skills/npm/SKILL.md
npm registry ops: login, whoami, names, publish; 1Password tmux.
npx skillsauth add steipete/agent-scripts npmInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use for npm registry/account tasks: npm whoami, package availability, package reservation, publish, org checks, and auth debugging.
one-password first for secret rules.op directly in the shell tool.npm Registry - steipete - Release Automation in Molty.OP_SERVICE_ACCOUNT_TOKEN; no desktop unlock. The item carries the working registry session (registry_token) plus username/password/TOTP fallback.npmjs fallback is explicit only: pass --account my.1password.com when Molty is unavailable and the user wants the fallback. Explicit release/publish requests are consent for its unlock prompt.op-work tmux session (clawdbot-op.sock; see one-password). Reuse the window on failure; kill it when the npm task is done. Never mint an npm-specific socket or session.scripts/npm-auth.sh: stored registry_token session first, then scripts/npm-auth-login.mjs registry login with a fresh six-digit OTP; successful fallback sessions are cached back to the same item. Do not hand-roll field extraction, registry login, or cache writes.npm-auth.sh owns NPM_AUTH_SCRIPT_DIR without changing the caller's SCRIPT_DIR or working directory. Node helpers also support file symlinks, including --preserve-symlinks-main.id, then purpose, then a unique label; duplicate label-only matches are rejected (legacy npmjs may retain same-label fields).scripts/npm-service.sh -- <npm args...>; use publish-package.sh for a local package.printf ... | npm login --auth-type=legacy.expect for npm login unless necessary; logs can echo prompts and are easy to get wrong.npm-profile loginCouch) for automation.npm whoami fails, stop and ask for the exact field label / credential fix. Do not probe more 1Password items or open another tmux window/session.From the package root, inside the same auth tmux window:
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/publish-package.sh
The helper verifies identity, refuses an existing package version, publishes with a fresh OTP, retries one expired OTP, verifies registry visibility, and cleans auth files.
Use scripts/reserve-packages.sh from inside the same tmux window:
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/reserve-packages.sh package-one package-two
What it does:
op0.0.0 placeholder packages with a generic READMENotes:
npm login.npm view can lag/404 even when the package exists. Check npm access get status <pkg>; public or a publish failure saying previously published versions means the name is reserved.From the repo root; synthetic fixtures only, no real 1Password/npm auth. Always use an empty environment (the shell mock checks its environment for token leaks):
test_home="$(mktemp -d)"
(
set -e
trap 'rm -rf "$test_home"' EXIT
env -i HOME="$test_home" PATH="$PATH" node --test skills/npm/scripts/*.test.mjs </dev/null
env -i HOME="$test_home" PATH="$PATH" /bin/bash skills/npm/scripts/npm-auth.test.sh </dev/null
)
development
Mac fleet inventory and upkeep with full/worker profiles: collect installed apps and packages, compare desired versus observed state, audit local-account escrow references, update Homebrew/global packages, safely sync repos and Xcode, and report disk, service, backup, update, and security health.
tools
Claude Code work routing: delegate implementation, fixing, exploratory subagents, rebasing, and PR merging/landing to Codex CLI while the parent specifies, decides, reviews, and verifies. Load a private codex-next policy first when available; otherwise use the native-Claude model gate. Codex-backed autoreview is always allowed and preferred.
tools
macOS screen capture, accessibility inspection, and background-first app/window/UI automation with Peekaboo v4.
data-ai
Remote Macs: MacBooks, Mac Studios, hosted claw Macs, Tailscale, SSH, and OpenClaw.