JustHandled Labs
// Developer Tools

npm Publish Payload Preflight

Review an npm pack file list for missing runtime output, sensitive files, and payload drift before publish.

What problem does npm Publish Payload Preflight solve?

A package can publish successfully while omitting built runtime files, leaking local configuration, or silently changing its shipped surface.

Use it to

What it returns

A representative input and result

fixture-backed sample
input {"package":{"name":"tiny-kit","version":"1.0.0"},"pack_files":["package.json","dist/index.js"]}
result READY; runtime payload present; new-file information recorded without publishing.

Access and approval boundaries

Known limitations

// choose with context

Is npm Publish Payload Preflight the right skill?

Best fit

A package can publish successfully while omitting built runtime files, leaking local configuration, or silently changing its shipped surface.

It returns

findings.csv with stable codes and record identifiers. review-manifest.csv with every reviewed item.

Do not use it as

It relies on a supplied pack manifest and does not run npm or publish.

Compatibility, access, version, and licence

Reads or accesses
Declared local scope: one owner-selected local JSON input, one owner-selected local output directory.
Compatibility
Normalized UTF-8 JSON input documented in the package. Python 3.10 or newer on Windows, macOS, or Linux. Local files only; no live account or provider connection.
Version
1.0.0
Licence
Review the package licence and seller terms at the linked destination.

What happens next

The Agensi listing opens at the current offer. Complete purchase there, inspect SKILL.md and its bundled files, then add the complete folder to your agent.

Questions

Does it change or upload anything?

No. It reads supplied local evidence and writes only to the selected output directory.

Is this an AI judgment?

No. The packaged checker is deterministic and applies documented rules to the supplied input.

What does a ready result mean?

It means no automated finding was produced. The responsible owner still reviews the original source and decides what to do.

How does malformed input behave?

Invalid JSON, duplicate identifiers, missing required arrays, and invalid core values fail closed.

Can I audit the result?

Yes. Every finding carries a stable code, record identifier, severity, source, and message.

npm Publish Payload Preflight keeps proof and approval boundaries visible.

The listing includes the tested package, realistic samples, declared permissions, and known limitations.

Get npm Publish Payload Preflight on Agensi