npm Publish Payload Preflight
Review an npm pack file list for missing runtime output, sensitive files, and payload drift before publish.
What problem does npm Publish Payload Preflight solve?
A package can publish successfully while omitting built runtime files, leaking local configuration, or silently changing its shipped surface.
Use it to
- Review a pack dry-run before npm publish.
- Catch sensitive-looking files in a tarball manifest.
- Compare the current payload with a prior release.
What it returns
- findings.csv with stable codes and record identifiers
- review-manifest.csv with every reviewed item
- result.json with READY, REVIEW, or BLOCK gate
- report.md with a human-readable decision handoff
A representative input and result
Access and approval boundaries
- Read access to one user-supplied local JSON evidence file.
- Write access only to the selected local output directory.
- No browser, network, credential, account, environment-variable, or external-action permission.
Known limitations
- It relies on a supplied pack manifest and does not run npm or publish.
- Runtime output directory conventions may need project-specific review.
- A passing payload check does not prove package behavior or registry acceptance.
Questions
Does it change or upload anything?
No. It reads supplied local evidence and writes only to the selected output directory.
Is this an AI judgment?
No. The packaged checker is deterministic and applies documented rules to the supplied input.
What does a ready result mean?
It means no automated finding was produced. The responsible owner still reviews the original source and decides what to do.
How does malformed input behave?
Invalid JSON, duplicate identifiers, missing required arrays, and invalid core values fail closed.
Can I audit the result?
Yes. Every finding carries a stable code, record identifier, severity, source, and message.
npm Publish Payload Preflight keeps proof and approval boundaries visible.
The listing includes the tested package, realistic samples, declared permissions, and known limitations.
Get npm Publish Payload Preflight on Agensi