# NPM Package Auditor

> Audits NPM packages using the NPM Registry API with dependency tree resolution and vulnerability scanning via OSV.dev API. Generates SBOM in CycloneDX format and checks license compliance against SPDX expression parser.

- Skill: `agentskillexchange/npm-package-auditor` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/npm-package-auditor`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/npm-package-auditor/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Integrations & APIs
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/npm-package-auditor

---


# NPM Package Auditor

Audits NPM packages using the NPM Registry API with dependency tree resolution and vulnerability scanning via OSV.dev API. Generates SBOM in CycloneDX format and checks license compliance against SPDX expression parser.

## Installation

Use the upstream install or setup path that matches your environment:
- npm Docs
- npm package scope, access level, and visibility
- Docker and private modules
- npm License

Requirements and caveats from upstream:
- Downloading and installing Node.js and npm
- Try the latest stable version of node
- Creating Node.js modules

Basic usage or getting-started notes:
- Creating a strong password
- Receiving a one-time password over email
- About two-factor authentication

- Source: https://docs.npmjs.com/cli/v10/using-npm/registry/

## Documentation

- https://docs.npmjs.com/cli/v10/using-npm/registry/

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/npm-package-auditor-registry-api/)

