Agent skill

Dep Refs

by BytePioneer-AI in BytePioneer-AI/codex-host

Trace TypeScript exports, imports, and re-exports in codexhost before refactoring interfaces or deleting code.

LGPL-3.0Auto-check passedDevelopment

Install Dep Refs

skills CLI
$ npx skills add BytePioneer-AI/codex-host --skill dep-refs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BytePioneer-AI/codex-host dep-refs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BytePioneer-AI/codex-host.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dep-refs .claude/skills/dep-refs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dep-refs
GitHub stars
2.8k
Token cost
~488 tokens
SKILL.md length
192 words
Files
2
Skills in repo
9
Repo updated
First seen
Licence
LGPL-3.0

At a glance

Trace TypeScript exports, imports, and re-exports in codexhost before refactoring interfaces or deleting code.

  • Works in 5 steps: Read the target declaration and owning… → Prefer a TypeScript language-service… → Use rg to find candidate references,… → …
  • Tasks that involve Refactoring
  • Calls rg and pnpm

What it does

Dep Refs is an agent skill from BytePioneer-AI/codex-host. Trace TypeScript exports, imports, and re-exports in codexhost before refactoring interfaces or deleting code. Use available symbol tooling and repository searches to identify actual callers.

Its SKILL.md is about 490 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Refactoring. It works with TypeScript. The repository describes itself as: Run Pi and Claude Code directly in Codex Desktop. 在 Codex Desktop 中直接运行 Pi 和 Claude Code。 The licence is LGPL-3.0.

When your agent uses it

  • Tasks that involve Refactoring

Example prompts

  • “/dep-refs”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read the target declaration and owning package's package.json exports. Follow its public entrypoint and any re-export chain.
  2. Prefer a TypeScript language-service references query when the session provides one. Ensure it covers workspace callers, including…
  3. Use rg to find candidate references, then inspect aliases, namespace imports, re-exports and relevant consumers. For example
  4. For a deletion, search the whole repository, including hidden configuration when relevant. Check public exports, dynamic loading, plugin…
  5. Report concrete callers with paths and lines, re-exported public surfaces, and the limits of the search. Zero text matches or zero static…

What it can do on your machine

Read from SKILL.md and the folder at commit 08c7d65. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dep Refs loads about 488 tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 192 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~488

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BytePioneer-AI/codex-host at commit 08c7d65, republished under its LGPL-3.0 licence (© BytePioneer-AI). 192 words, ~488 tokens.

Download SKILL.mdSave it as .claude/skills/dep-refs/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
dep-refs
description
Trace TypeScript exports, imports, and re-exports in codexhost before refactoring interfaces or deleting code. Use available symbol tooling and repository searches to identify actual callers.
<!-- Adapted for codexhost from ZCode 872ad960de7ec172591f7e1952f7849229f94521. See ../NOTICE.md for provenance and licenses. -->

Export and reference tracing

Work from the repository root. The ZCode-specific pnpm dep:refs and pnpm knip commands are not installed here; use current tools and package exports rather than adding dependencies for a lookup.

  1. Read the target declaration and owning package's package.json exports. Follow its public entrypoint and any re-export chain.
  2. Prefer a TypeScript language-service references query when the session provides one. Ensure it covers workspace callers, including packages/adapters/*, scripts and tests.
  3. Use rg to find candidate references, then inspect aliases, namespace imports, re-exports and relevant consumers. For example:
sh
rg -n --glob '*.{ts,tsx,mts,cts,mjs,js,json}' '\bHarnessAdapter\b' packages tests tools scripts
rg -n --glob '*.{ts,tsx,mts,cts,mjs,js,json}' '@codexhost/harness-adapter' packages tests tools scripts
  1. For a deletion, search the whole repository, including hidden configuration when relevant. Check public exports, dynamic loading, plugin manifests, string-based dispatch and generated consumers. Read the current boundary checker before changing dependency directions.
  2. Report concrete callers with paths and lines, re-exported public surfaces, and the limits of the search. Zero text matches or zero static references is not proof that an externally consumed export can be removed.

After changing an interface, validate its actual consumers with the applicable typecheck/build and focused tests from package scripts. This skill is read-only unless the user has also requested an implementation change.

© BytePioneer-AI, LGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/dep-refs of BytePioneer-AI/codex-host.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 08c7d65

Compare with similar skills

Dep Refs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dep Refs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dep Refs this skillBytePioneer-AI/codex-host2.8k—~488Automated safety check: PassLGPL-3.0
Svelte5 Best PracticesSikandarJODD/cnblocks4311 repos~810Automated safety check: PassMIT
Dinero Best Practicesdinerojs/dinero.js6.8k—~756Automated safety check: PassMIT
Code Guidelinesgetsentry/sentry-react-native1.8k—~3.2kAutomated safety check: PassMIT
AST Visitor Pattern for Unionsprisma/orm48k—~830Automated safety check: PassApache-2.0
ast-grep Codemod Referencewarp-drive-data/warp-drive3.2k—~2.6kAutomated safety check: PassMIT

Similar skills

  • Svelte5 Best Practices

    SikandarJODD/cnblocks

    Svelte 5 runes, snippets, SvelteKit patterns, and modern best practices for TypeScript and component development.

    431 GitHub starsUsed in 1 repo~810 tokens
    DevelopmentAuto-check passed
  • Dinero Best Practices

    dinerojs/dinero.js

    Core best practices for the Dinero.js money library. An agent skill from dinerojs/dinero.js.

    6.8k GitHub stars~756 tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Code Guidelines

    getsentry/sentry-react-native

    Official

    Enforce Sentry React Native SDK code guidelines for implementation, refactoring, and review.

    1.8k GitHub stars~3.2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Official

    Replaces a plain TypeScript union plus switch statements with frozen subclasses and a visitor interface when several places dispatch on the same variants.

    48k GitHub stars~830 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • ast-grep Codemod Reference

    warp-drive-data/warp-drive

    Reference for writing and debugging TypeScript and JavaScript codemods with @ast-grep/napi: parsing, node queries, meta-variables, rule objects and editing.

    3.2k GitHub stars~2.6k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Deep Refactor Audit

    AlmanacCode/codealmanac

    A skill your agent uses when a user asks for a major architecture/refactor audit, codebase smell investigation, boundary critique, feature simplification review, vibe-coded or AI-generated code…

    997 GitHub stars~3.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from BytePioneer-AI/codex-host

All 9 skills in this repo
  • Codexhost PR Triage

    BytePioneer-AI/codex-host

    手动增量分诊 codexhost Issue 与 PR,评估 PR 价值和实现克制,生成只读本地看板与回复草稿. An agent skill from BytePioneer-AI/codex-host.

    2.8k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Codexhost Add Harness

    BytePioneer-AI/codex-host

    为 codexhost 新增 Harness 插件,或规划、审查、补全现有 Harness Adapter。按当前公共契约实现原生能力,区分插件后端、预装发行和 Desktop 产品接入;不用于单纯添加 Model、Provider 或账号。

    2.8k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Codexhost Release

    BytePioneer-AI/codex-host

    发布 codexhost 正式版、预览版,编写或确认 Release Notes,检查发布 CI,暂停、恢复或排查发布。支持正常正式发布,以及 npm latest + GitHub Prerelease、不给现有用户更新提示的预览发行。不用于普通代码提交或 Harness CLI 更新。

    2.8k GitHub stars~998 tokensUpdated 2 days ago
    Auto-check passed
  • Web Gui Tester

    BytePioneer-AI/codex-host

    Verify web frontend behavior through real GUI interactions, read-only page inspection, and screenshots.

    2.8k GitHub starsUsed in 1 repo~4.1k tokens
    Auto-check passed
  • Feature Boundary Planner

    BytePioneer-AI/codex-host

    Trace a codexhost feature change across UI surfaces, Host routing, Harness capabilities, state ownership, persistence, and validation.

    2.8k GitHub stars~755 tokensUpdated 2 days ago
    Auto-check passed
  • Codexhost Update Impact Audit

    BytePioneer-AI/codex-host

    Diagnose whether a Codex Desktop update changed codexhost Composer/CDP bindings, private Renderer DOM or React state, Host bridges, routing, the Codex usage submission gate, or injected UI.

    2.8k GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Dep Refs

What does Dep Refs do?

Trace TypeScript exports, imports, and re-exports in codexhost before refactoring interfaces or deleting code. Dep Refs is an agent skill from BytePioneer-AI/codex-host. Trace TypeScript exports, imports, and re-exports in codexhost before refactoring interfaces or deleting code.

When should I use Dep Refs?

Dep Refs fits situations like: tasks that involve Refactoring.

How do I install Dep Refs in Claude Code?

Run `npx skills add BytePioneer-AI/codex-host --skill dep-refs -a claude-code`. Or copy the skill folder (.agents/skills/dep-refs in BytePioneer-AI/codex-host) into .claude/skills/dep-refs in your project. Claude Code loads it when a task matches its description.

How do I install Dep Refs in Codex?

Run `npx skills add BytePioneer-AI/codex-host --skill dep-refs -a codex`. Or copy the skill folder (.agents/skills/dep-refs in BytePioneer-AI/codex-host) into .agents/skills/dep-refs in your project. Codex loads it when a task matches its description.

Can I use Dep Refs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BytePioneer-AI/codex-host --skill dep-refs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-refs, .gemini/skills/dep-refs, .github/skills/dep-refs and .opencode/skills/dep-refs in your project.

What does Dep Refs need to run?

Going by SKILL.md and its folder, Dep Refs needs the command-line tools its instructions call (rg and pnpm).

Does Dep Refs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dep Refs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dep Refs use?

Dep Refs is published under the LGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dep Refs use?

About 488 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dep Refs?

Skills that share tags, products or a category with Dep Refs: Svelte5 Best Practices (SikandarJODD/cnblocks, 431 stars), Dinero Best Practices (dinerojs/dinero.js, 6.8k stars), Code Guidelines (getsentry/sentry-react-native, 1.8k stars) and AST Visitor Pattern for Unions (prisma/orm, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dep Refs?

BytePioneer-AI (a GitHub user) maintains it in BytePioneer-AI/codex-host, which has 2,791 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 9, 2026.

Source: BytePioneer-AI/codex-host on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.