Skip to content
Back to skills

Install Package

ASecurity

Installing a package dependency

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
documentationbash

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned October 5, 2026

npx -y skills add JacobLey/leyman --skill install-package --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Install Package?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Install Package
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jacobley-install-package/badge)](https://www.skillsdirectory.com/skills/jacobley-install-package)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: install-package
description: Installing a package dependency
---

# Installing a package

## 1. Add the version to the default `catalog:` in [`pnpm-workspace.yaml`](../../../pnpm-workspace.yaml)

Skip if it is already there. Use the default `catalog:` only. Don't add a named catalog: every package should use the same version.

The named catalogs under `catalogs:` are reserved for depending on the **npm-published** build of a package in this repo, to break a dev-time circular dependency. Read the comments there before adding to them.

## 2. Reference it from the package's `package.json`

```json
"dependencies": { "some-lib": "catalog:" },
"devDependencies": { "@leyman/expect": "workspace:^" }
```

External packages use `catalog:`. Packages in this repo use `workspace:^`. A `peerDependency` or `optionalDependency` must also be listed in `devDependencies` to be installed locally.

Workspace packages are injected, not symlinked: a dependent sees a copy of only the files the package publishes, and the package's peers resolve from the dependent, as they would from npm. The dependency's `build` keeps the copy current (see [`sync-injected`](../nx-tasks-reference/SKILL.md#sync-injected)).

## 3. Install and build

```bash
pnpm i
nx run-many -t build
```

The build also syncs `tsconfig.json` `references` for new workspace dependencies.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…