It really depends what's in the .npmrc. For example, you might have one containing only a setting to use absolute versions when installing packages and saving them. It's also worth noting that it's a good idea (although I always forget) to use the files field of package.json to act as a whitelist.
Edit: the author notes that these are excluded by npm anyway these days. The documentation does not reflect this.