Agent skill

Dependency Updates

by championswimmer in championswimmer/TwoFac

Audit repo dependencies by default and only apply library upgrades when explicitly requested.

No licenceAuto-check passedDevelopment

Install Dependency Updates

skills CLI
$ npx skills add championswimmer/TwoFac --skill dependency-updates -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install championswimmer/TwoFac dependency-updates --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/championswimmer/TwoFac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-updates .claude/skills/dependency-updates && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-updates
GitHub stars
130
Token cost
~1k tokens
SKILL.md length
381 words
Files
7 (incl. scripts)
Skills in repo
8
Repo updated
First seen
Licence
None found

At a glance

Audit repo dependencies by default and only apply library upgrades when explicitly requested.

  • Works in 5 steps: Run the default report first unless the… → Read the generated markdown report in… → Summarize the main stable candidates and… → …
  • Tasks that involve Dependency management
  • SKILL.md covers Repo dependency surfaces…, Default behavior, Scripts in this skill and How to use it, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls node and npm

What it does

Dependency Updates is an agent skill from championswimmer/TwoFac. Audit repo dependencies by default and only apply library upgrades when explicitly requested.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `UPGRADING.md`).

It sits in Development, covering Dependency management. It works with npm, Gradle and Kotlin. The repository describes itself as: 2FA Authenticator app that works on mobile, web, desktop, watches and CLI!

When your agent uses it

  • Tasks that involve Dependency management

Example prompts

  • “/dependency-updates”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run the default report first unless the user directly asked for upgrades.
  2. Read the generated markdown report in .agents/plans/dependency-update-reports/.
  3. Summarize the main stable candidates and call out any major-version or pre-release jumps.
  4. Only if explicitly asked, run the relevant upgrade command, keeping to latest stable versions unless the user approved pre-releases.
  5. After upgrades, run the validation checklist from UPGRADING.md.

What it can do on your machine

Read from SKILL.md and the folder at commit 1360a71. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Updates loads about 1k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 381 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 381 words (~1,018 tokens).

“Use this skill when the user asks to:”

— opening of SKILL.md by championswimmer
name
dependency-updates

Read the full SKILL.md on GitHub

Files

SKILL.md and 6 other files (scripts) in .agents/skills/dependency-updates of championswimmer/TwoFac.

  • SKILL.md
  • UPGRADING.md
  • scripts/cocoapods-updates.mjs
  • scripts/dependency-updates.mjs
  • scripts/dependencyUpdateTools.mjs
  • scripts/gradle-updates.mjs
  • scripts/npm-updates.mjs

Open the folder on GitHubat commit 1360a71

Compare with similar skills

Dependency Updates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Updates compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Updates this skillchampionswimmer/TwoFac130—~1kAutomated safety check: PassNone
Dependency Managementaiskillstore/marketplace4301 repos~1.1kAutomated safety check: PassNone
Kotlin Multiplatform Library FinderJetBrains/klibs-io108—~1.1kAutomated safety check: PassApache-2.0
Upgrade Notesgetknit/knit132—~1.2kAutomated safety check: PassGPL-3.0
Exposed Bug Fix WorkflowJetBrains/Exposed9.3k—~3.8kAutomated safety check: PassApache-2.0
Validator Dependency Upgradeexpress-validator/express-validator6.2k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Dependency Management

    aiskillstore/marketplace

    Dependency management specialist. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Looks up Kotlin Multiplatform libraries, their latest stable versions, Gradle coordinates and verified target support through klibs.io instead of guessing.

    108 GitHub stars~1.1k tokensUpdated yesterday
    MobileAuto-check passed
  • Upgrade Notes

    getknit/knit

    Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

    132 GitHub stars~1.2k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Exposed Bug Fix Workflow

    JetBrains/Exposed

    Official

    Takes a GitHub or YouTrack issue for the Exposed project through reproduction, a failing test, a fix, validation and a pull request.

    9.3k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Validator Dependency Upgrade

    express-validator/express-validator

    Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.

    6.2k GitHub stars~1.2k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Claude Code Version Check

    ykdojo/claude-code-tips

    Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.

    10k GitHub stars~1.8k tokensUpdated 14 days ago
    DevelopmentAuto-check passed

More from championswimmer/TwoFac

All 8 skills in this repo
  • Simulators Emulators

    championswimmer/TwoFac

    How to list, pick, and boot Android emulators and iOS simulators for local app runs.

    130 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Gradle Build

    championswimmer/TwoFac

    Use Gradle commands to build and run the app by platform. An agent skill from championswimmer/TwoFac.

    130 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Kmp Modules

    championswimmer/TwoFac

    Guidance on where to place different types of code in this Kotlin Multiplatform project.

    130 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • UI Components

    championswimmer/TwoFac

    Structure and routing guide for composeApp screens, components, and their relationships.

    130 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • UI Testing

    championswimmer/TwoFac

    How to run, write, and debug local UI tests for Android, iOS, and browser builds.

    130 GitHub stars~215 tokensUpdated 4 mo ago
    Auto-check passed
  • Plan Roadmap

    championswimmer/TwoFac

    How to create plans and follow roadmaps

    130 GitHub stars~278 tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Dependency Updates

What does Dependency Updates do?

Audit repo dependencies by default and only apply library upgrades when explicitly requested. Dependency Updates is an agent skill from championswimmer/TwoFac. Audit repo dependencies by default and only apply library upgrades when explicitly requested.

When should I use Dependency Updates?

Dependency Updates fits situations like: tasks that involve Dependency management.

How do I install Dependency Updates in Claude Code?

Run `npx skills add championswimmer/TwoFac --skill dependency-updates -a claude-code`. Or copy the skill folder (.agents/skills/dependency-updates in championswimmer/TwoFac) into .claude/skills/dependency-updates in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Updates in Codex?

Run `npx skills add championswimmer/TwoFac --skill dependency-updates -a codex`. Or copy the skill folder (.agents/skills/dependency-updates in championswimmer/TwoFac) into .agents/skills/dependency-updates in your project. Codex loads it when a task matches its description.

Can I use Dependency Updates in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add championswimmer/TwoFac --skill dependency-updates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-updates, .gemini/skills/dependency-updates, .github/skills/dependency-updates and .opencode/skills/dependency-updates in your project.

What does Dependency Updates need to run?

Going by SKILL.md and its folder, Dependency Updates needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and npm). Our summary lists: Node.js.

Does Dependency Updates access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Updates safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dependency Updates use?

No licence was found for Dependency Updates or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Dependency Updates use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Updates?

Skills that share tags, products or a category with Dependency Updates: Dependency Management (aiskillstore/marketplace, 430 stars), Kotlin Multiplatform Library Finder (JetBrains/klibs-io, 108 stars), Upgrade Notes (getknit/knit, 132 stars) and Exposed Bug Fix Workflow (JetBrains/Exposed, 9.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Updates?

championswimmer (a GitHub user) maintains it in championswimmer/TwoFac, which has 130 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: championswimmer/TwoFac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.