Agent skill

Dependency Resolver

by ArabelaTso in ArabelaTso/Skills-4-SE

Identify, analyze, and manage software dependencies before deployment.

Apache-2.0Auto-check: notesDevelopment

Install Dependency Resolver

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill dependency-resolver -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE dependency-resolver --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-resolver .claude/skills/dependency-resolver && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-resolver
GitHub stars
253
Token cost
~3.9k tokens
SKILL.md length
559 words
Files
1
Skills in repo
151
Repo updated
First seen
Licence
Apache-2.0

At a glance

Identify, analyze, and manage software dependencies before deployment.

  • Works in 12 steps: Dependency Analysis → Conflict Detection → Security Auditing → …
  • Preparing applications for deployment
  • SKILL.md covers Core Capabilities, Dependency Resolution Workflow, Dependency Management Patterns and Version Constraint Syntax, plus 1 more section
  • Calls npm, yarn and pip; reaches npmjs.com and registry.npmjs.org

What it does

Dependency Resolver is an agent skill from ArabelaTso/Skills-4-SE. Identify, analyze, and manage software dependencies before deployment. Use this skill when preparing applications for deployment, resolving dependency conflicts, updating dependencies, auditing security vulnerabilities, managing package versions, or troubleshooting dependency-related issues. Supports multiple package managers (npm, pip, maven, cargo, go mod, composer) and provides actionable recommendations for dependency management.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, GraphQL and Deployment. It works with npm and Go. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Preparing applications for deployment
  • Resolving dependency conflicts
  • Updating dependencies
  • Auditing security vulnerabilities

Example prompts

  • “/dependency-resolver”

Requirements

  • Python 3
  • Node.js

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Dependency Analysis
  2. Conflict Detection
  3. Security Auditing
  4. Dependency Resolution
  5. Identify Package Manager
  6. Parse Dependency Manifest
  7. Analyze Dependency Tree
  8. Detect Issues
  9. Propose Solutions
  10. Dependency Installation
  11. Security Audit
  12. License Compliance

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • yarn
    • pip
    • go
    • mvn
    • npx
    • pytest
    • git
    • nvm
    • node
    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • npmjs.com
    • registry.npmjs.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Resolver loads about 3.9k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 559 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:779
    sudo apt-get install build-essential python3

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 559 words, ~3,918 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-resolver/SKILL.md (or your agent's skills folder).
name
dependency-resolver
description
Identify, analyze, and manage software dependencies before deployment. Use this skill when preparing applications for deployment, resolving dependency conflicts, updating dependencies, auditing security vulnerabilities, managing package versions, or troubleshooting dependency-related issues. Supports multiple package managers (npm, pip, maven, cargo, go mod, composer) and provides actionable recommendations for dependency management.

Dependency Resolver

Analyze, manage, and resolve software dependencies to ensure safe and successful deployments. Identifies conflicts, security vulnerabilities, version mismatches, and missing dependencies.

Core Capabilities

1. Dependency Analysis

Examine project dependencies:

  • Direct dependencies - Packages explicitly required
  • Transitive dependencies - Dependencies of dependencies
  • Dev dependencies - Development-only packages
  • Peer dependencies - Required by packages but not auto-installed
  • Optional dependencies - Non-critical packages
2. Conflict Detection

Identify dependency issues:

  • Version conflicts - Multiple versions of same package
  • Missing dependencies - Required but not installed
  • Incompatible versions - Version constraints that can't be satisfied
  • Circular dependencies - Packages depending on each other
  • Platform incompatibility - OS or architecture mismatches
3. Security Auditing

Check for vulnerabilities:

  • Known CVEs - Common Vulnerabilities and Exposures
  • Outdated packages - Old versions with security patches available
  • Malicious packages - Typosquatting or compromised packages
  • License issues - Incompatible or restrictive licenses
4. Dependency Resolution

Provide solutions:

  • Version pinning - Lock compatible versions
  • Conflict resolution - Strategies to resolve version conflicts
  • Dependency updates - Safe upgrade paths
  • Alternative packages - Replacement suggestions
  • Minimal installations - Remove unnecessary dependencies

Dependency Resolution Workflow

Step 1: Identify Package Manager

Detect which dependency system is in use:

Package manager files:

npm/yarn:     package.json, package-lock.json, yarn.lock
pip:          requirements.txt, Pipfile, setup.py, pyproject.toml
maven:        pom.xml
gradle:       build.gradle, build.gradle.kts
cargo:        Cargo.toml, Cargo.lock
go:           go.mod, go.sum
composer:     composer.json, composer.lock
bundler:      Gemfile, Gemfile.lock
nuget:        *.csproj, packages.config
Step 2: Parse Dependency Manifest

Read and understand dependency declarations:

npm (package.json):

json
{
  "dependencies": {
    "express": "^4.18.0",
    "lodash": "~4.17.21"
  },
  "devDependencies": {
    "jest": "^29.0.0"
  },
  "peerDependencies": {
    "react": ">=16.0.0"
  }
}

Python (requirements.txt):

django>=4.0,<5.0
requests==2.28.1
numpy>=1.20.0
pytest  # No version specified

Maven (pom.xml):

xml
<dependencies>
  <dependency>
    <groupId>org.springframework</groupId>
    <artifactId>spring-core</artifactId>
    <version>5.3.23</version>
  </dependency>
</dependencies>
Step 3: Analyze Dependency Tree

Build complete dependency graph:

my-app
├── express@4.18.2
│   ├── body-parser@1.20.1
│   │   └── bytes@3.1.2
│   ├── cookie@0.5.0
│   └── debug@2.6.9
│       └── ms@2.0.0
└── lodash@4.17.21

Check for:

  • Multiple versions of same package
  • Deeply nested dependencies
  • Large dependency trees
  • Unmaintained packages
Step 4: Detect Issues

Identify problems:

Version conflicts:

app requires:
  - package-a@1.0.0 (depends on shared@^1.0.0)
  - package-b@2.0.0 (depends on shared@^2.0.0)

Conflict: shared@1.x vs shared@2.x

Missing dependencies:

Error: Cannot find module 'missing-package'
Cause: Listed in package.json but not installed

Security vulnerabilities:

lodash@4.17.20 has known vulnerability CVE-2020-8203
Severity: High
Fix available: Upgrade to lodash@4.17.21
Step 5: Propose Solutions

Recommend fixes:

For version conflicts:

  • Use compatible versions
  • Update conflicting packages
  • Use resolutions/overrides
  • Consider alternatives

For missing dependencies:

  • Install missing packages
  • Add to manifest file
  • Check for typos

For security issues:

  • Update vulnerable packages
  • Apply security patches
  • Replace with secure alternatives

Dependency Management Patterns

Pattern 1: Version Conflict Resolution

Issue:

json
// package.json
{
  "dependencies": {
    "package-a": "^1.0.0",  // requires lodash@^3.0.0
    "package-b": "^2.0.0"   // requires lodash@^4.0.0
  }
}

Analysis:

Dependency tree:
├── package-a@1.0.0
│   └── lodash@3.10.1
└── package-b@2.0.0
    └── lodash@4.17.21

Conflict: Two versions of lodash (3.10.1 and 4.17.21)

Solution 1: Update package-a

json
{
  "dependencies": {
    "package-a": "^2.0.0",  // Updated version uses lodash@^4.0.0
    "package-b": "^2.0.0"
  }
}

Solution 2: Use resolutions (npm/yarn)

json
{
  "dependencies": {
    "package-a": "^1.0.0",
    "package-b": "^2.0.0"
  },
  "resolutions": {
    "lodash": "^4.17.21"
  }
}

Solution 3: Find alternative

json
{
  "dependencies": {
    "alternative-package-a": "^1.0.0",  // Doesn't depend on lodash
    "package-b": "^2.0.0"
  }
}
Pattern 2: Security Vulnerability Fix

Audit result:

bash
$ npm audit

found 3 vulnerabilities (1 moderate, 2 high)

High: Prototype Pollution
Package: lodash
Dependency of: express
Path: express > lodash
More info: https://npmjs.com/advisories/1065

Solution:

bash
# Check if update fixes it
npm audit fix

# Force update if needed
npm audit fix --force

# Or manually update
npm install lodash@latest

Verify fix:

bash
npm audit
# 0 vulnerabilities
Pattern 3: Missing Peer Dependency

Error:

npm WARN package-b@1.0.0 requires a peer of react@>=16.0.0 but none is installed.

Analysis:

json
// package-b requires react but doesn't install it
{
  "peerDependencies": {
    "react": ">=16.0.0"
  }
}

Solution:

bash
npm install react@^18.0.0

Update package.json:

json
{
  "dependencies": {
    "react": "^18.0.0",
    "package-b": "^1.0.0"
  }
}
Pattern 4: Outdated Dependencies

Check for updates:

bash
npm outdated

Package    Current  Wanted  Latest  Location
express    4.17.1   4.18.2  4.18.2  my-app
lodash     4.17.20  4.17.21 4.17.21 my-app
react      17.0.2   17.0.2  18.2.0  my-app

Analysis:

  • Current: Installed version
  • Wanted: Max version satisfying semver
  • Latest: Newest version available

Solution strategy:

bash
# Safe: Update to wanted versions
npm update

# Major updates (breaking changes)
npm install react@latest  # Review changelog first

# Pin specific version
npm install express@4.18.2 --save-exact
Show full SKILL.md (219 more words)Show less
Pattern 5: Circular Dependencies

Detection:

Circular dependency detected:
  package-a → package-b → package-c → package-a

Analysis:

javascript
// package-a/index.js
const b = require('./package-b');

// package-b/index.js
const c = require('./package-c');

// package-c/index.js
const a = require('./package-a');  // Circular!

Solution:

javascript
// Restructure to break cycle
// 1. Extract shared code to new package
// 2. Use dependency injection
// 3. Lazy loading

// Option 1: Extract shared functionality
// package-shared/index.js
module.exports = { sharedFunction };

// package-a/index.js
const shared = require('./package-shared');

// package-c/index.js
const shared = require('./package-shared');
Pattern 6: Platform-Specific Dependencies

Issue:

json
{
  "dependencies": {
    "fsevents": "^2.3.2"  // macOS only
  }
}

Error on Linux:

npm ERR! notsup Unsupported platform for fsevents@2.3.2

Solution:

json
{
  "dependencies": {
    "chokidar": "^3.5.3"  // Cross-platform alternative
  },
  "optionalDependencies": {
    "fsevents": "^2.3.2"  // macOS optimization
  }
}
Pattern 7: Dependency Bloat

Analysis:

bash
# Check installed package sizes
npm ls --all --depth=0
du -sh node_modules/

# Result: 500MB for small app!

Identify large packages:

bash
npx cost-of-modules

┌────────────────────────┬───────────┬────────────┐
│ name                   │ size      │ dependencies│
├────────────────────────┼───────────┼────────────┤
│ @babel/core            │ 45 MB     │ 234        │
│ webpack                │ 38 MB     │ 189        │
│ lodash                 │ 1.5 MB    │ 0          │
└────────────────────────┴───────────┴────────────┘

Solutions:

json
// Use lighter alternatives
{
  "dependencies": {
    "lodash.debounce": "^4.0.8",  // Instead of full lodash
    "date-fns": "^2.29.3"         // Instead of moment.js
  }
}

// Remove unused dependencies
// Use: npm prune
// Or: yarn autoclean

Version Constraint Syntax

npm/JavaScript (Semver)
^1.2.3   - Compatible with 1.2.3 (>=1.2.3 <2.0.0)
~1.2.3   - Approximately 1.2.3 (>=1.2.3 <1.3.0)
1.2.x    - 1.2.0, 1.2.1, etc. (>=1.2.0 <1.3.0)
*        - Any version
latest   - Latest version
1.2.3    - Exact version
>=1.2.3  - Greater than or equal
<2.0.0   - Less than
1.2.3 - 2.3.4  - Range
Python (PEP 440)
==1.2.3      - Exact version
>=1.2.3      - Minimum version
>=1.2,<2.0   - Range
~=1.2.3      - Compatible release (>=1.2.3, ==1.2.*)
!=1.2.3      - Exclude version
package      - Any version
Maven/Java
xml
<version>1.2.3</version>           <!-- Exact -->
<version>[1.2.3]</version>         <!-- Exact (hard) -->
<version>[1.0,2.0)</version>       <!-- Range: 1.0 <= x < 2.0 -->
<version>[1.0,)</version>          <!-- Minimum 1.0 -->
<version>(,2.0)</version>          <!-- Maximum < 2.0 -->
Cargo/Rust
toml
[dependencies]
package = "1.2.3"        # Exact: =1.2.3
package = "^1.2.3"       # Caret: >=1.2.3, <2.0.0
package = "~1.2.3"       # Tilde: >=1.2.3, <1.3.0
package = ">= 1.2.3"     # Inequality
package = "*"            # Any version

Dependency Commands Reference

npm/yarn
bash
# Install dependencies
npm install
yarn install

# Add dependency
npm install package-name
yarn add package-name

# Add dev dependency
npm install --save-dev package-name
yarn add --dev package-name

# Update dependencies
npm update
yarn upgrade

# Check for outdated
npm outdated
yarn outdated

# Security audit
npm audit
yarn audit

# Fix vulnerabilities
npm audit fix
yarn audit fix

# List dependencies
npm ls
yarn list

# Remove unused
npm prune
yarn autoclean

# Lock file
npm ci  # Clean install from lock file
yarn install --frozen-lockfile
Python (pip)
bash
# Install dependencies
pip install -r requirements.txt

# Install package
pip install package-name

# Install specific version
pip install package-name==1.2.3

# Upgrade package
pip install --upgrade package-name

# List installed
pip list

# Show outdated
pip list --outdated

# Security check
pip-audit  # Requires pip-audit package

# Freeze dependencies
pip freeze > requirements.txt

# Uninstall
pip uninstall package-name
Maven
bash
# Install dependencies
mvn install

# Update dependencies
mvn versions:update-properties

# Dependency tree
mvn dependency:tree

# Analyze dependencies
mvn dependency:analyze

# Check for updates
mvn versions:display-dependency-updates

# Security check (with OWASP plugin)
mvn dependency-check:check
Go
bash
# Install dependencies
go mod download

# Add dependency
go get package-name

# Update dependencies
go get -u ./...

# Tidy dependencies
go mod tidy

# Verify dependencies
go mod verify

# List dependencies
go list -m all

# Dependency graph
go mod graph

# Security check
go list -json -m all | nancy sleuth

Pre-Deployment Checklist

1. Dependency Installation
bash
# Verify all dependencies install successfully
npm ci  # or equivalent for your package manager

# Check for installation errors
echo $?  # Should be 0
2. Security Audit
bash
# Run security audit
npm audit

# Check for high/critical vulnerabilities
# Fix if found
npm audit fix
3. License Compliance
bash
# Check licenses
npx license-checker --summary

# Verify no GPL or incompatible licenses
npx license-checker --excludeLicenses "GPL,AGPL"
4. Dependency Tree Analysis
bash
# Check for duplicate packages
npm dedupe

# Verify no circular dependencies
npm ls

# Check tree depth
npm ls --depth=5
5. Platform Compatibility
bash
# Test on target platform
# Verify OS-specific dependencies work
# Check architecture compatibility (x64, arm64)
6. Lock File Consistency
bash
# Ensure lock file is committed
git ls-files package-lock.json

# Verify lock file is up to date
npm ci
7. Size Check
bash
# Check total size
du -sh node_modules/

# Identify large packages
npx cost-of-modules

# Remove dev dependencies for production
npm prune --production

Common Issues and Solutions

Issue 1: "Cannot find module"

Error:

Error: Cannot find module 'express'

Causes:

  • Dependency not installed
  • Not listed in package.json
  • Wrong import path

Solutions:

bash
# Install missing package
npm install express

# Add to package.json
npm install express --save

# Reinstall all dependencies
rm -rf node_modules
npm install
Issue 2: Version Conflict

Error:

npm ERR! peer dep missing: react@>=16.0.0

Solution:

bash
# Check peer dependencies
npm info package-name peerDependencies

# Install required peer dependency
npm install react@^16.0.0
Issue 3: Lock File Out of Sync

Error:

npm ERR! package-lock.json lockfileVersion mismatch

Solution:

bash
# Delete and regenerate
rm package-lock.json
npm install

# Or use correct npm version
nvm use 16
npm install
Issue 4: Network/Registry Errors

Error:

npm ERR! network timeout

Solution:

bash
# Increase timeout
npm config set timeout 60000

# Try different registry
npm config set registry https://registry.npmjs.org/

# Clear cache
npm cache clean --force
Issue 5: Post-Install Script Failures

Error:

npm ERR! postinstall script failed

Solution:

bash
# Check node/npm version
node --version
npm --version

# Update build tools
npm install -g node-gyp

# Install system dependencies (example for Ubuntu)
sudo apt-get install build-essential python3

Best Practices

  1. Use lock files - Commit package-lock.json, yarn.lock, Cargo.lock
  2. Pin major versions - Avoid wildcards in production
  3. Regular updates - Keep dependencies current, not cutting-edge
  4. Security audits - Run before every deployment
  5. Minimal dependencies - Only include what you need
  6. Review licenses - Ensure compatibility with your project
  7. Test after updates - Run full test suite
  8. Document decisions - Note why specific versions are used
  9. Use semantic versioning - Understand version implications
  10. Monitor size - Keep bundle size reasonable

Ecosystem-Specific Guides

For detailed ecosystem-specific information:

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/dependency-resolver of ArabelaTso/Skills-4-SE.

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Dependency Resolver next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Resolver compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Resolver this skillArabelaTso/Skills-4-SE253—~3.9kAutomated safety check: NotesApache-2.0
Dependency Conflict Resolvermohitagw15856/pm-claude-skills1.4k—~709Automated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh877—~895Automated safety check: PassMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Audit And Reduce Dependenciesgrafana/skills278—~3.6kAutomated safety check: WarnApache-2.0
Remotion Bits Releaseav/remotion-bits486—~1.2kAutomated safety check: PassNone

Similar skills

  • Dependency Conflict Resolver

    mohitagw15856/pm-claude-skills

    Resolve a dependency or version conflict (npm, pip, yarn, pnpm, Maven, Go modules) step by step.

    1.4k GitHub stars~709 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    877 GitHub stars~895 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Official

    Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

    278 GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Remotion Bits Release

    av/remotion-bits

    Runs the full release of the remotion-bits package: version bump, changelog, registry build, release commit, GitHub release, docs deploy and npm publish.

    486 GitHub stars~1.2k tokensUpdated 22 days ago
    DevelopmentAuto-check passed
  • Walks through releasing the Cline CLI package to npm: release notes, version bump, matching git tag, and either the GitHub workflow or a local publish.

    70k GitHub stars~3.4k tokensUpdated today
    DevelopmentAuto-check: warnings

More from ArabelaTso/Skills-4-SE

All 151 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Dependency Resolver

What does Dependency Resolver do?

Identify, analyze, and manage software dependencies before deployment. Dependency Resolver is an agent skill from ArabelaTso/Skills-4-SE. Identify, analyze, and manage software dependencies before deployment.

When should I use Dependency Resolver?

Dependency Resolver fits situations like: preparing applications for deployment; resolving dependency conflicts; updating dependencies; auditing security vulnerabilities.

How do I install Dependency Resolver in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill dependency-resolver -a claude-code`. Or copy the skill folder (skills/dependency-resolver in ArabelaTso/Skills-4-SE) into .claude/skills/dependency-resolver in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Resolver in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill dependency-resolver -a codex`. Or copy the skill folder (skills/dependency-resolver in ArabelaTso/Skills-4-SE) into .agents/skills/dependency-resolver in your project. Codex loads it when a task matches its description.

Can I use Dependency Resolver in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill dependency-resolver -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-resolver, .gemini/skills/dependency-resolver, .github/skills/dependency-resolver and .opencode/skills/dependency-resolver in your project.

What does Dependency Resolver need to run?

Going by SKILL.md and its folder, Dependency Resolver needs the command-line tools its instructions call (npm, yarn, pip, go, mvn and npx). Our summary lists: Python 3; Node.js.

Does Dependency Resolver access the network?

SKILL.md names 2 domains. In commands or code: npmjs.com and registry.npmjs.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dependency Resolver safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dependency Resolver use?

Dependency Resolver is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Resolver use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Resolver?

Skills that share tags, products or a category with Dependency Resolver: Dependency Conflict Resolver (mohitagw15856/pm-claude-skills, 1.4k stars), Dep Auditor (laolaoshiren/claude-code-skills-zh, 877 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Audit And Reduce Dependencies (grafana/skills, 278 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Resolver?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 151 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.