{"_id":"@rhize/skill-forge","_rev":"29-ff23659473c36c63a9101d8dc54ee637","name":"@rhize/skill-forge","dist-tags":{"latest":"0.22.0"},"versions":{"0.1.0":{"name":"@rhize/skill-forge","version":"0.1.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"MIT","_id":"@rhize/skill-forge@0.1.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"53ad7f7ef8081412e0d571af93ddfbaeca11603c","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.1.0.tgz","fileCount":5,"integrity":"sha512-bdA3TuVR5qvuQ00NaTSEspFeTL8Q3ume4Y4201U2CIocu5HPSCwYa2/fhKo83Hac0Y8JvnVnMnXMOOMP5ivt9A==","signatures":[{"sig":"MEQCIF4ZxbBAQ4wCkd/CoFh4My4rC2MxgTpBny0jxgFoRXvjAiBDmcb6h0QGB8yYUNJHQVTp8OUIfVnCBhtbfe/Cg+QJVw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165449},"type":"module","engines":{"node":">=18"},"gitHead":"899e822d78aa15e22a03d210da126b372695b550","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"jdeola","email":"jim@rhize.media"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"11.18.0","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"26.4.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.1.0_1783796989639_0.5754612982080267","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@rhize/skill-forge","version":"0.2.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.2.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"dc942cb41272c5b177d8037efcbb115e364d8623","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.2.0.tgz","fileCount":7,"integrity":"sha512-HhIWETRTZdHzWPnh7DtpbTc7mH/rTNS2/wjywYlvv8qMoqRfvnza0mBSTDYUGmWDDKgiQDnTk9jgjxzXryOKRQ==","signatures":[{"sig":"MEUCIEv1J6fZe/AZfuOC/2hOHXyUgEihwoP6gpyosOxMd0dvAiEAwSENQaI4itAV5BC6Tjpo2vA69cGR+kz5/PP7cHweSvc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":170040},"type":"module","engines":{"node":">=18"},"gitHead":"2184e75a12d0a6a9605a44153152e7e7d495ad07","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.2.0_1783799153548_0.37930264541726855","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@rhize/skill-forge","version":"0.3.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.3.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"00c86daab940d6596f8cf80e453fc6a2cb558dc3","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.3.0.tgz","fileCount":8,"integrity":"sha512-H9n2E8MtKRERdjGlk4Q+5jjg6R6rYrt7by0/KEyHDpNZmcxvRAPfU1IPL9P1MXqx4bxfLVKcZu0zy6WTmi2GaA==","signatures":[{"sig":"MEUCICgJN3c1f2NamxOX30ZakgYu7z7GX8EgRPcvOUFKxzh2AiEAheHrKCLW0mU/aQwvkDZVVW1ON3JdGe9jiSF+aHQfc6g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":257671},"type":"module","engines":{"node":">=18"},"gitHead":"f14ef4ff92523d0e93ebeb43cc353bf4eaa11f3a","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.3.0_1783822108144_0.7718406319434996","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@rhize/skill-forge","version":"0.4.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.4.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"dfeb3afc44f9d8813c09e6999173528ceac6d9b6","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.4.0.tgz","fileCount":8,"integrity":"sha512-1agkqjk9qWJjM5xy19cuku9LlL1Z3V1pxyoYjzOIN5M3JV9TB1HvtsAhDYUztyvYrBBHo6u9oUg4dyPm9SMG5w==","signatures":[{"sig":"MEQCIFrVxkT6TmagisIvUQp9QXIQAZ03bA54pR/0CfyZ8F/vAiB3i8PpzAMtmes5sxoqwahW5dOG4v2+GfysxYIgimFe3g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":263896},"type":"module","engines":{"node":">=18"},"gitHead":"a431b04ffbb7652607bad0ffdfdacf050369e334","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.3","@types/node":"^22.10.5"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.4.0_1783825731936_0.3592756806193065","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@rhize/skill-forge","version":"0.5.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.5.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"a29e8c3016f31bdee51ad25ad4e1184e5367a9e5","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.5.0.tgz","fileCount":8,"integrity":"sha512-Vs1y4VndeHBKnlg2o2S6D456hkMINsXvCAyIdMp24Q8jsmVHr1kWLSnEPBitfT0bI406VxC56uBqfBjFxT6LHA==","signatures":[{"sig":"MEUCIQD+g/HbvlQ8+5ObBkCpgkEY/Weh3pVRdn6RZ1YQuuCU3gIgac9qJuyjyuEfUx+otQXpZwk4Fnreik+B/zrIbF2H+w8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":371444},"type":"module","engines":{"node":">=18"},"gitHead":"2a4c76dfef5ad68083cd8ea4229a49c9683c735f","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.5.0_1783873299001_0.5693168092656047","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@rhize/skill-forge","version":"0.6.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.6.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"a047d14af24a3cb220bf87070b56522e15786795","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.6.0.tgz","fileCount":8,"integrity":"sha512-b7GK09G4MNlRGfKzBFeictLGOjDleoWfWqAG8kY0r4PiYP+NH4sK+n2qmCkX4jfwWJWi9hQeBPAjMac6AjLR4Q==","signatures":[{"sig":"MEYCIQD1kPb4VjhyzNv919WemG7nrS03Xh84d5ar9s9TK0VnGAIhAKREIBjghpH6CUEpZigoOEWaxeb5E2lRyliRBGj2PIz7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":403240},"type":"module","engines":{"node":">=18"},"gitHead":"2a8d305bd577273e44b2389b66d43c612b805799","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.6.0_1783883475223_0.5640171087288037","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@rhize/skill-forge","version":"0.6.1","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.6.1","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"bc62b5432816330767ea2ca4de8ff5e0c6db3500","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.6.1.tgz","fileCount":8,"integrity":"sha512-EB0Z25TymKOHnxgmY1fWTXb2eqALYdBI0VS3htjMb7eyr8UuYbuBYYF6FxgSZM+lvfeGCZiSA8HmMwWgdIfNWA==","signatures":[{"sig":"MEUCIDgqnRqqsjKq3taCOnOd/B1/xzF0inYDymU2xwnwyLUCAiEAmxxXc2UpvIU57Vf4C0nSP0bIj6TRSA8wS8hLoFGTrf8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":405644},"type":"module","engines":{"node":">=18"},"gitHead":"bdc3b453aa1be7377ffc4b07c958f39e8c50e985","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.6.1_1784324871090_0.1116163230627436","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@rhize/skill-forge","version":"0.7.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.7.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"588b371bf659f9ea61e15054998eca40a86d9d67","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.7.0.tgz","fileCount":8,"integrity":"sha512-l8limeQ2lU8M2EFo/Bm3YqN9nFX/BE9ngePlcIb6FyIVl4/VjnmhzxZbPhO1hQMxEqN51cJK+/UUAfE6HgeAtw==","signatures":[{"sig":"MEYCIQCzFMgEsAjd1Nr+7CJ/AHnckuep2JMTweYTKyCiOTDgMQIhAIpeorniASM1NYqFPhapQ3CeKtf+wbSCSPr89s2cxewU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":464523},"type":"module","engines":{"node":">=18"},"gitHead":"49715b8edcc2b8986e533755b3f64897440bac1c","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.7.0_1784347923767_0.24816478396175334","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@rhize/skill-forge","version":"0.7.1","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.7.1","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"f9dc2ca6b49b1fd0f820cf29d626a8494fffe99f","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.7.1.tgz","fileCount":8,"integrity":"sha512-Gw6JDEl0/AJSAoeFv+XO/54fYrG5xM2By3oaXbXWBUd+dDFQcV3PMYU9Qyh1vcq89UhsoPEtZnL4xGOqBEJlXQ==","signatures":[{"sig":"MEYCIQCu4XkuTkh96GS0Y58Ksvr1bHFefnlrvRETHevl6pPTyAIhAMmPUTnN2tv/QxavSwqjorMrwvdCXyuKfb96aotDYHKh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":484606},"type":"module","engines":{"node":">=18"},"gitHead":"b04bf42f7e8c173c018adffd483b0a4fb0693349","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.7.1_1784392598020_0.13854226078689802","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@rhize/skill-forge","version":"0.8.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.8.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"165a7d29211dbe24f3eb98bc220d27265f1c84aa","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.8.0.tgz","fileCount":9,"integrity":"sha512-wnAa8EfT0RZJzvNNMB0KTfo8ma0a+BzA2NuTZKshpbBeB1Q+KEq79XU4qvPKPVtdpg2+R1nemEKZiT/uQfMteg==","signatures":[{"sig":"MEUCIGp/XF+X30UW7Nkq87pqn2BRi/WEg8W6sBvcqog7cw6lAiEAlshDyIq+a8pDZl99LPOmNcBmIppFvEvFUiPTRdtyji4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":614463},"type":"module","engines":{"node":">=18"},"gitHead":"bdf737a785319335fe13fd89d01e050d5b00d1c4","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.8.0_1784568136473_0.7095253624872411","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@rhize/skill-forge","version":"0.9.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.9.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"ba3b7bfdba021dcc1218411b8f4a6a7bf9aed0e2","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.9.0.tgz","fileCount":9,"integrity":"sha512-hD4PHjGi+tj1NxPkfn8t7SrNUk699ee/KunIQwgh9zN73ovJAjq2tBdhbhpBhwyRYWL+Urh5eCWT4gpewAq1Ow==","signatures":[{"sig":"MEUCIDEEdfeQw/r3YW06idz/ZeniSsCdy6EDs3lKh95wFrtxAiEA9wQM8/C6dUtmyECghWYk34TBgSZ0BWwMnGFYYi9CBp4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":775640},"type":"module","engines":{"node":">=18"},"gitHead":"e465e974b1f383430a9806707bc2cf2b14580f29","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.9.0_1784579068828_0.9246939015586522","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@rhize/skill-forge","version":"0.10.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.10.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"86b7a7ea9df3340e50215e7d14aeb939b4294993","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.10.0.tgz","fileCount":12,"integrity":"sha512-c5edlKA/KhVwz1af1y0M3dh7ASf7D4LIyO1YSvqRvb4ZO0kR0Z5i9a7z2pR48jqjp0DV46e3J8x9PrrHWEnNOw==","signatures":[{"sig":"MEUCIHlvsW49+F7HNsg/e6bRdYwPma6FGUnGYPO/9lHZYC2pAiEAuCdsOyev7doyYt3tbUlpq9uO1fJW4FsPm/2WkJIFpTc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1054186},"type":"module","engines":{"node":">=18"},"gitHead":"9d643c362cfd8a3bdcffd32930a8f529e1209969","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.10.0_1784589499544_0.7978900718121713","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@rhize/skill-forge","version":"0.11.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.11.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"f967f44579134062756e573ef6ce23ba04640da7","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.11.0.tgz","fileCount":12,"integrity":"sha512-eANVlH9TAeAzxSAmYOweuERjUZSgIjP64V5NfUbyoOlR8XKnGXBWxF/VSRr8qu0qp38ABh+6SPCKgq0jshfWMg==","signatures":[{"sig":"MEUCIQC0Elk0PMeajEPhDrggBIvWJRKrHGwvgIDNJZCjDnLRpQIgbaQv9xqpmooGzZhPPK8pBfiPUgGefpQvszGOfhQvWCM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1263492},"type":"module","engines":{"node":">=18"},"gitHead":"afd2145400d3a4d948ae3fd7589ca09766fb32aa","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.11.0_1785186599488_0.7204223461025485","host":"s3://npm-registry-packages-npm-production"}},"0.11.1":{"name":"@rhize/skill-forge","version":"0.11.1","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.11.1","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"9f814ae6feb58f81688463b524711dceb8073dba","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.11.1.tgz","fileCount":12,"integrity":"sha512-LHeUAomM4TZnTyKuxQcTBETavxd9rFTXfOTPJ5zL/7OmhBIFCn0mBw8+YltmQPKhBVqRKfldyB7ZeWSrwJjdrw==","signatures":[{"sig":"MEQCIFn6JfhFb9lMxFSaV2HJvSIeZbXdfnWV5hBAp3iQ6Q0OAiAH810PvuUr31PkOtggFYpKLH3WXlK9IvUixLYc3qoJ+A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1283399},"type":"module","engines":{"node":">=18"},"gitHead":"9d3e574662825c74dd446fd9bc439c8421d31ea0","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.1","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.11.1_1785187584544_0.4714213624983583","host":"s3://npm-registry-packages-npm-production"}},"0.11.2":{"name":"@rhize/skill-forge","version":"0.11.2","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.11.2","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"125814ab9d6a2445803b94650800fdddf0aa5273","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.11.2.tgz","fileCount":12,"integrity":"sha512-YGI2G0xBD6lUaCwSFs7RkmpYUjQDo/ZI/i5+IQGcojEeCvkFmzjQzAddV6g6EYJB+FINf9imjpIkL4sCRXgzzg==","signatures":[{"sig":"MEUCIH3nY6/RYDhLuLwoQ6ZJf7R44LVJ2e/fg2vRQJv5qGvVAiEAiEqMzi1PxaM0+Yw88Ea25govGca/LQbkaMORRhOhdWY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1291093},"type":"module","engines":{"node":">=18"},"gitHead":"807da0dae216e021deea9c0c3ff2e6963c81e284","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.11.2_1786285462018_0.9365837887215602","host":"s3://npm-registry-packages-npm-production"}},"0.11.3":{"name":"@rhize/skill-forge","version":"0.11.3","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.11.3","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"6faabc2671b1aa29c984c157dad4fd7ad35f70c7","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.11.3.tgz","fileCount":12,"integrity":"sha512-CzQeNSv6CTe3TnEIMgNONtg7zMWGXa/JzI87airbdLZTyGSqTbOvM90C42StwjCTPeAyvosit7CGeV7BVbFmuQ==","signatures":[{"sig":"MEQCIGgoEtuxvq3vYNfIfLu1OzQwpWTELgYPgKCy/LmUcxYXAiA8+qago0GJhiVExm0+Q8QttvOR2NKmWAHfKv/7uRI7zA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1297753},"type":"module","engines":{"node":">=18"},"gitHead":"a5496e93ea5a322bc58f08a7c7bb2de2627d5341","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.11.3_1786286254726_0.8076513924894186","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@rhize/skill-forge","version":"0.12.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.12.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"4a64257d5679890d4ae893e6444dd09de29a52c5","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.12.0.tgz","fileCount":12,"integrity":"sha512-GST+iIg2oTDtZJOfkckqVwUZW6Rq7OcuQBnWFc3Sxo1bvjPWeCU0VA8byNu+Qa7F/4yDcZThLXM6c9f2O7IXzA==","signatures":[{"sig":"MEUCIQD0IsCs2dgIEU/5JkcjNmibNvZNayYkw0h2P/2+l9D3AwIgUJQHYSypH4o2AMvJ0ufB7eZbGMZ7N8AzLw0ScyWDuio=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1399932},"type":"module","engines":{"node":">=18"},"gitHead":"06def7e4bd098b037e89628864bbdf4a3c352f3b","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.12.0_1786291704659_0.5011749027997685","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"@rhize/skill-forge","version":"0.13.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.13.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"ca687aa04f71bec07dbd0c8d6eaac093c01e6678","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.13.0.tgz","fileCount":12,"integrity":"sha512-aa5lVdmyxE2l1M1qDALKQ74W531TsCd13jWMq3uwGscfpF4MyJuMFOwSkWghMKI9ZMwuZ5c+FWL7pQkkvMG9aA==","signatures":[{"sig":"MEUCIDueKfO/B9mbx+DQz0rNi4bVVIgz4kX0oMAqOukJphVWAiEA6vE6qaAJovYaRV+hUZQgrTJ87HoyuUZngJSUM+33JP4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1427109},"type":"module","engines":{"node":">=18"},"gitHead":"4766cd88c5e9f2821204beccb6c2f20326700b9b","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.18.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.13.0_1786376722334_0.40202028884826513","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"@rhize/skill-forge","version":"0.14.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.14.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"eadf9a17d5025e98d9ede198a07d1785ebc6ec04","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.14.0.tgz","fileCount":12,"integrity":"sha512-YskDg1wFbMWartZ1os+SxYUyyT14KHQqM94rhZ+5LgipFZGigKfpOv5FLtkKlLjZ4ZxKWVAqtNqBz0DKTyiY5g==","signatures":[{"sig":"MEYCIQDkyDHcr8uI4HSEA44ngCp4F3/GCVLctGIwQQOIq0MsewIhAKO70pjxitgxpiPxR8HWFh5f8Bb/FD6e3kt/azSZLUdO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1434790},"type":"module","engines":{"node":">=18"},"gitHead":"49e81a422aa9863c8061fc102fbdb286a5900bce","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"jdeola","email":"jim@rhize.media"},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"26.7.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.14.0_1787658205445_0.07819838203281715","host":"s3://npm-registry-packages-npm-production"}},"0.16.0":{"name":"@rhize/skill-forge","version":"0.16.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.16.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"21a1d71b8d407b6a8477bc571d6d0a8ccc4644ae","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.16.0.tgz","fileCount":18,"integrity":"sha512-QgHM2fBM69kZi+vSan4dGulBOpDt8fzhvxMGsOJ+CX/Vftv4qshV8z6mFbKPjR3jaCFnOxBL7QSuL/mzs1hbXg==","signatures":[{"sig":"MEQCIH7re9sR6NLMia4bHGxJTGbhsCaVVbmErKvhKki5c+76AiAdwrBps70v5WxRUPXjCzU5wj7qQ2WmY3ngSnefUHB0DA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1792579},"type":"module","engines":{"node":">=18"},"gitHead":"314bf5c5e63fb21adfc9252fd48246c34654ce95","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.19.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.16.0_1788377695174_0.18005072848278836","host":"s3://npm-registry-packages-npm-production"}},"0.17.0":{"name":"@rhize/skill-forge","version":"0.17.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.17.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"cb043a7d658ffa9dce9a5d7b666d3873789216ad","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.17.0.tgz","fileCount":18,"integrity":"sha512-pDMPdmwPk0wi2QbV91Cd/X3lmx/8k2A7yyL5F+gGb0nbvu6p5kmPfzSqis4JCOyeGS6LZHRJxm43l6DS3HytLA==","signatures":[{"sig":"MEQCIBR41HoqHj7LjGeAAE6SPFxYsZZnhYBRLaP+TtYfaF3lAiAr+vPrl2dIJYQVVIGrAuQXRrnx+R+TYKMjbXdtmi3BAw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1908400},"type":"module","engines":{"node":">=18"},"gitHead":"a956fdd0e284cb8074556a8516ec2ad0b86e7f5f","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.20.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.17.0_1788612503278_0.35983051949816103","host":"s3://npm-registry-packages-npm-production"}},"0.17.1":{"name":"@rhize/skill-forge","version":"0.17.1","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.17.1","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"15ac327e4a9a5b09eb65a8b7c90629b168dcaca8","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.17.1.tgz","fileCount":18,"integrity":"sha512-Y4YD91gEY/MblX7WzqL+BJkeUpAZ560KXt1ELgwZJvgpfRLjkTeNhniJY3Zj/XApSKzcThmDWmrXo5dc+bGflQ==","signatures":[{"sig":"MEQCIGwhsXikG3kp/OY6RGmqT9IIJS78naixMLBpCVgKW6o4AiBcYOv3dkQwk++dC0hvTRXGWuZNzyIJPzN4IO4sEtb+hA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1923870},"type":"module","engines":{"node":">=18"},"gitHead":"58bbd08e26e98979265e04b9bc0cec3a6f4ab2f0","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.20.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.17.1_1788616363006_0.2667846498515254","host":"s3://npm-registry-packages-npm-production"}},"0.19.0":{"name":"@rhize/skill-forge","version":"0.19.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.19.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"9327b946579c60a53d61026208d75edb2af8ec02","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.19.0.tgz","fileCount":18,"integrity":"sha512-tcOWRXCeV0F4h+nCnO8acYjfLT/TtM1KYv+Uhj5l6oLr/qyxR+sb/Blp/e40RmaxJArrXz2CfcYlA0ZYxyiAjQ==","signatures":[{"sig":"MEUCIFl27vtguKE5wmTutcElhP7PFMkqa6IMLqt4Wm4YlUwhAiEA/76csUKgAH1ZfnkaGfAsLrQdtS+eSChgGDSjl4DAFyI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2014198},"type":"module","engines":{"node":">=18"},"gitHead":"ff639f38025a978200aa3d6a1bd0b676016dc0f8","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.20.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.19.0_1788625263548_0.9854651614121301","host":"s3://npm-registry-packages-npm-production"}},"0.20.0":{"name":"@rhize/skill-forge","version":"0.20.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.20.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"80427826141bceb25902a5b61e81b963427abe94","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.20.0.tgz","fileCount":18,"integrity":"sha512-YWvfSPLnF8l3Pi2JF4NWq4r8Y9r2aRDkKq53kG1KUaa6e9bYb1B0X6t8Tm+hsOAuu0VAxgU42/t3IUqeWZ2PnA==","signatures":[{"sig":"MEUCIQDmpDckcOaBVEAnCwOjCm67x+ZQ5BEc6llCT3//mfp5dgIgbDIeIsXY7Y0aMY4RxLsz0nZKJwwXrVtv2UTuCw9ii1w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIEepdevi9HDrOfP3cviv6V0RLPA3oKwMuddN7EZYU5TSAiEAjK/gaoPQ3mKqoX/rEVtsTehVkRkkbaZeqQsSZQZeq9w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2042453},"type":"module","engines":{"node":">=18"},"gitHead":"8678dd73cc9ea6c51f7af5f0523a7944ac55089d","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.20.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.20.0_1789407369065_0.5348931796944603","host":"s3://npm-registry-packages-npm-production"}},"0.20.1":{"name":"@rhize/skill-forge","version":"0.20.1","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.20.1","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"64b64037e4adb2d47626d3def8411bbcf4c85f15","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.20.1.tgz","fileCount":18,"integrity":"sha512-g7UzTX8AxtpZyksXGH1atVkaxBd8Sn6ey4DgLuHoZBaIUY9QeLS8rtw9SzES2hH99zOMDjw49dAkhtby3mpn+A==","signatures":[{"sig":"MEUCIQCDfVKKApgR99KxxfO+ye1psVvbVD1R3XHcXHvRh4Cl5wIgVEHyPA/nuvHrW0m7QQgW22PbYxLBRSJtyxP9mz0IuEg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGmEzVe0Unz/1wmVdb+nzBV3R1JN7aMB7f/0NjILc98uAiA7pZ/g0ipelsKMSsCtglQWazVciC6rlil3iR3vP9mcJA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2049391},"type":"module","engines":{"node":">=18"},"gitHead":"feab09cb12421be9ddd2ccf87ece31be2c3ccfad","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.0.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.20.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.20.1_1789493218515_0.0034223413388474455","host":"s3://npm-registry-packages-npm-production"}},"0.21.0":{"name":"@rhize/skill-forge","version":"0.21.0","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.21.0","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"23d1d401f67989577c91d9f4f3c7f3497c08ea3b","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.21.0.tgz","fileCount":18,"integrity":"sha512-Cp/6wGRnqAM/xHqj21qQ90vPR3I6DeEaizmMy8xDr+OO2XIYdV9VK6ASeBouLGFQjTzGm+usrfdNHd5QfpO8XQ==","signatures":[{"sig":"MEQCIGy/mL8flhQrGWgS50bthSV7w9ZtKhmz+Z0jO0k3oAsNAiAZfDTYphnNXBjqsQsGrCOnqVXc54EL+De1SlB+bktbrg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFdZ31NgT1FiR6X/Z0kwpxFL0PmnYWSK+0jWsgYCOTsbAiEArIz6VvxY/Iy3USHhujFqKGyDCOM9NBG0gbZf2qwt1H8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2067396},"type":"module","engines":{"node":">=18"},"gitHead":"3c71d18605e1acf28082ceb4d03cec7fd82e92a0","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"12.1.0","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.21.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.21.0_1790363080786_0.4663691747826726","host":"s3://npm-registry-packages-npm-production"}},"0.21.1":{"name":"@rhize/skill-forge","version":"0.21.1","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.21.1","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"d4f3a8e6e12c0fdbf277541e8f5b42cfb8f9e81f","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.21.1.tgz","fileCount":18,"integrity":"sha512-HAR7ck0cs/D/LjyRv0wLnesOY3Vb1EEzhyJmWtje9I/GVGmlm/Y6eE95reSuS0JOzmgbs694N7FDWsQYL0/RAA==","signatures":[{"sig":"MEYCIQCOUM6d1qoSrNnIOSh+T46RWA1WMACZyYl0xq+nMAFBywIhAKCrYSEeyLwXU5YfEwh2aarI/OJ01I6DNq2Nz+UWWC6U","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQC2qcLc3/jG9gWfNWBKEBCRSUoxlRc8YOlf2aUHeAjyJwIgUJVplkDS+flEGSadEZRllR48Nrltayg1tGSa5E+LVIw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2096250},"type":"module","engines":{"node":">=18"},"gitHead":"6895a68018b9c446245a32e59e4516e647f438e3","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"11.6.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.21.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.21.1_1790602461991_0.10480059698786581","host":"s3://npm-registry-packages-npm-production"}},"0.21.2":{"name":"@rhize/skill-forge","version":"0.21.2","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"license":"SEE LICENSE IN LICENSE","_id":"@rhize/skill-forge@0.21.2","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"homepage":"https://github.com/Rhize-Media/skill-forge#readme","bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"bin":{"skill-forge":"dist/cli.js"},"dist":{"shasum":"927ab031fdeb85d59a54c2687363a0fa65676c45","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.21.2.tgz","fileCount":18,"integrity":"sha512-SpCOYYTmTFv7qaXUexWiqPhl7ndlDsu0+2EBTBehxRTmQAAjTgUpTB8eWPM7KGQHtAbtm77wC2zXkfCJ7xMe/A==","signatures":[{"sig":"MEYCIQDBGqXcav4b7Gg5joLn7fZm87YGDKUss9aB6CrYb61k3gIhAOQ6T+1queQbaHA3nHyfJ2unGD0vcT5UCFFsjpLdfIwS","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIHVEaw0t0lt9qK4tSrtGExLT9nfZ3leUBZRZb040+3sTAiEAmXyLUmqm5Vqscg6HWEuVtjC87SJbqeLEkgl2mWrGY7k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2102598},"type":"module","engines":{"node":">=18"},"gitHead":"e43b982681fd12dccd08b6210e918131736ce874","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:84ad46cd-59e8-41c3-9659-3133e3305389"}},"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"11.6.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"_nodeVersion":"24.21.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/skill-forge_0.21.2_1790622122908_0.08801866488495902","host":"s3://npm-registry-packages-npm-production"}},"0.22.0":{"_id":"@rhize/skill-forge@0.22.0","bin":{"skill-forge":"dist/cli.js"},"bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"dist":{"shasum":"65d1effbad32de64a483cbeb38dd942e6a389a33","tarball":"https://registry.npmjs.org/@rhize/skill-forge/-/skill-forge-0.22.0.tgz","fileCount":18,"integrity":"sha512-nGXdSukz7VtHR5r16EjU+Js9TdE+MFhrsu0XxaaDu1WAruD6n1m0jshxO2YSbSfNqLUOnsnjazxNcgDAZzZnfg==","signatures":[{"sig":"MEYCIQDlcbQz/3sQfYbI0a5TPj7094iH1lnwefLDztX6azYlvwIhAMH4L9/5cQeTc2o/CMnJMwKMBRyS96GJimckjgrALARy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDuWviQzcpGNNNNjHZFmIng2J9HGYvylp/bGxFMRsA6XQIgaOoMMZb+z4sx/76yWEBLwVzybLWmKZOHxnqC9F8lgjg="}],"unpackedSize":2249180},"name":"@rhize/skill-forge","type":"module","engines":{"node":">=18"},"gitHead":"1f7ad9bbc695bc0452e53b156c5e9264353f6694","license":"SEE LICENSE IN LICENSE","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit -p tsconfig.json"},"version":"0.22.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"84ad46cd-59e8-41c3-9659-3133e3305389"}},"homepage":"https://github.com/Rhize-Media/skill-forge#readme","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"overrides":{"esbuild":"0.28.1"},"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"_npmVersion":"11.6.2","description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","directories":{},"maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"_nodeVersion":"24.21.0","dependencies":{"commander":"^12.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skill-forge_0.22.0_1790713457320_0.23256819469963186"}}},"time":{"created":"2026-07-11T19:09:49.499Z","modified":"2026-09-29T20:24:17.657Z","0.1.0":"2026-07-11T19:09:49.783Z","0.2.0":"2026-07-11T19:45:53.705Z","0.3.0":"2026-07-12T02:08:28.291Z","0.4.0":"2026-07-12T03:08:52.107Z","0.5.0":"2026-07-12T16:21:39.135Z","0.6.0":"2026-07-12T19:11:15.454Z","0.6.1":"2026-07-17T21:47:51.293Z","0.7.0":"2026-07-18T04:12:03.912Z","0.7.1":"2026-07-18T16:36:38.342Z","0.8.0":"2026-07-20T17:22:16.695Z","0.9.0":"2026-07-20T20:24:29.021Z","0.10.0":"2026-07-20T23:18:19.715Z","0.11.0":"2026-07-27T21:09:59.670Z","0.11.1":"2026-07-27T21:26:24.695Z","0.11.2":"2026-08-09T14:24:22.175Z","0.11.3":"2026-08-09T14:37:34.908Z","0.12.0":"2026-08-09T16:08:24.815Z","0.13.0":"2026-08-10T15:45:22.523Z","0.14.0":"2026-08-25T11:43:25.577Z","0.16.0":"2026-09-02T19:34:55.325Z","0.17.0":"2026-09-05T12:48:23.440Z","0.17.1":"2026-09-05T13:52:43.186Z","0.19.0":"2026-09-05T16:21:03.691Z","0.20.0":"2026-09-14T17:36:09.179Z","0.20.1":"2026-09-15T17:26:58.618Z","0.21.0":"2026-09-25T19:04:40.898Z","0.21.1":"2026-09-28T13:34:22.087Z","0.21.2":"2026-09-28T19:02:03.032Z","0.22.0":"2026-09-29T20:24:17.459Z"},"bugs":{"url":"https://github.com/Rhize-Media/skill-forge/issues"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/Rhize-Media/skill-forge#readme","keywords":["skills","agents","claude","cli","security","supply-chain","skills.sh"],"repository":{"url":"git+https://github.com/Rhize-Media/skill-forge.git","type":"git"},"description":"The supply-chain gate for agent skills — quarantine, scan, and curate agent skills before they enter your set","maintainers":[{"name":"jdeola","email":"jim@rhize.media"}],"readme":"# skill-forge\n\n**The supply-chain gate for agent skills.**\n\n`audit --laya-shadow --json` can add a local Laya ranking of current finding metadata\nfor human triage. It leaves all safety findings and gate decisions unchanged. See\n[the audit contract](docs/commands/audit.md).\n\nSource version: `@rhize/skill-forge@0.21.0`, 0.x beta (Pro features free until 1.0).\nPublishing uses the tag/OIDC workflow; `npm view @rhize/skill-forge version` reports the\ncurrent published version independently of this checkout.\n\n> This project is unrelated to the [`skillforge`](https://www.npmjs.com/package/skillforge)\n> package on npm, which is a Claude Skills *evaluation* framework. `skill-forge` (this package,\n> hyphenated) is a supply-chain security gate for skill *installation* — see the [FAQ](#faq).\n\n## Why\n\nAgent skills can include third-party instructions and executable resources. Existing marketplaces\nalready provide safeguards: [skills.sh offers partner security audits and installation risk\ninformation](https://vercel.com/changelog/automated-security-audits-now-available-for-skills-sh).\nSkill Forge adds a local review and maintenance workflow around the skills you actually use:\nprovenance, overlap review, drift checks, and recoverable project refinements.\n\nCandidates submitted through Skill Forge follow **quarantine → profile → safety scan → overlap\nanalysis (when available/configured) → report → an explicit promote/hold/reject decision**.\nThis gate applies to the Skill Forge path; it does not prevent direct installs through other tools\nor replace host-managed restrictions. Passing a scan does not prove that a skill is safe.\nSee the [product spec](docs/PRODUCT.md) for current competitive positioning and evidence limits.\n\n## Quickstart\n\n```bash\nnpx @rhize/skill-forge init\n```\n\nOptional, but recommended first: `init` detects which coding agents you have installed (73 known\nagents) and lets you pick which of their skill directories to gate, a default promotion target,\nand an optional agent to hand follow-up prompts off to. It also checks whether each picked root is\nunder Git version control yet and, if not, offers to give it a baseline commit (exact commands\nshown first, default No). No configuration is required either way — skip `init` and skill-forge\ndefaults to `<cwd>/.claude/skills` as its promotion target (and offers to run `init` for you the\nfirst time `add`/`scan`/`list`/`status` runs with no config present, in an interactive terminal).\nSee [docs/commands/init.md](docs/commands/init.md) for the full detection/menu/Git-preflight\nbehavior and [docs/configuration.md](docs/configuration.md) for the config field reference.\n\n```bash\nnpx @rhize/skill-forge add <owner>/<skill-name>\n```\n\nOne command runs the whole gate:\n\n1. Installs the source into an isolated quarantine sandbox — never your live skill set.\n2. Profiles it: name, version, license, structure, declared MCP/tool dependencies.\n3. Runs the safety gate (a built-in deny-pattern ruleset, always; SkillSpector too, if installed).\n4. Runs overlap analysis against your configured skill set, if one is configured.\n5. Prints a report and asks you to **promote**, **hold**, or **reject** the candidate.\n\nTo gate a skill without installing it (always cleans up afterward):\n\n```bash\nnpx @rhize/skill-forge scan <owner>/<skill-name>\n```\n\n### Plugin-heavy setups (v0.17)\n\nIf most of your skills arrive through Claude Code plugins rather than `npx skills add`, the\ninstall gate rarely fires — the audit is where the value is. `skill-forge audit --claude-plugins`\nreads Claude Code's enabled-plugin registry, walks each plugin's manifest-declared skill dirs, and\nreports every enabled plugin (safety findings, skill count, and — with `--usage-snapshot\n<file|dir>` pointing at skill-monitor snapshots — an advisory `keep` / `review` / `unobserved` /\n`unknown` recommendation). Plugin roots are never promotion targets, the safety scan surface\nnever shrinks, and nothing here changes an `add`/`scan` verdict. `init` asks once whether to\nenable this; `routine` carries the same flags for cron. See\n[docs/commands/audit.md](docs/commands/audit.md). For a practical maintenance loop and the limits\nof invocation-based advice, see [Plugin governance](docs/plugin-governance.md).\n\n`<source>` accepts a `skills.sh` `owner/name` slug, a git URL (`https://...`, `git@...`, or\nanything ending in `.git`), or a local filesystem path.\n\n## Commands\n\n| Command | Description | Docs |\n|---|---|---|\n| `init [options]` | Detect installed agents, set gate targets / handoff agent, opt in to Claude plugin audits | [docs/commands/init.md](docs/commands/init.md) |\n| `add <source> [options]` | Quarantine-install a skill and run it through the gate | [docs/commands/add.md](docs/commands/add.md) |\n| `scan <source> [options]` | Gate a skill without installing it (always cleans up) | [docs/commands/scan.md](docs/commands/scan.md) |\n| `evolve <skill-dir> [options]` (Pro) | Self-evolve an installed skill via SkillOpt-Sleep, re-gate, decide | [docs/commands/evolve.md](docs/commands/evolve.md) |\n| `audit [options]` (alias `doctor`) | Doctor-style health check over the configured skill/MCP set — and, with `--claude-plugins`, every enabled Claude Code plugin's skills, plus a usage join and per-plugin advisory summary | [docs/commands/audit.md](docs/commands/audit.md) |\n| `finding accept\\|revoke\\|list` | Acknowledge, revoke, or list reviewed audit findings (human-only, no gate effect) | [docs/commands/finding.md](docs/commands/finding.md) |\n| `organize [options]` (Pro) | Set-level capability registry + dependency graph across configured skills roots (reads flat or nested `metadata.rhize` frontmatter) | [docs/commands/organize.md](docs/commands/organize.md) |\n| `find [query] [options]` | Discover skills via skills.sh and check partner security audits (free) | [docs/commands/find.md](docs/commands/find.md) |\n| `watch [options]` (Pro) | Drift check across every `SOURCES.md` provenance ledger | [docs/commands/watch.md](docs/commands/watch.md) |\n| `ingest [options]` / `queue close <id>` (Pro) | Hand the pending-ingestion queue off to a coding agent for the decide/absorb pass | [docs/commands/ingest.md](docs/commands/ingest.md) |\n| `plugins keep/list/forget` | Record explicit host/project keep rationale without suppressing safety findings | [governance additions](docs/governance-improvements.md) |\n| `refine [options]` (Pro) | Capture, list, review, promote, and roll back project-scope skill overrides | [docs/commands/refine.md](docs/commands/refine.md) |\n| `insight <subcommand>` (Pro) | Turn sources into evidence-backed capability plans and Jira manifests | [docs/commands/insight.md](docs/commands/insight.md) |\n| `routine [options]` (Pro) | One scheduled maintenance pass: audit (plugins + usage aware) + drift + registry, cron-friendly | [docs/commands/routine.md](docs/commands/routine.md) |\n| `promote <id>` / `reject <id>` [options] | Re-gate and finish a held quarantine decision, or discard it | [docs/commands/promote-reject.md](docs/commands/promote-reject.md) |\n| `config <sub> [args]` | Read/write open-ended preferences (`list`\\|`get`\\|`set`\\|`unset`\\|`propose`\\|`review`) | [docs/commands/config.md](docs/commands/config.md) |\n| `list` / `status` | List held quarantine entries, or show configuration and quarantine summary | [docs/commands/list-status.md](docs/commands/list-status.md) |\n| `guide [topic]` | Orientation: what this does, your current state, the next command | [docs/commands/guide.md](docs/commands/guide.md) |\n\n`add`/`scan` also gate an **MCP server** instead of a skill via `--artifact mcp` — see\n[docs/mcp-gating.md](docs/mcp-gating.md).\nAn MCP server that serves skills over the MCP Skills extension (`io.modelcontextprotocol/skills`) is\ngated as an instructional-content surface — promoting it is effectively a skill install (static\ndetection only; `allowed-tools`, bundled scripts, `\"dynamic\"` resources, digest/size checks and\nlocal-name collisions are reported, and unreachable live content is flagged unverified) — see\n[docs/mcp-gating.md](docs/mcp-gating.md). Under `--yes`, such a server is held rather than\nauto-promoted; promote it explicitly with `skill-forge promote <id>`.\n\n## Free vs. Pro\n\nFree is the complete safety gate on its own — quarantine, profile, safety scan, and an explicit\npromote/reject decision, with nothing held back. Pro is the curation layer on top: whether a new\ncandidate duplicates something you already have, and an ongoing provenance record across your\nwhole skill set rather than a single install-time decision.\n\n**Everything free until 1.0.** This is a 0.x beta build, and the Pro tier's runtime license check\nis intentionally asleep for the whole 0.x line: overlap analysis, the provenance ledger, and the\npending-ingestion queue / `--ingest` handoff all run for everyone, licensed or not — `add` prints a\none-line \"free during the beta\" notice above the report when no valid license is set, and otherwise\nruns exactly as a licensed run would.\n\nSee [docs/pro.md](docs/pro.md#free-vs-pro) for the full Free/Pro capability table and the\nper-feature implementation status.\n\n## Security model\n\n- **Quarantine-first.** Every source is installed into an isolated sandbox before anything is\n  inspected — nothing reaches your working skill set without an explicit promote decision.\n- **Built-in safety ruleset, always on, fully offline.** A deny-pattern scan (curl/wget-into-shell,\n  base64-obfuscated exec, reverse shells, credential-file access/exfil, `shell=True` subprocess,\n  persistence via shell rc files or cron, `sudo` usage, and more) runs against every candidate with\n  no external dependency and no network call.\n- **Block on HIGH/CRITICAL.** Any finding at `HIGH` or `CRITICAL` severity blocks the candidate\n  outright; a lower-severity finding produces `warn`; a clean scan is `pass`.\n- **npm-sourced MCP candidates:** fetched with `--ignore-scripts`, and every tarball member path is\n  validated before extraction (a path-traversal guard).\n- **SkillSpector, when installed,** adds its individual findings, including modern `issues`\n  reports. Its absence preserves the built-in-only gate. A failed, malformed or incomplete\n  installed scan is an explicit HIGH `skillspector-unavailable` finding, which blocks under\n  default strictness. A LOW aggregate score cannot hide a HIGH individual issue.\n\nSee [docs/security-model.md](docs/security-model.md) for the full rule table and current status of\neach check.\n\n## Configuration\n\nConfig lives at `~/.skill-forge/config.json` (or `$SKILL_FORGE_HOME/config.json`). Run\n`skill-forge init` to generate it interactively, or write it by hand:\n\n```json\n{\n  \"skillsRoots\": [\"/path/to/.claude/skills\"],\n  \"quarantineDir\": \"/path/to/quarantine\",\n  \"strictness\": \"block-high\",\n  \"defaultTarget\": \"/path/to/.claude/skills\",\n  \"agents\": [{ \"id\": \"claude-code\", \"skillsRoot\": \"/path/to/.claude/skills\" }],\n  \"handoffCommand\": [\"claude\", \"-p\", \"Read {prompt} and follow its instructions for the skill installed at {path}\"]\n}\n```\n\nMissing keys fall back to defaults (`skillsRoots: [\"<cwd>/.claude/skills\"]`); `defaultTarget`,\n`agents`, and `handoffCommand` are optional and only written by `init`. Full field reference,\nincluding current caveats, in [docs/configuration.md](docs/configuration.md).\n\n## FAQ\n\n**Is this related to the `skillforge` npm package?**\nNo. [`skillforge`](https://www.npmjs.com/package/skillforge) is a Claude Skills *evaluation*\nframework — it tests whether a skill performs well. `skill-forge` (this package, hyphenated) is a\nreview gate for skill *installation* and ongoing collection maintenance. It reports detected\nrisks and potential overlap; it does not certify safety or task effectiveness. The similarly named\npackages are independently maintained.\n\n**Does skill-forge replace `npx skills@latest add`?**\nNo, it wraps it. `add` uses the same install mechanisms (skills.sh, git, local copy) but stages\nthe result in a quarantine sandbox and runs it through the gate before anything touches your live\nskill set.\n\n**What happens if I never configure a skills root?**\n`add`/`scan` still run — profiling and the safety scan work on any candidate independent of a\nskills root. Overlap analysis is skipped (a message goes to stderr, it isn't fatal) if\n`skillsRoots[0]` doesn't resolve to a directory containing existing skills.\n\n**Does the safety gate call out to the network?**\nThe built-in ruleset is fully offline. SkillSpector, if installed, runs with `--no-llm` by default.\nSee [docs/gate-policy.md](docs/gate-policy.md).\n\n**Is there a license key or activation step?**\nAn offline-verified license key exists (`SKILL_FORGE_LICENSE` env var or `config.json`'s\n`licenseKey`), but there's no `license`/`activate` CLI command — you set the key via config or\nenvironment, not a command. Through the 0.x beta the key doesn't gate anything: overlap analysis,\nthe provenance ledger, and the pending-ingestion queue / `--ingest` handoff all run for everyone,\nwith a one-line \"free during the beta\" notice if no valid key is set. See\n[docs/pro.md](docs/pro.md) for details.\n\n**How do I roll back a customization?**\nIt depends what changed. If `skill-forge init` gave a skills root a Git baseline (or you'd already\ncommitted it yourself), rolling back a change under that root is ordinary Git —\n`git checkout -- <path>` or `git reset`, run by you; skill-forge doesn't ship its own rollback for\nthat. `refine rollback <backup-id>` is different and narrower: it only undoes a `refine promote`\n(a base-skill update recorded by `skill-forge refine`), not a Git commit or anything else. See\n[Git preflight](docs/commands/init.md#git-preflight-v016) and\n[`refine`](docs/commands/refine.md) for both.\n\n**Where's the full documentation?**\nSee the [docs index](docs/README.md) for every command reference and background doc.\n\n## License\n\nskill-forge is open-core with a split license (as of v0.2.0):\n\n- **Free tier — MIT.** Everything except the Pro modules: quarantine install, profile,\n  safety gate, report, promote/hold/reject. See [LICENSE-MIT](LICENSE-MIT).\n- **Pro modules — Rhize Commercial License.** `src/license.ts`, `src/gate/overlap.ts`,\n  `src/provenance.ts`, `src/queue.ts` (overlap analysis, provenance ledger, pending\n  queue / `--ingest` handoff), and `src/refine/` (v0.10 — capture/apply/generalize skill\n  overrides), plus `src/insights/` (source studies, evidence validation, inventory mapping,\n  plans, and Jira manifests). The source is available to read and audit, but production use of Pro\n  functionality requires a license key — see [LICENSE-COMMERCIAL](LICENSE-COMMERCIAL).\n\n[LICENSE](LICENSE) is the authoritative map of which files fall under which license.\nVersions up to and including 0.1.0 were published entirely under MIT.\n\n## Governance utility additions (0.19)\n\nUse `plugins keep/list/forget` for explicit host/project retention rationale without\nsuppressing safety findings. `audit --plugin-inventory <file>` and the same option\non `routine` import static host evidence; Codex never joins Claude usage counts.\n`audit --compare <full-audit.json>` highlights changes while preserving all findings.\n`refine activate --skill <capture> --base <dir> --as <unique-name> --host claude|codex`\nmaterializes a captured patch/extend as a new project skill after a staged safety scan.\nPreview with `--dry-run --json`; activation requires confirmation. Verify actual host\nloading in a fresh task before treating the refinement as consumed. Roll back using\nthe returned backup ID with `refine rollback <id> --project --yes`.\n\nSee the [governance operating guide](docs/governance-improvements.md) for scope, schemas, examples and limits.\n\n## Advisory instruction diagnostics (0.20)\n\n`audit` reports description, entrypoint and resource measurements separately, with review\nsuggestions for broad triggers and resource routing. These suggestions never change safety\nfindings, gate decisions or installed skills. Static reports keep actual host loading and\ntruncation unknown; rough token estimates are not measured usage. Comparisons show covered\nskills and description/body deltas when both reports contain the new evidence. See\n[the audit command](docs/commands/audit.md) for metric definitions and unavailable-resource handling.\n\n## CI environment documentation contract\n\nCI checks tracked application, operational script and test JavaScript/TypeScript against this\ntable using a deterministic AST scanner. It reads variable names, never secret values, and\ndoes not generate prose or call a model. Source-hash-bound exceptions cover reviewed injected\nenvironment aliases and test subprocess forwarding; forwarding may inherit additional host\nvariables and is not claimed to be a finite allowlist.\n\n| Variable | Purpose | Requirement |\n| --- | --- | --- |\n| `SKILL_FORGE_HOME` | Override local Skill Forge state directory; tests use isolated fixture homes. | Optional. |\n| `SKILL_FORGE_LICENSE` | Provide the optional license key through the existing license resolver. | Conditional on licensed features and current beta policy. |\n| `DEBUG` | Set to `skill-forge` for CLI error diagnostics. | Optional. |\n| `PATH` | Discover agent CLIs and optional safety tooling. | Required host execution environment. |\n| `PATHEXT` | Windows executable extensions for tool discovery. | Optional; Windows defaults apply. |\n| `VERCEL_OIDC_TOKEN` | Authenticate explicitly invoked skills.sh discovery/API requests. | Conditional on those commands; CI fixtures use fake inputs. |\n| `SKILLSPECTOR_PROVIDER` | Identify the optional SkillSpector provider for readiness reporting. | Optional. |\n| `OPENAI_API_KEY` | Presence check for the optional OpenAI SkillSpector provider. | Conditional on external provider use; not supplied to CI. |\n| `ANTHROPIC_API_KEY` | Presence check for the optional Anthropic SkillSpector provider. | Conditional on external provider use; not supplied to CI. |\n| `NVIDIA_INFERENCE_KEY` | Presence check for the optional NVIDIA SkillSpector provider. | Conditional on external provider use; not supplied to CI. |\n| `HOME` | Test subprocess home override to isolate user installations. | Required test fixture setting. |\n| `USERPROFILE` | Windows-compatible test subprocess home override. | Required test fixture setting. |\n\n## CI cost and release boundaries\n\nMain pushes and PRs run Linux Node24 CI, preserving **build before test**. Superseded checks\ncancel, with a ten-minute job limit. Narrative Markdown, root docs and agent state directories\ntrigger no run; bundled `assets/**` prompts, workflow instructions and `test/fixtures/**`\nregression inputs remain tested, including Markdown. Feature pushes do not duplicate PR builds. Docs-only tips receive no CI check result.\n\nThe repository's TypeScript7 package has no JavaScript compiler API. A separate CI-only\nTypeScript5.9.3 lockfile supplies the AST documentation scanner; runtime dependencies remain\nunchanged. Scanner helpers are copied byte-for-byte from the recorded Infra revision in\n`.github/ci/source.json`, with local hash verification. This subset deliberately preserves\nthe native build-before-test workflow rather than replacing it with an application pipeline.\n\nWeekly grouped minor/patch dependency updates run the same checks; application major updates remain\nseparate, and nothing auto-merges. No Copilot or LLM is required by CI. The existing explicit\n`v*` tag release retains OIDC trusted publishing, build/test checks and Node24, pins npm11.6.2,\nand serializes publication without cancellation with a fifteen-minute limit. GitHub does not\napply file-path filters to tag events; creating a release tag remains a separate release action.\n\nCI acceptance (2026-09-27): [reviewed PR run](https://github.com/Rhize-Media/skill-forge/actions/runs/36345897118) and [main control run](https://github.com/Rhize-Media/skill-forge/actions/runs/36346111479). This separate narrative-only README change is the push/PR docs-filter acceptance case; settled run results are recorded in the cross-repository hardening report.\n\n### CI parser update policy\n\nDependabot holds semantic-major updates only for `typescript` in `.github/ci-tools`.\nThe documentation scanner requires the TypeScript 5 compiler API (`createSourceFile`\nand `ScriptTarget`); TypeScript 7.0.2 does not export that API. A parser migration\nrequires a reviewed compatibility change. Weekly grouped minor/patch parser updates\ncontinue through CI. Application dependency updates and Actions updates retain their\nexisting policies. This is an explicit compatibility and CI-cost policy, not a fix\nfor the unresolved historical Dependabot HTTP 400 PR-creation errors.\n\nSplitting the npm entries retains the root limit of two open PRs and adds one for the parser: up to three combined, versus the previous shared limit of two.\n","readmeFilename":"README.md"}