Dep Auditor
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add aubepkg/aube --skill aube -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aubepkg/aube aube --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aubepkg/aube.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aube .claude/skills/aube && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aube" agent skill from https://github.com/aubepkg/aube/tree/main/skills/aube into .claude/skills/aube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aube", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aubepkg/aube/tree/main/skills/aubeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aubepkg/aube --skill aube -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aubepkg/aube aube --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aubepkg/aube.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/aube .agents/skills/aube && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aube" agent skill from https://github.com/aubepkg/aube/tree/main/skills/aube into .agents/skills/aube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aube", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aubepkg/aube --skill aube -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aubepkg/aube aube --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aubepkg/aube.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/aube .cursor/skills/aube && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aube" agent skill from https://github.com/aubepkg/aube/tree/main/skills/aube into .cursor/skills/aube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aube", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aubepkg/aube.git --path skills/aube--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aubepkg/aube --skill aube -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aubepkg/aube aube --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aubepkg/aube.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/aube .gemini/skills/aube && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aube" agent skill from https://github.com/aubepkg/aube/tree/main/skills/aube into .gemini/skills/aube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aube", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aubepkg/aube aubeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aubepkg/aube --skill aube -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aubepkg/aube.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/aube .github/skills/aube && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aube" agent skill from https://github.com/aubepkg/aube/tree/main/skills/aube into .github/skills/aube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aube", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aubepkg/aube --skill aube -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aubepkg/aube aube --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aubepkg/aube.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/aube .opencode/skills/aube && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aube" agent skill from https://github.com/aubepkg/aube/tree/main/skills/aube into .opencode/skills/aube/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aube", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aubeManages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.
Before changing dependencies, the skill checks the aube version, the project's package.json, lockfile, workspace YAML and npmrc, and preserves the project's existing package manager choice unless migration is explicitly part of the task. aube reads and updates supported pnpm, npm, Yarn and Bun lockfiles in place, picking the first one it finds in a fixed priority order, and the skill warns against deleting or importing a working lockfile just to use aube, since importing creates its own lockfile format that then takes precedence.
It chooses a command by the effect needed: install for a stale lockfile, a frozen-lockfile flag to install without changing a committed one, a ci command for a clean install that removes node_modules, add or add with a dev flag for a new dependency, update for one dependency within its current range, and a why command to inspect why a dependency is installed. The run shorthand prefers a package script then a local binary and auto-installs missing dependencies unless told not to; the dlx shorthand uses a matching local binary first and falls back to a throwaway install.
Read from SKILL.md and the folder at commit ebf4494. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
aube.shFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Aube Package Manager Helper loads about 1.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 580 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
and `.npmrc` before changing dependencies. Preserve the project's package managerin environment variables referenced by `.npmrc`.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aubepkg/aube at commit ebf4494, republished under its MIT licence (© aubepkg). 580 words, ~1,120 tokens.
.claude/skills/aube/SKILL.md (or your agent's skills folder).Check aube --version, the project's package.json, lockfile, workspace YAML,
and .npmrc before changing dependencies. Preserve the project's package manager
choice and existing configuration unless migration is part of the task.
aube reads and updates supported pnpm, npm, Yarn, and Bun text lockfiles in place.
It selects the first existing file in this order: aube-lock.yaml,
pnpm-lock.yaml, bun.lock, yarn.lock, npm-shrinkwrap.json, package-lock.json.
Do not delete or import a working lockfile just to use aube: aube import creates
an aube-lock.yaml that takes precedence and is an intentional format migration.
Use aube-workspace.yaml when present; otherwise preserve an existing
pnpm-workspace.yaml. Creating an aube workspace file alongside the pnpm file
changes which configuration wins. Preserve workspace: and catalog: dependency
specifiers when updating packages that use them.
| Task | Command |
|---|---|
| Install and update a stale lockfile | aube install |
| Install without changing a committed lockfile | aube install --frozen-lockfile |
Clean CI install, removing existing node_modules | aube ci |
| Update only the lockfile | aube install --lockfile-only |
| Add a runtime or development dependency | aube add <package> / aube add -D <package> |
| Update one dependency within its current range | aube update <package> |
| Inspect why a dependency is installed | aube why <package> |
| Run a project script | aubr build / aube run build |
| Run an installed binary | aube exec tsc -- --noEmit |
aube update --latest <package> can move beyond the current range and rewrites the
manifest; use it when that upgrade is intended. Review the manifest and lockfile
diffs together and run the affected project's checks.
aubr is aube run; it prefers a package script, then a local binary. Script and
exec commands automatically install missing or stale dependencies. After an
explicit install, aube run --no-install test skips that install check. Put aube
options before the script name; later arguments are forwarded to the script.
aubx is aube dlx; it uses a matching local binary first, then a throwaway
installation. aubx --package <package> <binary> forces a separate installation.
Prefer a project's existing script or binary when the task needs its pinned
toolchain.
In a workspace, install from the root and scope work with a quoted filter:
aube -F '@acme/api' run test
aube -F '@acme/api' add zod
aube -r run build-r runs across workspace packages; recursive builds use dependency order by
default. Keep a targeted change scoped to the intended package.
Read the first ERR_AUBE_* or WARN_AUBE_* diagnostic and use aube doctor for
environment details. For settings, aube config find <words> locates relevant
keys and aube config explain <key> describes their sources. Use project-scoped
configuration for a project fix; aube config set otherwise defaults to user
scope. Keep registry tokens in environment variables referenced by .npmrc.
If a frozen install rejects manifest drift, update the lockfile with
aube install only when the manifest change is intended. Do not remove frozen
mode from CI to hide the mismatch.
Root lifecycle scripts run unless scripts are ignored. Dependency scripts need
project approval or built-in trust; explicit denies win. For a missing native
build, inspect aube ignored-builds and the package's scripts, approve only the
reviewed package with aube approve-builds <package>, then aube rebuild. Include
the resulting allowBuilds policy in the project change. Do not approve every
build or disable security checks just to clear an install failure.
The default isolated layout does not expose every transitive dependency at the
project root. Check aube why <package> and the importing package's manifest
before changing the linker or deleting stores.
For less common flags and compatibility details, prefer the installed command's
--help, then the workflow guides and
troubleshooting.
© aubepkg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/aube of aubepkg/aube.
Open the folder on GitHubat commit ebf4494
Aube Package Manager Helper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Aube Package Manager Helper this skillaubepkg/aube | 2k | — | ~1.1k | Automated safety check: Warn | MIT | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 879 | — | ~895 | Automated safety check: Pass | MIT | |
| Bun Runtime and Toolkitmweinbach/agent-coworker | 156 | — | ~2.2k | Automated safety check: Notes | Custom licence | |
| Handsontable Node Script Conventionshandsontable/handsontable | 22k | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Migrate to Denodenoland/skills | 100 | — | ~2.2k | Automated safety check: Warn | MIT | |
| Upgrade Runtime StackPackmindHub/packmind | 317 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
mweinbach/agent-coworker
Quick reference for using Bun to run TypeScript and JavaScript, install packages, bundle code, run tests and serve HTTP, with the key files and commands.
handsontable/handsontable
Conventions for .mjs files in the Handsontable monorepo: native node: imports, top-level await, the tasks.json dispatcher and native modules instead of extra dependencies.
denoland/skills
Moves a Node.js, npm, Yarn, pnpm or Bun project to Deno in reversible steps, starting with Deno as the package manager and changing no code unless needed.
PackmindHub/packmind
Check whether newer stable versions of Node.js (24.x line), Nx, or Vite are available and, if so, generate a detailed upgrade plan markdown file at the repo root.
jeremylongshore/tons-of-skills-marketplace
Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema.
Categories
Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format. json, lockfile, workspace YAML and npmrc, and preserves the project's existing package manager choice unless migration is explicitly part of the task. aube reads and updates supported pnpm, npm, Yarn and Bun lockfiles in place, picking the first one it finds in a fixed priority order, and the skill warns against deleting or importing a working lockfile just to use aube, since importing creates its own lockfile format that then takes precedence.
Aube Package Manager Helper fits situations like: installing or updating dependencies in a project that uses aube; running a project script or binary through aube's run or dlx commands; adopting aube in a project that currently uses pnpm, npm, Yarn or Bun.
Run `npx skills add aubepkg/aube --skill aube -a claude-code`. Or copy the skill folder (skills/aube in aubepkg/aube) into .claude/skills/aube in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aubepkg/aube --skill aube -a codex`. Or copy the skill folder (skills/aube in aubepkg/aube) into .agents/skills/aube in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aubepkg/aube --skill aube -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aube, .gemini/skills/aube, .github/skills/aube and .opencode/skills/aube in your project.
SKILL.md names no scripts, command-line tools or credentials: Aube Package Manager Helper is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: aube.sh. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Aube Package Manager Helper is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Aube Package Manager Helper: Dep Auditor (laolaoshiren/claude-code-skills-zh, 879 stars), Bun Runtime and Toolkit (mweinbach/agent-coworker, 156 stars), Handsontable Node Script Conventions (handsontable/handsontable, 22k stars) and Migrate to Deno (denoland/skills, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aubepkg (a GitHub organization) maintains it in aubepkg/aube, which has 2,028 GitHub stars. The repository was last updated on October 8, 2026.
Source: aubepkg/aube on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.