agentsclimarketplace

Package lock parsing

Skill cxcscmu/SkillLearnBench/skills/b1-one-shot-claude-haiku-4-5/dependency-vulnerability-check/package-lock-parsing

Parse and extract package information from npm package-lock.json files to identify dependencies and their installed versions.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill package-lock-parsing

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

1.9 KB, 413 tokens by cl100k_base, as published. Nobody here has run it

Package-lock.json Parsing

Overview

The package-lock.json file is an npm lock file that records exact dependency versions used in a project. It enables reproducible installs and is essential for vulnerability scanning.

File Structure

The package-lock.json follows this structure:

{
  "name": "project-name",
  "version": "1.0.0",
  "lockfileVersion": 3,
  "packages": {
    "": {
      "name": "project-name",
      "version": "1.0.0",
      "dependencies": {
        "express": "^4.18.0"
      }
    },
    "node_modules/express": {
      "version": "4.18.2",
      "resolved": "https://registry.npmjs.org/express/-/express-4.18.2.tgz"
    }
  }
}

Key Properties

  • packages: Contains all packages (root + node_modules)
  • version: The installed version of each package
  • dependencies: Direct dependencies of a package

Extraction Pattern

import json

def parse_package_lock(file_path):
    with open(file_path, 'r') as f:
        lock_data = json.load(f)

    packages = {}
    for pkg_path, pkg_info in lock_data.get('packages', {}).items():
        # Skip root package
        if pkg_path == '':
            continue

        pkg_name = pkg_path.split('/')[-1]
        version = pkg_info.get('version')
        packages[pkg_name] = version

    return packages

Usage

Use this skill when:

  • Extracting dependency lists from package-lock.json
  • Building vulnerability scanning pipelines
  • Analyzing dependency versions for compliance
  • Creating inventory reports of installed packages

Related Skills

  • trivy-vulnerability-scanning: Use parsed packages as input to vulnerability scanner
  • security-audit-csv-reporting: Output results in structured CSV format

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.