Agent skill

Android Add Dependency

by Adyen in Adyen/adyen-android

Add, remove or update an external dependency in the SDK. An agent skill from Adyen/adyen-android.

MITAuto-check passedDevelopment

Install Android Add Dependency

skills CLI
$ npx skills add Adyen/adyen-android --skill android-add-dependency -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Adyen/adyen-android android-add-dependency --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Adyen/adyen-android.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/android-add-dependency .claude/skills/android-add-dependency && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
android-add-dependency
GitHub stars
149
Token cost
~2.6k tokens
SKILL.md length
1,405 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Add, remove or update an external dependency in the SDK. An agent skill from Adyen/adyen-android.

  • Works in 7 steps: Stop and get approval for the dependency… → Choose the version and declaration → Update gradle/libs.versions.toml → …
  • Development work in your project
  • SKILL.md covers Usage, Steps, Modifying and removing… and Important
  • Calls python3; reaches developer.android.com and github.com

What it does

Android Add Dependency is an agent skill from Adyen/adyen-android. Add, remove or update an external dependency in the SDK. Use before touching gradle/libs.versions.toml, including when the change is a side effect of a larger task.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with Android and Gradle. The repository describes itself as: Adyen Android Drop-in and Components. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/android-add-dependency”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Stop and get approval for the dependency itself
  2. Choose the version and declaration
  3. Update gradle/libs.versions.toml
  4. Update .github/release_notes_dependency_list.toml
  5. Confirm the entry with the developer
  6. Update verification metadata
  7. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 475ca6a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • developer.android.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Android Add Dependency loads about 2.6k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 1,405 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Adyen/adyen-android at commit 475ca6a, republished under its MIT licence (© Adyen). 1,405 words, ~2,645 tokens.

Download SKILL.mdSave it as .claude/skills/android-add-dependency/SKILL.md (or your agent's skills folder).
name
android-add-dependency
description
Add, remove or update an external dependency in the SDK. Use before touching gradle/libs.versions.toml, including when the change is a side effect of a larger task.

android-add-dependency

Decide whether to add, change, or remove a dependency in the Adyen Android SDK, then apply it without breaking release notes generation or dependency verification.

Usage

Invoke this skill before touching gradle/libs.versions.toml — as soon as it looks like work will need a new library or plugin, a different version or artifact, or the removal of an existing one. This applies even when the dependency change is a side effect of a larger task, and even when the developer named the dependency themselves.

Renovate handles routine version bumps. This skill is for dependency changes made by hand.

Steps

1. Stop and get approval for the dependency itself

Do not edit any file yet. This is a decision, not a mechanical step. We are an SDK: every dependency we take is imposed on every merchant that integrates us, and every one we drop or re-point can break them. The default answer to a new dependency is no.

First, try to avoid it:

  • Does the Android platform, AndroidX, or something already in gradle/libs.versions.toml cover this?
  • Is the part we actually need small enough to implement ourselves? For published modules, prefer a small internal implementation over a new dependency.
  • Does it already reach us transitively? Declaring an existing transitive dependency explicitly is a much smaller step than taking a genuinely new artifact.

Then present the impact. Answer every line — "none" is a valid answer, guessing is not:

Impact of <group:name:version>

  • Scope — which modules, and which configuration (api, implementation, compileOnly, testImplementation, androidTestImplementation)
  • Merchants — does it end up in merchant builds? Cover version conflicts with libraries merchants commonly use, minSdk (ours is 23), download size and method count, and the transitive artifacts it drags in
  • Public API — do its types appear in our public API? If so its version becomes part of our contract and later upgrades turn into breaking changes. Prefer keeping it out of signatures and off api
  • R8 / ProGuard — consumer rules or dontwarn needed? If it is an optional external SDK, does it need the compileOnly + runCompileOnly treatment described in the android-add-module skill (.agents/skills/android-add-module/SKILL.md)?
  • Release notes — [included] or [excluded], and why (step 4 works out the exact entry)
  • Build and CI — verification metadata churn, build and CI time, added Renovate surface
  • Tests — impact on the test suite, if any
  • Maintenance and supply chain — license, release cadence, last release, maintainer, and whether the version is at least 14 days old (matching the minimumReleaseAge Renovate uses in renovate.json)
  • Alternatives considered — what you rejected, and why this is the better option

For a change, also state what moves: the size of the version jump, breaking changes in the new version, and any coordinate or artifact swap.

For a removal, also state whether anything still uses it, whether its types were exposed in our public API, and whether merchants may be resolving it through us. Removing a dependency merchants rely on transitively is a breaking change — follow the android-public-api-change skill (.agents/skills/android-public-api-change/SKILL.md).

Ask for explicit approval and wait for an answer. This holds even when the developer already asked for this exact dependency; they should see the impact before it lands. If they have clearly already decided, keep the summary short, but still show it.

2. Choose the version and declaration
  • Never use a dynamic version (+, latest.release).
  • If the artifact is covered by a BoM that is already declared (e.g. compose-bom), declare it without a version — see compose-ui-main in gradle/libs.versions.toml.
  • Use the narrowest configuration that works. implementation over api, and test configurations over production ones.
3. Update gradle/libs.versions.toml
  • Add the version to [versions] under the matching comment group, and the entry to [libraries] or [plugins].
  • Follow the ordering of the group you are adding to.
  • Omit version.ref when the version comes from a BoM.
4. Update .github/release_notes_dependency_list.toml

Every dependency must appear in [included] or [excluded]. This is enforced: scripts/validate_dependencies_for_release_notes.py runs on every PR through .github/workflows/validate_dependencies.yml and fails the build for unlisted dependencies.

Derive the id. The key is not the alias. It is derived from the entry:

Entry hasId to use
group and name<group>:<name>
modulethe module value
neither (plugins)the id value

Choose the section. Use [included] only when both are true:

  1. The dependency is merchant-relevant, meaning either:
    • It ships to merchants — declared in a published SDK module as api, implementation, or compileOnly, so it resolves in a merchant's build. Compare com.squareup.okhttp3:okhttp (in core and checkout-core, included) against com.squareup.okhttp3:logging-interceptor (example app only, excluded).
    • Or it is part of the toolchain merchants have to be compatible with. This applies to the Android Gradle Plugin and Kotlin only — every other build, CI, and code quality tool is excluded.
  2. No existing [included] entry already represents it. A BoM covers its artifacts, or a sibling from the same release train is already listed. The Kotlin artifacts and plugins are all represented by the single kotlin entry, and com.android.application/com.android.library by com.android.tools.build:gradle.

Everything else goes in [excluded]: test-only, example-app-only, lint, build-logic, CI, and code quality tooling.

Do not use the comment groups in libs.versions.toml to decide. # Production libraries also holds example-app and tooling dependencies such as leak-canary, retrofit-main, and ktlint-cli. Find where the alias is actually used, and in which configuration.

Write the entry.

[excluded] values are an empty string. Add a comment when the reason is not obvious — in particular when a production dependency is excluded because another entry covers it:

toml
# This dependency is already defined by another
"androidx.navigation3:navigation3-ui" = ""

[included] values are a markdown link. {} is replaced with the new version when release notes are generated:

toml
"androidx.startup:startup-runtime" = "[AndroidX Startup](https://developer.android.com/jetpack/androidx/releases/startup#{})"
  • Use a version-anchored URL so the entry deep-links to the notes for that release. Follow a neighbouring entry from the same vendor:
    • AndroidX: https://developer.android.com/jetpack/androidx/releases/<artifact>#{}
    • GitHub releases: https://github.com/<org>/<repo>/releases/tag/{} — check whether the project prefixes its tags with v.
  • If the project publishes no per-version anchor, use a stable changelog or docs URL and leave out {}. See the OkHttp and TWINT entries.
  • Verify the formatted URL resolves for the version you are adding. A misplaced {} produces a dead link in published release notes.
  • Use a human-readable display name in the style of the surrounding entries.
  • Keep the list alphabetically ordered by id.
Show full SKILL.md (405 more words)Show less
5. Confirm the entry with the developer

This is the second confirmation, and it is about the entry rather than the dependency. Always ask, even when the choice looks obvious. Show:

  • The id, and the section you propose
  • Why that section applies
  • For [included], the link template and the URL it produces for the version being added

Do not write the entry before you get an answer. If you cannot work out a good link, ask instead of guessing.

6. Update verification metadata

Dependency verification is enabled in gradle/verification-metadata.xml, so a new artifact fails the build until its checksum is recorded:

bash
./gradlew --write-verification-metadata sha256 resolveDependencies --refresh-dependencies

--refresh-dependencies is required: metadata files (BOM and parent poms) that are already in the module metadata cache are not re-parsed, so without it they are silently left out of the verification metadata and the build fails later on a machine with a cold cache. Review the diff — it should only add entries for the new dependency and its transitives — and include the file in the commit.

7. Verify
  • Run the same validation CI runs: python3 scripts/validate_dependencies_for_release_notes.py. It compares against the merge base with origin/main, so run it on your branch.
  • Use the android-check skill (.agents/skills/android-check/SKILL.md) to run compile, lint, and unit tests.

Modifying and removing dependencies

  • Changed coordinates on an existing alias (group, name, or module): update the id in .github/release_notes_dependency_list.toml too. PR validation only inspects newly added aliases, so a coordinate change passes CI and instead breaks release notes generation later with Dependency not recognized.
  • Removed dependency: remove its entry from [included] or [excluded] in the same change, unless the same id is still declared by another alias.
  • Version-only bumps: no change to the dependency list is needed. Step 1 still applies for a major version jump, since that is a merchant-visible change.

Important

  • Never add, change, or remove a dependency without approval from the developer first. Present the impact before making any change, including when they named the dependency themselves.
  • Taking a new dependency in a published module is a decision about our SDK's contract with merchants, not an implementation detail.
  • Never change gradle/libs.versions.toml without updating .github/release_notes_dependency_list.toml in the same change.
  • Always have the developer confirm the [included]/[excluded] choice and the link before writing it.
  • Never guess a release notes URL, a license, or a maintenance status. Look it up, or say you could not determine it.
  • [included] entries are published to merchants in the release notes. Treat them as merchant-facing content.

© Adyen, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/android-add-dependency of Adyen/adyen-android.

Open the folder on GitHubat commit 475ca6a

Compare with similar skills

Android Add Dependency next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Android Add Dependency compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Android Add Dependency this skillAdyen/adyen-android149—~2.6kAutomated safety check: PassMIT
Update Version CatalogRedMadRobot/gradle-version-catalogs118—~9.5kAutomated safety check: PassMIT
Pre-PR Reviewyuga-hashimoto/and-code123—~710Automated safety check: PassMIT
Project Gradle Third Party Version UpgradeafkT/DevUtils1.6k—~1.2kAutomated safety check: PassApache-2.0
Docs Engineeringhiroshiyui/GuilelessBopomofo135—~806Automated safety check: PassGPL-3.0
Using Git Worktreec5inco/compose-pokedexer143—~1.4kAutomated safety check: PassMIT

Similar skills

  • Update Version Catalog

    RedMadRobot/gradle-version-catalogs

    Use EVERY time the user asks to update / bump the version catalogs, "сделать обновление", "обновить каталог(и)", "обнови версии", "оформи изменения", "update the catalog", or to record dependency…

    118 GitHub stars~9.5k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Pre-PR Review

    yuga-hashimoto/and-code

    Runs local checks and a repo-reviewer subagent over the whole branch diff before a pull request is opened, then records the approval in the PR description.

    123 GitHub stars~710 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • 对 DevUtils 工程(DEPSROOT=file/gradle、DEPSMANIFEST=file/deps)中定义的第三方库 GAV 依赖做版本查证与升级;结合 Maven Central、Google Maven、Gradle Plugin Portal、 JitPack 与 GitHub Releases/README 交叉校验「最新可用版本」;必要时修正…

    1.6k GitHub stars~1.2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Docs Engineering

    hiroshiyui/GuilelessBopomofo

    Writing/updating project documentation (README, PRIVACY-POLICY, NOTICES, changelogs) and maintaining F-Droid metadata.

    135 GitHub stars~806 tokensUpdated 11 days ago
    DevelopmentAuto-check passed
  • Using Git Worktree

    c5inco/compose-pokedexer

    Creates and manages isolated Git worktrees with safe directory selection, explicit approval, clean-baseline verification, and Gradle-specific safeguards.

    143 GitHub stars~1.4k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Release Engineering

    hiroshiyui/GuilelessBopomofo

    Release engineering tasks including version bumping, building release APKs, creating git tags, writing changelogs, and preparing F-Droid releases.

    135 GitHub stars~1.6k tokensUpdated 11 days ago
    DevelopmentAuto-check passed

More from Adyen/adyen-android

All 9 skills in this repo
  • Plan and execute the migration of a v5 payment method to the v6 component architecture.

    149 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Android Add Module

    Adyen/adyen-android

    Add a new Gradle module and wire in optional external SDKs. An agent skill from Adyen/adyen-android.

    149 GitHub stars~988 tokensUpdated yesterday
    Auto-check passed
  • Android Branch Create

    Adyen/adyen-android

    Create a branch with correct prefix and base. An agent skill from Adyen/adyen-android.

    149 GitHub stars~782 tokensUpdated yesterday
    Auto-check passed
  • Android Commit

    Adyen/adyen-android

    Create a commit with pre-commit checks and conventions. An agent skill from Adyen/adyen-android.

    149 GitHub stars~835 tokensUpdated yesterday
    Auto-check: notes
  • Android PR Create

    Adyen/adyen-android

    Create a PR with title, body, and checklist. An agent skill from Adyen/adyen-android.

    149 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Android Public API Change

    Adyen/adyen-android

    Change the public API surface: visibility, breaking changes, and apiDump.

    149 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Android Add Dependency

What does Android Add Dependency do?

Add, remove or update an external dependency in the SDK. An agent skill from Adyen/adyen-android. Android Add Dependency is an agent skill from Adyen/adyen-android. Add, remove or update an external dependency in the SDK.

When should I use Android Add Dependency?

Android Add Dependency fits situations like: development work in your project.

How do I install Android Add Dependency in Claude Code?

Run `npx skills add Adyen/adyen-android --skill android-add-dependency -a claude-code`. Or copy the skill folder (.agents/skills/android-add-dependency in Adyen/adyen-android) into .claude/skills/android-add-dependency in your project. Claude Code loads it when a task matches its description.

How do I install Android Add Dependency in Codex?

Run `npx skills add Adyen/adyen-android --skill android-add-dependency -a codex`. Or copy the skill folder (.agents/skills/android-add-dependency in Adyen/adyen-android) into .agents/skills/android-add-dependency in your project. Codex loads it when a task matches its description.

Can I use Android Add Dependency in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Adyen/adyen-android --skill android-add-dependency -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/android-add-dependency, .gemini/skills/android-add-dependency, .github/skills/android-add-dependency and .opencode/skills/android-add-dependency in your project.

What does Android Add Dependency need to run?

Going by SKILL.md and its folder, Android Add Dependency needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Android Add Dependency access the network?

SKILL.md names 2 domains. In commands or code: developer.android.com and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Android Add Dependency safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Android Add Dependency use?

Android Add Dependency is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Android Add Dependency use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Android Add Dependency?

Skills that share tags, products or a category with Android Add Dependency: Update Version Catalog (RedMadRobot/gradle-version-catalogs, 118 stars), Pre-PR Review (yuga-hashimoto/and-code, 123 stars), Project Gradle Third Party Version Upgrade (afkT/DevUtils, 1.6k stars) and Docs Engineering (hiroshiyui/GuilelessBopomofo, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Android Add Dependency?

Adyen (a GitHub organization) maintains it in Adyen/adyen-android, which has 149 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: Adyen/adyen-android on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.