Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins.

MITAuto-check passedDevelopment

Install Doorman

skills CLI
$ npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccplugins/awesome-claude-code-plugins doorman --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bullpen/skills/doorman .claude/skills/doorman && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
doorman
GitHub stars
967
Token cost
~1.5k tokens
SKILL.md length
810 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
MIT

At a glance

Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins.

  • Works in 4 steps: Does the stdlib do it? Dates, UUIDs,… → Does the runtime/platform ship it? Intl,… → Is it already installed? A dep you have… → …
  • The user says doorman
  • SKILL.md covers When you check the ID, The four questions at the door, The carve-out that matters and Rules, plus 4 more sections
  • Calls npm, pip and go

What it does

Doorman is an agent skill from ccplugins/awesome-claude-code-plugins. Dependency gatekeeper. Before you add any new package — npm install, pip install, go get, a new import of something not already in the lockfile — stop at the door and make it earn entry. Ask whether the stdlib, the runtime/platform, or a dep already installed does the job, and whether a few lines would too. A dependency is a permanent cost: maintenance, supply chain, bundle weight, breakage on someone else's schedule. Weigh size, last release, and transitive deps — not just "does it work." Supports intensity…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management and Supply chain security. It works with npm. The repository describes itself as: Awesome Claude Code plugins — a curated list of slash commands, subagents, MCP servers, and hooks for Claude Code. The licence is MIT.

When your agent uses it

  • The user says doorman
  • Do we need this dep
  • Vet this package
  • Can we avoid the dependency

Example prompts

  • “s schedule. Weigh size, last release, and transitive deps — not just”
  • “doorman”
  • “do we need this dep”
  • “/doorman”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Does the stdlib do it? Dates, UUIDs, hashing, path joins, JSON, HTTP —
  2. Does the runtime/platform ship it? Intl, crypto.subtle, fetch,
  3. Is it already installed? A dep you have beats a new one that overlaps.
  4. Is it a few lines? If you could write and own it in ten lines, own it.

What it can do on your machine

Read from SKILL.md and the folder at commit 5bd4f16. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pip
    • go
    • cargo
    • gem

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Doorman loads about 1.5k tokens when it runs. Until then it costs about 196 tokens; SKILL.md has 810 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~196
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccplugins/awesome-claude-code-plugins at commit 5bd4f16, republished under its MIT licence (© ccplugins). 810 words, ~1,497 tokens.

Download SKILL.mdSave it as .claude/skills/doorman/SKILL.md (or your agent's skills folder).
name
doorman
description
Dependency gatekeeper. Before you add any new package — `npm install`, `pip install`, `go get`, a new import of something not already in the lockfile — stop at the door and make it earn entry. Ask whether the stdlib, the runtime/platform, or a dep already installed does the job, and whether a few lines would too. A dependency is a permanent cost: maintenance, supply chain, bundle weight, breakage on someone else's schedule. Weigh size, last release, and transitive deps — not just "does it work." Supports intensity levels: lite, full (default), ultra. Use whenever the user says "doorman", "do we need this dep", "vet this package", "can we avoid the dependency", or reaches for a new install. Do NOT use for deps the task explicitly requires, or for non-coding requests.
argument-hint
[lite|full|ultra]
license
MIT

The Doorman

You are the bouncer at the door of the lockfile. Every package wants in, and most of them are trouble you'll be babysitting long after the person who added them has moved on. You've been paged at 2am by a transitive dependency three levels down that you never chose and can't name. So you check IDs at the door.

A dependency isn't code you get for free. It's code you adopt forever.

When you check the ID

Not every install is a fight. The door stays shut on new dependencies — anything not already in the lockfile. That's where the reflex fires:

  • npm install, pip install, go get, cargo add, gem install
  • a new import of a package the project doesn't already depend on
  • a micro-dep that wraps a one-liner (left-pad energy)
  • a heavyweight lib pulled in for one function you'd use

Already in the lockfile, or the task explicitly names the package? Wave it through — one line, move on. YAGNI applies to gatekeeping too; don't relitigate what's already load-bearing.

The four questions at the door

Before the package crosses the threshold, make it answer:

  1. Does the stdlib do it? Dates, UUIDs, hashing, path joins, JSON, HTTP — modern stdlibs cover more than the ecosystem admits.
  2. Does the runtime/platform ship it? Intl, crypto.subtle, fetch, structuredClone are already in the box you're running in.
  3. Is it already installed? A dep you have beats a new one that overlaps. Check the lockfile before you reach outward.
  4. Is it a few lines? If you could write and own it in ten lines, own it.

Only when all four say no does the package earn its keep — and then you still weigh what it drags in: install size, last release date (abandoned?), transitive dep count, license, maintainer count. "It works in the demo" is not entry.

The carve-out that matters

Do NOT push hand-rolling crypto, authentication, or parsing of hostile formats. Home-grown JWT validation, a bespoke password hash, a hand-written XML/PDF/ZIP/image parser fed untrusted bytes — these are exactly where a vetted, widely-audited dependency is the lazy AND correct call. The stdlib heuristic inverts here: reaching for libsodium, the platform's crypto, or the maintained parser is good laziness. Rolling your own is not thrift, it's a CVE with your name on it. Name this exception out loud when it applies.

Rules

  • Every dependency is a liability you maintain forever — treat the lockfile like a guest list, not a suggestion box.
  • Never add a package for what a few lines do. A micro-dep for a one-liner is a no.
  • Prefer what's already in the lockfile over anything new that overlaps it.
  • Weigh the whole cost: transitive deps, bundle size, last release, maintainer bus factor — not just the happy-path API.
  • The failure mode to avoid: waving in a "tiny helper" that drags a subtree of transitive deps behind it. Small surface, large shadow.
  • Crypto / auth / hostile-format parsing → the vetted dep wins. Don't play bouncer with security primitives.
Show full SKILL.md (316 more words)Show less

Output

The working code first — using the stdlib/native/existing path when one wins. Then a short Doorman: note: what was proposed, what replaced it, or why the dep earned entry. One or two lines. If the note outruns the fix, cut it.

Pattern: [code] → Doorman: [proposed X] → [replaced with native/stdlib Y] · or [X earns it: reason]

Intensity

LevelWhat change
liteAdd the dep the task reached for, but name the stdlib/native one-liner that avoids it — one line. User decides.
fullRun the four questions; use the no-dep path when it wins, add the package only when it earns entry, and say why. Default.
ultraRefuse the dep unless it clears the bar: prove stdlib/native can't do it, and audit what it drags in (size, last release, transitive count) before it enters.

Example — "install moment to format a date":

  • lite: "Installed. Note: Intl.DateTimeFormat ships in the runtime and covers this — moment is ~300KB you don't need."
  • full: "Skipped the install. new Intl.DateTimeFormat('en-US', {…}).format(d) does the formatting natively — no dependency added."
  • ultra: full, plus — checked the lockfile for existing date libs (none needed), confirmed Intl covers the locale/timezone cases in use, and left the one-line helper so nothing reaches for moment again.

When NOT to gatekeep

Skip it when the dep is already in the lockfile, when the task explicitly names the package, or when told to stop. And honor the carve-out: never talk someone out of a vetted crypto/auth/hostile-parser dependency in the name of thrift — that's the one door you hold open. The human's explicit call wins; push once, then comply.

Boundaries

The Doorman governs what enters your dependency tree, not how much you build — pair it with Ponytail, which keeps the code lazy, and the Doorman keeps lazy from meaning "just npm install it." "stop doorman" / "normal mode": revert. Level persists until changed or session end.

The cheapest dependency is the one you never let in.

© ccplugins, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/bullpen/skills/doorman of ccplugins/awesome-claude-code-plugins.

Open the folder on GitHubat commit 5bd4f16

Compare with similar skills

Doorman next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Doorman compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Doorman this skillccplugins/awesome-claude-code-plugins967—~1.5kAutomated safety check: PassMIT
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT
Dependency Upgrade Protocoldralgorhythm/claude-agentic-framework124—~1.5kAutomated safety check: PassNone
Detecting Malicious npm Packagesmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: WarnApache-2.0
npm Supply Chain Securitybodadotsh/npm-security-best-practices859—~1kAutomated safety check: WarnMIT
Dependency Update Auditbacknotprop/plannotator9.2k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Dependency Upgrade Protocol

    dralgorhythm/claude-agentic-framework

    Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

    124 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Detecting Malicious npm Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    DevelopmentAuto-check: warnings
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    859 GitHub stars~1k tokensUpdated 7 days ago
    SecurityAuto-check: warnings
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.2k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Detecting Typosquatting Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ccplugins/awesome-claude-code-plugins

All 68 skills in this repo
  • AI Meeting

    ccplugins/awesome-claude-code-plugins

    Run structured AI meetings for plans, product ideas, technical designs, business decisions, feature proposals, and strategy choices.

    967 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check: notes
  • Fastapi App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Flutter App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Flutter mobile app with clean architecture, Riverpod, FVM-pinned SDK, current packages, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Nextjs App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Next.js (App Router, TypeScript) web app with current packages and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Dev Report

    ccplugins/awesome-claude-code-plugins

    Write up a coding session for a non-technical stakeholder — the context, what was built, and the engineering reasoning behind it — the way a senior engineer briefs a product manager who does not…

    967 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Difesa Attacchi

    ccplugins/awesome-claude-code-plugins

    Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che…

    967 GitHub stars~781 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Doorman

What does Doorman do?

Dependency gatekeeper. An agent skill from ccplugins/awesome-claude-code-plugins. Doorman is an agent skill from ccplugins/awesome-claude-code-plugins. Dependency gatekeeper.

When should I use Doorman?

Doorman fits situations like: the user says doorman; do we need this dep; vet this package; can we avoid the dependency.

How do I install Doorman in Claude Code?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a claude-code`. Or copy the skill folder (plugins/bullpen/skills/doorman in ccplugins/awesome-claude-code-plugins) into .claude/skills/doorman in your project. Claude Code loads it when a task matches its description.

How do I install Doorman in Codex?

Run `npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a codex`. Or copy the skill folder (plugins/bullpen/skills/doorman in ccplugins/awesome-claude-code-plugins) into .agents/skills/doorman in your project. Codex loads it when a task matches its description.

Can I use Doorman in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccplugins/awesome-claude-code-plugins --skill doorman -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/doorman, .gemini/skills/doorman, .github/skills/doorman and .opencode/skills/doorman in your project.

What does Doorman need to run?

Going by SKILL.md and its folder, Doorman needs the command-line tools its instructions call (npm, pip, go, cargo and gem). Our summary lists: Python 3; Node.js.

Does Doorman access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Doorman safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Doorman use?

Doorman is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Doorman use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Doorman?

Skills that share tags, products or a category with Doorman: Stash Supply Chain Security (cipherstash/stack, 157 stars), Dependency Upgrade Protocol (dralgorhythm/claude-agentic-framework, 124 stars), Detecting Malicious npm Packages (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and npm Supply Chain Security (bodadotsh/npm-security-best-practices, 859 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Doorman?

ccplugins (a GitHub organization) maintains it in ccplugins/awesome-claude-code-plugins, which has 967 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on August 12, 2026.

Source: ccplugins/awesome-claude-code-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.