PluginBench
Skill
Official
Pass
Audit score 90

list-npm-package-content

vercel/ai

List npm package tarball contents before publishing to verify what gets uploaded.

What is list-npm-package-content?

This skill lists the exact files that will be included in an npm package tarball—the same files users download. Use it to verify package contents, debug publish issues, or ensure only intended files are bundled.

  • Lists all files that will be included in the npm tarball
  • Shows the exact contents users will download
  • Helps verify the `files` field in package.json is correct
  • Identifies unintended files being bundled
  • Supports debugging npm publish configuration

How to install list-npm-package-content

npx skills add null --skill list-npm-package-content
Prerequisites
  • Must be run from a package directory (e.g., `packages/ai`)
  • Requires a `package.json` with valid configuration
Claude Code
Cursor
Windsurf
Cline

How to use list-npm-package-content

  1. 1.Navigate to the package directory
  2. 2.Run `bash scripts/list-package-files.sh`
  3. 3.Review the output to see all files in the tarball
  4. 4.Check that sensitive files are excluded and required files are included
  5. 5.Adjust `files` field or `.npmignore` if needed and re-run

Use cases

Good for
  • Verify a package tarball contains only intended source files before publishing
  • Check that build outputs are properly included in the bundle
  • Ensure sensitive files (credentials, tests, node_modules) are excluded
  • Debug why certain files appear or disappear in published packages
  • Validate `.npmignore` or `files` field configuration
Who it's for
  • Package maintainers
  • npm library authors
  • DevOps engineers managing package releases
  • Developers debugging publish workflows

list-npm-package-content FAQ

What determines which files are included in the tarball?

The `files` field in package.json (allowlist), `.npmignore` (exclusions), or `.gitignore` if no `.npmignore` exists. Always-included: package.json, README, LICENSE, CHANGELOG. Always-excluded: .git, node_modules, .npmrc, etc.

Can I exclude files from the package?

Yes, create or edit `.npmignore` to exclude specific files and directories. If no `.npmignore` exists, npm uses `.gitignore` rules instead.

Does this script modify my package?

No, the script builds the package, creates a temporary tarball, lists contents, and cleans up automatically without leaving artifacts.

When should I run this before publishing?

Run it before every publish to verify the bundle is correct, especially after changing package.json, adding new files, or modifying .npmignore.

Full instructions (SKILL.md)

Source of truth, from vercel/ai.


name: list-npm-package-content description: List the contents of an npm package tarball before publishing. Use when the user wants to see what files are included in an npm bundle, verify package contents, or debug npm publish issues. metadata: internal: true

List npm Package Content

This skill lists the exact contents of an npm package tarball - the same files that would be uploaded to npm and downloaded by users.

Usage

Run the script from the package directory (e.g., packages/ai):

bash scripts/list-package-files.sh

The script will build the package, create a tarball, list its contents, and clean up automatically.

Understanding Package Contents

The files included are determined by:

  1. files field in package.json - explicit allowlist of files/directories
  2. .npmignore - files to exclude (if present)
  3. .gitignore - used if no .npmignore exists
  4. Always included: package.json, README, LICENSE, CHANGELOG
  5. Always excluded: .git, node_modules, .npmrc, etc.