admission-control
Use when the user asks to "write a validator", "add validation", "implement admission…
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security,
$ npx -y skills add grafana/skills --skill check-npm --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/check-npmContext preview
The summary Claude sees to decide when to auto-load this skill.
Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security,
name: check-npm license: Apache-2.0 disable-model-invocation: false description: >- Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.
Read-only audit of the workspace root. Do not modify any files.
test -f package.json || { echo "STOP: no package.json at workspace root"; exit 1; }
jq -r '.packageManager // "unset"' package.json
ls -1 yarn.lock package-lock.json pnpm-lock.yaml 2>/dev/null || trueIf no `package.json`, stop. Priority: `packageManager` → lockfile → default npm.
npm --version # required ≥ 11.15.0 yarn --version # required ≥ 4.14.0 pnpm --version # required ≥ 11.0.0
Use semver comparison. Verify pinned `packageManager` meets threshold.
| Manager | Minimum | |---------|---------| | npm | 11.15.0 | | yarn | 4.14.0 | | pnpm | 11.0.0 |
grep -E '^ignore-scripts=' .npmrc 2>/dev/null grep -E 'enableScripts:' .yarnrc.yml 2>/dev/null grep -E 'strictDepBuilds:|dangerouslyAllowAllBuilds:|allowBuilds:' pnpm-workspace.yaml 2>/dev/null
| Manager | PASS | FAIL | |---------|------|------| | npm | `.npmrc` has `ignore-scripts=true` | missing or `false` | | yarn | `enableScripts: false` or key absent | `enableScripts: true` | | pnpm ≥ 11 | `strictDepBuilds` unset/`true`, `dangerouslyAllowAllBuilds` unset/`false`, and `allowBuilds` unset/`[]` | `strictDepBuilds: false`, `dangerouslyAllowAllBuilds: true`, or `allowBuilds` non-empty | | pnpm 10 | `.npmrc` `ignore-scripts=true` OR `strictDepBuilds: true` | neither |
pnpm 11+ ignores script settings in `.npmrc` and `package.json#pnpm`. pnpm 10 / yarn edge cases: [references/managers.md](references/managers.md).
Registry:
grep -E '^allow-git=' .npmrc 2>/dev/null grep -E 'approvedGitRepositories:' .yarnrc.yml 2>/dev/null grep -E 'blockExoticSubdeps:' pnpm-workspace.yaml 2>/dev/null
Scan workspace `package.json` files (`dependencies`, `devDependencies`, `optionalDependencies`, `peerDependencies`). Prefer workspace-member discovery (pnpm-workspace.yaml / root workspaces / lerna / rush) per [references/protocols.md](references/protocols.md), then scan only those manifests. Fallback (may overmatch non-workspace manifests):
find . -name package.json -not -path '*/node_modules/*'
**Safe values only:** semver range, `workspace:`, `patch:`, `npm:` alias to semver. Flag everything else (git URLs, tarballs, `user/repo` shorthand, `file:`, `link:`, `exec:`, …) as `path → name → value (protocol)`.
| Manager | PASS | FAIL | |---------|------|------| | npm | `allow-git=none` or `root` | missing or `all` | | yarn | `approvedGitRepositories: []` or grafana-scoped list, or omitted with policy comment + clean scan | unsafe entries or broad allow-list | | pnpm ≥ 11 | `blockExoticSubdeps` unset/`true` | `false` | | pnpm 10.x | `blockExoticSubdeps: true` | unset (default `false`) or `false` |
Protocol detection order and yarn posture details: [references/protocols.md](references/protocols.md).
3 days = 4320 minutes. npm uses **days**; yarn and pnpm use **minutes**.
grep -E '^min(imum)?-release-age=' .npmrc 2>/dev/null grep -E 'npmMinimalAgeGate:' .yarnrc.yml 2>/dev/null grep -E 'minimumReleaseAge:|minimumReleaseAgeStrict:' pnpm-workspace.yaml 2>/dev/null
| Manager | PASS | FAIL | |---------|------|------| | npm | `min-release-age` ≥ `3` | missing | | yarn | `npmMinimalAgeGate` ≥ 4320 min | missing or below | | pnpm ≥ 11 | `minimumReleaseAge` ≥ `4320` | unset (default `1440`) or below | | pnpm 10 | `minimum-release-age` / `minimumReleaseAge` ≥ `4320` | missing |
Flag `minimumReleaseAgeStrict: false` on pnpm 11.
| # | Check | Status | Detail | |---|---|---|---| | 0 | Package manager | (npm / yarn / pnpm) | version: x.y.z (pinned: y.y.y if set) | | 1 | Tool version ≥ threshold | PASS / FAIL | `actual` vs `required` | | 2 | Scripts disabled | PASS / FAIL | config line or "missing" | | 3 | Unsafe dep protocols | PASS / FAIL | registry state + flagged entries | | 4 | Min release age ≥ 3 days | PASS / FAIL | config + value |
Use `PASS` / `FAIL` only — no emojis.
For each FAIL, one paste-ready fix:
# npm — .npmrc ignore-scripts=true allow-git=none min-release-age=3
# pnpm 11 — pnpm-workspace.yaml strictDepBuilds: true dangerouslyAllowAllBuilds: false allowBuilds: [] minimumReleaseAge: 4320 blockExoticSubdeps: true
# yarn — .yarnrc.yml npmMinimalAgeGate: 4320
More fixes (tool upgrades, yarn git allow-list, pnpm 10): [references/fix-snippets.md](references/fix-snippets.md).
If all PASS: "All checks passed." and stop.
Public skills for working with Grafana, Prometheus, Loki, Tempo, Pyroscope, k6, and the broader LGTM observability stack. Compatible with Claude Code, Cursor, Codex, and any tool supporting the Agent Skills open standard.
Repo: grafana/skills
Use when the user asks to "write a validator", "add validation", "implement admission…
Use when starting any grafana-app-sdk work — scaffolding a Grafana app, initializing a…
Author CUE kind definitions for grafana-app-sdk apps - schemas, versioning, field…
Implement reconcilers and watchers for grafana-app-sdk apps — write…
Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics…