tsdown
Bundle TypeScript Libraries with tsdown
Library builds often need multiple formats, declarations, and package validation. This skill guides tsdown configuration, migration, framework integration, and troubleshooting.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "tsdown" from https://skillstore.io/skills/antfu-tsdown.md and its manifest at https://skillstore.io/api/skills/antfu-tsdown/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "tsdown". Bundle a TypeScript library for Node.js and browser consumers.
Expected outcome:
- Recommended build: ESM and CommonJS outputs, declarations, source maps, and a clean distribution directory.
- Dependency plan: externalize declared peers and test both runtime targets before publication.
Using "tsdown". Migrate an existing tsup build with multiple entries.
Expected outcome:
- Migration summary: preserve entry patterns, formats, declaration generation, and external dependencies.
- Review list: verify renamed options, output extensions, cleaning behavior, and package exports.
Using "tsdown". Improve slow rebuilds in a component library.
Expected outcome:
Use watch exclusions for dependencies, build output, repository metadata, and tests. Consider disabling declaration generation during local watch sessions.
Security Audit
High RiskReview confirmed eight findings covering compile-time environment-file loading and an automated release example that deletes output and publishes to npm. The remaining 158 detections are documentation, template literals, fixed local operations, or public links without malicious behavior. No prompt injection, exfiltration intent, or concealed execution was found.
Confirmed security concerns (5)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Env variables (13)
โ๏ธ External commands (50)
๐ Filesystem access (7)
โก Contains scripts (2)
๐ Network access (5)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/antfu-tsdown/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/antfu-tsdown?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/antfu-tsdown?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/antfu-tsdown/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/antfu-tsdown.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
antfu. (2026). tsdown security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/antfu-tsdown/audits/5BibTeX citation
@techreport{antfu-antfu-tsdown-2026,
author = {antfu},
title = {tsdown security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/antfu-tsdown/audits/5},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "tsdown security audit report (audit version 5)"
version: "unspecified"
type: report
authors:
- name: "antfu"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/antfu-tsdown/audits/5"
identifiers:
- type: other
value: "skillstore:antfu-tsdown:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Publish a TypeScript library
Create ESM and CommonJS outputs, declarations, exports, and validation settings for an npm package.
Migrate from tsup
Translate existing build settings to tsdown and identify incompatible or renamed options.
Standardize monorepo builds
Define shared workspace builds, framework plugins, dependency rules, and CI checks across packages.
Try These Prompts
Create a tsdown configuration for [entry file]. Output ESM and CommonJS, generate declarations, and clean only the distribution directory.
Migrate this tsup configuration to tsdown: [configuration]. Preserve entries, formats, declarations, externals, and source maps. Explain unsupported options.
Configure tsdown for a [framework] component library. Externalize framework peers, generate declarations, and include the required compiler plugin.
Design a monorepo build for [packages]. Add workspace filters, CI validation, output checks, and a publication step requiring explicit confirmation.
Best Practices
- Inspect the existing package manifest, runtime targets, and peer dependencies before creating a configuration.
- Keep output in a dedicated directory and validate the resolved path before cleaning.
- Test packed artifacts on every supported runtime before publishing.
Avoid
- Do not set the output directory to the project root while cleaning is enabled.
- Do not bundle framework peer dependencies unless consumers require embedded copies.
- Do not load secret environment values into compile-time definitions.
Frequently Asked Questions
Does this skill install or run tsdown automatically?
Which Node.js version is required?
Can it migrate a tsup configuration?
Does it support component libraries?
Can it generate TypeScript declarations?
How should environment values be handled?
Developer Details
Author
antfuLicense
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
89edfdc710d0846129dcee6a929477b04f08052c
Maintenance freshness
7/24/2026
Usage
9 downloads ยท 353 views
File structure
๐ LICENSE.md
๐ README.md
๐ references/
๐ advanced-ci.md
๐ advanced-hooks.md
๐ advanced-plugins.md
๐ advanced-rolldown-options.md
๐ guide-migrate-from-tsup.md
๐ option-cleaning.md
๐ option-css.md
๐ option-dts.md
๐ option-entry.md
๐ option-exe.md
๐ option-lint.md
๐ option-log-level.md
๐ option-output-directory.md
๐ option-package-exports.md
๐ option-platform.md
๐ option-root.md
๐ option-shims.md
๐ option-sourcemap.md
๐ option-target.md
๐ option-unbundle.md
๐ option-watch-mode.md
๐ README.md
๐ recipe-react.md
๐ recipe-solid.md
๐ recipe-svelte.md
๐ recipe-vue.md
๐ recipe-wasm.md
๐ reference-cli.md
๐ SKILL.md
๐ SYNC.md