010103 package operations
Day-to-day package management for npm, pnpm, and bun — install, update, audit, publish, dependency inspection, and version conflict resolution.From its SKILL.md
npx -y skills add natuleadan/skills --skill 010103-package-operationsAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- runs commandsInstructs the agent to run 5 commands, including `python scripts/validate.py install` and 4 more.
What its file declares
Copied from the file, not written here
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
1.9 KB, 471 tokens by cl100k_base, as published. Nobody here has run it
Package Operations
This skill covers day-to-day package management operations across npm, pnpm, and bun.
How to use this skill
- If the user asks about installing or removing packages → run
python scripts/validate.py install - If the user asks about updating dependencies → run
python scripts/validate.py outdated - If the user asks about auditing for vulnerabilities → run
python scripts/validate.py audit - If the user asks about publishing packages → run
python scripts/validate.py publish - If the user asks about dependency troubleshooting → run
python scripts/validate.py doctor
Quick reference
| Task | npm | pnpm | bun |
|---|---|---|---|
| Install | npm install | pnpm install | bun install |
| Add dep | npm install <pkg> | pnpm add <pkg> | bun add <pkg> |
| Remove | npm uninstall <pkg> | pnpm remove <pkg> | bun remove <pkg> |
| Update all | npm update | pnpm update | bun update |
| Audit | npm audit | pnpm audit | bun pm audit |
| Outdated | npm outdated | pnpm outdated | bun outdated |
| Publish | npm publish | pnpm publish | bun publish |
| Doctor | npm doctor | pnpm doctor | bun --help |
Best practices
- Always review lockfile changes before committing
- Use
--frozen-lockfilein CI (npm ci,pnpm install --frozen-lockfile,bun install --frozen-lockfile) - Pin exact versions in production: set
save-exact=truein.npmrc - Audit regularly:
npm audit --audit-level=high - Keep a change log when updating dependencies
References
references/ops-guide.md— PM-specific commands for install, update, audit, publish, and troubleshootingscripts/validate.py— Validation tool for package operations
What ships with it: 3 files
7.8 KB alongside SKILL.md, 1 of them executable
references/
- ops-guide.md2.8 KB
scripts/
- validate.pyruns4.8 KB
- metadata.json253 B
Gives 0 of the 12 instructions most operations skills give in 471 tokens
Counted across 483 of the 484 authors here whose files we hold, read 2026-08-07
- Collect monitoring data throughout the simulationin 14 of 483, across 6 files
- Set the random seed for reproducibilityin 14 of 483, across 6 files
- Validate simulations against analytical solutionsin 12 of 483, across 4 files
- Clarify goals, constraints, and inputsin 11 of 483, across 2 files
- Implement contract tests for integration pointsin 11 of 483, across 2 files
- Implement strangler fig infrastructure with API gatewayin 11 of 483, across 2 files
- Audit modernized components for security vulnerabilitiesin 11 of 483, across 2 files
- Avoid Python blocking calls in processesin 10 of 483, across 3 files
- Use resource context managers for automatic cleanupin 9 of 483, across 2 files
- Maintain consistent time unitsin 9 of 483, across 2 files
- Validate outcomes against success criteriain 8 of 483, across 1 file
- Analyze the legacy codebase for technical debtin 8 of 483, across 1 file
Said here and by no other author read
- run the validation script for package tasks
- review lockfile changes before committing
- use frozen-lockfile in CI
- pin exact versions in production
- audit dependencies regularly
- keep a change log when updating dependencies
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.