Skip to content
Back to skills

Npm Publish

ASecurity

Use when publishing this package to npm — a version release (npm publish), verifying the registry/pi.dev listing, or diagnosing npm auth failures (E403 2FA/token errors). Token-based flow via NPM_TOKEN in .env.local with a temp userconfig, the leakage gate before every publish, post-publish verification and marker/badge upkeep. Trigger on "publish to npm", "npm release", "E403 publish error".

  • 53 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 20, 2026
ai-agentsnode

Security analysis

A100/100

Scanned September 20, 2026

npx -y skills add Kanevry/session-orchestrator --skill npm-publish --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Npm Publish?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Npm Publish
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/kanevry-npm-publish-e9d416c4/badge)](https://www.skillsdirectory.com/skills/kanevry-npm-publish-e9d416c4)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: npm-publish
description: Use when publishing this package to npm — a version release (npm publish), verifying the registry/pi.dev listing, or diagnosing npm auth failures (E403 2FA/token errors). Token-based flow via NPM_TOKEN in .env.local with a temp userconfig, the leakage gate before every publish, post-publish verification and marker/badge upkeep. Trigger on "publish to npm", "npm release", "E403 publish error".
metadata:
  user-invocable: 'false'
  model: sonnet
---

<!-- Generated by scripts/generate-codex-skills.mjs; do not edit. -->

# npm-publish

Read [`skills/npm-publish/SKILL.md`](../../../skills/npm-publish/SKILL.md) in full before taking any action, then follow its complete workflow.
The linked document is authoritative, including its prechecks, argument rules, and stop conditions.

Resolve this link relative to this SKILL.md, not the project working directory. The plugin root is three directories above this file. Resolve package paths such as `skills/` and `scripts/` from that root; resolve relative links inside the canonical document from its own directory. Keep the user’s project as the target of project operations.

Regenerate with `node scripts/generate-codex-skills.mjs`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…