Jfrog Package Curation

Check/download a package (npm, Maven, PyPI, Go...) via JFrog — safe, allowed, curated? Or: package op fails/blocked (ETARGET, 403, blocked by curation policy, missing version, waiver) — root cause it. Checks the JFrog Public Catalog and stored packages for a version, interprets catalog security signals, and downloads through Artifactory (JFrog Platform locations, remote cache, curation-aware package managers, or repo proxy). Do NOT use for pure CVE or vulnerability lookups (e.g. "details on CVE-2021-23337") — those are handled by the jfrog skill's Public security domain queries without this workflow. Do NOT use for installing, listing, or approving MCP servers/tools (even when named like a package, e.g. `@scope/pkg`) — that's `jfrog-mcp-management`.

jfrog 300f785 2 files · 50.8 KB Updated

File contents

jfrog/devin-plugin/tree/main/skills/jfrog-package-curation commit 300f7856fe

Frequently asked questions

npx skillmds@latest add jfrog/jfrog-package-curation