Agent skill

Dependency Updater

by Asvarox in Asvarox/allkaraoke

Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.

MITAuto-check passedDevelopment

Install Dependency Updater

skills CLI
$ npx skills add Asvarox/allkaraoke --skill dependency-updater -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Asvarox/allkaraoke dependency-updater --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Asvarox/allkaraoke.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-updater .claude/skills/dependency-updater && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-updater
GitHub stars
261
Used in
4 other repos
Token cost
~3.5k tokens
SKILL.md length
633 words
Files
4 (incl. scripts)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.

  • Works in 3 steps: Check current directory first → Then check for workspace/monorepo patterns → Offer to run recursively if applicable
  • Tasks that involve Dependency management
  • SKILL.md covers Quick Start, Triggers, Supported Languages and Quick Reference, plus 6 more sections
  • Runs Shell scripts from its folder; calls npm, bundle and pip

What it does

Dependency Updater is an agent skill from Asvarox/allkaraoke. Smart dependency management for any language. Auto-detects project type, applies safe updates automatically, prompts for major versions, diagnoses and fixes dependency issues.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `README.md`, `scripts/check-tool.sh` and `scripts/run-taze.sh`).

It sits in Development, covering Dependency management. It works with .NET, Ruby and Rust. The repository describes itself as: Online Karaoke game with pitch detection in your browser. The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management

Example prompts

  • “/dependency-updater”

Requirements

  • Python 3
  • Node.js
  • A Bash shell

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Check current directory first
  2. Then check for workspace/monorepo patterns
  3. Offer to run recursively if applicable

What it can do on your machine

Read from SKILL.md and the folder at commit 15460f4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • bundle
    • pip
    • cargo
    • mvn
    • dotnet
    • go
    • python
    • jq
    • npx
    • yarn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Updater loads about 3.5k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 633 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from Asvarox/allkaraoke at commit 15460f4, republished under its MIT licence (© Asvarox). 633 words, ~3,470 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-updater/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
dependency-updater
description
Smart dependency management for any language. Auto-detects project type, applies safe updates automatically, prompts for major versions, diagnoses and fixes dependency issues.
license
MIT
metadata.version
1.0.0

Dependency Updater

Smart dependency management for any language with automatic detection and safe updates.


Quick Start

update my dependencies

The skill auto-detects your project type and handles the rest.


Triggers

TriggerExample
Update dependencies"update dependencies", "update deps"
Check outdated"check for outdated packages"
Fix dependency issues"fix my dependency problems"
Security audit"audit dependencies for vulnerabilities"
Diagnose deps"diagnose dependency issues"

Supported Languages

LanguagePackage FileUpdate ToolAudit Tool
Node.jspackage.jsontazenpm audit
Pythonrequirements.txt, pyproject.tomlpip-reviewsafety, pip-audit
Gogo.modgo get -ugovulncheck
RustCargo.tomlcargo updatecargo audit
RubyGemfilebundle updatebundle audit
Javapom.xml, build.gradlemvn versions:*mvn dependency:*
.NET*.csprojdotnet outdateddotnet list package --vulnerable

Quick Reference

Update TypeVersion ChangeAction
FixedNo ^ or ~Skip (intentionally pinned)
PATCHx.y.z → x.y.ZAuto-apply
MINORx.y.z → x.Y.0Auto-apply
MAJORx.y.z → X.0.0Prompt user individually

Workflow

User Request
    │
    ▼
┌─────────────────────────────────────────────────────┐
│ Step 1: DETECT PROJECT TYPE                         │
│ • Scan for package files (package.json, go.mod...) │
│ • Identify package manager                          │
├─────────────────────────────────────────────────────┤
│ Step 2: CHECK PREREQUISITES                         │
│ • Verify required tools are installed               │
│ • Suggest installation if missing                   │
├─────────────────────────────────────────────────────┤
│ Step 3: SCAN FOR UPDATES                            │
│ • Run language-specific outdated check              │
│ • Categorize: MAJOR / MINOR / PATCH / Fixed         │
├─────────────────────────────────────────────────────┤
│ Step 4: AUTO-APPLY SAFE UPDATES                     │
│ • Apply MINOR and PATCH automatically               │
│ • Report what was updated                           │
├─────────────────────────────────────────────────────┤
│ Step 5: PROMPT FOR MAJOR UPDATES                    │
│ • AskUserQuestion for each MAJOR update             │
│ • Show current → new version                        │
├─────────────────────────────────────────────────────┤
│ Step 6: APPLY APPROVED MAJORS                       │
│ • Update only approved packages                     │
├─────────────────────────────────────────────────────┤
│ Step 7: FINALIZE                                    │
│ • Run install command                               │
│ • Run security audit                                │
├─────────────────────────────────────────────────────┤
│ Step 8: DOCUMENT                                    │
│ • Update docs/dependency-updates-report.md          │
│ • Explain every override/resolution added           │
│ • Record unresolved audit or peer follow-up         │
└─────────────────────────────────────────────────────┘

Commands by Language

Node.js (npm/yarn/pnpm)
bash
# Check prerequisites
scripts/check-tool.sh taze "npm install -g taze"

# Scan for updates
taze

# Apply minor/patch
taze minor --write

# Apply specific majors
taze major --write --include pkg1,pkg2

# Monorepo support
taze -r  # recursive

# Security
npm audit
npm audit fix
Documentation Requirement

For Node.js projects that add or keep pnpm.overrides, overrides, resolutions, or other transitive pins, you MUST update docs/dependency-updates-report.md as part of the same task.

That report must include:

  • only the overrides/resolutions that are currently present
  • for each one: why it is needed
  • for each one: the installed dependency chain and versions that prevent a clean upstream update

If the file does not exist yet, create it.

Python
bash
# Check outdated
pip list --outdated

# Update all (careful!)
pip-review --auto

# Update specific
pip install --upgrade package-name

# Security
pip-audit
safety check
Go
bash
# Check outdated
go list -m -u all

# Update all
go get -u ./...

# Tidy up
go mod tidy

# Security
govulncheck ./...
Rust
bash
# Check outdated
cargo outdated

# Update within semver
cargo update

# Security
cargo audit
Ruby
bash
# Check outdated
bundle outdated

# Update all
bundle update

# Update specific
bundle update --conservative gem-name

# Security
bundle audit
Java (Maven)
bash
# Check outdated
mvn versions:display-dependency-updates

# Update to latest
mvn versions:use-latest-releases

# Security
mvn dependency:tree
mvn dependency-check:check
.NET
bash
# Check outdated
dotnet list package --outdated

# Update specific
dotnet add package PackageName

# Security
dotnet list package --vulnerable

Diagnosis Mode

When dependencies are broken, run diagnosis:

Common Issues & Fixes
IssueSymptomsFix
Version Conflict"Cannot resolve dependency tree"Clean install, use overrides/resolutions
Peer Dependency"Peer dependency not satisfied"Install required peer version
Security Vulnnpm audit shows issuesnpm audit fix or manual update
Unused DepsBloated bundleRun depcheck (Node) or equivalent
Duplicate DepsMultiple versions installedRun npm dedupe or equivalent
Temporary Override DriftNobody remembers why an override existsUpdate docs/dependency-updates-report.md in the same change
Emergency Fixes
bash
# Node.js - Nuclear reset
rm -rf node_modules package-lock.json
npm cache clean --force
npm install

# Python - Clean virtualenv
rm -rf venv
python -m venv venv
source venv/bin/activate
pip install -r requirements.txt

# Go - Reset modules
rm go.sum
go mod tidy

Security Audit

Run security checks for any project:

bash
# Node.js
npm audit
npm audit --json | jq '.metadata.vulnerabilities'

# Python
pip-audit
safety check

# Go
govulncheck ./...

# Rust
cargo audit

# Ruby
bundle audit

# .NET
dotnet list package --vulnerable
Severity Response
SeverityAction
CriticalFix immediately
HighFix within 24h
ModerateFix within 1 week
LowFix in next release

Anti-Patterns

AvoidWhyInstead
Update fixed versionsIntentionally pinnedSkip them
Auto-apply MAJORBreaking changesPrompt user
Batch MAJOR promptsLoses contextPrompt individually
Skip lock fileIrreproducible buildsAlways commit lock files
Ignore security alertsVulnerabilitiesAddress by severity

Show full SKILL.md (262 more words)Show less

Verification Checklist

After updates:

  • Updates scanned without errors
  • MINOR/PATCH auto-applied
  • MAJOR updates prompted individually
  • Fixed versions untouched
  • Lock file updated
  • Install command ran
  • Security audit passed (or issues noted)
  • docs/dependency-updates-report.md updated if overrides or resolutions remain, and it only lists the currently present overrides/resolutions with rationale and dependency chains

<details>
<summary><strong>Deep Dive: Project Detection</strong></summary>

The skill auto-detects project type by scanning for package files:

File FoundLanguagePackage Manager
package.jsonNode.jsnpm/yarn/pnpm
requirements.txtPythonpip
pyproject.tomlPythonpip/poetry
PipfilePythonpipenv
go.modGogo modules
Cargo.tomlRustcargo
GemfileRubybundler
pom.xmlJavaMaven
build.gradleJava/KotlinGradle
*.csproj.NETdotnet

Detection order matters for monorepos:

  1. Check current directory first
  2. Then check for workspace/monorepo patterns
  3. Offer to run recursively if applicable
</details>
<details>
<summary><strong>Deep Dive: Node.js with taze</strong></summary>
Prerequisites
bash
# Install taze globally (recommended)
npm install -g taze

# Or use npx
npx taze
Smart Update Flow
bash
# 1. Scan all updates
taze

# 2. Apply safe updates (minor + patch)
taze minor --write

# 3. For each major, prompt user:
#    "Update @types/node from ^20.0.0 to ^22.0.0?"
#    If yes, add to approved list

# 4. Apply approved majors
taze major --write --include approved-pkg1,approved-pkg2

# 5. Install
npm install  # or pnpm install / yarn
Auto-Approve List

Some packages have frequent major bumps but are backward-compatible:

PackageReason
lucide-reactIcon library, majors are additive
@types/*Type definitions, usually safe
</details>
<details>
<summary><strong>Deep Dive: Version Strategies</strong></summary>
Semantic Versioning
MAJOR.MINOR.PATCH (e.g., 2.3.1)

MAJOR: Breaking changes - requires code changes
MINOR: New features - backward compatible
PATCH: Bug fixes - backward compatible
Range Specifiers
SpecifierMeaningExample
^1.2.3Minor + Patch OK>=1.2.3 <2.0.0
~1.2.3Patch only>=1.2.3 <1.3.0
1.2.3Exact (fixed)Only 1.2.3
>=1.2.3At leastAny >=1.2.3
*AnyLatest (dangerous)
json
{
  "dependencies": {
    "critical-lib": "1.2.3", // Exact for critical
    "stable-lib": "~1.2.3", // Patch only for stable
    "modern-lib": "^1.2.3" // Minor OK for active
  }
}
</details>
<details>
<summary><strong>Deep Dive: Conflict Resolution</strong></summary>
Node.js Conflicts

Diagnosis:

bash
npm ls package-name      # See dependency tree
npm explain package-name # Why installed
yarn why package-name    # Yarn equivalent

Resolution with overrides:

json
// package.json
{
  "overrides": {
    "lodash": "^4.18.0"
  }
}

Resolution with resolutions (Yarn):

json
{
  "resolutions": {
    "lodash": "^4.18.0"
  }
}
Python Conflicts

Diagnosis:

bash
pip check
pipdeptree -p package-name

Resolution:

bash
# Use virtual environment
python -m venv venv
source venv/bin/activate
pip install -r requirements.txt

# Or use constraints
pip install -c constraints.txt -r requirements.txt
</details>

Script Reference

ScriptPurpose
scripts/check-tool.shVerify tool is installed
scripts/run-taze.shRun taze with proper flags

ToolLanguagePurpose
tazeNode.jsSmart dependency updates
npm-check-updatesNode.jsAlternative to taze
pip-reviewPythonInteractive pip updates
cargo-editRustCargo dependency management
bundler-auditRubySecurity auditing

© Asvarox, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts) in .agents/skills/dependency-updater of Asvarox/allkaraoke.

  • SKILL.md
  • README.md
  • scripts/check-tool.sh
  • scripts/run-taze.sh

Open the folder on GitHubat commit 15460f4

Used in 4 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in Asvarox/allkaraoke, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Dependency Updater next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Updater compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Updater this skillAsvarox/allkaraoke2614 repos~3.5kAutomated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh879—~895Automated safety check: PassMIT
Pyroscopegrafana/skills281—~1.2kAutomated safety check: PassApache-2.0
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
Sca AuditOWASP/secure-agent-playbook187—~494Automated safety check: PassCC-BY-4.0
Update .NET OS Packagesdotnet/core22k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    879 GitHub stars~895 tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Pyroscope

    grafana/skills

    Official

    Continuously profile applications with Grafana Pyroscope and read the result as flame graphs.

    281 GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    187 GitHub stars~494 tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed

More from Asvarox/allkaraoke

All 8 skills in this repo
  • Subagent Driven Development

    Asvarox/allkaraoke

    A skill your agent uses when executing implementation plans with independent tasks in the current session

    261 GitHub starsUsed in 37 repos~1.2k tokens
    Auto-check passed
  • Migrate Oxlint

    Asvarox/allkaraoke

    Guide for migrating a project from ESLint to Oxlint. An agent skill from Asvarox/allkaraoke.

    261 GitHub starsUsed in 4 repos~2.5k tokens
    Auto-check passed
  • E2E Playwright

    Asvarox/allkaraoke

    Run, write, and debug Playwright E2E tests for this project.

    261 GitHub stars~876 tokensUpdated today
    Auto-check passed
  • Using Tailwind

    Asvarox/allkaraoke

    The design language for this project and how to style UI with it — the colour, type, surface and layer tokens, when to reach for an AKUI component instead of writing classes, and when TWC…

    261 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Writing E2E Tests

    Asvarox/allkaraoke

    Patterns and guidelines for writing Playwright E2E tests in this project — page object rules, assertion placement, and locator conventions.

    261 GitHub stars~447 tokensUpdated today
    Auto-check passed
  • Writing Unit Tests

    Asvarox/allkaraoke

    A skill your agent uses when Codex updates, fixes, or adds unit tests in this project.

    261 GitHub stars~358 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Dependency Updater

What does Dependency Updater do?

Smart dependency management for any language. An agent skill from Asvarox/allkaraoke. Dependency Updater is an agent skill from Asvarox/allkaraoke. Smart dependency management for any language.

When should I use Dependency Updater?

Dependency Updater fits situations like: tasks that involve Dependency management.

How do I install Dependency Updater in Claude Code?

Run `npx skills add Asvarox/allkaraoke --skill dependency-updater -a claude-code`. Or copy the skill folder (.agents/skills/dependency-updater in Asvarox/allkaraoke) into .claude/skills/dependency-updater in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Updater in Codex?

Run `npx skills add Asvarox/allkaraoke --skill dependency-updater -a codex`. Or copy the skill folder (.agents/skills/dependency-updater in Asvarox/allkaraoke) into .agents/skills/dependency-updater in your project. Codex loads it when a task matches its description.

Can I use Dependency Updater in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Asvarox/allkaraoke --skill dependency-updater -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-updater, .gemini/skills/dependency-updater, .github/skills/dependency-updater and .opencode/skills/dependency-updater in your project.

What does Dependency Updater need to run?

Going by SKILL.md and its folder, Dependency Updater needs a shell for the scripts in its folder and the command-line tools its instructions call (npm, bundle, pip, cargo, mvn and dotnet). Our summary lists: Python 3; Node.js; A Bash shell.

Does Dependency Updater access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Dependency Updater safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dependency Updater use?

Dependency Updater is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Updater use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Updater?

Skills that share tags, products or a category with Dependency Updater: Dep Auditor (laolaoshiren/claude-code-skills-zh, 879 stars), Pyroscope (grafana/skills, 281 stars), Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars) and Sca Audit (OWASP/secure-agent-playbook, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Updater?

Asvarox (a GitHub user) maintains it in Asvarox/allkaraoke, which has 261 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.

Source: Asvarox/allkaraoke on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.