Package-lock.json Parsing
SkillFiles & storageParse and extract package information from npm package-lock.json files to identify dependencies and their installed versions.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Package-lock.json Parsing skill
What this skill tells your AI
The instructions your AI receives, as published by cxcscmu/skilllearnbench in skills/b1-one-shot-claude-haiku-4-5/dependency-vulnerability-check/package-lock-parsing/SKILL.md and read by ahel’s review.
Overview
The package-lock.json file is an npm lock file that records exact dependency versions used in a project. It enables reproducible installs and is essential for vulnerability scanning.
File Structure
The package-lock.json follows this structure:
{
"name": "project-name",
"version": "1.0.0",
"lockfileVersion": 3,
"packages": {
"": {
"name": "project-name",
"version": "1.0.0",
"dependencies": {
"express": "^4.18.0"
}
},
"node_modules/express": {
"version": "4.18.2",
"resolved": "https://registry.npmjs.org/express/-/express-4.18.2.tgz"
}
}
}
Key Properties
- packages: Contains all packages (root + node_modules)
- version: The installed version of each package
- dependencies: Direct dependencies of a package
Extraction Pattern
import json
def parse_package_lock(file_path):
with open(file_path, 'r') as f:
lock_data = json.load(f)
packages = {}
for pkg_path, pkg_info in lock_data.get('packages', {}).items():
# Skip root package
if pkg_path == '':
continue
pkg_name = pkg_path.split('/')[-1]
version = pkg_info.get('version')
packages[pkg_name] = version
return packages
Usage
Use this skill when:
- Extracting dependency lists from package-lock.json
- Building vulnerability scanning pipelines
- Analyzing dependency versions for compliance
- Creating inventory reports of installed packages
Related Skills
trivy-vulnerability-scanning: Use parsed packages as input to vulnerability scannersecurity-audit-csv-reporting: Output results in structured CSV format
Signals
- GitHub stars
- 83
- Forks
- 5
- Last commit
- Jul 2026
Advanced
- Catalog kind
- skill
- Gateway key
package-lock-parsing- Source
- github.com/cxcscmu/skilllearnbench