{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=lgoyal6/package-ship@0.1.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/package-ship@0.1.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/lgoyal6/package-ship@0.1.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/package-ship@0.1.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Reports what an npm package will actually publish, as against what its author believes it publishes. The gap between those two is where credentials and dead weight escape. Derives the tarball statically, the way npm does: the files allowlist if package.json has one, else .npmignore, else .gitignore, plus the always-included list (package.json, README, LICENSE, the main file) and the always-excluded list (.git, node_modules, .npmrc, lockfiles). Names the credentials that would ship and opens each one to confirm it holds a live value rather than a placeholder, the entry points in main, module, types, exports and bin that resolve to a path the tarball will not contain (a package that installs broken), the files patterns that match nothing, the total shipped size and the largest shipped files. Skips private packages, because a private package is never published and its contents are not a publishing risk. Never runs npm pack, which would need a network-capable npm, execute the package prepare scripts and write a t","distribution":{"digest":"sha256:7f8ea9b8cb1f70e8b9a61b9f9457df4d0325acd2da9a2b6c9a134984c3ef56f5","mediaType":"application/vnd.modiqo.rote-flow","size":22177,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/lgoyal6/package-ship@0.1.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/lgoyal6/package-ship@0.1.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/lgoyal6/package-ship@0.1.0.json"},"name":"package-ship","owner":{"kind":"user","slug":"lgoyal6"},"parameters":[{"description":"Directory to search for package.json manifests; each one is assessed as its own package","example":".","input":{"allowCustom":true,"choices":[],"label":"Root"},"name":"root","required":true,"type":"string"},{"default":"3","description":"How many directory levels below root to search for manifests, so a monorepo can be assessed package by package","example":"2","input":{"allowCustom":true,"choices":[],"label":"Depth"},"name":"depth","required":false,"type":"string"},{"default":"10","description":"How many of the largest shipped files to name per package","example":"5","input":{"allowCustom":true,"choices":[],"label":"Top"},"name":"top","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/package-ship@0.1.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/lgoyal6/package-ship@0.1.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/package-ship@0.1.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.78.0"},"publishedAt":"2026-09-03T00:45:36.185749+00:00","reference":"lgoyal6/package-ship@0.1.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3","bash","find","mktemp","rm","wc","tr","sort","head"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":0,"installs":0},"steps":{"count":2,"names":["analyze","discover"]},"title":"package-ship","type":"play","version":"0.1.0","visibility":"public"}