All skills
mblode avatar

/dx-audit

@b690e67
by Matthew Blodemblode/agent-skills134 stars
12

Audits libraries, CLIs, and SDKs using 38 rules for public contracts, package exports, piped output, errors, and configuration. Use when asked to "audit my CLI", "review my SDK", or diagnose package type resolution. For public site or docs agent scores use agent-ready; for agentic product trust use ax-audit; for docs prose use ghostwriter.

Use this Skill: https://skilld.dev/gh/mblode/agent-skills/dx-audit

This session only. Nothing lands on disk.

rulesonboard-exports-resolve-typed.md

≈470 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Make Every Export Resolve With Types Under the Module Systems You Claim

npm install succeeding is not onboarding; the first import resolving with types is. Every exports entry needs a types condition first in its block (TypeScript stops at the first matching condition, so types after import is never reached), a declaration file whose format matches the JavaScript it describes (.d.ts beside ESM, .d.cts beside CJS), a root "." entry, a bin file that starts with a shebang, and an engines.node floor. Verify with npx publint and npx @arethetypeswrong/cli --pack . rather than by reading the map. ESM-only is a valid answer for most libraries; ship a require condition only when a real consumer needs it.

Incorrect (types listed after import so it is never reached; require served an ESM file):

{
  "type": "module",
  "exports": {
    ".": {
      "import": "./dist/index.js",
      "require": "./dist/index.js",  // ESM under "type": "module" handed to require(): attw "masquerading as CJS"
      "types": "./dist/index.d.ts"   // after import and require: publint EXPORTS_TYPES_SHOULD_BE_FIRST
    }
  }
}

Correct (types first per condition, declaration format matches, verified before publish):

{
  "type": "module",
  "engines": { "node": ">=22" },
  "exports": {
    ".": {
      "import": { "types": "./dist/index.d.ts", "default": "./dist/index.js" },
      "require": { "types": "./dist/index.d.cts", "default": "./dist/index.cjs" }
    }
  },
  "scripts": { "prepublishOnly": "publint && attw --pack ." }
}

Source: SKILL.md on GitHub

No alerts9d3 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    The dx-audit skill is a developer experience auditing tool designed to review public APIs, CLIs, and SDKs. It demonstrates a strong security posture by including explicit instructions to validate inputs against path traversal and shell injection, and by warning the agent to inspect potentially malicious lifecycle scripts in audited repositories before running packaging probes. All external tools mentioned are industry-standard utilities.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

Signed by skilld at b690e67. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last week

README badge

README badge for mblode/agent-skills/dx-audit