A high-performance Node.js package manager that enforces strict dependency resolution and optimizes disk usage through content-addressable storage.

Install

mkdir -p .claude/skills/pnpm && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/1791" && unzip -o skill.zip -d .claude/skills/pnpm && rm skill.zip

Installs to .claude/skills/pnpm

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Node.js package manager with strict dependency resolution. Use when running pnpm specific commands, configuring workspaces, or managing dependencies with catalogs, patches, or overrides.
186 chars✓ has a “when” trigger
Beginner

Key capabilities

  • Manage monorepo workspaces via pnpm-workspace.yaml
  • Centralize dependency versions using catalogs
  • Patch third-party packages for fixes
  • Enforce strict dependency resolution

How it works

Uses content-addressable storage to manage package links and executes commands against strict resolution rules defined in local config files.

Inputs & outputs

You give it
Pnpm command or configuration change request
You get back
Modified dependency graph and lockfile

When to use pnpm

  • Install dependencies in a monorepo
  • Configure workspace catalogs for versions
  • Apply dependency patches or overrides
  • Manage project packages with frozen lockfiles

About this skill

pnpm is a fast, disk space efficient package manager. It uses a content-addressable store to deduplicate packages across all projects on a machine, and enforces strict dependency resolution by default, preventing phantom dependencies.

Configuration model (important): pnpm settings now live in pnpm-workspace.yaml (and the global config.yaml) using camelCase keys. .npmrc is used only for authentication/registry credentials, and the pnpm field of package.json is no longer read. When working in a pnpm project, check pnpm-workspace.yaml for settings/workspace structure and .npmrc only for auth. Always use --frozen-lockfile (or pnpm ci) in CI.

The skill is based on pnpm 10.x, generated at 2026-06-22. It also covers v11 behavior changes (config split, isolated global packages, allowBuilds, pmOnFail, global virtual store) where current docs describe them.

Core

TopicDescriptionReference
CLI Commandsinstall/add/remove/update, run, dlx/pnx, workspace, runtime, publishing (version, view, sbom, stage)core-cli
Configurationpnpm-workspace.yaml settings (camelCase), global config.yaml, packageConfigs, .npmrc authcore-config
WorkspacesMonorepo support: filtering, workspace protocol, shared lockfile, packageConfigscore-workspaces
StoreContent-addressable store, virtual store, node linker modes, frozen/read-only storecore-store

Features

TopicDescriptionReference
CatalogsCentralized dependency versions; catalogMode, catalog: in overridesfeatures-catalogs
OverridesForce versions (incl. transitive & peer deps); packageExtensionsfeatures-overrides
PatchesModify third-party packages; patchedDependencies in pnpm-workspace.yamlfeatures-patches
AliasesInstall under custom names (npm:) and registry aliases (namedRegistries)features-aliases
Hooks.pnpmfile.mjs hooks (readPackage, updateConfig, beforePacking), finders, resolvers/fetchersfeatures-hooks
Peer DependenciesAuto-install, strict mode, rules, dedupePeers, peers checkfeatures-peer-deps
Config DependenciesShare hooks/settings/catalogs/patches across repos via configDependenciesfeatures-config-dependencies
Global Virtual StoreShared node_modules, git-worktree multi-agent setups, isolated global packagesfeatures-global-virtual-store
Supply-Chain SecurityBuild approval (allowBuilds), minimumReleaseAge, trustPolicy, lockfile integrityfeatures-supply-chain-security

Best Practices

TopicDescriptionReference
CI/CD SetupGitHub Actions, GitLab, Docker, pnpm ci, store caching, frozen lockfilesbest-practices-ci
Migrationnpm/Yarn → pnpm, phantom deps, and pnpm v10 → v11 config migrationbest-practices-migration
PerformanceInstall optimizations, allowBuilds, global virtual store, workspace parallelizationbest-practices-performance

When not to use it

  • Managing projects requiring npm-specific global hoisting
  • Small projects where simplicity outweighs strictness

Prerequisites

node.jsPnpm installed globally

Limitations

  • Strict resolution can cause version conflicts in unmanaged repos
  • Requires specific workspace config files

How it compares

It deduplicates packages across projects using hard links, preventing the phantom dependency issues common in other package managers.

Compared to similar skills

pnpm side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
pnpm (this skill)46moNo flagsBeginner
upgrading-expo34moReviewIntermediate
dependency-upgrade265moReviewIntermediate
pnpm-upgrade23moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

Search skills

Search the agent skills registry