Install the "npm-deps-cleanup" agent skill from https://github.com/Asymmetric-al/core/tree/develop/.agents/skills/npm-deps-cleanup into .claude/skills/npm-deps-cleanup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-deps-cleanup", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "npm-deps-cleanup" agent skill from https://github.com/Asymmetric-al/core/tree/develop/.agents/skills/npm-deps-cleanup into .agents/skills/npm-deps-cleanup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-deps-cleanup", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "npm-deps-cleanup" agent skill from https://github.com/Asymmetric-al/core/tree/develop/.agents/skills/npm-deps-cleanup into .cursor/skills/npm-deps-cleanup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-deps-cleanup", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "npm-deps-cleanup" agent skill from https://github.com/Asymmetric-al/core/tree/develop/.agents/skills/npm-deps-cleanup into .gemini/skills/npm-deps-cleanup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-deps-cleanup", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "npm-deps-cleanup" agent skill from https://github.com/Asymmetric-al/core/tree/develop/.agents/skills/npm-deps-cleanup into .github/skills/npm-deps-cleanup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-deps-cleanup", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "npm-deps-cleanup" agent skill from https://github.com/Asymmetric-al/core/tree/develop/.agents/skills/npm-deps-cleanup into .opencode/skills/npm-deps-cleanup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-deps-cleanup", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
npm-deps-cleanup
GitHub stars
381
Token cost
~2.5k tokens
SKILL.md length
1,141 words
Files
2 (incl. references)
Skills in repo
43
Repo updated
First seen
Licence
AGPL-3.0
At a glance
Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects.
Works in 7 steps: Baseline → Remove Unused Direct Dependencies → Deduplicate Monorepo Direct Versions → …
Asked to remove unused dependencies
SKILL.md covers Workflow, Package Manager Detection, Safety Rules and Step 1: Baseline, plus 7 more sections
Calls pnpm, yarn and npm; reaches e18e.dev
What it does
npm Deps Cleanup is an agent skill from Asymmetric-al/core. Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. Use when asked to remove unused dependencies, deduplicate workspace dependency versions, lockfiles or nodemodules, analyze direct dependencies' transitive lockfile closure, find low-risk upgrades that reduce dependency trees, inline trivial dependencies, or apply e18e dependency replacement recommendations.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/upstream.md`).
It sits in Development, covering Dependency management. It works with npm, pnpm and JavaScript. The repository describes itself as: A high-performance, enterprise-grade Next.js 16 application for mission-focused non-profit organizations. Built for high impact teams. The licence is AGPL-3.0.
When your agent uses it
Asked to remove unused dependencies
Deduplicate workspace dependency versions
Analyze direct dependencies transitive lockfile closure
Find low-risk upgrades that reduce dependency trees
Example prompts
“/npm-deps-cleanup”
Requirements
Node.js
Workflow steps
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c30c8ff. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
pnpm
yarn
npm
bun
git
npx
bunx
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
e18e.dev
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
npm Deps Cleanup loads about 2.5k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 1,141 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~106
When it runs· the whole SKILL.md, loaded when a task matches
~2.5k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~2.7k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/npm-deps-cleanup/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
npm-deps-cleanup
description
Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. Use when asked to remove unused dependencies, deduplicate workspace dependency versions, lockfiles or node_modules, analyze direct dependencies' transitive lockfile closure, find low-risk upgrades that reduce dependency trees, inline trivial dependencies, or apply e18e dependency replacement recommendations.
npm Dependency Cleanup
Reduce JavaScript dependency footprint. Preserve the existing package manager, lockfile, workspace layout, and dependency range style unless there is a concrete reason to change them.
Workflow
Establish the baseline.
Remove unused direct dependencies.
Deduplicate direct dependency versions in monorepos.
Rank direct dependencies by transitive lockfile closure.
Use closure data to find low-risk minor/patch upgrades.
Use closure data to find trivial dependencies worth inlining.
Check e18e recommendations for replacements/removals.
Reinstall, verify, and report measured impact.
Package Manager Detection
Use the repo's existing package manager. Prefer explicit package metadata before lockfiles:
packageManager in the root package.json.
devEngines.packageManager.name in the root package.json.
Lockfile inference.
When devEngines.packageManager is present, use its name for npm, pnpm, Yarn, or Bun detection. Treat its version and onFail fields as policy signals, not as permission to change package managers.
Infer from lockfiles only when package metadata does not identify the package manager:
Signal
Package manager
package-lock.json or npm-shrinkwrap.json
npm
pnpm-lock.yaml
pnpm
yarn.lock
Yarn
bun.lock or bun.lockb
Bun
Use the matching command family:
Action
npm
pnpm
Yarn
Bun
Install/update lockfile
npm install
pnpm install
yarn install
bun install
Remove direct dependency
npm uninstall <pkg>
pnpm remove <pkg>
yarn remove <pkg>
bun remove <pkg>
Add/update direct dependency
npm install <pkg>@<version>
pnpm add <pkg>@<version>
yarn add <pkg>@<version>
bun add <pkg>@<version>
Explain dependency
npm explain <pkg>
pnpm why <pkg>
yarn why <pkg>
bun pm why <pkg> if available
Dedupe lockfile
npm dedupe
pnpm dedupe
yarn dedupe if available
reinstall and inspect
One-off tools
npx <tool>
pnpm dlx <tool>
yarn dlx <tool> if available
bunx <tool>
Safety Rules
Work in small batches so lockfile diffs remain reviewable.
You may write scripting and parsing to verify package.json and lockfile dependency accounts.
Treat peerDependencies, optionalDependencies, package bin usage, test fixtures, and published package manifests as higher risk.
Do not remove or inline dependencies used for security, parsing, crypto, Unicode, URL handling, date/time, i18n, or platform compatibility unless the replacement is proven equivalent.
Do not change package managers, delete lockfiles, or rewrite workspace structure as part of cleanup.
Treat package manager dedupe commands as potentially behavior-changing. They can alter selected transitive versions within allowed ranges, so inspect lockfile diffs and run focused verification before keeping the result.
Measure before and after: direct dependency count, lockfile line count or entry count, package count, and estimated node_modules size when available.
Step 1: Baseline
Collect:
All package.json files and workspace boundaries.
Current package manager and lockfile.
Direct dependency names by manifest section: dependencies, devDependencies, peerDependencies, optionalDependencies.
Existing verification commands from scripts, CI, or repo docs.
Record baseline metrics before edits:
sh
git status --short
wc -l <lockfile>
If node_modules is installed, also estimate installed footprint with platform-appropriate filesystem tools. Do not make footprint cleanup depend on node_modules being present; lockfile reductions are the primary metric.
Step 2: Remove Unused Direct Dependencies
Use a static analyzer as a starting point, not as proof. Good candidates include knip, depcheck, or repo-native tooling if already configured. Run them through the detected package manager's one-off executor when they are not installed.
For each candidate:
Search code, configs, package scripts, build tooling, tests, and docs for the package name and known import paths.
Check whether the dependency is required by a published package manifest, peer contract, plugin loader, CLI command, or dynamic require/import.
Remove only when no real usage remains.
Reinstall with the detected package manager and run focused verification.
If usage is only in a script or config, consider moving between dependencies and devDependencies instead of removing.
Step 3: Deduplicate Monorepo Direct Versions
In monorepos, look for the same direct dependency declared with multiple versions/ranges across package manifests. Use existing policy first: exact pins, caret ranges, catalog/protocol usage, workspace protocol, or central constraints.
Good approaches:
Use syncpack list-mismatches or equivalent package-manager-neutral tooling for discovery.
Standardize direct ranges when packages can share the same compatible version.
Prefer manifest-level consistency before adding overrides/resolutions.
Use overrides/resolutions only for transitive dependency convergence or security fixes, and document why.
After deduping, reinstall and inspect both manifest and lockfile diffs.
Then consider the package manager's native lockfile dedupe command: npm dedupe, pnpm dedupe, or yarn dedupe when available. Bun has no direct equivalent; run bun install and inspect whether the lockfile converges. Apply these commands carefully because they may change transitive dependency resolution and introduce breakage even without manifest edits.
Show full SKILL.md (398 more words)Show less
Step 4: Rank Transitive Lockfile Closure
For each important direct dependency, estimate its closure: the set of transitive lockfile entries reachable from that direct dependency.
Report both:
Total closure: all packages reachable from the dependency.
Exclusive closure: packages that disappear if this dependency is removed and are not retained by other direct dependencies.
Prefer deterministic measurement over guesses. Package-manager-neutral fallback:
Save baseline lockfile metrics.
Temporarily remove one direct dependency from the owning manifest.
Run the detected package manager install.
Measure lockfile line/entry reduction and package count reduction.
Revert the temporary removal before measuring the next dependency.
Use npm explain, pnpm why, yarn why, or available package-manager graph commands to understand why large transitive packages exist. Rank dependencies by impact and risk, not just raw size.
Step 5: Find Low-Risk High-Impact Upgrades
Use closure rankings to target direct dependencies whose newer minor/patch versions reduce transitive dependencies.
For each candidate:
Check available non-major versions with the package manager's outdated/info commands.
Review changelog/release notes for dependency tree changes and compatibility notes.
Upgrade one dependency or tight cluster at a time.
Reinstall and compare closure metrics before/after.
Run focused tests and relevant build/typecheck commands.
Avoid major upgrades unless the user explicitly accepts the migration risk.
Step 6: Inline Trivial Usage
Use closure rankings to find direct dependencies with small, obvious usage in the codebase but large transitive cost.
Inline only when all are true:
Usage is tiny and easy to fully characterize.
Equivalent code is shorter or clearer than retaining the dependency.
Behavior is covered by tests or can be covered with small characterization tests.
The dependency is not solving cross-platform, security, parsing, Unicode, locale, or spec-compliance edge cases.
Prefer native APIs over new replacement dependencies when the required behavior is simple.
Step 7: Apply e18e Guidance
Consult e18e for additional removal and replacement candidates:
Replace <runner> with the detected one-off executor: npx, pnpm dlx, yarn dlx, or bunx.
Also check the e18e module replacements list at https://e18e.dev/docs/replacements/ for known alternatives. Treat recommendations as candidates, not mandates; verify bundle/runtime behavior and run tests.
Reporting
Summarize outcomes with measured impact:
Direct dependencies removed or moved.
Direct versions deduplicated.
Lockfile line/entry reduction.
Estimated package or node_modules reduction when available.
High-impact candidates deferred and why.
Verification commands run and results.
Call out risk explicitly when a removal depends on static analysis rather than runtime coverage.
npm Deps Cleanup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.
Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…
A skill your agent uses when building any system where email content triggers actions — AI agent inboxes, automated support handlers, email-to-task pipelines, or any workflow processing untrusted…
Guides a one-question-at-a-time design interview, captures alignment in agent/EVE-BRIEF.md, then scaffolds and implements a runnable eve agent with verbose teaching comments.
Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. npm Deps Cleanup is an agent skill from Asymmetric-al/core. Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects.
When should I use npm Deps Cleanup?
npm Deps Cleanup fits situations like: asked to remove unused dependencies; deduplicate workspace dependency versions; analyze direct dependencies transitive lockfile closure; find low-risk upgrades that reduce dependency trees.
How do I install npm Deps Cleanup in Claude Code?
Run `npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a claude-code`. Or copy the skill folder (.agents/skills/npm-deps-cleanup in Asymmetric-al/core) into .claude/skills/npm-deps-cleanup in your project. Claude Code loads it when a task matches its description.
How do I install npm Deps Cleanup in Codex?
Run `npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a codex`. Or copy the skill folder (.agents/skills/npm-deps-cleanup in Asymmetric-al/core) into .agents/skills/npm-deps-cleanup in your project. Codex loads it when a task matches its description.
Can I use npm Deps Cleanup in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm-deps-cleanup, .gemini/skills/npm-deps-cleanup, .github/skills/npm-deps-cleanup and .opencode/skills/npm-deps-cleanup in your project.
What does npm Deps Cleanup need to run?
Going by SKILL.md and its folder, npm Deps Cleanup needs the command-line tools its instructions call (pnpm, yarn, npm, bun, git and npx). Our summary lists: Node.js.
Does npm Deps Cleanup access the network?
SKILL.md names 1 domain. In commands or code: e18e.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Is npm Deps Cleanup safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does npm Deps Cleanup use?
npm Deps Cleanup is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does npm Deps Cleanup use?
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 197 tokens, read only when the agent opens those files.
What are the alternatives to npm Deps Cleanup?
Skills that share tags, products or a category with npm Deps Cleanup: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), Audit And Reduce Dependencies (grafana/skills, 282 stars) and Pnpm Engine (teambit/bit, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains npm Deps Cleanup?
Asymmetric-al (a GitHub organization) maintains it in Asymmetric-al/core, which has 381 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on October 9, 2026.
Source: Asymmetric-al/core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.