Agent skill

npm Deps Cleanup

by Asymmetric-al in Asymmetric-al/core

Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects.

AGPL-3.0Auto-check passedDevelopment

Install npm Deps Cleanup

skills CLI
$ npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Asymmetric-al/core npm-deps-cleanup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Asymmetric-al/core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/npm-deps-cleanup .claude/skills/npm-deps-cleanup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
npm-deps-cleanup
GitHub stars
381
Token cost
~2.5k tokens
SKILL.md length
1,141 words
Files
2 (incl. references)
Skills in repo
43
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects.

  • Works in 7 steps: Baseline → Remove Unused Direct Dependencies → Deduplicate Monorepo Direct Versions → …
  • Asked to remove unused dependencies
  • SKILL.md covers Workflow, Package Manager Detection, Safety Rules and Step 1: Baseline, plus 7 more sections
  • Calls pnpm, yarn and npm; reaches e18e.dev

What it does

npm Deps Cleanup is an agent skill from Asymmetric-al/core. Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. Use when asked to remove unused dependencies, deduplicate workspace dependency versions, lockfiles or nodemodules, analyze direct dependencies' transitive lockfile closure, find low-risk upgrades that reduce dependency trees, inline trivial dependencies, or apply e18e dependency replacement recommendations.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/upstream.md`).

It sits in Development, covering Dependency management. It works with npm, pnpm and JavaScript. The repository describes itself as: A high-performance, enterprise-grade Next.js 16 application for mission-focused non-profit organizations. Built for high impact teams. The licence is AGPL-3.0.

When your agent uses it

  • Asked to remove unused dependencies
  • Deduplicate workspace dependency versions
  • Analyze direct dependencies transitive lockfile closure
  • Find low-risk upgrades that reduce dependency trees

Example prompts

  • “/npm-deps-cleanup”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Baseline
  2. Remove Unused Direct Dependencies
  3. Deduplicate Monorepo Direct Versions
  4. Rank Transitive Lockfile Closure
  5. Find Low-Risk High-Impact Upgrades
  6. Inline Trivial Usage
  7. Apply e18e Guidance

What it can do on your machine

Read from SKILL.md and the folder at commit c30c8ff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • yarn
    • npm
    • bun
    • git
    • npx
    • bunx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • e18e.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

npm Deps Cleanup loads about 2.5k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 1,141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Asymmetric-al/core at commit c30c8ff, republished under its AGPL-3.0 licence (© Asymmetric-al). 1,141 words, ~2,526 tokens.

Download SKILL.mdSave it as .claude/skills/npm-deps-cleanup/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
npm-deps-cleanup
description
Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. Use when asked to remove unused dependencies, deduplicate workspace dependency versions, lockfiles or node_modules, analyze direct dependencies' transitive lockfile closure, find low-risk upgrades that reduce dependency trees, inline trivial dependencies, or apply e18e dependency replacement recommendations.

npm Dependency Cleanup

Reduce JavaScript dependency footprint. Preserve the existing package manager, lockfile, workspace layout, and dependency range style unless there is a concrete reason to change them.

Workflow

  1. Establish the baseline.
  2. Remove unused direct dependencies.
  3. Deduplicate direct dependency versions in monorepos.
  4. Rank direct dependencies by transitive lockfile closure.
  5. Use closure data to find low-risk minor/patch upgrades.
  6. Use closure data to find trivial dependencies worth inlining.
  7. Check e18e recommendations for replacements/removals.
  8. Reinstall, verify, and report measured impact.

Package Manager Detection

Use the repo's existing package manager. Prefer explicit package metadata before lockfiles:

  1. packageManager in the root package.json.
  2. devEngines.packageManager.name in the root package.json.
  3. Lockfile inference.

When devEngines.packageManager is present, use its name for npm, pnpm, Yarn, or Bun detection. Treat its version and onFail fields as policy signals, not as permission to change package managers.

Infer from lockfiles only when package metadata does not identify the package manager:

SignalPackage manager
package-lock.json or npm-shrinkwrap.jsonnpm
pnpm-lock.yamlpnpm
yarn.lockYarn
bun.lock or bun.lockbBun

Use the matching command family:

ActionnpmpnpmYarnBun
Install/update lockfilenpm installpnpm installyarn installbun install
Remove direct dependencynpm uninstall <pkg>pnpm remove <pkg>yarn remove <pkg>bun remove <pkg>
Add/update direct dependencynpm install <pkg>@<version>pnpm add <pkg>@<version>yarn add <pkg>@<version>bun add <pkg>@<version>
Explain dependencynpm explain <pkg>pnpm why <pkg>yarn why <pkg>bun pm why <pkg> if available
Dedupe lockfilenpm dedupepnpm dedupeyarn dedupe if availablereinstall and inspect
One-off toolsnpx <tool>pnpm dlx <tool>yarn dlx <tool> if availablebunx <tool>

Safety Rules

  • Work in small batches so lockfile diffs remain reviewable.
  • Never trust unused-dependency tools blindly; verify imports, config files, scripts, generated code hooks, framework conventions, plugin names, CLIs, and dynamic imports.
  • You may write scripting and parsing to verify package.json and lockfile dependency accounts.
  • Treat peerDependencies, optionalDependencies, package bin usage, test fixtures, and published package manifests as higher risk.
  • Do not remove or inline dependencies used for security, parsing, crypto, Unicode, URL handling, date/time, i18n, or platform compatibility unless the replacement is proven equivalent.
  • Do not change package managers, delete lockfiles, or rewrite workspace structure as part of cleanup.
  • Treat package manager dedupe commands as potentially behavior-changing. They can alter selected transitive versions within allowed ranges, so inspect lockfile diffs and run focused verification before keeping the result.
  • Measure before and after: direct dependency count, lockfile line count or entry count, package count, and estimated node_modules size when available.

Step 1: Baseline

Collect:

  • All package.json files and workspace boundaries.
  • Current package manager and lockfile.
  • Direct dependency names by manifest section: dependencies, devDependencies, peerDependencies, optionalDependencies.
  • Existing verification commands from scripts, CI, or repo docs.

Record baseline metrics before edits:

sh
git status --short
wc -l <lockfile>

If node_modules is installed, also estimate installed footprint with platform-appropriate filesystem tools. Do not make footprint cleanup depend on node_modules being present; lockfile reductions are the primary metric.

Step 2: Remove Unused Direct Dependencies

Use a static analyzer as a starting point, not as proof. Good candidates include knip, depcheck, or repo-native tooling if already configured. Run them through the detected package manager's one-off executor when they are not installed.

For each candidate:

  1. Search code, configs, package scripts, build tooling, tests, and docs for the package name and known import paths.
  2. Check whether the dependency is required by a published package manifest, peer contract, plugin loader, CLI command, or dynamic require/import.
  3. Remove only when no real usage remains.
  4. Reinstall with the detected package manager and run focused verification.

If usage is only in a script or config, consider moving between dependencies and devDependencies instead of removing.

Step 3: Deduplicate Monorepo Direct Versions

In monorepos, look for the same direct dependency declared with multiple versions/ranges across package manifests. Use existing policy first: exact pins, caret ranges, catalog/protocol usage, workspace protocol, or central constraints.

Good approaches:

  • Use syncpack list-mismatches or equivalent package-manager-neutral tooling for discovery.
  • Standardize direct ranges when packages can share the same compatible version.
  • Prefer manifest-level consistency before adding overrides/resolutions.
  • Use overrides/resolutions only for transitive dependency convergence or security fixes, and document why.

After deduping, reinstall and inspect both manifest and lockfile diffs.

Then consider the package manager's native lockfile dedupe command: npm dedupe, pnpm dedupe, or yarn dedupe when available. Bun has no direct equivalent; run bun install and inspect whether the lockfile converges. Apply these commands carefully because they may change transitive dependency resolution and introduce breakage even without manifest edits.

Show full SKILL.md (398 more words)Show less

Step 4: Rank Transitive Lockfile Closure

For each important direct dependency, estimate its closure: the set of transitive lockfile entries reachable from that direct dependency.

Report both:

  • Total closure: all packages reachable from the dependency.
  • Exclusive closure: packages that disappear if this dependency is removed and are not retained by other direct dependencies.

Prefer deterministic measurement over guesses. Package-manager-neutral fallback:

  1. Save baseline lockfile metrics.
  2. Temporarily remove one direct dependency from the owning manifest.
  3. Run the detected package manager install.
  4. Measure lockfile line/entry reduction and package count reduction.
  5. Revert the temporary removal before measuring the next dependency.

Use npm explain, pnpm why, yarn why, or available package-manager graph commands to understand why large transitive packages exist. Rank dependencies by impact and risk, not just raw size.

Step 5: Find Low-Risk High-Impact Upgrades

Use closure rankings to target direct dependencies whose newer minor/patch versions reduce transitive dependencies.

For each candidate:

  1. Check available non-major versions with the package manager's outdated/info commands.
  2. Review changelog/release notes for dependency tree changes and compatibility notes.
  3. Upgrade one dependency or tight cluster at a time.
  4. Reinstall and compare closure metrics before/after.
  5. Run focused tests and relevant build/typecheck commands.

Avoid major upgrades unless the user explicitly accepts the migration risk.

Step 6: Inline Trivial Usage

Use closure rankings to find direct dependencies with small, obvious usage in the codebase but large transitive cost.

Inline only when all are true:

  • Usage is tiny and easy to fully characterize.
  • Equivalent code is shorter or clearer than retaining the dependency.
  • Behavior is covered by tests or can be covered with small characterization tests.
  • The dependency is not solving cross-platform, security, parsing, Unicode, locale, or spec-compliance edge cases.

Prefer native APIs over new replacement dependencies when the required behavior is simple.

Step 7: Apply e18e Guidance

Consult e18e for additional removal and replacement candidates:

sh
<runner> @e18e/cli analyze
<runner> @e18e/cli migrate --dry-run

Replace <runner> with the detected one-off executor: npx, pnpm dlx, yarn dlx, or bunx.

Also check the e18e module replacements list at https://e18e.dev/docs/replacements/ for known alternatives. Treat recommendations as candidates, not mandates; verify bundle/runtime behavior and run tests.

Reporting

Summarize outcomes with measured impact:

  • Direct dependencies removed or moved.
  • Direct versions deduplicated.
  • Lockfile line/entry reduction.
  • Estimated package or node_modules reduction when available.
  • High-impact candidates deferred and why.
  • Verification commands run and results.

Call out risk explicitly when a removal depends on static analysis rather than runtime coverage.

© Asymmetric-al, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/npm-deps-cleanup of Asymmetric-al/core.

  • SKILL.md
  • references/upstream.md

Open the folder on GitHubat commit c30c8ff

Compare with similar skills

npm Deps Cleanup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

npm Deps Cleanup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
npm Deps Cleanup this skillAsymmetric-al/core381—~2.5kAutomated safety check: PassAGPL-3.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
Audit And Reduce Dependenciesgrafana/skills282—~3.6kAutomated safety check: WarnApache-2.0
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence
Monorepo Tooling and Dependenciespierrecomputer/pierre6.3k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 10 days ago
    SecurityAuto-check: warnings
  • Official

    Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

    282 GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: warnings
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.3k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

    165 GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from Asymmetric-al/core

All 43 skills in this repo
  • Idempotency Handling

    Asymmetric-al/core

    Implement idempotency keys and handling to ensure operations can be safely retried without duplicate effects.

    381 GitHub stars~867 tokensUpdated today
    Auto-check passed
  • Accessibility Review

    Asymmetric-al/core

    Audit and fix accessibility in Core UI. An agent skill from Asymmetric-al/core.

    381 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Email Inbox

    Asymmetric-al/core

    A skill your agent uses when building any system where email content triggers actions — AI agent inboxes, automated support handlers, email-to-task pipelines, or any workflow processing untrusted…

    381 GitHub stars~4.1k tokensUpdated today
    Auto-check: notes
  • Components Build

    Asymmetric-al/core

    Build modern, composable, and accessible React UI components following the components.build specification.

    381 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Create Agent

    Asymmetric-al/core

    Guides a one-question-at-a-time design interview, captures alignment in agent/EVE-BRIEF.md, then scaffolds and implements a runnable eve agent with verbose teaching comments.

    381 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Emil Design Engineering

    Asymmetric-al/core

    Design engineering principles and patterns for building polished, accessible web interfaces.

    381 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Categories

Questions about npm Deps Cleanup

What does npm Deps Cleanup do?

Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. npm Deps Cleanup is an agent skill from Asymmetric-al/core. Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects.

When should I use npm Deps Cleanup?

npm Deps Cleanup fits situations like: asked to remove unused dependencies; deduplicate workspace dependency versions; analyze direct dependencies transitive lockfile closure; find low-risk upgrades that reduce dependency trees.

How do I install npm Deps Cleanup in Claude Code?

Run `npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a claude-code`. Or copy the skill folder (.agents/skills/npm-deps-cleanup in Asymmetric-al/core) into .claude/skills/npm-deps-cleanup in your project. Claude Code loads it when a task matches its description.

How do I install npm Deps Cleanup in Codex?

Run `npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a codex`. Or copy the skill folder (.agents/skills/npm-deps-cleanup in Asymmetric-al/core) into .agents/skills/npm-deps-cleanup in your project. Codex loads it when a task matches its description.

Can I use npm Deps Cleanup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Asymmetric-al/core --skill npm-deps-cleanup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm-deps-cleanup, .gemini/skills/npm-deps-cleanup, .github/skills/npm-deps-cleanup and .opencode/skills/npm-deps-cleanup in your project.

What does npm Deps Cleanup need to run?

Going by SKILL.md and its folder, npm Deps Cleanup needs the command-line tools its instructions call (pnpm, yarn, npm, bun, git and npx). Our summary lists: Node.js.

Does npm Deps Cleanup access the network?

SKILL.md names 1 domain. In commands or code: e18e.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is npm Deps Cleanup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does npm Deps Cleanup use?

npm Deps Cleanup is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does npm Deps Cleanup use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 197 tokens, read only when the agent opens those files.

What are the alternatives to npm Deps Cleanup?

Skills that share tags, products or a category with npm Deps Cleanup: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars), Audit And Reduce Dependencies (grafana/skills, 282 stars) and Pnpm Engine (teambit/bit, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains npm Deps Cleanup?

Asymmetric-al (a GitHub organization) maintains it in Asymmetric-al/core, which has 381 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on October 9, 2026.

Source: Asymmetric-al/core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.