Lightlines
Catalogue
Sign in
By grafana

check-npm

grafana

Catch risky package settings before they ship.

supply-chain security

What it does

Audits a JavaScript/TypeScript repository's package-manager configuration for supply-chain hardening.

When to use it

Use it when the user invokes /check-npm or asks to audit package-manager security settings in a Grafana plugin or JavaScript/TypeScript project.

How to use it

Give it a JavaScript/TypeScript project; it returns a PASS/FAIL audit covering the package manager, tool version, scripts, dependency protocols, and release age.

What you provide

  • a package manager security audit
  • An existing project

Access · 0

No additional actions listed in the analysis.

What you need · 1

A package.json file must exist at the workspace root.


About this skill

Visibility
Public
Repository
grafana/skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
4