{"id":"5e764bd6-5be5-475b-8676-97e5f70045fd","entityType":"agent","slug":"clawhub-hith3sh-npm-registry","name":"npm Registry","canonicalUrl":"https://www.xpersona.co/agent/clawhub-hith3sh-npm-registry","canonicalPath":"/agent/clawhub-hith3sh-npm-registry","generatedAt":"2026-10-09T20:54:30.066Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T14:45:19.063Z","emptyReason":null},"description":"Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm regis... Skill: npm Registry Owner: hith3sh Summary: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm regis... Tags: latest:1.0.5 Version history: v1.0.5 | 2026-06-09T07:14:10.720Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.5K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173vws87a7ss71xf9rq53k5gd8568kv:npm-registry","sourceUrl":"https://clawhub.ai/hith3sh/npm-registry","homepage":"https://clawhub.ai/hith3sh/skills/npm-registry","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/hith3sh/npm-registry","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/hith3sh/skills/npm-registry","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":68,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm regis..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:45:19.063Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:45:19.063Z","emptyReason":null},"stars":null,"forks":null,"downloads":2455,"packageName":null,"latestVersion":"1.0.5","tractionLabel":"2.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:45:19.062Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T14:45:19.063Z","lastCrawledAt":"2026-10-09T14:45:19.062Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T14:45:19.062Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.5","createdAt":"2026-06-09T07:14:10.720Z","changelog":"Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source.","fileCount":3,"zipByteSize":5009},{"version":"1.0.4","createdAt":"2026-06-09T05:00:22.346Z","changelog":"- Removed the file skill-card.md. - No changes to features or workflow; documentation and usage remain unchanged.","fileCount":3,"zipByteSize":5028},{"version":"1.0.1","createdAt":"2026-06-08T16:39:57.384Z","changelog":"- Updated SKILL.md with a new header image for improved branding. - Removed the file skill-card.md. - No changes to skill logic or functionality.","fileCount":3,"zipByteSize":5177},{"version":"0.1.1","createdAt":"2026-06-07T13:33:31.735Z","changelog":"Full rewrite to new standard: added tool reference tables, 3-step GIF table, architecture diagram, code examples, error handling, and troubleshooting.","fileCount":3,"zipByteSize":5064},{"version":"0.1.0","createdAt":"2026-05-24T14:31:07.488Z","changelog":"Initial release of npm-registry skill. - Search npm packages, inspect registry metadata, view download stats, and check advisories directly from chat. - Powered by ClawLink for secure, no-configuration access to npm. - Setup instructions included for ClawLink plugin installation and pairing. - Automated discovery and execution of npm tools through ClawLink—no manual schema handling needed. - Emphasizes safe, credential-free workflows and provides troubleshooting guidance.","fileCount":3,"zipByteSize":3495}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173vws87a7ss71xf9rq53k5gd8568kv:npm-registry","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T20:54:30.064Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-npm-registry/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T14:45:19.063Z","emptyReason":null},"readme":"Skill: npm Registry\n\nOwner: hith3sh\n\nSummary: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm regis...\n\nTags: latest:1.0.5\n\nVersion history:\n\nv1.0.5 | 2026-06-09T07:14:10.720Z | user\n\nAdd UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source.\n\nv1.0.4 | 2026-06-09T05:00:22.346Z | auto\n\n- Removed the file skill-card.md.\n- No changes to features or workflow; documentation and usage remain unchanged.\n\nv1.0.1 | 2026-06-08T16:39:57.384Z | auto\n\n- Updated SKILL.md with a new header image for improved branding.\n- Removed the file skill-card.md.\n- No changes to skill logic or functionality.\n\nv0.1.1 | 2026-06-07T13:33:31.735Z | user\n\nFull rewrite to new standard: added tool reference tables, 3-step GIF table, architecture diagram, code examples, error handling, and troubleshooting.\n\nv0.1.0 | 2026-05-24T14:31:07.488Z | auto\n\nInitial release of npm-registry skill.\n\n- Search npm packages, inspect registry metadata, view download stats, and check advisories directly from chat.\n- Powered by ClawLink for secure, no-configuration access to npm.\n- Setup instructions included for ClawLink plugin installation and pairing.\n- Automated discovery and execution of npm tools through ClawLink—no manual schema handling needed.\n- Emphasizes safe, credential-free workflows and provides troubleshooting guidance.\n\nArchive index:\n\nArchive v1.0.5: 3 files, 5009 bytes\n\nFiles: skill-card.md (2102b), SKILL.md (11047b), _meta.json (131b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: npm-registry\ndescription: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm registry data, verify package integrity, or monitor package health via the npm API.\n---\n\n# npm Registry\n\n![npm Registry](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/npm.svg)\n\nAccess the npm public registry via the npm API. Search packages, inspect metadata and versions, review download statistics, and check security advisories and registry health.\n\nThis skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=npm-registry) for hosted connection flows and credentials so you do not need to configure npm API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect npm |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect npm |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│   npm Registry    │\n│   (User Chat)   │     │   (API Key)  │     │   (npmjs.com)    │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n          │                       │                       │\n          │  1. Install Plugin │                       │\n          │  2. Pair Device      │                       │\n          │  3. Connect npm       │                       │\n          │ │  4. Secure Proxy      │\n          │                       │  5. API Requests │\n          │                       │                       │\n          ▼                       ▼                       ▼\n    ┌──────────┐           ┌──────────┐           ┌──────────┐\n    │  SKILL   │           │ Dashboard│           │  npm │\n    │  File    │           │ Auth     │           │ Registry │\n    └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for npm again.\"\n\n## Quick Start\n\n```bash\n# Search for packages\nclawlink_call_tool --tool \"npm_search_packages\" --params '{\"query\": \"express\", \"size\": 10}'\n\n# Get package metadata\nclawlink_call_tool --tool \"npm_get_package\" --params '{\"package_name\": \"express\"}'\n\n# Get download statistics\nclawlink_call_tool --tool \"npm_get_download_stats\" --params '{\"package_name\": \"lodash\", \"period\": \"last-month\"}'\n```\n\n## Authentication\n\nAll npm tool calls are authenticated automatically by ClawLink using the user's npm account.\n\n**No API key is required in chat.** ClawLink handles authentication securely and injects it into every npm API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=npm and connect npm.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `npm` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration npm\n```\n\n**Response:** Returns the live tool catalog for npm.\n\n### Reconnect\n\nIf npm tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=npm\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration npm`\n\n## Security & Permissions\n\n- Access is scoped to public and private package data within the connected npm account.\n- **Write operations (token deletion, scope changes) require explicit user confirmation.**\n- Read operations (search, metadata, downloads) are safe and do not modify any data.\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm npm is connected.\n2. Call `clawlink_list_tools --integration npm` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `npm`.\n5. If no npm tools appear, direct the user to https://claw-link.dev/dashboard?add=npm.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: Search packages → Read metadata → Show results    │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview changes → User approves   │\n│           → Execute update                                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Code Examples\n\n### Search packages\n\n```bash\nclawlink_call_tool --tool \"npm_search_packages\" \\\n  --params '{\n    \"query\": \"react framework\",\n    \"size\": 20,\n    \"quality\": 0.8,\n    \"popularity\": 0.5\n  }'\n```\n\n### Get package details\n\n```bash\nclawlink_call_tool --tool \"npm_get_package\" \\\n  --params '{\n    \"package_name\": \"next\",\n    \"version\": \"latest\"\n  }'\n```\n\n### Get download counts\n\n```bash\nclawlink_call_tool --tool \"npm_get_download_counts\" \\\n  --params '{\n    \"package_name\": \"axios\",\n    \"start\": \"2024-01-01\",\n    \"end\": \"2024-01-31\"\n  }'\n```\n\n### Check security advisories\n\n```bash\nclawlink_call_tool --tool \"npm_get_advisories\" \\\n  --params '{\n    \"package_name\": \"lodash\"\n  }'\n```\n\n## Notes\n\n- npm Registry API has rate limits. Use exponential backoff when encountering 429 errors.\n- Some endpoints require authentication for private packages — public package data is available without connection.\n- Download statistics are available with a delay of up to 48 hours.\n- Package names must be lowercase and may include scoped packages (e.g., `@org/package`).\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration npm`. |\n| Missing connection | npm is not connected. Direct the user to https://claw-link.dev/dashboard?add=npm. |\n| `not_found` | Package does not exist in the registry. Check the package name spelling. |\n| `validation_error` | Invalid parameter or missing required field. Review the tool schema with `clawlink_describe_tool`. |\n| Rate limited | Too many requests. Wait and retry with exponential backoff. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `npm`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [npm Documentation](https://docs.npmjs.com/)\n- [npm Registry API](https://github.com/npm/registry)\n- [npm Security Advisories](https://www.npmjs.com/advisories)\n- ClawLink: https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=npm-registry\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [GitHub Repos](https://clawhub.ai/hith3sh/github-repos) — For GitHub repository operations\n- [npm](https://clawhub.ai/hith3sh/npm-registry) — For this skill's native documentation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=npm-registry)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"npm-registry\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1780989250720\n}\n\nFile v1.0.5:skill-card.md\n\n## Description:\n\nSearch npm packages, inspect metadata and versions, review download stats, and check security advisories.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hith3sh](https://clawhub.ai/user/hith3sh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, package maintainers, and security reviewers use this skill to search npm packages, inspect package metadata and versions, review download activity, and check advisories through npm registry tooling.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill asks the user to install and allow a third-party ClawLink plugin that can use an npm account, including private package data.\n\nMitigation: Install only if ClawLink is trusted, review permissions in the ClawLink dashboard, and prefer a least-privilege npm account or token.\n\nRisk: Write operations such as token deletion or scope changes can affect npm account state.\n\nMitigation: Preview and explicitly confirm write operations before execution, and reject actions that do not match the user's intent.\n\n## Reference(s):\n\n- [npm Documentation](https://docs.npmjs.com/)\n- [npm Registry API](https://github.com/npm/registry)\n- [npm Security Advisories](https://www.npmjs.com/advisories)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON parameter examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include npm package metadata, download statistics, advisory checks, connection guidance, and confirmation steps for write operations.]\n\n## Skill Version(s):\n\n1.0.5 (source: release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.4: 3 files, 5028 bytes\n\nFiles: skill-card.md (2396b), SKILL.md (10852b), _meta.json (131b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: npm-registry\ndescription: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm registry data, verify package integrity, or monitor package health via the npm API.\n---\n\n# npm Registry\n\n![npm Registry](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/npm.svg)\n\nAccess the npm public registry via the npm API. Search packages, inspect metadata and versions, review download statistics, and check security advisories and registry health.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure npm API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect npm |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect npm |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│   npm Registry    │\n│   (User Chat)   │     │   (API Key)  │     │   (npmjs.com)    │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n          │                       │                       │\n          │  1. Install Plugin │                       │\n          │  2. Pair Device      │                       │\n          │  3. Connect npm       │                       │\n          │ │  4. Secure Proxy      │\n          │                       │  5. API Requests │\n          │                       │                       │\n          ▼                       ▼                       ▼\n    ┌──────────┐           ┌──────────┐           ┌──────────┐\n    │  SKILL   │           │ Dashboard│           │  npm │\n    │  File    │           │ Auth     │           │ Registry │\n    └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for npm again.\"\n\n## Quick Start\n\n```bash\n# Search for packages\nclawlink_call_tool --tool \"npm_search_packages\" --params '{\"query\": \"express\", \"size\": 10}'\n\n# Get package metadata\nclawlink_call_tool --tool \"npm_get_package\" --params '{\"package_name\": \"express\"}'\n\n# Get download statistics\nclawlink_call_tool --tool \"npm_get_download_stats\" --params '{\"package_name\": \"lodash\", \"period\": \"last-month\"}'\n```\n\n## Authentication\n\nAll npm tool calls are authenticated automatically by ClawLink using the user's npm account.\n\n**No API key is required in chat.** ClawLink handles authentication securely and injects it into every npm API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=npm and connect npm.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `npm` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration npm\n```\n\n**Response:** Returns the live tool catalog for npm.\n\n### Reconnect\n\nIf npm tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=npm\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration npm`\n\n## Security & Permissions\n\n- Access is scoped to public and private package data within the connected npm account.\n- **Write operations (token deletion, scope changes) require explicit user confirmation.**\n- Read operations (search, metadata, downloads) are safe and do not modify any data.\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm npm is connected.\n2. Call `clawlink_list_tools --integration npm` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `npm`.\n5. If no npm tools appear, direct the user to https://claw-link.dev/dashboard?add=npm.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: Search packages → Read metadata → Show results    │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview changes → User approves   │\n│           → Execute update                                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Code Examples\n\n### Search packages\n\n```bash\nclawlink_call_tool --tool \"npm_search_packages\" \\\n  --params '{\n    \"query\": \"react framework\",\n    \"size\": 20,\n    \"quality\": 0.8,\n    \"popularity\": 0.5\n  }'\n```\n\n### Get package details\n\n```bash\nclawlink_call_tool --tool \"npm_get_package\" \\\n  --params '{\n    \"package_name\": \"next\",\n    \"version\": \"latest\"\n  }'\n```\n\n### Get download counts\n\n```bash\nclawlink_call_tool --tool \"npm_get_download_counts\" \\\n  --params '{\n    \"package_name\": \"axios\",\n    \"start\": \"2024-01-01\",\n    \"end\": \"2024-01-31\"\n  }'\n```\n\n### Check security advisories\n\n```bash\nclawlink_call_tool --tool \"npm_get_advisories\" \\\n  --params '{\n    \"package_name\": \"lodash\"\n  }'\n```\n\n## Notes\n\n- npm Registry API has rate limits. Use exponential backoff when encountering 429 errors.\n- Some endpoints require authentication for private packages — public package data is available without connection.\n- Download statistics are available with a delay of up to 48 hours.\n- Package names must be lowercase and may include scoped packages (e.g., `@org/package`).\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration npm`. |\n| Missing connection | npm is not connected. Direct the user to https://claw-link.dev/dashboard?add=npm. |\n| `not_found` | Package does not exist in the registry. Check the package name spelling. |\n| `validation_error` | Invalid parameter or missing required field. Review the tool schema with `clawlink_describe_tool`. |\n| Rate limited | Too many requests. Wait and retry with exponential backoff. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `npm`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [npm Documentation](https://docs.npmjs.com/)\n- [npm Registry API](https://github.com/npm/registry)\n- [npm Security Advisories](https://www.npmjs.com/advisories)\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [GitHub Repos](https://clawhub.ai/hith3sh/github-repos) — For GitHub repository operations\n- [npm](https://clawhub.ai/hith3sh/npm-registry) — For this skill's native documentation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"npm-registry\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1780981222346\n}\n\nFile v1.0.4:skill-card.md\n\n## Description: <br>\nSearch npm packages, inspect metadata and versions, review download statistics, and check security advisories via the npm API. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, package maintainers, and external users use this skill to search npm packages, inspect package metadata and versions, review download statistics, and check advisories through npm registry tools. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill connects to an npm account through ClawLink and may access public or private package data available to that account. <br>\nMitigation: Install only when account access through ClawLink is acceptable, verify the npm connection status, and disconnect the integration when it is no longer needed. <br>\nRisk: Some npm tools may perform account-changing actions such as token deletion or scope changes. <br>\nMitigation: Use preview and explicit user confirmation before write actions, and approve execution only when the preview matches the intended change. <br>\n\n\n## Reference(s): <br>\n- [ClawHub npm Registry Skill](https://clawhub.ai/hith3sh/npm-registry) <br>\n- [npm Documentation](https://docs.npmjs.com/) <br>\n- [npm Registry API](https://github.com/npm/registry) <br>\n- [npm Security Advisories](https://www.npmjs.com/advisories) <br>\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw) <br>\n- [ClawLink Verification](https://claw-link.dev/verify) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and JSON tool parameters] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include npm package metadata, version information, download statistics, advisory summaries, setup steps, and confirmation guidance for write actions.] <br>\n\n## Skill Version(s): <br>\n1.0.4 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 3 files, 5177 bytes\n\nFiles: skill-card.md (2771b), SKILL.md (10852b), _meta.json (131b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: npm-registry\ndescription: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm registry data, verify package integrity, or monitor package health via the npm API.\n---\n\n# npm Registry\n\n![npm Registry](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/npm.svg)\n\nAccess the npm public registry via the npm API. Search packages, inspect metadata and versions, review download statistics, and check security advisories and registry health.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure npm API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect npm |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect npm |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│   npm Registry    │\n│   (User Chat)   │     │   (API Key)  │     │   (npmjs.com)    │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n          │                       │                       │\n          │  1. Install Plugin │                       │\n          │  2. Pair Device      │                       │\n          │  3. Connect npm       │                       │\n          │ │  4. Secure Proxy      │\n          │                       │  5. API Requests │\n          │                       │                       │\n          ▼                       ▼                       ▼\n    ┌──────────┐           ┌──────────┐           ┌──────────┐\n    │  SKILL   │           │ Dashboard│           │  npm │\n    │  File    │           │ Auth     │           │ Registry │\n    └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for npm again.\"\n\n## Quick Start\n\n```bash\n# Search for packages\nclawlink_call_tool --tool \"npm_search_packages\" --params '{\"query\": \"express\", \"size\": 10}'\n\n# Get package metadata\nclawlink_call_tool --tool \"npm_get_package\" --params '{\"package_name\": \"express\"}'\n\n# Get download statistics\nclawlink_call_tool --tool \"npm_get_download_stats\" --params '{\"package_name\": \"lodash\", \"period\": \"last-month\"}'\n```\n\n## Authentication\n\nAll npm tool calls are authenticated automatically by ClawLink using the user's npm account.\n\n**No API key is required in chat.** ClawLink handles authentication securely and injects it into every npm API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=npm and connect npm.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `npm` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration npm\n```\n\n**Response:** Returns the live tool catalog for npm.\n\n### Reconnect\n\nIf npm tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=npm\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration npm`\n\n## Security & Permissions\n\n- Access is scoped to public and private package data within the connected npm account.\n- **Write operations (token deletion, scope changes) require explicit user confirmation.**\n- Read operations (search, metadata, downloads) are safe and do not modify any data.\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm npm is connected.\n2. Call `clawlink_list_tools --integration npm` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `npm`.\n5. If no npm tools appear, direct the user to https://claw-link.dev/dashboard?add=npm.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: Search packages → Read metadata → Show results    │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview changes → User approves   │\n│           → Execute update                                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Code Examples\n\n### Search packages\n\n```bash\nclawlink_call_tool --tool \"npm_search_packages\" \\\n  --params '{\n    \"query\": \"react framework\",\n    \"size\": 20,\n    \"quality\": 0.8,\n    \"popularity\": 0.5\n  }'\n```\n\n### Get package details\n\n```bash\nclawlink_call_tool --tool \"npm_get_package\" \\\n  --params '{\n    \"package_name\": \"next\",\n    \"version\": \"latest\"\n  }'\n```\n\n### Get download counts\n\n```bash\nclawlink_call_tool --tool \"npm_get_download_counts\" \\\n  --params '{\n    \"package_name\": \"axios\",\n    \"start\": \"2024-01-01\",\n    \"end\": \"2024-01-31\"\n  }'\n```\n\n### Check security advisories\n\n```bash\nclawlink_call_tool --tool \"npm_get_advisories\" \\\n  --params '{\n    \"package_name\": \"lodash\"\n  }'\n```\n\n## Notes\n\n- npm Registry API has rate limits. Use exponential backoff when encountering 429 errors.\n- Some endpoints require authentication for private packages — public package data is available without connection.\n- Download statistics are available with a delay of up to 48 hours.\n- Package names must be lowercase and may include scoped packages (e.g., `@org/package`).\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration npm`. |\n| Missing connection | npm is not connected. Direct the user to https://claw-link.dev/dashboard?add=npm. |\n| `not_found` | Package does not exist in the registry. Check the package name spelling. |\n| `validation_error` | Invalid parameter or missing required field. Review the tool schema with `clawlink_describe_tool`. |\n| Rate limited | Too many requests. Wait and retry with exponential backoff. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `npm`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [npm Documentation](https://docs.npmjs.com/)\n- [npm Registry API](https://github.com/npm/registry)\n- [npm Security Advisories](https://www.npmjs.com/advisories)\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [GitHub Repos](https://clawhub.ai/hith3sh/github-repos) — For GitHub repository operations\n- [npm](https://clawhub.ai/hith3sh/npm-registry) — For this skill's native documentation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"npm-registry\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1780936797384\n}\n\nFile v1.0.1:skill-card.md\n\n## Description: <br>\nSearch npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm registry data, verify package integrity, or monitor package health via the npm API. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to search npm packages, inspect package metadata and versions, review download statistics, and check npm security advisories through a connected ClawLink npm integration. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill requires a ClawLink connection with sensitive npm account access. <br>\nMitigation: Install and use it only when the user trusts ClawLink with the npm account connection, and prefer read-only package lookup workflows unless the user intentionally approves an account change. <br>\nRisk: Setup installs and allowlists a plugin, restarts OpenClaw, and persists the plugin for future chats. <br>\nMitigation: Make the setup step explicit to the user and verify the live integration catalog after restart before relying on npm tools. <br>\nRisk: Some npm operations can modify account state, including token deletion or scope changes. <br>\nMitigation: Describe and preview write operations first, then execute them only after explicit user confirmation. <br>\n\n\n## Reference(s): <br>\n- [ClawHub npm Registry listing](https://clawhub.ai/hith3sh/npm-registry) <br>\n- [npm Documentation](https://docs.npmjs.com/) <br>\n- [npm Registry API](https://github.com/npm/registry) <br>\n- [npm Security Advisories](https://www.npmjs.com/advisories) <br>\n- [ClawLink](https://claw-link.dev) <br>\n- [ClawLink OpenClaw documentation](https://docs.claw-link.dev/openclaw) <br>\n- [ClawLink verification](https://claw-link.dev/verify) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance, API calls] <br>\n**Output Format:** [Markdown guidance with bash commands and JSON tool-call examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May return npm package metadata, version information, download statistics, advisory summaries, connection status, or setup and troubleshooting guidance.] <br>\n\n## Skill Version(s): <br>\n1.0.1 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.1: 3 files, 5064 bytes\n\nFiles: skill-card.md (2477b), SKILL.md (10740b), _meta.json (131b)\n\nFile v0.1.1:SKILL.md\n\n---\nname: npm-registry\ndescription: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm registry data, verify package integrity, or monitor package health via the npm API.\n---\n\n# npm Registry\n\nAccess the npm public registry via the npm API. Search packages, inspect metadata and versions, review download statistics, and check security advisories and registry health.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure npm API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect npm |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect npm |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│   npm Registry    │\n│   (User Chat)   │     │   (API Key)  │     │   (npmjs.com)    │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n          │                       │                       │\n          │  1. Install Plugin │                       │\n          │  2. Pair Device      │                       │\n          │  3. Connect npm       │                       │\n          │ │  4. Secure Proxy      │\n          │                       │  5. API Requests │\n          │                       │                       │\n          ▼                       ▼                       ▼\n    ┌──────────┐           ┌──────────┐           ┌──────────┐\n    │  SKILL   │           │ Dashboard│           │  npm │\n    │  File    │           │ Auth     │           │ Registry │\n    └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for npm again.\"\n\n## Quick Start\n\n```bash\n# Search for packages\nclawlink_call_tool --tool \"npm_search_packages\" --params '{\"query\": \"express\", \"size\": 10}'\n\n# Get package metadata\nclawlink_call_tool --tool \"npm_get_package\" --params '{\"package_name\": \"express\"}'\n\n# Get download statistics\nclawlink_call_tool --tool \"npm_get_download_stats\" --params '{\"package_name\": \"lodash\", \"period\": \"last-month\"}'\n```\n\n## Authentication\n\nAll npm tool calls are authenticated automatically by ClawLink using the user's npm account.\n\n**No API key is required in chat.** ClawLink handles authentication securely and injects it into every npm API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=npm and connect npm.\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `npm` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration npm\n```\n\n**Response:** Returns the live tool catalog for npm.\n\n### Reconnect\n\nIf npm tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=npm\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration npm`\n\n## Security & Permissions\n\n- Access is scoped to public and private package data within the connected npm account.\n- **Write operations (token deletion, scope changes) require explicit user confirmation.**\n- Read operations (search, metadata, downloads) are safe and do not modify any data.\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm npm is connected.\n2. Call `clawlink_list_tools --integration npm` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `npm`.\n5. If no npm tools appear, direct the user to https://claw-link.dev/dashboard?add=npm.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: Search packages → Read metadata → Show results    │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview changes → User approves   │\n│           → Execute update                                  │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Code Examples\n\n### Search packages\n\n```bash\nclawlink_call_tool --tool \"npm_search_packages\" \\\n  --params '{\n    \"query\": \"react framework\",\n    \"size\": 20,\n    \"quality\": 0.8,\n    \"popularity\": 0.5\n  }'\n```\n\n### Get package details\n\n```bash\nclawlink_call_tool --tool \"npm_get_package\" \\\n  --params '{\n    \"package_name\": \"next\",\n    \"version\": \"latest\"\n  }'\n```\n\n### Get download counts\n\n```bash\nclawlink_call_tool --tool \"npm_get_download_counts\" \\\n  --params '{\n    \"package_name\": \"axios\",\n    \"start\": \"2024-01-01\",\n    \"end\": \"2024-01-31\"\n  }'\n```\n\n### Check security advisories\n\n```bash\nclawlink_call_tool --tool \"npm_get_advisories\" \\\n  --params '{\n    \"package_name\": \"lodash\"\n  }'\n```\n\n## Notes\n\n- npm Registry API has rate limits. Use exponential backoff when encountering 429 errors.\n- Some endpoints require authentication for private packages — public package data is available without connection.\n- Download statistics are available with a delay of up to 48 hours.\n- Package names must be lowercase and may include scoped packages (e.g., `@org/package`).\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration npm`. |\n| Missing connection | npm is not connected. Direct the user to https://claw-link.dev/dashboard?add=npm. |\n| `not_found` | Package does not exist in the registry. Check the package name spelling. |\n| `validation_error` | Invalid parameter or missing required field. Review the tool schema with `clawlink_describe_tool`. |\n| Rate limited | Too many requests. Wait and retry with exponential backoff. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Invalid Tool Call\n\n1. Ensure the integration slug is exactly `npm`.\n2. Use `clawlink_describe_tool` to verify parameter names and types before calling.\n3. For write operations, always call `clawlink_preview_tool` first.\n\n## Resources\n\n- [npm Documentation](https://docs.npmjs.com/)\n- [npm Registry API](https://github.com/npm/registry)\n- [npm Security Advisories](https://www.npmjs.com/advisories)\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [GitHub Repos](https://clawhub.ai/hith3sh/github-repos) — For GitHub repository operations\n- [npm](https://clawhub.ai/hith3sh/npm-registry) — For this skill's native documentation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"npm-registry\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1780839211735\n}\n\nFile v0.1.1:skill-card.md\n\n## Description: <br>\nSearch npm packages, inspect metadata and versions, review download stats, and check security advisories via the npm API. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and maintainers use this skill to explore npm registry data, inspect package health, review download activity, and check security advisories through ClawLink-backed npm tools. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill connects to a user's npm account through ClawLink and may access private package data available to that account. <br>\nMitigation: Use a least-privilege npm connection where available and install only when account connection through ClawLink is acceptable. <br>\nRisk: Disclosed npm write actions such as token deletion or scope changes could affect packages or account state. <br>\nMitigation: Require explicit confirmation for any token, scope, package, or account change, and preview unfamiliar write tools before execution. <br>\nRisk: The live npm tool catalog can change, so guessed tool names or parameters may be wrong. <br>\nMitigation: Review the live tool catalog and describe tools before use when the exact capability or schema is unclear. <br>\n\n\n## Reference(s): <br>\n- [ClawHub npm Registry Skill](https://clawhub.ai/hith3sh/npm-registry) <br>\n- [npm Documentation](https://docs.npmjs.com/) <br>\n- [npm Registry API](https://github.com/npm/registry) <br>\n- [npm Security Advisories](https://www.npmjs.com/advisories) <br>\n- [ClawLink OpenClaw Docs](https://docs.claw-link.dev/openclaw) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples and JSON tool-call parameters] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include npm package metadata, download statistics, advisory summaries, and tool-call parameters.] <br>\n\n## Skill Version(s): <br>\n0.1.1 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.0: 3 files, 3495 bytes\n\nFiles: skill-card.md (2404b), SKILL.md (4922b), _meta.json (131b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: npm-registry\ndescription: Search packages, inspect registry metadata, review download stats, and check advisories in npm - powered by ClawLink.\n---\n\n# npm\n\nWork with npm from chat - search packages, inspect metadata, review download stats, and check registry health or advisories.\n\nPowered by [ClawLink](https://claw-link.dev), an integration hub for OpenClaw that handles hosted connection flows and credentials so you don't need to configure npm API access yourself.\n\n## Quick start\n\n1. Install the verified ClawLink plugin: `openclaw plugins install clawhub:clawlink-plugin`\n2. Start a fresh OpenClaw chat if the plugin was just installed and ClawLink tools are not visible yet\n3. If ClawLink is not configured, call `clawlink_begin_pairing`\n4. Tell the user to open the returned pairing URL, sign in to ClawLink if needed, and approve the device\n5. After the user confirms approval, call `clawlink_get_pairing_status`\n6. Tell the user to connect npm at [claw-link.dev/dashboard?add=npm](https://claw-link.dev/dashboard?add=npm)\n7. When the user confirms npm is connected, call `clawlink_list_integrations` and then `clawlink_list_tools` with the `npm` integration slug\n\n## Setup details\n\n### Installing the plugin\n\nIf the ClawLink plugin is not installed yet, tell the user to run:\n\n```\nopenclaw plugins install clawhub:clawlink-plugin\n```\n\nIf the current chat started before the plugin was installed and ClawLink tools are still unavailable, tell the user to start a fresh chat so OpenClaw reloads the plugin tool catalog.\n\n### Pairing ClawLink\n\nIf ClawLink reports that the plugin is not configured, the plugin has not been paired with the user's ClawLink account yet.\n\n1. Call `clawlink_begin_pairing`.\n2. Tell the user to open the returned pairing URL in their browser.\n3. The user signs in to ClawLink if needed and approves the OpenClaw device.\n4. After the user confirms approval, call `clawlink_get_pairing_status` to finish local setup.\n\nThe resulting device credential is stored locally in OpenClaw's plugin config and is only sent to `claw-link.dev`. The user should not paste raw credentials into chat.\n\n### Connecting npm\n\nTell the user to open https://claw-link.dev/dashboard?add=npm and connect npm there. The page opens the add-connection panel filtered to npm. ClawLink's hosted page runs the npm provider connection flow. When they confirm it is done, call `clawlink_list_integrations` to verify, then call `clawlink_list_tools` with integration `npm`.\n\n## Using npm tools\n\nClawLink provides tools dynamically based on what the user has connected. You do not need to know tool names or schemas in advance.\n\n### Discovery\n\n1. Call `clawlink_list_integrations` to confirm npm is connected.\n2. Call `clawlink_list_tools` with integration `npm`.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `npm`.\n5. If no npm tools appear, direct the user to https://claw-link.dev/dashboard?add=npm.\n\n### Execution\n\n1. Call `clawlink_describe_tool` before using an unfamiliar tool, before any write, or when the request is ambiguous.\n2. Use the returned schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups`.\n3. Prefer search, package metadata, download metrics, and advisory reads before account-changing operations.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first, then confirm with the user.\n5. Execute with `clawlink_call_tool`.\n6. If it fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## What you can do\n\nTypical npm tasks (actual availability depends on the user's connected account, permissions, scopes, and current ClawLink tool catalog):\n\n- Search the npm registry for packages\n- Inspect package metadata, versions, and registry changes\n- Review package download counts for points in time or date ranges\n- Check security advisories and registry incidents\n- Inspect overall registry status and metadata\n\n## Rules\n\n- Always use ClawLink tools for npm. Do not ask the user for separate npm credentials.\n- Do not claim a capability is missing without checking the live ClawLink catalog in the current turn.\n- Do not invent slash commands or ask the user to paste raw credentials.\n- Ask for confirmation before deleting tokens or making account-changing actions.\n- If npm is not connected, direct the user to https://claw-link.dev/dashboard?add=npm.\n- Never echo or repeat the user's ClawLink credential.\n\n## Resources\n\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n- ClawLink Source: https://github.com/hith3sh/clawlink\n- npm Docs: https://docs.npmjs.com/\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"npm-registry\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1779633067488\n}\n\nFile v0.1.0:skill-card.md\n\n## Description: <br>\nSearch packages, inspect registry metadata, review download stats, and check advisories in npm - powered by ClawLink. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and package maintainers use this skill to work with npm from chat, including package search, metadata inspection, download statistics review, registry health checks, and advisory checks through a connected ClawLink npm integration. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The connected npm integration may expose account-changing tools beyond the skill's read-focused registry description. <br>\nMitigation: Review the live ClawLink tool catalog, describe unfamiliar tools before use, and preview plus confirm any write or account-changing action before execution. <br>\nRisk: The skill depends on ClawLink pairing and connected-account permissions, so available npm actions vary by user configuration. <br>\nMitigation: Verify npm is connected through ClawLink in the current session and treat the returned tool list as the source of truth. <br>\nRisk: ClawLink device credentials are involved in setup. <br>\nMitigation: Do not ask users to paste raw credentials into chat, and never echo or repeat ClawLink credentials. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/hith3sh/npm-registry) <br>\n- [ClawLink](https://claw-link.dev) <br>\n- [ClawLink OpenClaw Docs](https://docs.claw-link.dev/openclaw) <br>\n- [npm Docs](https://docs.npmjs.com/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration instructions, Guidance] <br>\n**Output Format:** [Markdown with inline shell commands and tool-use guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Outputs depend on the live ClawLink npm tool catalog and the user's connected npm permissions.] <br>\n\n## Skill Version(s): <br>\n0.1.0 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: npm Registry Owner: hith3sh Summary: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm regis... Tags: latest:1.0.5 Version history: v1.0.5 | 2026-06-09T07:14:10.720Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic ","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│   npm Registry    │\n│   (User Chat)   │     │   (API Key)  │     │   (npmjs.com)    │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n          │                       │                       │\n          │  1. Install Plugin │                       │\n          │  2. Pair Device      │                       │\n          │  3. Connect npm       │                       │\n          │ │  4. Secure Proxy      │\n          │                       │  5. API Requests │\n          │                       │                       │\n          ▼                       ▼                       ▼\n    ┌──────────┐           ┌──────────┐           ┌──────────┐\n    │  SKILL   │           │ Dashboard│           │  npm │\n    │  File    │           │ Auth     │           │ Registry │\n    └──────────┘           └──────────┘           └──────────┘"},{"language":"bash","snippet":"openclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart"},{"language":"bash","snippet":"# Search for packages\nclawlink_call_tool --tool \"npm_search_packages\" --params '{\"query\": \"express\", \"size\": 10}'\n\n# Get package metadata\nclawlink_call_tool --tool \"npm_get_package\" --params '{\"package_name\": \"express\"}'\n\n# Get download statistics\nclawlink_call_tool --tool \"npm_get_download_stats\" --params '{\"package_name\": \"lodash\", \"period\": \"last-month\"}'"},{"language":"bash","snippet":"clawlink_list_integrations"},{"language":"bash","snippet":"clawlink_list_tools --integration npm"},{"language":"text","snippet":"┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                      │\n│                                                             │\n│  Example: Search packages → Read metadata → Show results    │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call           │\n│                                                             │\n│  Example: Describe tool → Preview changes → User approves   │\n│           → Execute update                                  │\n└─────────────────────────────────────────────────────────────┘"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: npm-registry\ndescription: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm registry data, verify package integrity, or monitor package health via the npm API.\n---\n\n# npm Registry\n\n![npm Registry](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/npm.svg)\n\nAccess the npm public registry via the npm API. Search packages, inspect metadata and versions, review download statistics, and check security advisories and registry health.\n\nThis skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=npm-registry) for hosted connection flows and credentials so you do not need to configure npm API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect npm |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n| Run the install command in OpenClaw | Sign in and approve the device | Open the dashboard and connect npm |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│   npm Registry    │\n│   (User Chat)   │     │   (API Key)  │     │   (npmjs.com)    │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n          │                       │                       │\n          │  1. Install Plugin │                       │\n          │  2. Pair Device      │                       │\n          │  3. Connect npm       │                       │\n          │ │  4. Secure Proxy      │\n          │                       │  5. API Requests │\n          │                       │                       │\n          ▼                       ▼                       ▼\n    ┌──────────┐           ┌──────────┐           ┌──────────┐\n    │  SKILL   │           │ Dashboard│           │  npm │\n    │  File    │           │ Auth     │           │ Registry │\n    └──────────┘           └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for npm again.\"\n\n## Quick Start\n\n```bash\n# Search for packages\nclawlink_call_tool --tool \"npm_search_packages\" --params '{\"query\": \"express\", \"size\": 10}'\n\n# Get package metadata\nclawlink_call_tool --tool \"npm_get_package\" --params '{\"package_name\": \"express\"}'\n\n# Get download statis"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"npm-registry\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1780989250720\n}"},{"path":"skill-card.md","content":"## Description:\n\nSearch npm packages, inspect metadata and versions, review download stats, and check security advisories.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hith3sh](https://clawhub.ai/user/hith3sh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, package maintainers, and security reviewers use this skill to search npm packages, inspect package metadata and versions, review download activity, and check advisories through npm registry tooling.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill asks the user to install and allow a third-party ClawLink plugin that can use an npm account, including private package data.\n\nMitigation: Install only if ClawLink is trusted, review permissions in the ClawLink dashboard, and prefer a least-privilege npm account or token.\n\nRisk: Write operations such as token deletion or scope changes can affect npm account state.\n\nMitigation: Preview and explicitly confirm write operations before execution, and reject actions that do not match the user's intent.\n\n## Reference(s):\n\n- [npm Documentation](https://docs.npmjs.com/)\n- [npm Registry API](https://github.com/npm/registry)\n- [npm Security Advisories](https://www.npmjs.com/advisories)\n- [ClawLink Docs](https://docs.claw-link.dev/openclaw)\n- [ClawLink Verification](https://claw-link.dev/verify)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON parameter examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include npm package metadata, download statistics, advisory checks, connection guidance, and confirmation steps for write operations.]\n\n## Skill Version(s):\n\n1.0.5 (source: release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm regis... Skill: npm Registry Owner: hith3sh Summary: Search npm packages, inspect metadata and versions, review download stats, and check security advisories. Use this skill when users want to explore npm regis... Tags: latest:1.0.5 Version history: v1.0.5 | 2026-06-09T07:14:10.720Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1002,"uniquenessScore":50,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:45:19.063Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:45:19.063Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:54:30.066Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}