Agent skill

Outdated Dependencies

by adobe in adobe/skills

AEM Cloud Service expert skill — upgrade outdated Maven dependencies in pom.xml, both literal <version and same-pom ${property} shapes.

Apache-2.0Auto-check passedDevelopment

Install Outdated Dependencies

skills CLI
$ npx skills add adobe/skills --skill outdated-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install adobe/skills outdated-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aem/cloud-service/skills/code-assessment/outdated-dependencies .claude/skills/outdated-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
outdated-dependencies
GitHub stars
195
Token cost
~1.4k tokens
SKILL.md length
603 words
Files
2
Skills in repo
105
Repo updated
First seen
Licence
Apache-2.0

At a glance

AEM Cloud Service expert skill — upgrade outdated Maven dependencies in pom.xml, both literal <version and same-pom ${property} shapes.

  • Works in 4 steps: Run discovery via the analyzer… → Present every located coordinate in the… → State plainly: "Found N versioned… → …
  • Update my aem-sdk-api
  • SKILL.md covers Overview, Answering "are my dependencies…, Classification — confirm this… and Discovery, plus 4 more sections
  • Calls bash, mvn and npm

What it does

Outdated Dependencies is an agent skill from adobe/skills. AEM Cloud Service expert skill — upgrade outdated Maven dependencies in pom.xml, both literal <version and same-pom ${property} shapes. Use for "update my aem-sdk-api", "upgrade mockito", or scanning a project for stale dependency versions. Discovery can find <dependency blocks but "outdated" needs a target version, which the user supplies. Pattern A/B locators and editing strategy are in recipe.md.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `recipe.md`).

It sits in Development, covering Dependency management. It works with Adobe Experience Manager. The repository describes itself as: Adobe Skills for Agents. The licence is Apache-2.0.

When your agent uses it

  • Update my aem-sdk-api
  • Upgrade mockito
  • Scanning a project for stale dependency versions

Example prompts

  • “update my aem-sdk-api”
  • “upgrade mockito”
  • “outdated”
  • “/outdated-dependencies”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Run discovery via the analyzer (--pattern outdated-dependencies, or a full audit).
  2. Present every located coordinate in the Step 7 Candidates table with planned action skipped and reason needs-user-target (no target…
  3. State plainly: "Found N versioned dependencies across M pom files. Supply target versions to mark upgrades. For aem-sdk-api, align with…
  4. Offer follow-up: reply with target versions to apply, or name coordinates then say apply.

What it can do on your machine

Read from SKILL.md and the folder at commit cbc9952. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • mvn
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Outdated Dependencies loads about 1.4k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 603 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from adobe/skills at commit cbc9952, republished under its Apache-2.0 licence (© adobe). 603 words, ~1,350 tokens.

Download SKILL.mdSave it as .claude/skills/outdated-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
outdated-dependencies
description
AEM Cloud Service expert skill — upgrade outdated Maven dependencies in pom.xml, both literal <version> and same-pom ${property} shapes. Use for "update my aem-sdk-api", "upgrade mockito", or scanning a project for stale dependency versions. Discovery can find <dependency> blocks but "outdated" needs a target version, which the user supplies. Pattern A/B locators and editing strategy are in recipe.md.
license
Apache-2.0

Outdated Maven dependencies — AEM as a Cloud Service

This pattern is executed by the code-assessment runbook — follow ../references/runbook.md for the full flow (preflight → plan → apply → verify, run log). This skill supplies the detection + recipe the runbook applies.

Overview

Stale Maven dependencies (notably aem-sdk-api) cause build failures and local/runtime drift. This skill bumps a dependency's version surgically — literal <version> or a same-pom ${property} — without reformatting the pom.

Answering "are my dependencies up to date?"

This pattern locates Maven coordinates; it does not declare a dependency outdated vs current without a user-supplied target version (see Resolution contract). For a comparative ask ("up to date?", "stale?", "outdated?") with report intent:

  1. Run discovery via the analyzer (--pattern outdated-dependencies, or a full audit).
  2. Present every located coordinate in the Step 7 Candidates table with planned action skipped and reason needs-user-target (no target supplied).
  3. State plainly: "Found N versioned dependencies across M pom files. Supply target versions to mark upgrades. For aem-sdk-api, align with your Cloud Manager environment SDK — do not assume the latest public version."
  4. Offer follow-up: reply with target versions to apply, or name coordinates then say apply.

Do not run mvn versions:display-*, npm outdated, or Maven Central / registry lookups in place of this inventory. A live registry comparison needs network and is advisory only — if the user explicitly asks, do it as a separate step after the skill report.

Classification — confirm this pattern applies

  • A pom.xml with a <dependency> whose version the user wants raised, either as a literal <version> or via a <version>${prop}</version> + <properties> entry.
  • Applies to a <dependency> that carries a <version> (literal or ${property}) in <dependencies> or <dependencyManagement>. Not for <plugin> / <build> dependencies, version-less (inherited) <dependency> entries, or versions defined only in an out-of-workspace parent pom.
Show full SKILL.md (313 more words)Show less

Discovery

Detection is performed by the analyzer (../scripts/analyze.sh), run by the runbook:

bash
bash ../scripts/analyze.sh <workspace-root> --pattern outdated-dependencies

Match criteria (what the detector flags): each <dependency> element carrying a <version> (literal or ${property}) under <dependencies> or <dependencyManagement> — excluding <plugin>/<pluginManagement>/<build>/<reporting> dependencies and version-less (inherited) <dependency> entries — emitted with its groupId:artifactId@version and the line of its <artifactId>. The analyzer only locates dependencies — "is this outdated?" and "what is the target version?" are user-supplied (see Resolution contract); the analyzer performs no network lookup. If the same (groupId, artifactId, version) appears in more than one <dependency> block in a file, the recipe's ambiguous-locator skip applies during planning.

Allowlist scope: by default the detector is scoped to a curated allowlist of coordinates where upgrades are actionable in AEM Cloud Service projects (currently com.adobe.aem:aem-sdk-api and org.mockito:*). Non-allowlisted versioned dependencies are silently skipped. To list every versioned dependency regardless of allowlist, pass --all to analyze.sh — but only for an explicit full audit ("all dependencies", "every library", "comprehensive"). For a normal "are my dependencies outdated?" ask, keep the default allowlist scope: it is the actionable answer, and --all adds platform deps (OSGi, JCR, servlet-api) that are not independently upgradeable. Adding a coordinate to the allowlist is a one-line change in OutdatedDependencies.java; analyze.sh recompiles automatically. Both exact groupId:artifactId and prefix-wildcard groupId:prefix* forms are supported.

Resolution contract

user-supplied — list the found coordinates with their current versions and ask which to upgrade and to what target version before planning. Never guess a version.

Review checklist

  • Only the <version> text (or the <properties> entry) changed — no whitespace/attribute churn
  • Property shape edits validated: property exists, value matched, referenced by the target dependency
  • Ambiguous (multi-match) locators skipped, not guessed
  • Target version came from the user — never invented

Recipe

Read recipe.md in full before editing: input contract, Pattern A (literal), Pattern B (property), multi-module caveat, editing strategy.

Handoff

The skill never commits. See ../references/git-workflow.md for git vs in-place handoff and the suggested commit message.

© adobe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/aem/cloud-service/skills/code-assessment/outdated-dependencies of adobe/skills.

  • SKILL.md
  • recipe.md

Open the folder on GitHubat commit cbc9952

Compare with similar skills

Outdated Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Outdated Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Outdated Dependencies this skilladobe/skills195—~1.4kAutomated safety check: PassApache-2.0
Megatron-LM Container and Dependency SetupNVIDIA/Megatron-LM18k—~2.6kAutomated safety check: PassApache-2.0
Renovate Actions PR Reviewbacknotprop/plannotator9.2k—~640Automated safety check: PassApache-2.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Update .NET Distro Packagesdotnet/core22k—~4.3kAutomated safety check: NotesMIT
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Official

    Walks an agent through working inside the Megatron-LM CI container and changing dependencies with uv, so lock files resolve the same locally and in CI.

    18k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.2k GitHub stars~640 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Official

    Creates and maintains the per-distro JSON files that list the native packages .NET needs on each Linux distribution, scoped to one .NET version.

    22k GitHub stars~4.3k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from adobe/skills

All 105 skills in this repo
  • Scaffolds, implements, deploys and debugs Adobe Runtime actions in App Builder projects, with templates for webhooks, events, database CRUD, sequences and Asset Compute workers.

    195 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Launches Chrome with an unpacked extension over CDP, opens its sidepanel, popup or options page, and hands over to cdp-connect for clicks, typing and screenshots.

    195 GitHub stars~952 tokensUpdated today
    Auto-check passed
  • Extracts icons, metadata, text, forms, videos and social links from any web page with playwright-cli, with SVG icon classification and cleanup.

    195 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Page Langs

    adobe/skills

    Detect all languages used on a webpage — both declared (html@lang, hreflang alternate links, nested lang= attributes, meta content-language) and actually present in the body text (Google CLD3 via…

    195 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Page Prep

    adobe/skills

    Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).

    195 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Page Reduce

    adobe/skills

    Reduce a webpage to a structural skeleton with semantic tokens.

    195 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Questions about Outdated Dependencies

What does Outdated Dependencies do?

AEM Cloud Service expert skill — upgrade outdated Maven dependencies in pom.xml, both literal <version and same-pom ${property} shapes. Outdated Dependencies is an agent skill from adobe/skills.xml, both literal <version and same-pom ${property} shapes.

When should I use Outdated Dependencies?

Outdated Dependencies fits situations like: update my aem-sdk-api; upgrade mockito; scanning a project for stale dependency versions.

How do I install Outdated Dependencies in Claude Code?

Run `npx skills add adobe/skills --skill outdated-dependencies -a claude-code`. Or copy the skill folder (plugins/aem/cloud-service/skills/code-assessment/outdated-dependencies in adobe/skills) into .claude/skills/outdated-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Outdated Dependencies in Codex?

Run `npx skills add adobe/skills --skill outdated-dependencies -a codex`. Or copy the skill folder (plugins/aem/cloud-service/skills/code-assessment/outdated-dependencies in adobe/skills) into .agents/skills/outdated-dependencies in your project. Codex loads it when a task matches its description.

Can I use Outdated Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adobe/skills --skill outdated-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/outdated-dependencies, .gemini/skills/outdated-dependencies, .github/skills/outdated-dependencies and .opencode/skills/outdated-dependencies in your project.

What does Outdated Dependencies need to run?

Going by SKILL.md and its folder, Outdated Dependencies needs the command-line tools its instructions call (bash, mvn and npm).

Does Outdated Dependencies access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Outdated Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Outdated Dependencies use?

Outdated Dependencies is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Outdated Dependencies use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Outdated Dependencies?

Skills that share tags, products or a category with Outdated Dependencies: Megatron-LM Container and Dependency Setup (NVIDIA/Megatron-LM, 18k stars), Renovate Actions PR Review (backnotprop/plannotator, 9.2k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Update .NET Distro Packages (dotnet/core, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Outdated Dependencies?

adobe (a GitHub organization) maintains it in adobe/skills, which has 195 GitHub stars. The repository holds 105 skills in this directory. The repository was last updated on October 6, 2026.

Source: adobe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.