Install
openclaw skills install @geoffrey-xiao/npm-package-scanAudit JavaScript and TypeScript repository dependencies for security, supply-chain, maintenance, version, lockfile, and cleanup risks. Use for npm, pnpm, Yarn, or Bun package reviews; do not use for automatic dependency upgrades unless the user explicitly requests changes.
openclaw skills install @geoffrey-xiao/npm-package-scanReview package risk without changing the repository by default. Separate observed facts from inferences and make every recommendation verifiable.
package.json files, lockfiles, workspace declarations, package-manager metadata, and dependency-related configuration. Ignore generated and vendored directories such as node_modules, build output, caches, and VCS metadata.packageManager field, lockfile, workspace configuration, and available binaries. If these disagree, report the mismatch; do not generate a new lockfile.scripts/export_report.py; report the output path and whether registry-backed checks were included.Use confirmed, likely, or needs verification for confidence. A package being old, unpopular, or lightly maintained is not by itself proof that it is unsafe or abandoned.
npm audit fix, npm audit fix --force, pnpm audit --fix, yarn npm audit --fix, or equivalent mutating commands during a review.A useful review states what was inspected, what could not be verified, whether networked checks ran, the highest-priority findings, and a sequenced action plan. If no actionable risk is found, say so explicitly and list remaining blind spots.