Agent skill

Aube Package Manager Helper

by aubepkg in aubepkg/aube

Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.

MITAuto-check: warningsDevelopment

Install Aube Package Manager Helper

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add aubepkg/aube --skill aube -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aubepkg/aube aube --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aubepkg/aube.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aube .claude/skills/aube && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aube
GitHub stars
2k
Token cost
~1.1k tokens
SKILL.md length
580 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.

  • Installing or updating dependencies in a project that uses aube
  • SKILL.md covers Keep the existing lockfile and…, Choose the command by its… and Diagnose installs and…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Running a project script or binary through aube's run or dlx commands

What it does

Before changing dependencies, the skill checks the aube version, the project's package.json, lockfile, workspace YAML and npmrc, and preserves the project's existing package manager choice unless migration is explicitly part of the task. aube reads and updates supported pnpm, npm, Yarn and Bun lockfiles in place, picking the first one it finds in a fixed priority order, and the skill warns against deleting or importing a working lockfile just to use aube, since importing creates its own lockfile format that then takes precedence.

It chooses a command by the effect needed: install for a stale lockfile, a frozen-lockfile flag to install without changing a committed one, a ci command for a clean install that removes node_modules, add or add with a dev flag for a new dependency, update for one dependency within its current range, and a why command to inspect why a dependency is installed. The run shorthand prefers a package script then a local binary and auto-installs missing dependencies unless told not to; the dlx shorthand uses a matching local binary first and falls back to a throwaway install.

When your agent uses it

  • Installing or updating dependencies in a project that uses aube
  • Running a project script or binary through aube's run or dlx commands
  • Adopting aube in a project that currently uses pnpm, npm, Yarn or Bun

Example prompts

  • “Install dependencies with aube without touching the committed lockfile.”
  • “Add this package as a dev dependency and update the lockfile.”
  • “Run the build script through aube and show me any errors.”

What it can do on your machine

Read from SKILL.md and the folder at commit ebf4494. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • aube.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aube Package Manager Helper loads about 1.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 580 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:9
    and `.npmrc` before changing dependencies. Preserve the project's package manager
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:70
    in environment variables referenced by `.npmrc`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aubepkg/aube at commit ebf4494, republished under its MIT licence (© aubepkg). 580 words, ~1,120 tokens.

Download SKILL.mdSave it as .claude/skills/aube/SKILL.md (or your agent's skills folder).
name
aube
description
Manage dependencies, run scripts, and diagnose installs in Node.js projects using aube, aubr, or aubx. Use when the project already uses aube or the user asks to adopt it.

Use aube in a project

Check aube --version, the project's package.json, lockfile, workspace YAML, and .npmrc before changing dependencies. Preserve the project's package manager choice and existing configuration unless migration is part of the task.

Keep the existing lockfile and workspace

aube reads and updates supported pnpm, npm, Yarn, and Bun text lockfiles in place. It selects the first existing file in this order: aube-lock.yaml, pnpm-lock.yaml, bun.lock, yarn.lock, npm-shrinkwrap.json, package-lock.json. Do not delete or import a working lockfile just to use aube: aube import creates an aube-lock.yaml that takes precedence and is an intentional format migration.

Use aube-workspace.yaml when present; otherwise preserve an existing pnpm-workspace.yaml. Creating an aube workspace file alongside the pnpm file changes which configuration wins. Preserve workspace: and catalog: dependency specifiers when updating packages that use them.

Choose the command by its effects

TaskCommand
Install and update a stale lockfileaube install
Install without changing a committed lockfileaube install --frozen-lockfile
Clean CI install, removing existing node_modulesaube ci
Update only the lockfileaube install --lockfile-only
Add a runtime or development dependencyaube add <package> / aube add -D <package>
Update one dependency within its current rangeaube update <package>
Inspect why a dependency is installedaube why <package>
Run a project scriptaubr build / aube run build
Run an installed binaryaube exec tsc -- --noEmit

aube update --latest <package> can move beyond the current range and rewrites the manifest; use it when that upgrade is intended. Review the manifest and lockfile diffs together and run the affected project's checks.

aubr is aube run; it prefers a package script, then a local binary. Script and exec commands automatically install missing or stale dependencies. After an explicit install, aube run --no-install test skips that install check. Put aube options before the script name; later arguments are forwarded to the script.

aubx is aube dlx; it uses a matching local binary first, then a throwaway installation. aubx --package <package> <binary> forces a separate installation. Prefer a project's existing script or binary when the task needs its pinned toolchain.

In a workspace, install from the root and scope work with a quoted filter:

sh
aube -F '@acme/api' run test
aube -F '@acme/api' add zod
aube -r run build

-r runs across workspace packages; recursive builds use dependency order by default. Keep a targeted change scoped to the intended package.

Show full SKILL.md (206 more words)Show less

Diagnose installs and dependency builds

Read the first ERR_AUBE_* or WARN_AUBE_* diagnostic and use aube doctor for environment details. For settings, aube config find <words> locates relevant keys and aube config explain <key> describes their sources. Use project-scoped configuration for a project fix; aube config set otherwise defaults to user scope. Keep registry tokens in environment variables referenced by .npmrc.

If a frozen install rejects manifest drift, update the lockfile with aube install only when the manifest change is intended. Do not remove frozen mode from CI to hide the mismatch.

Root lifecycle scripts run unless scripts are ignored. Dependency scripts need project approval or built-in trust; explicit denies win. For a missing native build, inspect aube ignored-builds and the package's scripts, approve only the reviewed package with aube approve-builds <package>, then aube rebuild. Include the resulting allowBuilds policy in the project change. Do not approve every build or disable security checks just to clear an install failure.

The default isolated layout does not expose every transitive dependency at the project root. Check aube why <package> and the importing package's manifest before changing the linker or deleting stores.

For less common flags and compatibility details, prefer the installed command's --help, then the workflow guides and troubleshooting.

© aubepkg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/aube of aubepkg/aube.

Open the folder on GitHubat commit ebf4494

Compare with similar skills

Aube Package Manager Helper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aube Package Manager Helper compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aube Package Manager Helper this skillaubepkg/aube2k—~1.1kAutomated safety check: WarnMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh879—~895Automated safety check: PassMIT
Bun Runtime and Toolkitmweinbach/agent-coworker156—~2.2kAutomated safety check: NotesCustom licence
Handsontable Node Script Conventionshandsontable/handsontable22k—~1.1kAutomated safety check: PassCustom licence
Migrate to Denodenoland/skills100—~2.2kAutomated safety check: WarnMIT
Upgrade Runtime StackPackmindHub/packmind317—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    879 GitHub stars~895 tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Bun Runtime and Toolkit

    mweinbach/agent-coworker

    Quick reference for using Bun to run TypeScript and JavaScript, install packages, bundle code, run tests and serve HTTP, with the key files and commands.

    156 GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Handsontable Node Script Conventions

    handsontable/handsontable

    Conventions for .mjs files in the Handsontable monorepo: native node: imports, top-level await, the tasks.json dispatcher and native modules instead of extra dependencies.

    22k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Migrate to Deno

    denoland/skills

    Official

    Moves a Node.js, npm, Yarn, pnpm or Bun project to Deno in reversible steps, starting with Deno as the package manager and changing no code unless needed.

    100 GitHub stars~2.2k tokensUpdated 2 mo ago
    DevelopmentAuto-check: warnings
  • Upgrade Runtime Stack

    PackmindHub/packmind

    Check whether newer stable versions of Node.js (24.x line), Nx, or Vite are available and, if so, generate a detailed upgrade plan markdown file at the repo root.

    317 GitHub stars~2.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Auditing npm Dependencies

    jeremylongshore/tons-of-skills-marketplace

    Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema.

    2.8k GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check: notes

Works with

Categories

Questions about Aube Package Manager Helper

What does Aube Package Manager Helper do?

Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format. json, lockfile, workspace YAML and npmrc, and preserves the project's existing package manager choice unless migration is explicitly part of the task. aube reads and updates supported pnpm, npm, Yarn and Bun lockfiles in place, picking the first one it finds in a fixed priority order, and the skill warns against deleting or importing a working lockfile just to use aube, since importing creates its own lockfile format that then takes precedence.

When should I use Aube Package Manager Helper?

Aube Package Manager Helper fits situations like: installing or updating dependencies in a project that uses aube; running a project script or binary through aube's run or dlx commands; adopting aube in a project that currently uses pnpm, npm, Yarn or Bun.

How do I install Aube Package Manager Helper in Claude Code?

Run `npx skills add aubepkg/aube --skill aube -a claude-code`. Or copy the skill folder (skills/aube in aubepkg/aube) into .claude/skills/aube in your project. Claude Code loads it when a task matches its description.

How do I install Aube Package Manager Helper in Codex?

Run `npx skills add aubepkg/aube --skill aube -a codex`. Or copy the skill folder (skills/aube in aubepkg/aube) into .agents/skills/aube in your project. Codex loads it when a task matches its description.

Can I use Aube Package Manager Helper in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aubepkg/aube --skill aube -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aube, .gemini/skills/aube, .github/skills/aube and .opencode/skills/aube in your project.

What does Aube Package Manager Helper need to run?

SKILL.md names no scripts, command-line tools or credentials: Aube Package Manager Helper is instructions for the agent only.

Does Aube Package Manager Helper access the network?

SKILL.md names 1 domain. As links in the text: aube.sh. This is read from the text; nothing was executed.

Is Aube Package Manager Helper safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Aube Package Manager Helper use?

Aube Package Manager Helper is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aube Package Manager Helper use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aube Package Manager Helper?

Skills that share tags, products or a category with Aube Package Manager Helper: Dep Auditor (laolaoshiren/claude-code-skills-zh, 879 stars), Bun Runtime and Toolkit (mweinbach/agent-coworker, 156 stars), Handsontable Node Script Conventions (handsontable/handsontable, 22k stars) and Migrate to Deno (denoland/skills, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aube Package Manager Helper?

aubepkg (a GitHub organization) maintains it in aubepkg/aube, which has 2,028 GitHub stars. The repository was last updated on October 8, 2026.

Source: aubepkg/aube on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.