Skip to content
Back to skills

Npm Publish

ASecurity

Use when publishing this package to npm — a version release (npm publish), verifying the registry/pi.dev listing, or diagnosing npm auth failures (E403 2FA/token errors). Token-based flow via NPM_TOKEN in .env.local with a temp userconfig, the leakage gate before every publish, post-publish verification and marker/badge upkeep. Trigger on "publish to npm", "npm release", "E403 publish error".

  • 53 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 20, 2026
ai-agentsnode

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add Kanevry/session-orchestrator --skill npm-publish --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Npm Publish?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Npm Publish
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/kanevry-npm-publish-bd5e76c9/badge)](https://www.skillsdirectory.com/skills/kanevry-npm-publish-bd5e76c9)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: npm-publish
description: Use when publishing this package to npm — a version release (npm publish), verifying the registry/pi.dev listing, or diagnosing npm auth failures (E403 2FA/token errors). Token-based flow via NPM_TOKEN in .env.local with a temp userconfig, the leakage gate before every publish, post-publish verification and marker/badge upkeep. Trigger on "publish to npm", "npm release", "E403 publish error".
metadata:
  user-invocable: "false"
  model: sonnet
---

# npm-publish

> **Portable mirror — generated, do not edit.** The canonical workflow lives at
> [`skills/npm-publish/SKILL.md`](../../../skills/npm-publish/SKILL.md); read that file for the full instructions.
> This mirror carries only agentskills.io-spec-legal frontmatter so harnesses that
> discover skills under `.agents/skills/` can find and route to the skill.
>
> Regenerate with `node scripts/generate-agents-skills.mjs`.

Read the linked document in full and follow its complete workflow, including prechecks and stop conditions. Resolve its link relative to this SKILL.md, not the project working directory. The plugin root is three directories above this file. Resolve package paths such as `skills/` and `scripts/` from that root and relative links in the canonical document from its own directory. Keep the user’s project as the target of project operations.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…