npm-security-best-practices
[Updated for AI 🤖] Continuous updates on how to stay safe from NPM supply chain attacks
npm-security-best-practices is an agent skill that instructs AI coding agents to follow secure NPM dependency management practices. The skill provides guidance on disabling lifecycle scripts, setting package cooldowns, pinning versions, and other supply-chain attack mitigations. Developers install it using the skills CLI, allowing agents to automatically apply security configurations when managing JavaScript dependencies across npm, pnpm, yarn, bun, and deno package managers.
Key Features
Use Cases
- 01Equipping AI coding agents with knowledge to secure JavaScript projects against supply-chain attacks
- 02Automatically configuring secure package manager settings when agents scaffold new projects
- 03Guiding agents to review and harden dependency configurations in existing codebases
- 04Teaching agents to recommend security tools and scanners before installing packages
- 05Ensuring agents apply cooldown periods and version pinning in enterprise development workflows
- 06Having agents set up isolated development environments with proper permission models
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
npm-security-best-practices — FAQ
What is npm-security-best-practices?+
It's an agent skill that teaches AI coding assistants to follow secure NPM dependency management practices, including disabling lifecycle scripts, setting package cooldowns, and pinning dependency versions across multiple JavaScript package managers.
How do I install this agent skill?+
Run 'npx skills add bodadotsh/npm-security-best-practices' to install the SKILL.md file that your AI agent will reference when working with NPM dependencies.
Which AI clients and agents does this work with?+
This skill works with any AI coding agent that supports the skills framework and can read SKILL.md files, including tools like Claude Code and other AI pair programmers that manage dependencies.
Do I need API keys or special prerequisites?+
No API keys are required. You need Node.js and the skills CLI installed, plus at least one JavaScript package manager (npm, pnpm, yarn, bun, or deno) that the agent will configure.
Is this free to use?+
Yes, the skill is open-source and free. It references free tools like Socket Firewall and OSV scanner, though some advanced security platforms mentioned have premium tiers.
What security protections does this skill enable?+
The skill guides agents to disable lifecycle scripts, set minimum package age requirements, pin exact versions, configure runtime permissions, use preinstall scanners, and apply other supply-chain attack mitigations recommended by security experts.
How do I install npm-security-best-practices?+
Open the source repository on GitHub and follow its README. npm-security-best-practices is a skill — MCP Agents Market links you directly to the official repo.
Is npm-security-best-practices free?+
npm-security-best-practices is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.