All skills
vercel avatar

/list-npm-package-content

@fd133e0 official
by vercelvercel/ai27k stars
5,232

List the contents of an npm package tarball before publishing. Use when the user wants to see what files are included in an npm bundle, verify package contents, or debug npm publish issues.

Use this Skill: https://skilld.dev/gh/vercel/ai/list-npm-package-content

This session only. Nothing lands on disk.

SKILL.md

≈54 tokens always: the name and description. ≈196 when used: this file.

List npm Package Content

This skill lists the exact contents of an npm package tarball - the same files that would be uploaded to npm and downloaded by users.

Usage

Run the script from the package directory (e.g., packages/ai):

bash scripts/list-package-files.sh

The script will build the package, create a tarball, list its contents, and clean up automatically.

Understanding Package Contents

The files included are determined by:

  1. files field in package.json - explicit allowlist of files/directories
  2. .npmignore - files to exclude (if present)
  3. .gitignore - used if no .npmignore exists
  4. Always included: package.json, README, LICENSE, CHANGELOG
  5. Always excluded: .git, node_modules, .npmrc, etc.

Source: SKILL.md on GitHub

No alerts5mo5 checks · Risk SAFE
  • Gen Agent Trust Hub7mo

    This skill provides a utility to inspect npm package contents before publication. It executes standard local development commands to build and list files within a tarball, ensuring the package contains only intended files. All operations are local and consistent with standard development workflows.

  • Socket6mo

    No alerts

  • Snyk7mo

    Risk: LOW · No issues

  • Runlayer7mo

    1/2 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at fd133e0. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 12 hours ago.

Activeupdated 8 months ago
metadata
{
  "internal": true
}
  • Debugging
  • npm
  • packaging
  • vercel-ai
  • tarball
  • publish
  • node

README badge

README badge for vercel/ai/list-npm-package-content

Lists the exact files that will be included in an npm package tarball, using the package.json files field, .npmignore, and .gitignore to determine contents. Useful for verifying what gets published to npm or debugging unexpected inclusions before release.

Generated from the current SKILL.md.

What files does this skill include in the tarball?
The skill lists files based on the `files` field in package.json, .npmignore (or .gitignore if absent), plus always-included files like package.json, README, LICENSE, and CHANGELOG. It excludes .git, node_modules, .npmrc, and other standard npm-ignored paths.
Does this skill actually publish to npm?
No. It builds the package, creates a tarball, lists its contents, and cleans up locally. It does not upload anything to npm.
Can I use this outside the vercel/ai monorepo?
The skill is designed to run from a package directory with a standard npm setup. It should work with any package that has a package.json and uses npm's standard file inclusion rules.

Generated from the current SKILL.md. These answers refresh after source changes.