Point people to the website docs (https://verdaccio.org/docs/plugins and the plugin-auth, plugin-storage, plugin-middleware, plugin-filter, plugin-theme pages); the contracts below are the same, and @verdaccio/plugin-verifier checks the result. The scaffolding tools for external plugins are not used in this repository.

The bundled plugins

PackagePathCategoryNotes
verdaccio-htpasswdpackages/plugins/htpasswdauthenticationDefault auth in default.yaml; file resolved relative to configPath
@verdaccio/local-storagepackages/plugins/local-storagestorageDefault storage; the production reference for StorageHandler
verdaccio-auth-memorypackages/plugins/auth-memoryauthenticationSmallest complete auth plugin; the reference for the auth chain
verdaccio-memorypackages/plugins/memorystorageIn-memory storage used by tests; smallest complete storage plugin
verdaccio-auditpackages/plugins/auditmiddlewarenpm audit proxy; loaded by default when no middleware is configured
@verdaccio/package-filterpackages/plugins/package-filterfilterRegistered under its scoped name in filters:
@verdaccio/ui-themepackages/plugins/ui-themethemeThe default web UI; consumed as a published dependency by every line

packages/tools/verdaccio-*-fake-plugin are test fixtures for the loader, not plugins to maintain.

The contracts

The interfaces live in packages/core/core/src/plugin-utils.ts (pluginUtils), the shared types in @verdaccio/types. Every plugin extends pluginUtils.Plugin<Config> and is constructed as (pluginConfig, { config, logger }).

CategoryConfig sectionInterfaceSanity check (loader refuses the plugin without it)
authenticationauth:Auth<Config>one of authenticate, allow_access, allow_publish
storagestore:Storage<Config> + StorageHandlergetPackageStorage
middlewaremiddlewares:ExpressMiddleware<Config, Storage, Auth>register_middlewares
filterfilters:ManifestFilter<Config>filter_metadata
themetheme:object with staticPath, manifest, manifestFilesall three properties

Changing a contract is a breaking change for every third-party plugin. Adding an optional method (as allow_stage was added) is backwards compatible; renaming, removing, changing a signature, or turning a callback into a promise is major: it needs a major changeset, an entry in docs/migrations-guide.md, the bundled plugins updated in the same PR, and a look at the external plugins the organisation maintains (verdaccio-aws-s3-storage, verdaccio-google-cloud, verdaccio-azure, verdaccio-auth-ldap, ...) so they can be ported. The loader's sanity checks in plugin-utils.ts are part of the contract too.

Semantics the bundled plugins rely on and that a fix must preserve:

  • Auth chain. Plugins run in config order; authenticate answers cb(null, groups) on success, cb(null, false) to let the next plugin try, and a VerdaccioError (errorUtils.getUnauthorized(API_ERROR.BAD_USERNAME_PASSWORD)) to stop. The allow_* methods honour $all, $anonymous, $authenticated, and the user's groups exactly as auth-memory does; a change there alters package-access rules for every deployment.
  • Storage. StorageHandler is promise-based; readTarball/writeTarball return Node streams and receive an AbortSignal; writes are atomic and fail-safe; updatePackage(name, async manifest => manifest) serialises concurrent updates to the same manifest; a failed writeTarball leaves nothing behind. Only one storage plugin is used (the first loaded, with a warning).
  • Middleware. register_middlewares(app, auth, storage) mounts routes on the Express app; protect them with auth.apiJWTmiddleware() rather than parsing tokens. audit is the default when middlewares: is empty.
  • Filter. filter_metadata(manifest) returns a new manifest and runs on every packument read; package-filter shows the versions/time/dist-tags/_distfiles cleanup that must stay consistent.
  • Theme. A factory returning { staticPath, manifest, manifestFiles: { js, css } }; only the first theme is used.

How plugins load

asyncLoadPlugin in packages/loaders/src/plugin-async-loader.ts is the only loader, used by auth, store (storage and filters), server/express (middleware) and web (theme), and by @verdaccio/plugin-verifier:

  • Key foo resolves to package verdaccio-foo (verdaccio-theme-foo for themes); server.pluginPrefix replaces the prefix. A scoped key is used verbatim.
  • With plugins: ./plugins in the config, <plugins dir>/<package name> is tried first (relative to the config file, so configPath must be set), then Node resolution from node_modules.
  • The export is a default class (new plugin.default(config, options)) or a CJS factory function. require() is tried first, import() second; the entry point for a folder is read from exports['.'], then module, then main.
  • A plugin that fails the category's sanity check is logged and skipped; the registry keeps starting. A throwing constructor is only guaranteed to be caught this way when loaded from a configured plugins: folder (that path wraps executePlugin in a try/catch); the npm-resolved (node_modules) path calls executePlugin unguarded, so a throwing constructor there currently propagates out of asyncLoadPlugin instead of being skipped — a known loader gap, not a guarantee.

Loader changes are tested in packages/loaders/test and through every bundled plugin's plugin-load.spec.ts; run both.

Show full SKILL.md (458 more words)Show less

Diagnosing "plugin not loaded"

Run the verifier first: verdaccio-plugin-verifier <key> --category <category> [--plugins-folder <abs path>] [--prefix <prefix>], or verifyPlugin({ pluginPath, category, pluginsFolder, prefix, pluginConfig, configPath }) from @verdaccio/plugin-verifier. Its diagnostics name the failing phase: resolve, export, instantiate, or sanity-check. Then check, in order: the key-to-name mapping and pluginPrefix, the plugins: folder versus node_modules resolution, the export shape, a throwing constructor or a missing dependency of the plugin, and the sanity check. The loader logs package not found for resolution problems, error loading plugin for constructor and dependency errors, and doesn't look like a valid plugin for a sanity failure; DEBUG=verdaccio:plugin:* verdaccio prints every step.

A "plugin not loaded" report from a user is usually one of these, not a loader bug; triage it against this list before opening the loader.

Fixing a bundled plugin

  1. Reproduce with the plugin's own tests (pnpm --filter <pkg> test) or a config that registers it, started with node packages/verdaccio/bin/verdaccio --config <yaml>.
  2. Fix in the plugin, not by special-casing it in store, auth, or server: a bundled plugin gets no privilege a third-party plugin cannot have.
  3. Tests: unit tests instantiate the class with a config object and a fake logger (see packages/plugins/auth-memory/test/index.spec.ts; new Config(getDefaultConfig()) from @verdaccio/config for the app config), and every bundled plugin keeps a plugin-load.spec.ts through verifyPlugin. Auth and middleware changes get an integration test through initializeServer from @verdaccio/test-helper; storage changes run the store tests and the e2e CLI battery (./scripts/e2e-cli-local.sh npm@11).
  4. Rebuild the plugin before testing anything that consumes it (build/ is what other packages import), then follow the testing-changes skill.
  5. One changeset for the PR, naming the plugin package (and @verdaccio/core when a contract moved). htpasswd, audit, and package-filter are dependencies of the verdaccio package and ship with every release; ui-theme is in the fixed version group.
  6. Port to 6.x/8.x when the bug exists there; the plugin sources differ between lines, so re-run that line's tests rather than cherry-picking blindly.

Plugin configuration is not validated by core: a plugin validates its own section in the constructor and fails there with a clear message, never on the first request, and it does not read process.env for what belongs in the YAML. Never log credentials, debug output included.

Adding a bundled plugin (only with an accepted discussion)

Mirror packages/plugins/auth-memory: vite.config.mjs calling createLibConfig from the root vite.lib.config.mjs, tsconfig.json and tsconfig.build.json extending the base, package.json with build/watch/test/clean scripts and exports pointing at build/, @verdaccio/core as a workspace: dependency, a types.ts for the plugin's config, a README with the config snippet. Then add the folder to pnpm-workspace.yaml, pnpm install, build it, register it where the discussion decided (default.yaml, packages/verdaccio/package.json), add the unit and plugin-load.spec.ts tests, a minor changeset for the new package, and link the discussion from the PR body.

© verdaccio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/plugins of verdaccio/verdaccio.

Open the folder on GitHubat commit 2d3bcca

Compare with similar skills

Verdaccio Plugin Maintenance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verdaccio Plugin Maintenance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verdaccio Plugin Maintenance this skillverdaccio/verdaccio18k—~3kAutomated safety check: PassMIT
Lerdliberusoftware/real-estate-laravel112—~7.8kAutomated safety check: WarnMIT
EasyEDA Pro API Bridgeeasyeda/easyeda-api-skill855—~7.8kAutomated safety check: PassMIT
Aube Package Manager Helperaubepkg/aube2k—~1.1kAutomated safety check: WarnMIT
Nodejs CLI Best Practiceslirantal/nodejs-cli-apps-best-practices4.1k—~2kAutomated safety check: PassCC-BY-SA-4.0
Dep Auditorlaolaoshiren/claude-code-skills-zh877—~895Automated safety check: PassMIT

Similar skills

  • Lerd

    liberusoftware/real-estate-laravel

    Manage the lerd local PHP development environment via MCP tools: run framework console commands (artisan, bin/console, etc.), manage services, start/stop queue workers, run composer, manage Node.js…

    112 GitHub stars~7.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check: warnings
  • EasyEDA Pro API Bridge

    easyeda/easyeda-api-skill

    Gives an agent the EasyEDA Pro API reference and a WebSocket bridge to run code in a live EasyEDA client, for PCB, schematic and library work and extension development.

    855 GitHub stars~7.8k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.

    2k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Nodejs CLI Best Practices

    lirantal/nodejs-cli-apps-best-practices

    Guide and audit Node.js CLI application development against 41 established best practices covering UX, distribution, interoperability, accessibility, testing, error handling, development setup…

    4.1k GitHub stars~2k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    877 GitHub stars~895 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Swpm Code Review

    deinsoftware/swpm

    Automated code review bash script for SWPM. An agent skill from deinsoftware/swpm.

    125 GitHub stars~1.1k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed

More from verdaccio/verdaccio

All 8 skills in this repo
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Verdaccio PR Review

    verdaccio/verdaccio

    Reviews an existing verdaccio/verdaccio pull request end to end, verifies each finding and reports whether it is mergeable, optionally fixing it on the PR branch.

    18k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Verdaccio Issue Triage

    verdaccio/verdaccio

    Triages an incoming verdaccio/verdaccio issue against the code, the affected release line and related issues, and picks labels from the repository's existing taxonomy.

    18k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated today
    Auto-check passed
  • Figures out which rebuild and test suites actually cover a change in the verdaccio monorepo, instead of a scoped run that passes untested.

    18k GitHub stars~1.6k tokensUpdated today
    Auto-check: warnings
  • A workflow for implementing a Verdaccio bug fix, feature or refactor: pick the release lines, check existing options, edit the owning layer, test and add a changeset.

    18k GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Works with

Questions about Verdaccio Plugin Maintenance

What does Verdaccio Plugin Maintenance do?

Maintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems. The repository ships a small set of bundled plugins (htpasswd, local-storage, auth-memory, memory, audit, package-filter and ui-theme) and owns the contracts that third-party plugins implement. The work is maintenance: fixing bundled plugins, keeping the `pluginUtils` interfaces stable, making sure plugins load and verifying them with `@verdaccio/plugin-verifier`.

When should I use Verdaccio Plugin Maintenance?

Verdaccio Plugin Maintenance fits situations like: fixing a bug in a bundled Verdaccio plugin; changing a pluginUtils interface without breaking plugins; diagnosing why a plugin does not load; handling a request to add a new bundled plugin.

How do I install Verdaccio Plugin Maintenance in Claude Code?

Run `npx skills add verdaccio/verdaccio --skill plugins -a claude-code`. Or copy the skill folder (.agents/skills/plugins in verdaccio/verdaccio) into .claude/skills/plugins in your project. Claude Code loads it when a task matches its description.

How do I install Verdaccio Plugin Maintenance in Codex?

Run `npx skills add verdaccio/verdaccio --skill plugins -a codex`. Or copy the skill folder (.agents/skills/plugins in verdaccio/verdaccio) into .agents/skills/plugins in your project. Codex loads it when a task matches its description.

Can I use Verdaccio Plugin Maintenance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add verdaccio/verdaccio --skill plugins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugins, .gemini/skills/plugins, .github/skills/plugins and .opencode/skills/plugins in your project.

What does Verdaccio Plugin Maintenance need to run?

Going by SKILL.md and its folder, Verdaccio Plugin Maintenance needs the command-line tools its instructions call (pnpm, npm and node) and credentials named BAD_USERNAME_PASSWORD. Our summary lists: A checkout of the Verdaccio repository; `@verdaccio/plugin-verifier` for verifying plugins.

Does Verdaccio Plugin Maintenance access the network?

SKILL.md names 1 domain. As links in the text: verdaccio.org. This is read from the text; nothing was executed.

Is Verdaccio Plugin Maintenance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verdaccio Plugin Maintenance use?

Verdaccio Plugin Maintenance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verdaccio Plugin Maintenance use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verdaccio Plugin Maintenance?

Skills that share tags, products or a category with Verdaccio Plugin Maintenance: Lerd (liberusoftware/real-estate-laravel, 112 stars), EasyEDA Pro API Bridge (easyeda/easyeda-api-skill, 855 stars), Aube Package Manager Helper (aubepkg/aube, 2k stars) and Nodejs CLI Best Practices (lirantal/nodejs-cli-apps-best-practices, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verdaccio Plugin Maintenance?

verdaccio (a GitHub organization) maintains it in verdaccio/verdaccio, which has 17,913 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: verdaccio/verdaccio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.