{"_id":"@arcjet/skills","_rev":"2-af53612d2cb152201c982e1d27a3bf35","name":"@arcjet/skills","dist-tags":{"latest":"1.13.0"},"versions":{"1.12.0":{"name":"@arcjet/skills","version":"1.12.0","keywords":["agent-skills","ai","arcjet","security","tanstack-intent"],"author":{"url":"https://arcjet.com","name":"Arcjet","email":"support@arcjet.com"},"license":"Apache-2.0","_id":"@arcjet/skills@1.12.0","maintainers":[{"name":"quinn-arcjet","email":"quinn@arcjet.com"},{"name":"davidmytton","email":"david@arcjet.com"}],"homepage":"https://arcjet.com","bugs":{"url":"https://github.com/arcjet/arcjet-js/issues","email":"support@arcjet.com"},"dist":{"shasum":"e0a538da37069c446fdba8854e1c9945d1b65a2f","tarball":"https://registry.npmjs.org/@arcjet/skills/-/skills-1.12.0.tgz","fileCount":17,"integrity":"sha512-PfbXAf3GVx9nucsEi+D4DjtZGJ7dr5f1KqC7SJku/hzHrHQ75z3Jc9qbXnVDLe/9TPLyd2eWL2OyIdrCp882zw==","signatures":[{"sig":"MEUCIQCUseSPwTDtVEYZGpEwS4W0NPRILqtF/iBrASOrQ2FmBgIgHQLAaFgCBJH87vVf+enRBZuYfEelogU8PFVpp2lOVMw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":54403},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.21.0 <23 || >=24.5.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"lint":"oxlint --tsconfig=tsconfig.json","test":"npm run build && npm run test-coverage && npm run validate-skills && node ../.github/scripts/check-skill-source-stale.mjs","build":"tsdown","format":"oxfmt","test-api":"node --test -- test/*.test.ts","typecheck":"tsc --noEmit","format:check":"oxfmt --check","stale-skills":"node ../.github/scripts/intent-cli.mjs stale --json","test-coverage":"node --experimental-test-coverage --test -- test/*.test.ts","validate-skills":"node ../.github/scripts/intent-cli.mjs validate"},"_npmUser":{"name":"quinn-arcjet","email":"quinn@arcjet.com"},"repository":{"url":"git+https://github.com/arcjet/arcjet-js.git","type":"git","directory":"arcjet-skills"},"_npmVersion":"12.0.1","description":"Versioned Agent Skills for the Arcjet JavaScript SDK, shipped with TanStack Intent","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsdown":"0.22.14","typescript":"7.0.2","@types/node":"22.20.1","@tanstack/intent":"0.3.8"},"_npmOperationalInternal":{"tmp":"tmp/skills_1.12.0_1788888099785_0.9865529028024758","host":"s3://npm-registry-packages-npm-production"}},"1.13.0":{"name":"@arcjet/skills","version":"1.13.0","description":"Versioned Agent Skills for the Arcjet JavaScript SDK, shipped with TanStack Intent","keywords":["agent-skills","ai","arcjet","security","tanstack-intent"],"homepage":"https://arcjet.com","bugs":{"url":"https://github.com/arcjet/arcjet-js/issues","email":"support@arcjet.com"},"license":"Apache-2.0","author":{"name":"Arcjet","email":"support@arcjet.com","url":"https://arcjet.com"},"repository":{"type":"git","url":"git+https://github.com/arcjet/arcjet-js.git","directory":"arcjet-skills"},"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"publishConfig":{"access":"public"},"scripts":{"build":"tsdown","typecheck":"tsc --noEmit","lint":"oxlint --tsconfig=tsconfig.json","format":"oxfmt","format:check":"oxfmt --check","validate-skills":"node ../.github/scripts/intent-cli.mjs validate","stale-skills":"node ../.github/scripts/intent-cli.mjs stale --json","test-api":"node --test -- test/*.test.ts","test-coverage":"node --experimental-test-coverage --test -- test/*.test.ts","test":"npm run build && npm run test-coverage && npm run validate-skills && node ../.github/scripts/check-skill-source-stale.mjs"},"devDependencies":{"@tanstack/intent":"0.4.0","@types/node":"22.20.1","tsdown":"0.23.0","typescript":"7.0.2"},"engines":{"node":">=22.21.0 <23 || >=24.5.0"},"gitHead":"894bb9d3741f19b3306b986e869ca4ea8e42be71","_id":"@arcjet/skills@1.13.0","_nodeVersion":"24.20.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-im1LaoOK10aF9M26CC6yBdmku0ki3kcMS51v5dhQ8+btCstwXXHd7mE9Zb6OOxbqleDXnMr8qvW2d5L+8K6QBg==","shasum":"707423881017135a14a7f7a64e0e29dff64ab6ca","tarball":"https://registry.npmjs.org/@arcjet/skills/-/skills-1.13.0.tgz","fileCount":17,"unpackedSize":55631,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arcjet%2fskills@1.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICG4efeFAPIqI/7CS5dBF+ogoyQWFBfPt9LtxPJfYGcGAiBeuhlkYsKM6Qg7gUnPiXeYMYyeK6o7q8F+uDgKOalL6w=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bee4e473-52a5-46c1-abc7-ee2cfeda36c0"}},"directories":{},"maintainers":[{"name":"quinn-arcjet","email":"quinn@arcjet.com"},{"name":"davidmytton","email":"david@arcjet.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skills_1.13.0_1789601249137_0.7472559730560389"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-08T17:21:39.564Z","modified":"2026-09-16T23:27:29.563Z","1.12.0":"2026-09-08T17:21:39.924Z","1.13.0":"2026-09-16T23:27:29.285Z"},"bugs":{"url":"https://github.com/arcjet/arcjet-js/issues","email":"support@arcjet.com"},"author":{"name":"Arcjet","email":"support@arcjet.com","url":"https://arcjet.com"},"license":"Apache-2.0","homepage":"https://arcjet.com","keywords":["agent-skills","ai","arcjet","security","tanstack-intent"],"repository":{"type":"git","url":"git+https://github.com/arcjet/arcjet-js.git","directory":"arcjet-skills"},"description":"Versioned Agent Skills for the Arcjet JavaScript SDK, shipped with TanStack Intent","maintainers":[{"name":"quinn-arcjet","email":"quinn@arcjet.com"},{"name":"davidmytton","email":"david@arcjet.com"}],"readme":"<!-- trunk-ignore-all(markdownlint/MD024) -->\n<!-- trunk-ignore-all(markdownlint/MD001) -->\n\n<a href=\"https://arcjet.com\" target=\"_arcjet-home\">\n  <picture>\n    <source media=\"(prefers-color-scheme: dark)\" srcset=\"https://arcjet.com/logo/arcjet-dark-lockup-voyage-horizontal.svg\">\n    <img src=\"https://arcjet.com/logo/arcjet-light-lockup-voyage-horizontal.svg\" alt=\"Arcjet Logo\" height=\"128\" width=\"auto\">\n  </picture>\n</a>\n\n# `@arcjet/skills`\n\n<p>\n  <a href=\"https://www.npmjs.com/package/@arcjet/skills\">\n    <picture>\n      <source media=\"(prefers-color-scheme: dark)\" srcset=\"https://img.shields.io/npm/v/%40arcjet%2Fskills?style=flat-square&label=%E2%9C%A6Aj&labelColor=000000&color=5C5866\">\n      <img alt=\"npm badge\" src=\"https://img.shields.io/npm/v/%40arcjet%2Fskills?style=flat-square&label=%E2%9C%A6Aj&labelColor=ECE6F0&color=ECE6F0\">\n    </picture>\n  </a>\n</p>\n\nVersioned [Agent Skills](https://agentskills.io) for the Arcjet JavaScript SDK,\nshipped with [TanStack Intent](https://tanstack.com/intent).\n\n- [npm package (`@arcjet/skills`)](https://www.npmjs.com/package/@arcjet/skills)\n- [GitHub source code (`arcjet-skills/` in `arcjet/arcjet-js`)](https://github.com/arcjet/arcjet-js/tree/main/arcjet-skills)\n\nSkills travel with the installed package version. They are not a copy-pasted\nrules file and they are not the model's training cutoff.\n\nThe standalone marketplace install (`npx skills add arcjet/skills`) still\nworks from [`arcjet/skills`](https://github.com/arcjet/skills). Prefer this\npackage when you want skills that match the SDK version in `node_modules`.\n\n## What is this?\n\nA TypeScript package that publishes:\n\n- `skills/*/SKILL.md` — agent guidance, one skill per task\n- `docs/*.md` — the source documentation those skills were derived from\n- a small typed manifest (`skills`, `skillIdentity`) for the shipped leaf names\n\nTanStack Intent discovers the `SKILL.md` files as static files. It does not\nimport or execute this package (or any other package) to find them.\n\n## Install\n\nThis package is ESM only.\n\n```sh\nnpm install @arcjet/skills\n```\n\nFramework adapters that depend on `arcjet` also install this package\ntransitively, so a typical `@arcjet/next` app already has the files on disk.\n\nGuard integration skills ship in [`@arcjet/guard`](../arcjet-guard/README.md)\nnext to that package's README. Allow both packages if you use Guard.\n\n## Use with TanStack Intent\n\nIntent scans installed dependencies for `skills/**/SKILL.md`. Discovery is\nnot trust. Put an explicit allowlist in the **application** `package.json`:\n\n```json\n{\n  \"intent\": {\n    \"skills\": [\"@arcjet/skills\", \"@arcjet/guard\"],\n    \"exclude\": []\n  }\n}\n```\n\n`intent.skills` permits packages, not individual skills. Use `intent.exclude`\nto drop a package or one skill (`@arcjet/guard#integrate-arcjet-guard-eve`).\n\nAn omitted `intent.skills` key currently surfaces every discovered package\nand prints a deprecation notice. Do not use `\"skills\": [\"*\"]` unless you\naccept unvetted skills from the whole tree.\n\n```sh\nnpx @tanstack/intent@latest install\nnpx @tanstack/intent@latest list\nnpx @tanstack/intent@latest load @arcjet/skills#protect\n```\n\n`install` writes loading guidance to `AGENTS.md` (or an existing agent\nconfig). `list` shows what the allowlist permits. `load` prints one\n`SKILL.md` — load only the skill the current task needs.\n\n| Task | Load |\n| --- | --- |\n| HTTP routes, APIs, middleware | `@arcjet/skills#protect` |\n| Which rules to apply | `@arcjet/skills#choose-protections` |\n| Sign in and write `ARCJET_KEY` | `@arcjet/skills#cli` |\n| MCP server setup | `@arcjet/skills#mcp` |\n| Tool calls, MCP handlers, jobs | `@arcjet/skills#guard` |\n| A specific Guard vendor SDK | `@arcjet/guard#integrate-arcjet-guard-*` |\n\n### Trust model\n\n- Intent reads package metadata and skill files. It does not execute package\n  code to discover or load a skill.\n- The allowlist and exclusions are the trust decision.\n- `intent load` returning content means the file resolved under current\n  policy. It does not mean the skill was relevant or that the model followed\n  it.\n- `npx @tanstack/intent@latest hooks install` can add session catalogs and\n  edit gates for some agents. Treat those hooks as convenience, not a\n  security boundary. They can observe a load command; they cannot prove the\n  agent used the guidance.\n\n## Typed manifest\n\n```ts\nimport {\n  PACKAGE_NAME,\n  VERSION,\n  getSkill,\n  skillIdentity,\n  skills,\n} from \"@arcjet/skills\";\n\nskillIdentity(\"protect\"); // \"@arcjet/skills#protect\"\ngetSkill(\"cli\")?.file; // \"skills/cli/SKILL.md\"\n```\n\nThis list is for this package only. It does not scan other dependencies.\n\n## Maintainers\n\nSkill files live beside the docs they were derived from (`docs/` in this\npackage; `README.md` for `@arcjet/guard` skills). Each `SKILL.md` declares\nthose paths in `sources`.\n\n```sh\nnpx @tanstack/intent@latest validate\nnpx @tanstack/intent@latest stale --json\n```\n\n`validate` is required in CI. `stale` is conservative: a changed source is a\nreview signal, not proof the skill is wrong. CI fails a pull request when a\ndeclared source changes and the matching `SKILL.md` does not.\n\nThe `tanstack-intent` keyword and the `skills/` `files` entry put the skills\nin the npm tarball so the registry can index them.\n\n## License\n\n[Apache License, Version 2.0][apache-license] © [Arcjet Labs, Inc.][arcjet]\n\n[apache-license]: http://www.apache.org/licenses/LICENSE-2.0\n[arcjet]: https://arcjet.com\n","readmeFilename":"README.md"}