Package JSON Linter for Openclaw

A comprehensive auditing tool for Node.js package.json files to ensure security, valid semver, and project best practices.

charlie-morrison
v1.0.1
May 1, 2026
0
786
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install package-json-linter

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install package-json-linter using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Package JSON Linter?

The Package JSON Linter is a specialized utility designed for developers to maintain high-quality metadata and secure configurations in Node.js environments. As part of the Openclaw Skills ecosystem, this tool automates the validation of package files by checking against 22 distinct rules covering everything from naming conventions to supply chain security. It helps teams catch common mistakes like invalid semantic versions or missing required fields before they impact production or deployment workflows.

By leveraging this skill, developers can perform deep analysis on project scripts and dependencies. The tool specifically flags risky lifecycle scripts and identifies deprecated packages or wildcard dependencies that could lead to environment instability. Whether you are prepping a package for npm publication or auditing a large monorepo, this skill ensures your configuration remains robust and compliant with industry standards.

Package JSON Linter Use Cases

  • Auditing Node.js projects for supply chain security risks in lifecycle scripts.
  • Validating npm naming conventions and semver compliance for new package releases.
  • Identifying fragile dependencies like wildcard versions, git URLs, or file protocols.
  • Automating project health checks during code reviews by generating Markdown-formatted linting reports.

How Package JSON Linter Works

  1. The AI agent triggers the underlying Python linter script targeting a specific package.json file or a directory path.
  2. The script recursively scans the provided location, ignoring node_modules to maintain performance.
  3. A suite of 22 validation rules is executed, categorizing findings into errors, warnings, or informational notes.
  4. The linter analyzes the scripts section for suspicious patterns such as curl, wget, or pipe-to-shell commands.
  5. The tool generates a report in the specified format—text, JSON, or Markdown—and returns an exit code indicating the project status.

Package JSON Linter Setup

To use this feature within Openclaw Skills, ensure Python 3 is available in your environment. You can run the linter directly via the CLI using the bundled script.

python3 scripts/package_json_linter.py lint <path-to-project> --format markdown

For security-focused audits, use the security command:

python3 scripts/package_json_linter.py security <path-to-project>

Package JSON Linter Data Schema & Taxonomy

The skill organizes its findings into a structured taxonomy of rules. Reports can be outputted as JSON for programmatic use or Markdown tables for documentation.

Rule Category Count Focus Areas
Required Fields 5 Name, version, and npm naming rules
Dependencies 6 Wildcards, git dependencies, and deprecated packages
Security 4 Install scripts and suspicious shell commands
Best Practices 7 Licenses, engine specifications, and HTTPS URLs

Package JSON Linter Advanced Features

  • Strict mode integration that converts all warnings into non-zero exit codes for strict CI/CD gatekeeping.
  • Recursive scanning capabilities to audit entire monorepos in a single command pass.
  • Multiple output formats including raw JSON for integration with other automated Openclaw Skills workflows.
  • Specialized script analysis that detects obfuscated or dangerous command patterns in the npm lifecycle.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*