npm registry ops: login, whoami, names, publish; 1Password tmux.
68
83%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Use for npm registry/account tasks: npm whoami, package availability, package reservation, publish, org checks, and auth debugging.
one-password first for secret rules.op directly in the shell tool.npm Registry - steipete - Release Automation in Molty.OP_SERVICE_ACCOUNT_TOKEN; no desktop unlock. The item carries the working registry session (registry_token) plus username/password/TOTP fallback.npmjs fallback is explicit only: pass --account my.1password.com when Molty is unavailable and the user wants the fallback. Explicit release/publish requests are consent for its unlock prompt.op-work tmux session (clawdbot-op.sock; see one-password). Reuse the window on failure; kill it when the npm task is done. Never mint an npm-specific socket or session.scripts/npm-auth.sh: stored registry_token session first, then scripts/npm-auth-login.mjs registry login with a fresh six-digit OTP; successful fallback sessions are cached back to the same item. Do not hand-roll field extraction, registry login, or cache writes.id, then purpose, then a unique label; duplicate label-only matches are rejected (legacy npmjs may retain same-label fields).scripts/npm-service.sh -- <npm args...>; use publish-package.sh for a local package.printf ... | npm login --auth-type=legacy.expect for npm login unless necessary; logs can echo prompts and are easy to get wrong.npm-profile loginCouch) for automation.npm whoami fails, stop and ask for the exact field label / credential fix. Do not probe more 1Password items or open another tmux window/session.From the package root, inside the same auth tmux window:
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/publish-package.shThe helper verifies identity, refuses an existing package version, publishes with a fresh OTP, retries one expired OTP, verifies registry visibility, and cleans auth files.
Use scripts/reserve-packages.sh from inside the same tmux window:
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/reserve-packages.sh package-one package-twoWhat it does:
op0.0.0 placeholder packages with a generic READMENotes:
npm login.npm view can lag/404 even when the package exists. Check npm access get status <pkg>; public or a publish failure saying previously published versions means the name is reserved.bb36883
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.