Search
npm · Dependency management
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release. | express-validator/ | 6.2k | — | ~1.2k | Automated safety check: Pass | MIT | 8 days ago |
| 2 | Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog. | ykdojo/ | 10k | — | ~1.8k | Automated safety check: Pass | Unknown | 16 days ago |
| 3 | Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions… | logseq/ | 45k | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 4 | Upgrades a pinned agent SDK in the agor project, such as the Claude, Codex or Gemini CLI one, and plans the release that carries it to packaged installs. | preset-io/ | 1.4k | — | ~1.4k | Automated safety check: Pass | Unknown | yesterday |
| 5 | Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions… | Consensys-Incorporated/ | 177 | 1 repo | ~3.7k | Automated safety check: Warn | MIT | 10 days ago |
| 6 | Bumps the pinned Electron version across the RStudio repository, updating NEWS.md, package.json, the lockfile and the allowScripts entry. | rstudio/ | 5.1k | — | ~964 | Automated safety check: Pass | Unknown | today |
| 7 | Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format. | aubepkg/ | 2k | — | ~1.1k | Automated safety check: Warn | MIT | yesterday |
| 8 | Check if package.json files are in sync with pnpm-lock.yaml. | Hyk260/ | 546 | — | ~594 | Automated safety check: Pass | MIT | 24 days ago |
| 9 | Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files… | livesession/ | 114 | — | ~2k | Automated safety check: Pass | MIT | 2 days ago |
| 10 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 858 | — | ~1k | Automated safety check: Warn | MIT | 10 days ago |
| 11 | Guides writing, running and configuring Deno 2.9+ projects: installing npm and JSR dependencies, permissions, config file precedence and the built-in fmt, lint, test and compile toolchain. | denoland/ | 100 | — | ~2.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 12 | Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way. | pierrecomputer/ | 6.3k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 13 | Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt… | ossf/ | 165 | — | ~1.7k | Automated safety check: Notes | MIT | yesterday |
| 14 | 14.Dep Auditor 审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用 | laolaoshiren/ | 880 | — | ~895 | Automated safety check: Pass | MIT | 6 days ago |
| 15 | Audit repo dependencies by default and only apply library upgrades when explicitly requested. | championswimmer/ | 130 | — | ~1k | Automated safety check: Pass | No licence | 4 mo ago |
| 16 | Points the agent at Bun 1.4 built-in APIs before it installs an npm package, so image, browser, markdown, cron, PTY and test work uses what Bun already ships. | code-yeongyu/ | 474 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 17 | Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision. | backnotprop/ | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 18 | Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. | unional/ | 133 | — | ~1.4k | Automated safety check: Warn | MIT | today |
| 19 | Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does. | Edwardvaneechoud/ | 389 | — | ~7.3k | Automated safety check: Notes | MIT | yesterday |
| 20 | Quick reference for using Bun to run TypeScript and JavaScript, install packages, bundle code, run tests and serve HTTP, with the key files and commands. | mweinbach/ | 156 | — | ~2.2k | Automated safety check: Notes | Unknown | 2 days ago |
| 21 | Aligns a Lens extension's package.json ranges with the dependency versions bundled in the running Lens build, then reinstalls and rebuilds. | nevalla/ | 404 | — | ~709 | Automated safety check: Pass | MIT | 5 days ago |
| 22 | An extremely strict maintainability review for abstraction quality, giant files, and spaghetti-condition growth. | diyanbogdanov/ | 58 | — | ~1.9k | Automated safety check: Pass | MIT | 3 days ago |
| 23 | Keep dependencies up-to-date. An agent skill from github/rust-gems. | github/ | 135 | — | ~2.7k | Automated safety check: Pass | MIT | 3 days ago |
| 24 | Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner. | majiayu000/ | 287 | — | ~1.5k | Automated safety check: Pass | MIT | 3 days ago |
| 25 | Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. | alirezarezvani/ | 777 | — | ~1.2k | Automated safety check: Notes | MIT | 3 mo ago |
| 26 | Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration… | trailofbits/ | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 27 | 27.npm Release A skill your agent uses when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli. | luochang212/ | 117 | — | ~3.1k | Automated safety check: Warn | MIT | today |
| 28 | Finds two or three well-maintained npm packages for a Front-End Checklist rule, checks download and release thresholds, and adds them to the rule's frontmatter. | thedaviddias/ | 74k | — | ~989 | Automated safety check: Pass | MIT | 5 days ago |
| 29 | Conventions for .mjs files in the Handsontable monorepo: native node: imports, top-level await, the tasks.json dispatcher and native modules instead of extra dependencies. | handsontable/ | 22k | — | ~1.1k | Automated safety check: Pass | Unknown | yesterday |
| 30 | What a dependency migration must do before it is finished, regardless of how good the code is. | diyanbogdanov/ | 58 | — | ~542 | Automated safety check: Pass | MIT | 3 days ago |
| 31 | Moves a Node.js, npm, Yarn, pnpm or Bun project to Deno in reversible steps, starting with Deno as the package manager and changing no code unless needed. | denoland/ | 100 | — | ~2.2k | Automated safety check: Warn | MIT | 2 mo ago |
| 32 | 32.Dependabot Find all open Dependabot alerts for this repo and create a plan to resolve them using the appropriate package manager overrides (pnpm, bun, npm, cargo). | macro-inc/ | 4.6k | — | ~747 | Automated safety check: Notes | AGPL-3.0 | today |
| 33 | Fix a Dependabot PR by updating all monorepo instances of the dependency, running bun install, and pushing | remotion-dev/ | 63k | — | ~509 | Automated safety check: Pass | Unknown | 2 days ago |
| 34 | 34.Dep Security Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that… | tinyfish-io/ | 2.2k | — | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 35 | Supply-chain security controls for the @cipherstash/stack monorepo. | cipherstash/ | 157 | — | ~5.2k | Automated safety check: Warn | MIT | yesterday |
| 36 | 36.Update Deps Audit all outdated dependencies with detailed research on changelogs, breaking changes, bug fixes, and deprecations. | viclafouch/ | 110 | — | ~2.6k | Automated safety check: Pass | No licence | 6 mo ago |
| 37 | Check whether newer stable versions of Node.js (24.x line), Nx, or Vite are available and, if so, generate a detailed upgrade plan markdown file at the repo root. | PackmindHub/ | 318 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 38 | Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run. | dralgorhythm/ | 125 | — | ~1.5k | Automated safety check: Pass | No licence | 2 mo ago |
| 39 | Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles regenerated and tests green after… | maddhruv/ | 219 | 1 repo | ~1.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 40 | Respond to blocked package installs and manage the Interlinked supply-chain allowlist. | QuentinCody/ | 178 | — | ~2.8k | Automated safety check: Pass | MIT | 2 days ago |
| 41 | 41.Uv Workflow Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry. | Aedelon/ | 120 | — | ~1.2k | Automated safety check: Notes | Unknown | 7 mo ago |
| 42 | 42.Cve Scan Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart). | softspark/ | 180 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 43 | Scan package manifests and lockfiles for outdated and vulnerable dependencies. | cobusgreyling/ | 11k | — | ~531 | Automated safety check: Pass | MIT | today |
| 44 | Reviews Dependabot gem upgrade PRs for breaking changes, codebase impact, and merge readiness. | ThibautBaissac/ | 665 | — | ~3.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 45 | Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. | briiirussell/ | 413 | — | ~3.2k | Automated safety check: Warn | MIT | 4 mo ago |
| 46 | Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. | Varnan-Tech/ | 674 | — | ~3k | Automated safety check: Notes | MIT | 1 mo ago |
| 47 | Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 48 | Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. | c0x12c/ | 106 | — | ~1.6k | Automated safety check: Warn | No licence | 3 mo ago |