/check-npm
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security,
$ npx -y skills add grafana/skills --skill check-npm --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/check-npm
Context preview
The summary Claude sees to decide when to auto-load this skill.
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security,
SKILL.md
check-npm.SKILL.mdname: check-npm
license: Apache-2.0
disable-model-invocation: false
description: >-
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for
supply-chain hardening: tool version, lifecycle scripts, unsafe dependency
protocols, and minimum release age ≥3 days. Use when the user invokes
/check-npm or asks to audit package manager security, lifecycle scripts, git
dependencies, ignore-scripts, min-release-age, allow-git,
approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana
plugin or JS/TS project.
npm / yarn / pnpm supply-chain audit
Read-only audit of the workspace root. Do not modify any files.
0. Detect package manager
test -f package.json || { echo "STOP: no package.json at workspace root"; exit 1; }
jq -r '.packageManager // "unset"' package.json
ls -1 yarn.lock package-lock.json pnpm-lock.yaml 2>/dev/null || trueIf no `package.json`, stop. Priority: `packageManager` → lockfile → default npm.
1. Tool version
npm --version # required ≥ 11.15.0
yarn --version # required ≥ 4.14.0
pnpm --version # required ≥ 11.0.0
Use semver comparison. Verify pinned `packageManager` meets threshold.
| Manager | Minimum | |---------|---------| | npm | 11.15.0 | | yarn | 4.14.0 | | pnpm | 11.0.0 |
2. Lifecycle scripts disabled
grep -E '^ignore-scripts=' .npmrc 2>/dev/null
grep -E 'enableScripts:' .yarnrc.yml 2>/dev/null
grep -E 'strictDepBuilds:|dangerouslyAllowAllBuilds:|allowBuilds:' pnpm-workspace.yaml 2>/dev/null
| Manager | PASS | FAIL | |---------|------|------| | npm | `.npmrc` has `ignore-scripts=true` | missing or `false` | | yarn | `enableScripts: false` or key absent | `enableScripts: true` | | pnpm ≥ 11 | `strictDepBuilds` unset/`true`, `dangerouslyAllowAllBuilds` unset/`false`, and `allowBuilds` unset/`[]` | `strictDepBuilds: false`, `dangerouslyAllowAllBuilds: true`, or `allowBuilds` non-empty | | pnpm 10 | `.npmrc` `ignore-scripts=true` OR `strictDepBuilds: true` | neither |
pnpm 11+ ignores script settings in `.npmrc` and `package.json#pnpm`. pnpm 10 / yarn edge cases: [references/managers.md](references/managers.md).
3. Unsafe dependency protocols
Registry:
grep -E '^allow-git=' .npmrc 2>/dev/null
grep -E 'approvedGitRepositories:' .yarnrc.yml 2>/dev/null
grep -E 'blockExoticSubdeps:' pnpm-workspace.yaml 2>/dev/null
Scan workspace `package.json` files (`dependencies`, `devDependencies`, `optionalDependencies`, `peerDependencies`). Prefer workspace-member discovery (pnpm-workspace.yaml / root workspaces / lerna / rush) per [references/protocols.md](references/protocols.md), then scan only those manifests. Fallback (may overmatch non-workspace manifests):
find . -name package.json -not -path '*/node_modules/*'
**Safe values only:** semver range, `workspace:`, `patch:`, `npm:` alias to semver. Flag everything else (git URLs, tarballs, `user/repo` shorthand, `file:`, `link:`, `exec:`, …) as `path → name → value (protocol)`.
| Manager | PASS | FAIL | |---------|------|------| | npm | `allow-git=none` or `root` | missing or `all` | | yarn | `approvedGitRepositories: []` or grafana-scoped list, or omitted with policy comment + clean scan | unsafe entries or broad allow-list | | pnpm ≥ 11 | `blockExoticSubdeps` unset/`true` | `false` | | pnpm 10.x | `blockExoticSubdeps: true` | unset (default `false`) or `false` |
Protocol detection order and yarn posture details: [references/protocols.md](references/protocols.md).
4. Minimum release age ≥ 3 days
3 days = 4320 minutes. npm uses **days**; yarn and pnpm use **minutes**.
grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/null
grep -E 'npmMinimalAgeGate:' .yarnrc.yml 2>/dev/null
grep -E 'minimumReleaseAge:|minimumReleaseAgeStrict:' pnpm-workspace.yaml 2>/dev/null
| Manager | PASS | FAIL | |---------|------|------| | npm | `min-release-age` ≥ `3` | missing | | yarn | `npmMinimalAgeGate` ≥ 4320 min | missing or below | | pnpm ≥ 11 | `minimumReleaseAge` ≥ `4320` | unset (default `1440`) or below | | pnpm 10 | `minimum-release-age` / `minimumReleaseAge` ≥ `4320` | missing |
Flag `minimumReleaseAgeStrict: false` on pnpm 11.
5. Report
| # | Check | Status | Detail | |---|---|---|---| | 0 | Package manager | (npm / yarn / pnpm) | version: x.y.z (pinned: y.y.y if set) | | 1 | Tool version ≥ threshold | PASS / FAIL | `actual` vs `required` | | 2 | Scripts disabled | PASS / FAIL | config line or "missing" | | 3 | Unsafe dep protocols | PASS / FAIL | registry state + flagged entries | | 4 | Min release age ≥ 3 days | PASS / FAIL | config + value |
Use `PASS` / `FAIL` only — no emojis.
For each FAIL, one paste-ready fix:
# npm — .npmrc
ignore-scripts=true
allow-git=none
min-release-age=3
# pnpm 11 — pnpm-workspace.yaml
strictDepBuilds: true
dangerouslyAllowAllBuilds: false
allowBuilds: []
minimumReleaseAge: 4320
blockExoticSubdeps: true
# yarn — .yarnrc.yml
npmMinimalAgeGate: 4320
More fixes (tool upgrades, yarn git allow-list, pnpm 10): [references/fix-snippets.md](references/fix-snippets.md).
If all PASS: "All checks passed." and stop.
Read more
name: check-npm license: Apache-2.0 disable-model-invocation: false description: >- Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.
npm / yarn / pnpm supply-chain audit
Read-only audit of the workspace root. Do not modify any files.
0. Detect package manager
test -f package.json || { echo "STOP: no package.json at workspace root"; exit 1; }
jq -r '.packageManager // "unset"' package.json
ls -1 yarn.lock package-lock.json pnpm-lock.yaml 2>/dev/null || trueIf no `package.json`, stop. Priority: `packageManager` → lockfile → default npm.
1. Tool version
npm --version # required ≥ 11.15.0 yarn --version # required ≥ 4.14.0 pnpm --version # required ≥ 11.0.0
Use semver comparison. Verify pinned `packageManager` meets threshold.
| Manager | Minimum | |---------|---------| | npm | 11.15.0 | | yarn | 4.14.0 | | pnpm | 11.0.0 |
2. Lifecycle scripts disabled
grep -E '^ignore-scripts=' .npmrc 2>/dev/null grep -E 'enableScripts:' .yarnrc.yml 2>/dev/null grep -E 'strictDepBuilds:|dangerouslyAllowAllBuilds:|allowBuilds:' pnpm-workspace.yaml 2>/dev/null
| Manager | PASS | FAIL | |---------|------|------| | npm | `.npmrc` has `ignore-scripts=true` | missing or `false` | | yarn | `enableScripts: false` or key absent | `enableScripts: true` | | pnpm ≥ 11 | `strictDepBuilds` unset/`true`, `dangerouslyAllowAllBuilds` unset/`false`, and `allowBuilds` unset/`[]` | `strictDepBuilds: false`, `dangerouslyAllowAllBuilds: true`, or `allowBuilds` non-empty | | pnpm 10 | `.npmrc` `ignore-scripts=true` OR `strictDepBuilds: true` | neither |
pnpm 11+ ignores script settings in `.npmrc` and `package.json#pnpm`. pnpm 10 / yarn edge cases: [references/managers.md](references/managers.md).
3. Unsafe dependency protocols
Registry:
grep -E '^allow-git=' .npmrc 2>/dev/null grep -E 'approvedGitRepositories:' .yarnrc.yml 2>/dev/null grep -E 'blockExoticSubdeps:' pnpm-workspace.yaml 2>/dev/null
Scan workspace `package.json` files (`dependencies`, `devDependencies`, `optionalDependencies`, `peerDependencies`). Prefer workspace-member discovery (pnpm-workspace.yaml / root workspaces / lerna / rush) per [references/protocols.md](references/protocols.md), then scan only those manifests. Fallback (may overmatch non-workspace manifests):
find . -name package.json -not -path '*/node_modules/*'
**Safe values only:** semver range, `workspace:`, `patch:`, `npm:` alias to semver. Flag everything else (git URLs, tarballs, `user/repo` shorthand, `file:`, `link:`, `exec:`, …) as `path → name → value (protocol)`.
| Manager | PASS | FAIL | |---------|------|------| | npm | `allow-git=none` or `root` | missing or `all` | | yarn | `approvedGitRepositories: []` or grafana-scoped list, or omitted with policy comment + clean scan | unsafe entries or broad allow-list | | pnpm ≥ 11 | `blockExoticSubdeps` unset/`true` | `false` | | pnpm 10.x | `blockExoticSubdeps: true` | unset (default `false`) or `false` |
Protocol detection order and yarn posture details: [references/protocols.md](references/protocols.md).
4. Minimum release age ≥ 3 days
3 days = 4320 minutes. npm uses **days**; yarn and pnpm use **minutes**.
grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/null grep -E 'npmMinimalAgeGate:' .yarnrc.yml 2>/dev/null grep -E 'minimumReleaseAge:|minimumReleaseAgeStrict:' pnpm-workspace.yaml 2>/dev/null
| Manager | PASS | FAIL | |---------|------|------| | npm | `min-release-age` ≥ `3` | missing | | yarn | `npmMinimalAgeGate` ≥ 4320 min | missing or below | | pnpm ≥ 11 | `minimumReleaseAge` ≥ `4320` | unset (default `1440`) or below | | pnpm 10 | `minimum-release-age` / `minimumReleaseAge` ≥ `4320` | missing |
Flag `minimumReleaseAgeStrict: false` on pnpm 11.
5. Report
| # | Check | Status | Detail | |---|---|---|---| | 0 | Package manager | (npm / yarn / pnpm) | version: x.y.z (pinned: y.y.y if set) | | 1 | Tool version ≥ threshold | PASS / FAIL | `actual` vs `required` | | 2 | Scripts disabled | PASS / FAIL | config line or "missing" | | 3 | Unsafe dep protocols | PASS / FAIL | registry state + flagged entries | | 4 | Min release age ≥ 3 days | PASS / FAIL | config + value |
Use `PASS` / `FAIL` only — no emojis.
For each FAIL, one paste-ready fix:
# npm — .npmrc ignore-scripts=true allow-git=none min-release-age=3
# pnpm 11 — pnpm-workspace.yaml strictDepBuilds: true dangerouslyAllowAllBuilds: false allowBuilds: [] minimumReleaseAge: 4320 blockExoticSubdeps: true
# yarn — .yarnrc.yml npmMinimalAgeGate: 4320
More fixes (tool upgrades, yarn git allow-list, pnpm 10): [references/fix-snippets.md](references/fix-snippets.md).
If all PASS: "All checks passed." and stop.
Public skills for working with Grafana, Prometheus, Loki, Tempo, Pyroscope, k6, and the broader LGTM observability stack. Compatible with Claude Code, Cursor, Codex, and any tool supporting the Agent Skills open standard.
Repo: grafana/skills
Other skills on grafana-skills.
- /admission-control
Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to
Open skill - /app-sdk-concepts
Use when starting any grafana-app-sdk work — scaffolding a Grafana app, initializing a Grafana App Platform app, picking a deployment mode (standalone operator / grafana/apps / frontend-only), wiring app-specific config, or onboarding to the SDK. Covers `grafana-app-sdk` CLI
Open skill - /cue-kind-definition
Author CUE kind definitions for grafana-app-sdk apps - schemas, versioning, field constraints, named type definitions, custom routes, and codegen configuration. Scaffolds kinds via `grafana-app-sdk project kind add`, writes spec/status schemas with type constraints (regex, enum,
Open skill - /reconciler-logic
Implement reconcilers and watchers for grafana-app-sdk apps — write `TypedReconciler[*MyKind]` reconcile functions, apply generation-based skip patterns, do conflict-safe status updates via `resource.UpdateObject`, configure `BasicReconcileOptions` (namespace, label/field
Open skill - /adaptive-metrics
Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config, unused-metric detection, and Alloy remote_write fallback. Use when investigating a high
Open skill - /admin
Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role
Open skill

