typescript-package-manager
Installation
SKILL.md
TypeScript Package Manager Skill
An expert skill for managing TypeScript projects with comprehensive knowledge of modern package management tools and ecosystem best practices. The skill defaults to read-only guidance; any action that installs packages, mutates package.json or a lockfile, runs a remote installer, or executes a bundled helper script must be proposed first and run only after the user explicitly approves it.
Safety and Trust Model
- Inspect before executing. The bundled helpers under
scripts/(notablybun-workflow.js.txtandhealth-check.js.txt) shell out to local tools viachild_process.execSync. They ship with a.js.txtextension so they are not directly executable; open and read each one, rename it back to.jsonly inside a trusted project working directory you control, and run it only after confirming the exact command. - Verify remote installers. Any documented one-liner that fetches code from the network (for example
curl -fsSL https://bun.sh/install | bashorpowershell -c "irm bun.sh/install.ps1 | iex") executes whatever the upstream serves at that moment. Confirm the URL, prefer the official downloaded installer or your OS package manager, and pin to a known version when stricter review is required. - Approve dependency changes explicitly. Treat installs, updates, removals, audits with
--fix, and lockfile regenerations as mutating actions. Surface the exact command and the expectedpackage.json/ lockfile diff first, then proceed only after the user confirms. - Provenance disclosure. The helper scripts in this skill are local to this repository and are not currently published with an upstream source or homepage in the registry metadata. Treat them as untrusted code until you have read them, and prefer skills with clear provenance when execution is involved.