{"_id":"skillcap-lock","_rev":"3-18249e9156fe0edc45f1f8fa2c0de086","name":"skillcap-lock","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"skillcap-lock","version":"0.1.0","keywords":["agent-skills","security","capabilities","lockfile","cli"],"author":{"name":"Debaditya Hait"},"license":"MIT","_id":"skillcap-lock@0.1.0","maintainers":[{"name":"dhait","email":"debaditya2005hait@gmail.com"}],"homepage":"https://github.com/DebadityaHait/skillcap-lock#readme","bugs":{"url":"https://github.com/DebadityaHait/skillcap-lock/issues"},"bin":{"skillcap":"dist/cli.js"},"dist":{"shasum":"2f0e66d4ccf23173cf065ade7af1b82c4e7b5804","tarball":"https://registry.npmjs.org/skillcap-lock/-/skillcap-lock-0.1.0.tgz","fileCount":25,"integrity":"sha512-Qa7e4TMnt4xV/m2FHVWWrGoUUfdpbBCcTdTlCIzXDilnBLwMXm6hBqW6fYSePHlIquziD8sYpnLAPOJvGDl+Mg==","signatures":[{"sig":"MEQCIFOVts3RewqYRkfCnOZguehwzZp/cZf4sdBMvPe1OQsCAiAbUmtX2mB2Wnw32UcIFh0Sn2ymKZ8+8zjG3VRVO3TFFw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31740},"type":"module","engines":{"node":">=20"},"gitHead":"e1e123b9f289f53e975ed1eca27de48c58b48f9f","scripts":{"lint":"tsc -p tsconfig.json --noEmit","test":"npm run build:test && node --test dist/test/*.test.js","build":"tsc -p tsconfig.json && node -e \"require('node:fs').rmSync('dist/test',{recursive:true,force:true})\"","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","test:cli":"npm run build && node dist/cli.js --help && node dist/cli.js --json","typecheck":"tsc -p tsconfig.json --noEmit","build:test":"tsc -p tsconfig.json"},"_npmUser":{"name":"dhait","email":"debaditya2005hait@gmail.com"},"repository":{"url":"git+https://github.com/DebadityaHait/skillcap-lock.git","type":"git"},"_npmVersion":"12.0.1","description":"Review what an Agent Skill can newly do, not just what bytes changed.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/skillcap-lock_0.1.0_1787160516602_0.5576339311536962","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"skillcap-lock","version":"0.2.0","keywords":["agent-skills","security","capabilities","lockfile","cli"],"author":{"name":"Debaditya Hait"},"license":"MIT","_id":"skillcap-lock@0.2.0","maintainers":[{"name":"dhait","email":"debaditya2005hait@gmail.com"}],"homepage":"https://github.com/DebadityaHait/skillcap-lock#readme","bugs":{"url":"https://github.com/DebadityaHait/skillcap-lock/issues"},"bin":{"skillcap":"dist/cli.js"},"dist":{"shasum":"7e064605b10dfc1b542ab80d771fed42623d80ab","tarball":"https://registry.npmjs.org/skillcap-lock/-/skillcap-lock-0.2.0.tgz","fileCount":25,"integrity":"sha512-gfj4SAG3wzTKSoudYZ3vU9bRXS4uUpk0CzKhP5Phag7DHJbqlBI0KkbVLrWIGPa9McDKB2fvuJjr1ycCdoSdNQ==","signatures":[{"sig":"MEQCIFRafIha5bx8GIj/WIRK7ZIhFRzgTNnS1H9R7nL/YB/rAiAkwkVRezHP/p1Y0qVR6DQE1Sg7Pb2ZCy29XzWiB+nrJA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":46668},"type":"module","engines":{"node":">=20"},"gitHead":"5a389b7eed4c2070b132d755dc5304a19ba692c2","scripts":{"lint":"tsc -p tsconfig.json --noEmit","test":"npm run build:test && node --test dist/test/*.test.js","build":"tsc -p tsconfig.json && node -e \"require('node:fs').rmSync('dist/test',{recursive:true,force:true})\"","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","test:cli":"npm run build && node dist/cli.js --help && node -e \"const {spawnSync}=require('node:child_process'); const r=spawnSync(process.execPath,['dist/cli.js','--json'],{stdio:'ignore'}); if(r.status!==0&&r.status!==1) process.exit(r.status??2)\"","typecheck":"tsc -p tsconfig.json --noEmit","build:test":"tsc -p tsconfig.json"},"_npmUser":{"name":"dhait","email":"debaditya2005hait@gmail.com"},"repository":{"url":"git+https://github.com/DebadityaHait/skillcap-lock.git","type":"git"},"_npmVersion":"12.0.1","description":"Review what an Agent Skill can newly do, not just what bytes changed.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/skillcap-lock_0.2.0_1787163241803_0.16120739537763362","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"skillcap-lock","version":"0.3.0","description":"Review what an Agent Skill can newly do, not just what bytes changed.","author":{"name":"Debaditya Hait"},"keywords":["agent-skills","security","capabilities","lockfile","cli"],"type":"module","bin":{"skillcap":"dist/cli.js"},"engines":{"node":">=20"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/DebadityaHait/skillcap-lock.git"},"bugs":{"url":"https://github.com/DebadityaHait/skillcap-lock/issues"},"homepage":"https://github.com/DebadityaHait/skillcap-lock#readme","publishConfig":{"access":"public","provenance":true},"scripts":{"build":"tsc -p tsconfig.json && node -e \"require('node:fs').rmSync('dist/test',{recursive:true,force:true})\"","build:test":"tsc -p tsconfig.json","lint":"tsc -p tsconfig.json --noEmit","typecheck":"tsc -p tsconfig.json --noEmit","test":"npm run build:test && node --test dist/test/*.test.js","test:cli":"npm run build && node dist/cli.js --help && node -e \"const {spawnSync}=require('node:child_process'); const r=spawnSync(process.execPath,['dist/cli.js','--json'],{stdio:'ignore'}); if(r.status!==0&&r.status!==1) process.exit(r.status??2)\"","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\""},"devDependencies":{"@types/node":"^22.10.0","typescript":"^5.7.2"},"gitHead":"0d1ef2067f94bd334e66421712dd6b7ffc4fa333","_id":"skillcap-lock@0.3.0","_nodeVersion":"24.18.0","_npmVersion":"12.0.1","dist":{"integrity":"sha512-85oMT+i/i1R4TcAVobdbL5/164lLTFyiEIt2CqYix5bmTtihyTfDWj7Pn+/VJ5MInaXsC71KC+fVvCapeeLS+g==","shasum":"1abdf67e06ad1ad58c8bd098bd64c7fdf92137d5","tarball":"https://registry.npmjs.org/skillcap-lock/-/skillcap-lock-0.3.0.tgz","fileCount":25,"unpackedSize":51557,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCIKoQX8CHnP1vyowy11pMG/kqjuDOdpT+l5KX1OHEQ+QIhAItVsSGvvoIbX0kWlSGgoQvkTKqmq6ESE14FQcBdYzs1"}]},"_npmUser":{"name":"dhait","email":"debaditya2005hait@gmail.com"},"directories":{},"maintainers":[{"name":"dhait","email":"debaditya2005hait@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/skillcap-lock_0.3.0_1787166756714_0.8509028351962002"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-19T17:28:36.417Z","modified":"2026-08-19T19:12:37.031Z","0.1.0":"2026-08-19T17:28:36.797Z","0.2.0":"2026-08-19T18:14:01.965Z","0.3.0":"2026-08-19T19:12:36.857Z"},"bugs":{"url":"https://github.com/DebadityaHait/skillcap-lock/issues"},"author":{"name":"Debaditya Hait"},"license":"MIT","homepage":"https://github.com/DebadityaHait/skillcap-lock#readme","keywords":["agent-skills","security","capabilities","lockfile","cli"],"repository":{"type":"git","url":"git+https://github.com/DebadityaHait/skillcap-lock.git"},"description":"Review what an Agent Skill can newly do, not just what bytes changed.","maintainers":[{"name":"dhait","email":"debaditya2005hait@gmail.com"}],"readme":"# SkillCap Lock\n\n[![npm version](https://img.shields.io/npm/v/skillcap-lock?logo=npm)](https://www.npmjs.com/package/skillcap-lock)\n[![CI](https://github.com/DebadityaHait/skillcap-lock/actions/workflows/ci.yml/badge.svg)](https://github.com/DebadityaHait/skillcap-lock/actions/workflows/ci.yml)\n[![Node.js](https://img.shields.io/node/v/skillcap-lock)](https://nodejs.org/)\n[![License](https://img.shields.io/npm/l/skillcap-lock)](./LICENSE)\n\nReview what an Agent Skill can do before an agent loads it. SkillCap Lock validates the [Agent Skills specification](https://github.com/agentskills/agentskills/blob/main/docs/specification.mdx), hashes every file, extracts observable capability evidence, scores instruction quality and risk, and compares the result with a reviewed baseline.\n\n## Position in the ecosystem\n\n[skills](https://www.npmjs.com/package/skills), [skillpm](https://github.com/sbroenne/skillpm), [skills-lock](https://github.com/luisalima/skills-lock), [sklock](https://github.com/artieax/sklock), and [Tank](https://github.com/tankpkg/tank) focus on discovery, installation, dependency resolution, or reproducible distribution. [skill-check](https://www.npmjs.com/package/skill-check) focuses on structural quality. SkillCap Lock is the static review layer for capability change and quality policy; it never installs or executes a skill.\n\n## Install\n\n```bash\nnpm install --save-dev skillcap-lock\nnpx skillcap --help\n```\n\nNode.js 20 or newer is required.\n\n## Baseline and CI\n\n```bash\n# Discover every nested SKILL.md and create the reviewed baseline\nnpx skillcap init ./skills\n\n# Review semantic changes after an update\nnpx skillcap check ./skills --markdown\nnpx skillcap check ./skills --json > skillcap-report.json\nnpx skillcap check ./skills --sarif > skillcap.sarif\n\n# Frozen CI: fail when the lock is missing or stale\nnpx skillcap check ./skills --frozen\n\n# Accept an intentionally reviewed update\nnpx skillcap update ./skills --accept\n```\n\nThe generated `skillcap.lock.json` stores file hashes, redacted capability evidence, quality/risk scores, validation issues, and provenance. It does not store skill bodies or secret values.\n\n## Evidence and scoring\n\nCapabilities are reported with kind, value, file, line, provenance, and confidence:\n\n| Evidence | Examples |\n| --- | --- |\n| network | URLs and remote destinations |\n| command / interpreter | `npm`, `curl`, `python`, shell and runtime invocations |\n| write / path | filesystem mutation language and paths |\n| executable | bundled scripts and executable filenames |\n| env / secret | environment names and token-shaped strings (redacted) |\n\nEach skill has:\n\n- a risk score reflecting observable network, command, write, executable, and secret signals;\n- a quality score reflecting valid frontmatter, useful descriptions, body size, and completeness;\n- stable validation IDs (`SKV001`–`SKV006`) and capability delta IDs (`SKC001`–`SKC008`).\n\nStatic evidence is deliberately conservative. It can miss behavior hidden behind indirection and can over-approximate examples; it is a review aid, not a sandbox or security certificate.\n\n## Policies\n\n```json\n{\n  \"maxRiskScore\": 35,\n  \"minQualityScore\": 75,\n  \"requireFrontmatter\": true,\n  \"deny\": [\n    { \"kind\": \"network\", \"value\": \"internal.example.com\" },\n    { \"kind\": \"executable\", \"value\": \"deploy.sh\" }\n  ]\n}\n```\n\nRun `npx skillcap check ./skills --policy skillcap.policy.json`. Policy violations fail with exit code `1`.\n\n## Commands and output\n\n```text\nskillcap init <directory>\nskillcap check <directory> [--policy file] [--frozen] [--json|--markdown|--sarif]\nskillcap update <directory> --accept\nskillcap explain <directory> <skill-name>\n```\n\nExit code `0` means no high-severity change or policy violation, `1` means review is required, and `2` means invalid input or scanner failure. JSON is schema-versioned; Markdown is suitable for pull requests; SARIF integrates with code scanning.\n\n## Development\n\n```bash\nnpm install\nnpm run lint\nnpm test\nnpm run test:cli\nnpm pack --dry-run\n```\n\nIssues and pull requests are welcome in the [GitHub repository](https://github.com/DebadityaHait/skillcap-lock).\n\n## License\n\nMIT © Debaditya Hait\n","readmeFilename":"README.md"}