Dependency Management
aiskillstore/marketplace
Dependency management specialist. An agent skill from aiskillstore/marketplace.
Audit repo dependencies by default and only apply library upgrades when explicitly requested.
$ npx skills add championswimmer/TwoFac --skill dependency-updates -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install championswimmer/TwoFac dependency-updates --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/championswimmer/TwoFac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-updates .claude/skills/dependency-updates && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-updates" agent skill from https://github.com/championswimmer/TwoFac/tree/main/.agents/skills/dependency-updates into .claude/skills/dependency-updates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updates", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/championswimmer/TwoFac/tree/main/.agents/skills/dependency-updatesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add championswimmer/TwoFac --skill dependency-updates -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install championswimmer/TwoFac dependency-updates --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/championswimmer/TwoFac.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dependency-updates .agents/skills/dependency-updates && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-updates" agent skill from https://github.com/championswimmer/TwoFac/tree/main/.agents/skills/dependency-updates into .agents/skills/dependency-updates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updates", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add championswimmer/TwoFac --skill dependency-updates -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install championswimmer/TwoFac dependency-updates --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/championswimmer/TwoFac.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dependency-updates .cursor/skills/dependency-updates && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-updates" agent skill from https://github.com/championswimmer/TwoFac/tree/main/.agents/skills/dependency-updates into .cursor/skills/dependency-updates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updates", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/championswimmer/TwoFac.git --path .agents/skills/dependency-updates--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add championswimmer/TwoFac --skill dependency-updates -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install championswimmer/TwoFac dependency-updates --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/championswimmer/TwoFac.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dependency-updates .gemini/skills/dependency-updates && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-updates" agent skill from https://github.com/championswimmer/TwoFac/tree/main/.agents/skills/dependency-updates into .gemini/skills/dependency-updates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updates", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install championswimmer/TwoFac dependency-updatesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add championswimmer/TwoFac --skill dependency-updates -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/championswimmer/TwoFac.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dependency-updates .github/skills/dependency-updates && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-updates" agent skill from https://github.com/championswimmer/TwoFac/tree/main/.agents/skills/dependency-updates into .github/skills/dependency-updates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updates", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add championswimmer/TwoFac --skill dependency-updates -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install championswimmer/TwoFac dependency-updates --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/championswimmer/TwoFac.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dependency-updates .opencode/skills/dependency-updates && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-updates" agent skill from https://github.com/championswimmer/TwoFac/tree/main/.agents/skills/dependency-updates into .opencode/skills/dependency-updates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-updates", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-updatesAudit repo dependencies by default and only apply library upgrades when explicitly requested.
Dependency Updates is an agent skill from championswimmer/TwoFac. Audit repo dependencies by default and only apply library upgrades when explicitly requested.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `UPGRADING.md`).
It sits in Development, covering Dependency management. It works with npm, Gradle and Kotlin. The repository describes itself as: 2FA Authenticator app that works on mobile, web, desktop, watches and CLI!
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1360a71. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 5 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Updates loads about 1k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 381 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 381 words (~1,018 tokens).
“Use this skill when the user asks to:”
SKILL.md and 6 other files (scripts) in .agents/skills/dependency-updates of championswimmer/TwoFac.
Open the folder on GitHubat commit 1360a71
Dependency Updates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Updates this skillchampionswimmer/TwoFac | 130 | — | ~1k | Automated safety check: Pass | None | |
| Dependency Managementaiskillstore/marketplace | 430 | 1 repos | ~1.1k | Automated safety check: Pass | None | |
| Kotlin Multiplatform Library FinderJetBrains/klibs-io | 108 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Upgrade Notesgetknit/knit | 132 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | |
| Exposed Bug Fix WorkflowJetBrains/Exposed | 9.3k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Validator Dependency Upgradeexpress-validator/express-validator | 6.2k | — | ~1.2k | Automated safety check: Pass | MIT |
aiskillstore/marketplace
Dependency management specialist. An agent skill from aiskillstore/marketplace.
JetBrains/klibs-io
Looks up Kotlin Multiplatform libraries, their latest stable versions, Gradle coordinates and verified target support through klibs.io instead of guessing.
getknit/knit
Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.
JetBrains/Exposed
Takes a GitHub or YouTrack issue for the Exposed project through reproduction, a failing test, a fix, validation and a pull request.
express-validator/express-validator
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
ykdojo/claude-code-tips
Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.
championswimmer/TwoFac
How to list, pick, and boot Android emulators and iOS simulators for local app runs.
championswimmer/TwoFac
Use Gradle commands to build and run the app by platform. An agent skill from championswimmer/TwoFac.
championswimmer/TwoFac
Guidance on where to place different types of code in this Kotlin Multiplatform project.
championswimmer/TwoFac
Structure and routing guide for composeApp screens, components, and their relationships.
championswimmer/TwoFac
How to run, write, and debug local UI tests for Android, iOS, and browser builds.
championswimmer/TwoFac
How to create plans and follow roadmaps
Categories
Audit repo dependencies by default and only apply library upgrades when explicitly requested. Dependency Updates is an agent skill from championswimmer/TwoFac. Audit repo dependencies by default and only apply library upgrades when explicitly requested.
Dependency Updates fits situations like: tasks that involve Dependency management.
Run `npx skills add championswimmer/TwoFac --skill dependency-updates -a claude-code`. Or copy the skill folder (.agents/skills/dependency-updates in championswimmer/TwoFac) into .claude/skills/dependency-updates in your project. Claude Code loads it when a task matches its description.
Run `npx skills add championswimmer/TwoFac --skill dependency-updates -a codex`. Or copy the skill folder (.agents/skills/dependency-updates in championswimmer/TwoFac) into .agents/skills/dependency-updates in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add championswimmer/TwoFac --skill dependency-updates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-updates, .gemini/skills/dependency-updates, .github/skills/dependency-updates and .opencode/skills/dependency-updates in your project.
Going by SKILL.md and its folder, Dependency Updates needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and npm). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
No licence was found for Dependency Updates or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Updates: Dependency Management (aiskillstore/marketplace, 430 stars), Kotlin Multiplatform Library Finder (JetBrains/klibs-io, 108 stars), Upgrade Notes (getknit/knit, 132 stars) and Exposed Bug Fix Workflow (JetBrains/Exposed, 9.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
championswimmer (a GitHub user) maintains it in championswimmer/TwoFac, which has 130 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.
Source: championswimmer/TwoFac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.