Agent skill

Update Dependencies

by amwebexpert in amwebexpert/etoolbox

Upgrade this repo's npm dependencies safely — dry-run ncu, apply minor/patch only, migrate deprecated APIs, verify sanity scripts, run e2e and report the run.

MITAuto-check passedTesting & QA

Install Update Dependencies

skills CLI
$ npx skills add amwebexpert/etoolbox --skill update-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install amwebexpert/etoolbox update-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/amwebexpert/etoolbox.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/update-dependencies .claude/skills/update-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-dependencies
GitHub stars
114
Token cost
~1.3k tokens
SKILL.md length
621 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Upgrade this repo's npm dependencies safely — dry-run ncu, apply minor/patch only, migrate deprecated APIs, verify sanity scripts, run e2e and report the run.

  • Works in 6 steps: Classify → Apply the safe set → Migrate deprecated APIs → …
  • The user asks to update dependencies
  • SKILL.md covers 1. Classify, 2. Apply the safe set, 3. Migrate deprecated APIs and 4. Verify sanity scripts, plus 2 more sections
  • Calls bun, bunx and git

What it does

Update Dependencies is an agent skill from amwebexpert/etoolbox. Upgrade this repo's npm dependencies safely — dry-run ncu, apply minor/patch only, migrate deprecated APIs, verify sanity scripts, run e2e and report the run. Use when the user asks to update dependencies, upgrade packages, bump deps, check for outdated packages, or run ncu.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering End-to-end testing. It works with npm. The repository describes itself as: Collection of web developer utilities. Technologies: React, AntD, Typescript, Tanstack Query, Zustand. The licence is MIT.

When your agent uses it

  • The user asks to update dependencies
  • Upgrade packages
  • Check for outdated packages

Example prompts

  • “/update-dependencies”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Classify
  2. Apply the safe set
  3. Migrate deprecated APIs
  4. Verify sanity scripts
  5. Run e2e
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 9d08a1a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • bunx
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use bunx and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Dependencies loads about 1.3k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 621 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from amwebexpert/etoolbox at commit 9d08a1a, republished under its MIT licence (© amwebexpert). 621 words, ~1,273 tokens.

Download SKILL.mdSave it as .claude/skills/update-dependencies/SKILL.md (or your agent's skills folder).
name
update-dependencies
description
Upgrade this repo's npm dependencies safely — dry-run ncu, apply minor/patch only, migrate deprecated APIs, verify sanity scripts, run e2e and report the run. Use when the user asks to update dependencies, upgrade packages, bump deps, check for outdated packages, or run ncu.

Upgrades every minor/patch-bumpable dependency in one pass, skips majors, migrates deprecated API usage surfaced by the bump, then proves the upgrade didn't break anything before reporting. Never bump a major in this flow — log it for a separate, deliberate pass instead.

This repo uses Bun (packageManager: bun@1.3.14), bun.lock, and patch-package on install.

1. Classify

bash
bunx npm-check-updates

Sort every listed package into two sets by comparing its leftmost version segment: unchanged = minor/patch (safe), changed = major (skip).

Done when: every listed package is sorted into one of the two sets.

2. Apply the safe set

bash
bunx npm-check-updates -u -x <comma-separated-major-pkgs>
bun install

Excluding majors up front keeps this idempotent — rerunning after a partial failure is safe.

Project-specific checks after install:

  • postinstall runs patch-package. If install fails on eslint-plugin-react, the patch in patches/ no longer applies — stop and report; do not delete the patch to unblock.
  • vite is pinned as npm:rolldown-vite@<version> in both devDependencies and overrides. If ncu bumps vite, keep the alias form and sync both entries.

Done when: bun install exits 0.

3. Migrate deprecated APIs

Libraries often mark old APIs @deprecated in their types before removing them in the next major. Catch and fix usage here — before sanity scripts and e2e — so failures aren't misread as test/build regressions.

3a. Scan typed deprecations (primary)
bash
bunx eslint src --rule '@typescript-eslint/no-deprecated: error' --max-warnings 0

Reuses this repo's type-aware ESLint setup (projectService on src/**). Each hit includes the library's replacement hint from JSDoc (e.g. Ant Design prop renames). Fix every finding under src/ — including pre-existing ones; a dep-upgrade pass is the right time to clear them.

Re-run until the command exits 0.

3b. Skim upgraded-package release notes

For each package in the applied set, check for migration guidance the type checker won't surface (runtime-only deprecations, config renames, removed subpath exports):

bash
for pkg in <space-separated-upgraded-pkgs>; do
  ls "node_modules/$pkg"/{CHANGELOG,CHANGES,MIGRATION,UPGRADING}* 2>/dev/null
done

Also open the package's GitHub releases when the on-disk changelog is thin. Search for "deprecated", "removed", "migrate", "renamed". Cross-check with git diff -- package.json bun.lock.

Apply straightforward call-site fixes (import paths, prop/option renames, config key swaps). Stop and report when a deprecation needs a design call or touches many files — don't silently defer.

Done when: no-deprecated is clean and changelog-driven migrations for the applied set are fixed or explicitly deferred with reason.

Show full SKILL.md (271 more words)Show less

4. Verify sanity scripts

Run in order, stopping on the first failure — mirrors .github/workflows/ci.yml plus a local build:

bun run lint:ci → bun run format:check → bun run lint:package → bun run lint:unused → bun run typecheck → bun run test → bun run build

  • @playwright/test in the applied set → proactively run bunx playwright install chromium before e2e. Default e2e script uses --project=chromium only; a patch bump can orphan cached browser binaries (browserType.launch: Executable doesn't exist otherwise).
  • prettier in the applied set → a format:check failure on previously-clean files is expected on new rules. Run bun run format, then confirm the diff only touches the files format:check flagged — a wider diff means something else broke.
  • Ignore as pre-existing, not a regression: the "chunks larger than 500 kB" build warning from Vite/Rolldown.
  • Any other failure: trivial fix (type signature, import path) → apply and continue. Real API break → stop, report, never downgrade unilaterally to route around it.

bun run lint (habit-hooks coaching) is optional local feedback — CI gates on lint:ci, not habit-hooks.

Done when: all seven scripts exit 0.

5. Run e2e

bash
bun run test:e2e

Playwright starts the Vite dev server automatically (e2e/playwright.config.ts). E2E is local-only (not in CI) but required here. Scan output for runtime deprecated / DeprecationWarning lines — fix any tied to upgraded packages.

Done when: the full suite reports its pass/fail counts.

6. Report

Rank skipped majors by adoption risk: lint/test-only deps with no in-repo usage rank lowest; framework/runtime deps with heavy in-repo usage, or several majors jumped at once, rank highest.

Report to the user: what upgraded, deprecated APIs migrated, majors skipped with risk ranking, anything hit plus the fix applied, sanity/e2e result.

Done when: the user has the summary.

© amwebexpert, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/update-dependencies of amwebexpert/etoolbox.

Open the folder on GitHubat commit 9d08a1a

Compare with similar skills

Update Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Dependencies this skillamwebexpert/etoolbox114—~1.3kAutomated safety check: PassMIT
Interactive CLI Testing With tui-testslopus/happy24k—~603Automated safety check: PassMIT
OpenHarness End-to-End EvalsHKUDS/OpenHarness16k1 repos~2.1kAutomated safety check: NotesMIT
Qwen Code E2E TestingQwenLM/qwen-code28k—~2.1kAutomated safety check: PassApache-2.0
E2E TestingInsForge/InsForge13k—~1.5kAutomated safety check: PassApache-2.0
RStudio Playwright Test Runnerrstudio/rstudio5.1k—~801Automated safety check: PassCustom licence

Similar skills

  • Tests interactive CLI and TUI programs with Microsoft's tui-test, driving prompts, arrow keys and screen output in a real pseudo-terminal.

    24k GitHub stars~603 tokensUpdated today
    Testing & QAAuto-check passed
  • Validates OpenHarness features by running real multi-turn agent loops with live LLM calls against an unfamiliar codebase, checking actual tool execution.

    16k GitHub starsUsed in 1 repo~2.1k tokens
    Testing & QAAuto-check: notes
  • Qwen Code E2E Testing

    QwenLM/qwen-code

    Guides end-to-end testing of the Qwen Code CLI in headless mode with real model calls, MCP test servers and inspection of raw API traffic.

    28k GitHub stars~2.1k tokensUpdated today
    Testing & QAAuto-check passed
  • E2E Testing

    InsForge/InsForge

    A skill your agent uses when an InsForge maintainer has finished an OSS repo change and is ready to open, update, or submit the InsForge PR.

    13k GitHub stars~1.5k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Runs RStudio's Playwright end-to-end tests against the desktop app or a server build with the project's npm scripts, asking you which mode to use first.

    5.1k GitHub stars~801 tokensUpdated today
    Testing & QAAuto-check passed
  • tmux Real User Testing

    QwenLM/qwen-code

    Drives Qwen Code in a real tmux session the way a user would and saves a readable step-by-step transcript of each screen for maintainers to review.

    28k GitHub stars~2.3k tokensUpdated today
    Testing & QAAuto-check passed

Works with

Questions about Update Dependencies

What does Update Dependencies do?

Upgrade this repo's npm dependencies safely — dry-run ncu, apply minor/patch only, migrate deprecated APIs, verify sanity scripts, run e2e and report the run. Update Dependencies is an agent skill from amwebexpert/etoolbox. Upgrade this repo's npm dependencies safely — dry-run ncu, apply minor/patch only, migrate deprecated APIs, verify sanity scripts, run e2e and report the run.

When should I use Update Dependencies?

Update Dependencies fits situations like: the user asks to update dependencies; upgrade packages; check for outdated packages.

How do I install Update Dependencies in Claude Code?

Run `npx skills add amwebexpert/etoolbox --skill update-dependencies -a claude-code`. Or copy the skill folder (.claude/skills/update-dependencies in amwebexpert/etoolbox) into .claude/skills/update-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Update Dependencies in Codex?

Run `npx skills add amwebexpert/etoolbox --skill update-dependencies -a codex`. Or copy the skill folder (.claude/skills/update-dependencies in amwebexpert/etoolbox) into .agents/skills/update-dependencies in your project. Codex loads it when a task matches its description.

Can I use Update Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add amwebexpert/etoolbox --skill update-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-dependencies, .gemini/skills/update-dependencies, .github/skills/update-dependencies and .opencode/skills/update-dependencies in your project.

What does Update Dependencies need to run?

Going by SKILL.md and its folder, Update Dependencies needs the command-line tools its instructions call (bun, bunx and git).

Does Update Dependencies access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Dependencies use?

Update Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Dependencies use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Dependencies?

Skills that share tags, products or a category with Update Dependencies: Interactive CLI Testing With tui-test (slopus/happy, 24k stars), OpenHarness End-to-End Evals (HKUDS/OpenHarness, 16k stars), Qwen Code E2E Testing (QwenLM/qwen-code, 28k stars) and E2E Testing (InsForge/InsForge, 13k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Dependencies?

amwebexpert (a GitHub user) maintains it in amwebexpert/etoolbox, which has 114 GitHub stars. The repository was last updated on September 21, 2026.

Source: amwebexpert/etoolbox on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.