Skip to main content

jfrog-package-curation

Check/download a package (npm, Maven, PyPI, Go...) via JFrog — safe, allowed, curated? Or: package op fails/blocked (ETARGET, 403, blocked by curation policy, missing version, waiver) — root cause it. Checks the JFrog Public Catalog and stored packages for a version, interprets catalog security signals, and downloads through Artifactory (JFrog Platform locations, remote cache, curation-aware package managers, or repo proxy). Do NOT use for pure CVE or vulnerability lookups (e.g. "details on CVE-2021-23337") — those are handled by the jfrog skill's Public security domain queries without this workflow. Do NOT use for installing, listing, or approving MCP servers/tools (even when named like a package, e.g. `@scope/pkg`) — that's `jfrog-mcp-management`.

Jump to install

Source facts

Repository
jfrog/jfrog-skills
Last source activity
August 27, 2026 at 10:08
Detected SKILL.md language
English
Stars
21
Forks
10

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.