A comprehensive auditing tool for Node.js package.json files to ensure security, valid semver, and project best practices.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install package-json-linter
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install package-json-linter using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Package JSON Linter is a specialized utility designed for developers to maintain high-quality metadata and secure configurations in Node.js environments. As part of the Openclaw Skills ecosystem, this tool automates the validation of package files by checking against 22 distinct rules covering everything from naming conventions to supply chain security. It helps teams catch common mistakes like invalid semantic versions or missing required fields before they impact production or deployment workflows.
By leveraging this skill, developers can perform deep analysis on project scripts and dependencies. The tool specifically flags risky lifecycle scripts and identifies deprecated packages or wildcard dependencies that could lead to environment instability. Whether you are prepping a package for npm publication or auditing a large monorepo, this skill ensures your configuration remains robust and compliant with industry standards.
To use this feature within Openclaw Skills, ensure Python 3 is available in your environment. You can run the linter directly via the CLI using the bundled script.
python3 scripts/package_json_linter.py lint <path-to-project> --format markdown
For security-focused audits, use the security command:
python3 scripts/package_json_linter.py security <path-to-project>
The skill organizes its findings into a structured taxonomy of rules. Reports can be outputted as JSON for programmatic use or Markdown tables for documentation.
| Rule Category | Count | Focus Areas |
|---|---|---|
| Required Fields | 5 | Name, version, and npm naming rules |
| Dependencies | 6 | Wildcards, git dependencies, and deprecated packages |
| Security | 4 | Install scripts and suspicious shell commands |
| Best Practices | 7 | Licenses, engine specifications, and HTTPS URLs |
Loading
An automated assistant that provides structured feedback on code quality, security, and performance for pull requests.

A comprehensive diagnostic tool to find and fix performance-draining N+1 query patterns in ORM-based applications.

A comprehensive auditing tool that generates a 0-100 health score for any repository based on eight critical engineering dimensions.

A powerful tool to generate, validate, and lint hardened systemd unit files for services, timers, and sockets.

A comprehensive validation tool for Python pyproject.toml files ensuring PEP standard compliance and tool configuration integrity.

A professional diagnostic tool that audits Celery configurations for reliability, security vulnerabilities, and operational performance.








































