Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. Detects direct AND transitive vulnerabilities, normalizes npm's severity scale (info/low/moderate/ high/critical) to the shared Severity enum, and parses both v1 and v2 audit output formats so the skill works against npm 6 and npm 7+ lockfiles. Use when: pre-merge gate on a Node project, post-incident sweep after a transitive package compromise (e.g. event-stream, ua-parser, node-ipc, color.js), SOC2 vendor-management evidence collection, or auditing an inherited or acquired Node codebase. Threshold: any HIGH or CRITICAL CVE in the resolved dependency tree. MODERATE / LOW reported informationally. Trigger with: "audit npm deps", "npm vulnerability scan", "check node packages for CVEs", "npm audit".
日本語の概要は準備中です。原文の説明を表示しています。
jeremylongshore/tons-of-skills-marketplace☆ 2,8312026年10月11日 更新
modules/npm/packages/ に新しい npm/pnpm パッケージを追加するスキル
rito528/dotfiles☆ 22026年10月10日 更新
sparkle-design(公開 npm パッケージ)の新バージョンをリリースするための手順スキル。 package.json の version bump、CHANGELOG.md の更新、リリース PR 作成、PR マージ後の npm への stage、メンテナーによる 2FA 承認(npm stage approve)、承認後の git tag・ GitHub Release 作成までを一連の手順で実行する。 CHANGELOG 更新漏れと GitHub Release 作成漏れを防ぐためのチェックリストを含む。 「sparkle-design をリリース」「sparkle-design の新バージョンを切る」「vX.Y.Z をリリース」 「sparkle-design の CHANGELOG を更新」で発動。 English: "release sparkle-design", "cut a new sparkle-design version", "publish sparkle-design", "bump sparkle-design version".
goodpatch/sparkle-design☆ 162026年10月2日 更新
Apply npm/pnpm supply-chain hardening when adding a dependency, editing package.json/.npmrc/pnpm-workspace.yaml, reviewing a lockfile change, or configuring CI install steps. Covers the 17 practices from lirantal/npm-security-best-practices.
日本語の概要は準備中です。原文の説明を表示しています。
susomejias/rembric☆ 132026年10月9日 更新
Viteを使う開発で、設定ファイル、環境変数、APIへの接続、プラグイン、ビルド出力を整え、開発サーバーや依存関係の不具合調査を支援するスキル。
- 環境変数と開発用API転送の設定
- 開発サーバーの遅さや更新不良の調査
- 本番用ファイルの最適化と動作確認
affaan-m/ECC☆ 27.7万2026年10月10日 更新
Keep pnpm current: preflight the published package and pnpm/action-setup self-installer, update pnpm locally, align packageManager in package.json, and refresh CI pins. Use this when refreshing the pnpm toolchain manually or in automation.
日本語の概要は準備中です。原文の説明を表示しています。
openai/openai-agents-js☆ 3,9042026年10月10日 更新
MCP設定を読み、承認後も取得するコードが変わり得るパッケージ参照を確認するスキル。サーバーを実行せず、npm・Python・Dockerの指定を分類します。
- MCP設定を承認前に確認したいとき
- latestタグや版の範囲指定の確認
- CIへの再現可能な設定チェックの追加
affaan-m/ECC☆ 27.7万2026年10月10日 更新
新しい機能を実装する前に、既存コードやnpm・PyPIのパッケージ、MCP serversなどを調べます。候補を比較し、採用・拡張・自作の判断につなげるスキルです。
- 機能追加前に既存の解決策を調べたいとき
- 依存パッケージの導入前の比較
- 外部連携に使えるツールの調査
affaan-m/ECC☆ 27.7万2026年10月10日 更新
Bumps `biome` package versions (e.g. `@biomejs/biome`) using `pnpm`, aligns `biome.jsonc` files with the new version/s across the repository and runs biome-related checks. Use when required to update `biome` to a newer version - explicitly or implicitly (e.g. after running `pnpm up`, `pnpm update`, `pnpm upgrade` without specific package names).
日本語の概要は準備中です。原文の説明を表示しています。
prisma/orm☆ 4.8万2026年10月10日 更新
Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and flagging download count anomalies where suspicious packages have disproportionately low usage compared to their legitimate targets. The analyst queries the PyPI JSON API and npm registry API to gather package metadata for automated comparison. Activates for requests involving package typosquatting detection, dependency confusion analysis, malicious package identification, or software supply chain threat hunting in package registries.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
npm package maintenance and lifecycle management for monorepo extensions. Covers health audits, dependency sync, version bumping, changelog updates, pre-publish checks, coordinated publishing, and post-publish verification. **Triggers — use this skill when:** - User asks to "publish", "release", or "version bump" extensions/packages - User says "audit packages", "check package health", "dependency sync" - User asks to "update changelogs", "prepare release", "pre-publish check" - User mentions "npm publish", "version management", "package lifecycle" - User wants to "sync dependencies" or "align versions" across packages - User asks "what needs publishing" or "which packages changed" **Covers:** Monorepo with multiple npm packages under `extensions/`. Each package has its own package.json, CHANGELOG.md, README.md, and version. Packages are scoped (e.g. `@e9n/pi-*`) and published individually.
日本語の概要は準備中です。原文の説明を表示しています。
espennilsen/pi☆ 1222026年9月22日 更新
Turborepo (高速モノレポビルドシステム) リファレンス。 turbo.json、turbo run、タスク依存 (dependsOn)、キャッシュ (local / remote)、 workspaces (pnpm / npm / yarn / bun)、--filter、Remote Cache (Vercel)、 parallel 実行、turbo gen (コード生成)、watch モード、 エラーメッセージ診断 (recursive turbo invocations, missing root task, invalid env prefix)。
Fandhe-AI/agent-reference-skills☆ 42026年10月9日 更新
依存パッケージ(Go modules / npm / Terraform provider / GitHub Actions / pre-commit 等)の アップグレードを、outdated 検出 → CHANGELOG・破壊的変更の確認 → 更新 → lint/test 検証 → コミットまで一連の手順で安全に適用する。「依存更新」「パッケージを上げて」「dependency update」 「go get -u」「npm update」「provider を上げる」等に言及されたときに使用する。
hodanov/my-pde☆ 32026年10月10日 更新
Detects typosquatting attacks in npm and PyPI package registries by analyzing package name similarity using Levenshtein distance and other string metrics, examining publish date heuristics to identify recently created packages mimicking established ones, and flagging download count anomalies where suspicious packages have disproportionately low usage compared to their legitimate targets. The analyst queries the PyPI JSON API and npm registry API to gather package metadata for automated comparison. Activates for requests involving package typosquatting detection, dependency confusion analysis, malicious package identification, or software supply chain threat hunting in package registries.
日本語の概要は準備中です。原文の説明を表示しています。
aniket2348823/Vul-Agent☆ 22026年6月9日 更新
OpenClawのリリース候補に対するCIを実行・監視し、実際のプロバイダー接続やインストール・更新を検証して、失敗の原因と結果を整理するスキルです。
- OpenClawのリリース候補を検証したいとき
- 失敗したCIジョブの調査と再実行
- プロバイダーの認証と推論利用を確認
openclaw/openclaw☆ 39.2万2026年10月11日 更新
OpenClawの通常版とextended-stable版について、公開先、配布物の出所、テスト結果、Gatewayの実動作を照合し、リリース状況を確認します。
- stable版の公開完了を確認したいとき
- プラグインの配布漏れを確認したいとき
- extended-stable版の証拠確認
openclaw/openclaw☆ 39.2万2026年10月11日 更新
Use when you need to find the 2-3 most popular and well-maintained npm packages relevant to a frontend checklist rule, validate they meet quality thresholds, and add them to the rule's frontmatter.
日本語の概要は準備中です。原文の説明を表示しています。
thedaviddias/Front-End-Checklist☆ 7.4万2026年10月6日 更新
Cuts the next release of Prisma 8: bumps the root package.json version (on the v8 RC line: 8.0.0-rc.N → rc.N+1), propagates it to every workspace package, and opens a PR titled "chore(release): bump to <next-version>". When the maintainer merges the PR, the `Publish to npm` workflow runs automatically and ships the new version to npm under the dist-tag its shape implies (`latest`; RC releases get a pre-release GitHub Release), plus a matching GitHub Release. Also prepares the matching prisma/web docs-site PR from the same release notes, to merge once the release is published. Use when a maintainer asks to "cut the next RC", "cut the next release", "bump to the next version", "open a release PR", or "prepare a publish PR".
日本語の概要は準備中です。原文の説明を表示しています。
prisma/orm☆ 4.8万2026年10月10日 更新
Audit MCP (Model Context Protocol) server configurations for security issues. Use this skill when: - Reviewing .mcp.json files for security risks - Checking MCP server args for hardcoded secrets or shell injection patterns - Validating that MCP package-runner dependencies use exact reviewed versions, not bare names, @latest, or ranges - Detecting mutable npm/npx, bunx, pnpm dlx, yarn dlx, and npm exec references in MCP configurations - Auditing which MCP servers a project registers and whether they're on an approved list - Checking for environment variable usage vs. hardcoded credentials in MCP configs - Any request like "is my MCP config secure?", "audit my MCP servers", or "check .mcp.json" keywords: [mcp, security, audit, secrets, shell-injection, supply-chain, governance]
日本語の概要は準備中です。原文の説明を表示しています。
github/awesome-copilot☆ 4万2026年10月9日 更新
Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem monitoring. Use when vetting a new dependency, reviewing a package.json/package-lock.json during code review, checking lockfiles against a supply-chain advisory's known-bad versions, or investigating a host suspected of installing a trojanized package.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like `confused` and OWASP `dep-scan`, then enforcing source restrictions via `.npmrc`, `pip.conf`/`pyproject.toml`, and Maven `settings.xml`. Use when onboarding a repo to a supply-chain security program, auditing lockfiles/manifests for confusable dependencies, or after an incident that may have leaked internal package names.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
Guide a Mastra maintainer through publishing an npm snapshot from a pull request or a specified repository branch. Use when asked to release, publish, or create a PR snapshot, branch snapshot, canary package build, or branch-specific npm tag. Performs source and branch preflight checks, requires confirmation before the irreversible publish, dispatches the existing Publish to npm workflow, monitors it, and reports installable package tags.
日本語の概要は準備中です。原文の説明を表示しています。
mastra-ai/mastra☆ 2.9万2026年10月11日 更新
Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces via pnpm-workspace.yaml, or managing dependencies with catalogs, patches, overrides, config dependencies, or the global virtual store.
日本語の概要は準備中です。原文の説明を表示しています。
antfu/skills☆ 5,9582026年10月9日 更新
Troubleshoot npm registry, proxy, and certificate failures on the Microsoft corporate network or VPN using the 1ES public npm feed.
日本語の概要は準備中です。原文の説明を表示しています。
github/gh-aw☆ 5,3812026年10月11日 更新