Audits NPM packages using the NPM Registry API with dependency tree resolution and vulnerability scanning via OSV.dev API. Generates SBOM in CycloneDX format and checks license compliance against SPDX expression parser.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "NPM Package Auditor"
slug: "npm-package-auditor-registry-api"
description: "Audits NPM packages using the NPM Registry API with dependency tree resolution and vulnerability scanning via OSV.dev API. Generates SBOM in CycloneDX format and checks license compliance against SPDX expression parser."
verification: "security_reviewed"
source: "https://docs.npmjs.com/cli/v10/using-npm/registry/"
author: "npm, Inc."
category: "Developer Tools"
framework: "MCP"
---
# NPM Package Auditor
Audits NPM packages using the NPM Registry API with dependency tree resolution and vulnerability scanning via OSV.dev API. Generates SBOM in CycloneDX format and checks license compliance against SPDX expression parser.
## Installation
Use the upstream install or setup path that matches your environment:
- npm Docs
- npm package scope, access level, and visibility
- Docker and private modules
- npm License
Requirements and caveats from upstream:
- Downloading and installing Node.js and npm
- Try the latest stable version of node
- Creating Node.js modules
Basic usage or getting-started notes:
- Creating a strong password
- Receiving a one-time password over email
- About two-factor authentication
- Source: https://docs.npmjs.com/cli/v10/using-npm/registry/
## Documentation
- https://docs.npmjs.com/cli/v10/using-npm/registry/
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/npm-package-auditor-registry-api/)
No comments yet. Be the first to comment!