Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add dhaupin/vant --skill vant-skill-npmgit clone --depth 1 https://github.com/dhaupin/vantWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dhaupin/vant/vant-skill-npm)<a href="https://agentmods.dev/skills/dhaupin/vant/vant-skill-npm"><img src="https://agentmods.dev/badge/skills/dhaupin/vant/vant-skill-npm.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00007 | $0.00353 |
| Opus 5 | $0.00003 | $0.00177 |
| Sonnet 5 | $0.00001 | $0.00071 |
| Haiku 4.5 | $0.00001 | $0.00035 |
Grade A, and why
npm scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
NPM
Node.js package manager.
When To Use
- package.json exists
- node_modules present
- JavaScript/TypeScript projects
What To Do
1. Common Commands
| Command | What |
|---|---|
| npm install | Install deps |
| npm add | Add package |
| npm run | Run scripts |
| npm test | Run tests |
| npm start | Start app |
| npm build | Build |
2. Install
# Install all deps
npm install
# Add package
npm install lodash
npm install --save-dev typescript
# Global
npm install -g typescript
3. Run Scripts
npm run dev
npm run build
npm run test
4. Package.json
{
"scripts": {
"dev": "vite",
"build": "vite build",
"test": "jest"
},
"dependencies": {
"lodash": "^4.0.0"
},
"devDependencies": {
"typescript": "^5.0.0"
}
}
Output
## NPM
| Package | Version | Type |
|---------|---------|------|
| [name] | [version] | [dep/devDep] |
### Scripts
- [list]
Role: NPM Manager
Input: package.json
Output: Dependencies
Node packages.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 98 lines · 7 tokens per session scan A 45adb2ed4032
npm is a skill published in the GitHub repository dhaupin/vant (9 stars, last pushed 8d ago), licensed MIT. It adds 7 tokens to every session and 353 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
rn-best-practices
This skill should be used when writing or reviewing React Native / Expo code — before writing list rendering, animations, data fetching, component APIs, navigation, or image/media UI — and when asked to "review best practices", "check performance", "optimize renders", "review list rendering", "check animation…
rn-feature-dev
Explicit Codex workflow: Guided feature development for React Native — explore codebase, design architecture, implement, verify live on device, and review quality.
vercel-composition-patterns
React composition patterns that scale. Use when refactoring components with boolean prop proliferation, building flexible component libraries, or designing reusable APIs. Triggers on tasks involving compound components, render props, context providers, or component architecture. Includes React 19 API changes.
vercel-react-best-practices
React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance…
dashboard-plugin-scaffold
Scaffold a new pi-dashboard plugin in the dashboard monorepo, OR augment an existing pi-extension project on disk with dashboard plugin contributions. Hybrid skill: a single askuser batch up front, then prescriptive steps the agent follows. Use when the user asks to "create a dashboard plugin", "add dashboard support…
component-architecture
Reusable component patterns for cards, sections, forms, and layouts with consistent prop interfaces and composition strategies. Use when creating new components, refactoring existing ones, or establishing component design patterns.