Skip to content
Back to skills

Install Node Stack

ASecurity

Plan a safe Node.js, package-manager, and Expo development setup. Use when the user says 'install node', 'set up nvm', 'install pnpm', 'node version manager', or 'I need newer node'.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
developmentshellbashnode

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add khadinakbarlabs/expo-mobile-app-builder --skill install-node-stack --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Install Node Stack?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Install Node Stack
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/khadinakbarlabs-install-node-stack/badge)](https://www.skillsdirectory.com/skills/khadinakbarlabs-install-node-stack)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "install-node-stack"
description: "Plan a safe Node.js, package-manager, and Expo development setup. Use when the user says 'install node', 'set up nvm', 'install pnpm', 'node version manager', or 'I need newer node'."
---

# Set Up the Node Stack Safely

Installing runtimes modifies the user's workstation and shell profile. Explain the selected toolchain first and wait for confirmation before executing any installation command. Never pipe a remote download directly into a shell.

## Expo SDK 54 baseline

- Use a currently supported Node 20.19+ runtime, then verify the project's exact Expo SDK compatibility.
- Use the package manager already approved for the project. Prefer `npm exec --no -- expo install` for Expo SDK-compatible dependencies.
- Keep runtime configuration local to the workstation; never place access tokens or private registry credentials in project source.

## Recommended installation paths

Choose one owner-approved package-manager or signed-installer path for the user's operating system:

| Tool | Safer default |
|---|---|
| Node version manager | A system package manager or the official release artifact after validating its published checksum/signature |
| pnpm | Corepack or the approved system package manager |
| Bun | The approved system package manager or a verified official release artifact |

For macOS users who have explicitly approved Homebrew, a typical local setup is:

```bash
brew install nvm pnpm bun
```

Follow the package manager's printed post-install instructions for shell configuration instead of copying profile changes blindly.

## Verify after installation

```bash
node --version
corepack --version
pnpm --version
bun --version
```

Pin a compatible runtime in a project-local `.nvmrc` only after confirming the project's toolchain. Then run `npx expo-doctor@1.20.4` from the app root to catch SDK or native dependency drift.

## Safety checks

- Do not pipe a network download directly into a shell or use an unverified global installer.
- Review package-manager output before accepting shell-profile changes.
- Keep npm registry tokens in owner-controlled credential storage, never in `.npmrc` committed to a public app or plugin.
- Confirm before changing the default Node version, installing global packages, or editing shell startup files.

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml185 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…