npm-research — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited npm-research (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill for in-depth npm package research: bundle sizes, vulnerability scanning, download comparisons, and dependency trees. No API keys needed.
| Tool | What it does |
|---|---|
search | Search npm packages by query |
package_info | Detailed info: description, license, repo, dependencies |
downloads | Download stats for a package |
compare_downloads | Compare download counts across multiple packages |
bundle_size | Bundle size (minified + gzip) via Bundlephobia |
vulnerabilities | Known vulnerability info and advisory links |
dependency_tree | Show direct dependencies as a tree |
download_trends | Daily breakdown with sparkline visualization |
compare_downloads + bundle_size for each candidatevulnerabilities on each dependencydownload_trends to see growth patternsdependency_tree before adding a new packagebundle_size calls Bundlephobia — some packages may not be analyzable (native modules, very large packages)compare_downloads accepts multiple package names — ideal for "zustand vs jotai vs valtio" comparisonsvulnerabilities checks npm audit advisories — always run this before recommending a packagedownload_trends includes a text sparkline for quick visual trend assessment~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.