npm
Shanone’s npm integration gives your agent 52 tools for managing packages, organizations, teams, tokens, and security across the npm registry.Getting Started
1
Generate an npm access token
Run
npm token create or go to npmjs.com Access Tokens settings and create a Granular Access Token scoped to the packages/orgs you need.2
Add the token in Shanone
Go to Integrations > npm in the Shanone dashboard and paste the access token in.
3
Retry your request
Once saved,
shanone_execute_tool calls for npm_* tools will succeed.Available Tools
Shanone provides 52 tools for npm, organized into these categories:Packages
Packages
npm_get_package, npm_get_package_version, npm_get_package_abbreviated, npm_search_packages, npm_search_packages_advanced, npm_get_dist_tags, npm_get_latest_version, npm_get_registry_infoAccess & collaborators
Access & collaborators
npm_get_package_visibility, npm_set_package_access, npm_list_package_collaborators, npm_add_package_collaborator, npm_remove_package_collaborator, npm_add_dist_tag, npm_remove_dist_tag, npm_list_dist_tags_authDownloads
Downloads
npm_get_download_point, npm_get_download_point_all, npm_get_download_range, npm_get_download_range_all, npm_get_download_bulk, npm_get_download_versionsOrganizations
Organizations
npm_list_org_members, npm_add_org_member, npm_remove_org_member, npm_list_org_teams, npm_list_org_packages, npm_get_orgTeams
Teams
npm_create_team, npm_delete_team, npm_list_team_members, npm_add_team_member, npm_remove_team_member, npm_list_team_packages, npm_grant_team_package_access, npm_revoke_team_package_accessTokens
Tokens
npm_list_tokens, npm_create_token, npm_delete_token, npm_whoami, npm_validate_tokenUsers & publishers
Users & publishers
npm_get_user_profile, npm_update_user_profile, npm_deprecate_package, npm_undeprecate_package, npm_list_trusted_publishers, npm_add_trusted_publisher, npm_remove_trusted_publisher, npm_star_packageSecurity audits
Security audits
npm_audit_bulk, npm_get_advisory, npm_search_advisoriesCommon Use Cases
Dependency security review
Bulk-audit a
package.json’s dependencies and surface known advisoriesPackage hygiene
Deprecate old package versions and check download trends before removing them
Access management
Add a new team member and grant them access to the right packages
Publish monitoring
Track download counts after a release to gauge adoption
Troubleshooting
npm_add_org_member or team tools fail with a permission error
npm_add_org_member or team tools fail with a permission error
Organization and team management requires the token to belong to an npm org owner or admin — a token scoped to a single package won’t work for these calls.
npm_audit_bulk returns fewer advisories than expected
npm_audit_bulk returns fewer advisories than expected
Bulk audit matches against exact package name + version ranges; ensure you’re passing the resolved versions from a lockfile rather than the semver ranges in
package.json.npm_set_package_access fails for a scoped package
npm_set_package_access fails for a scoped package
Setting visibility (public/restricted) on scoped packages requires a paid npm org plan for private packages — free accounts can only publish scoped packages as public.