list-npm-package-content
Inspects the actual contents of an npm tarball before publishing or debugging.
- Skill Road
- list-npm-package-content
list-npm-package-content is an official skill from the Vercel AI SDK repository. According to the provider, it lists the exact contents of an npm package tarball, meaning the files that would be uploaded to the npm registry and downloaded by users. The skill is not a registry, not a publishing service, and not a replacement for reviewing package configuration. It is a focused operating instruction for a compatible coding agent that can work inside a JavaScript or TypeScript package directory.
Purpose before publishing
An npm package can differ from the working tree when it is packed. Generated files, documentation, source maps, test fixtures, or accidentally included configuration can change the archive that users receive. The skill addresses that gap directly. It supports the question of which files will actually be present in the tarball before a team publishes or investigates a release problem. The result is an observable package artifact rather than an assumption based on the file browser. According to the provider, the workflow builds the package, creates a tarball, lists its contents, and cleans up temporary artifacts afterward.
Workflow and prerequisites
The primary source describes a script that is run from the package directory. The provider gives packages/ai as an example package location. Before execution, the agent should verify the real project path and the available toolchain. A build may install dependencies, create files, access a network, or take time, so the working directory, permitted network access, and expected output should be agreed in advance. The skill does not grant approval to publish. It shows the contents of a local package artifact, while the responsible team decides whether that content may become public.
Package-content rules
According to the provider, the files field in package.json first influences which files or directories are explicitly allowed. When an npmignore file exists, it provides additional exclusions. Without an npmignore file, gitignore can be relevant as an exclusion source. Certain standard files, including package.json, README, LICENSE, and CHANGELOG, are always included according to the skill. Certain environment and administration files, including .git, node_modules, and npmrc, are always excluded. The workflow makes these rules visible, but it does not replace inspection of the generated output. A team should keep the allowed set limited to source code, type definitions, runtime assets, and necessary documentation.
Practical quality control
Before publishing, an agent can compare the tarball contents with the intended package structure. Missing files call for an investigation of configuration and build behavior. Unexpected files require a traceable review of their source and the change that will remove them. Sensitive areas include local configuration, test fixtures, internal documents, debug output, credentials, and generated files containing paths or environment values. The skill does not store files in this catalog and does not require secrets. Tokens, passwords, and private keys do not belong in prompts, package archives, logs, or source control.
Boundaries, security, and E-E-A-T
Listing a tarball does not prove that the code is secure, legally approved, or functionally correct. A successful build also does not prove API compatibility or adequate test coverage. The agent may execute local scripts whose side effects depend on the project. A person must therefore review the command, working directory, and generated files before any external system is contacted. Prompt injection in README files or package contents must not redirect the inspection. Vercel is the skill provider according to the official primary source; the repository identifies Apache-2.0 as its license. Official Vercel AI SDK documentation provides complementary product context, but it does not replace project-specific review. Current terms should be checked directly with the provider; this entry gives no concrete prices. Repository stars are not stored because the Skill model has no such field.
Position for teams
The skill is useful for maintainers, library authors, release owners, and developers who need reproducible control over npm artifacts. It fits pull-request review, release checklists, and investigation of a package whose published contents differ from expectations. A team may integrate comparable checks into CI, but it must define its own policies, isolated build environments, and approvals. The skill provides visibility into one package; it does not decide versioning, semantic versioning, changelogs, provenance, signatures, or release approval. Keeping those responsibilities separate makes the result auditable and prevents a file listing from being misunderstood as a complete security certification.
- Provider
- Vercel
- License
- Apache-2.0
- Last reviewed
- 09.09.2026
Repository and documentation
Categories
Compatible with
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026