Agent skill

Dependency Triage

by cobusgreyling in cobusgreyling/loop-engineering

Scan package manifests and lockfiles for outdated and vulnerable dependencies.

MITAuto-check passedSecurity

Install Dependency Triage

skills CLI
$ npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cobusgreyling/loop-engineering dependency-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cobusgreyling/loop-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/starters/dependency-sweeper-opencode/skills/dependency-triage .claude/skills/dependency-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-triage
GitHub stars
11k
Token cost
~206 tokens
SKILL.md length
75 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Scan package manifests and lockfiles for outdated and vulnerable dependencies.

  • Tasks that involve Dependency management
  • SKILL.md covers Scan Sources, Classification, Output and Rules
  • Calls npm, cargo and pip
  • Tasks that involve Vulnerability scanning

What it does

Dependency Triage is an agent skill from cobusgreyling/loop-engineering. Scan package manifests and lockfiles for outdated and vulnerable dependencies. Classify by severity and update type.

Its SKILL.md is about 210 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Dependency management and Vulnerability scanning. It works with npm. The repository describes itself as: Practical patterns, starters & CLI tools for loop engineering with AI coding agents. Design systems that prompt and orchestrate agents (inspired by Addy Osmani and Boris Cherny)… The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/dependency-triage”

What it can do on your machine

Read from SKILL.md and the folder at commit d25c2f4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • cargo
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Triage loads about 206 tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 75 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~206

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cobusgreyling/loop-engineering at commit d25c2f4, republished under its MIT licence (© cobusgreyling). 75 words, ~206 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-triage/SKILL.md (or your agent's skills folder).
name
dependency-triage
description
Scan package manifests and lockfiles for outdated and vulnerable dependencies. Classify by severity and update type.
user_invocable
true

Dependency Triage Skill

You are a dependency sweeper agent. Scan for outdated and vulnerable packages.

Scan Sources

  • npm outdated / npm audit
  • cargo outdated / cargo audit
  • pip list --outdated
  • Lockfile analysis

Classification

  • Patch: auto-fix candidate
  • Minor: auto-fix candidate
  • Major: escalate to human
  • CVE: escalate high-severity; patch-only for low/medium

Output

Update dependency-sweeper-state.md with prioritized update list.

Rules

  • Patch-only by default in week one.
  • Honour denylist in state file.
  • Run npm ci && npm test (or equivalent) before approving.

© cobusgreyling, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in starters/dependency-sweeper-opencode/skills/dependency-triage of cobusgreyling/loop-engineering.

Open the folder on GitHubat commit d25c2f4

Compare with similar skills

Dependency Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Triage this skillcobusgreyling/loop-engineering11k—~206Automated safety check: PassMIT
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Dep Securitytinyfish-io/tinyfish-cookbook2.2k—~2.4kAutomated safety check: PassMIT
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0
Dependency Update BotVarnan-Tech/opendirectory674—~3kAutomated safety check: NotesMIT
Auditing npm Dependenciesjeremylongshore/tons-of-skills-marketplace2.8k—~2.5kAutomated safety check: NotesMIT

Similar skills

  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Dep Security

    tinyfish-io/tinyfish-cookbook

    Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

    2.2k GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Dependency Update Bot

    Varnan-Tech/opendirectory

    Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

    674 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Auditing npm Dependencies

    jeremylongshore/tons-of-skills-marketplace

    Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema.

    2.8k GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check: notes
  • Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

    159 GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed

More from cobusgreyling/loop-engineering

All 21 skills in this repo
  • Install Loop Engineering

    cobusgreyling/loop-engineering

    Installs Loop Engineering into a project through the single @cobusgreyling/loop CLI, scaffolding a report-only loop and a readiness score.

    11k GitHub starsUsed in 1 repo~648 tokens
    Auto-check passed
  • Loop Constraints Enforcer

    cobusgreyling/loop-engineering

    Loads a project's loop-constraints.md before any other action and blocks pushes, edits or merges that violate the rules it defines.

    11k GitHub starsUsed in 1 repo~475 tokens
    Auto-check: notes
  • Release Notes Drafter

    cobusgreyling/loop-engineering

    Turns a structured list of changes from changelog-scan into a categorized, user-facing release notes draft file, and never publishes anything.

    11k GitHub stars~555 tokensUpdated today
    Auto-check passed
  • Issue Triage Loop

    cobusgreyling/loop-engineering

    Scans open GitHub issues and discussions, flags duplicates, scores priority and proposes labels into issue-triage-state.md without ever labeling or closing.

    11k GitHub stars~522 tokensUpdated today
    Auto-check passed
  • Loop Triage Report

    cobusgreyling/loop-engineering

    Turns CI failures, open issues, recent commits and chat threads into a prioritized markdown report that an automation loop can act on without inventing architecture work.

    11k GitHub stars~500 tokensUpdated today
    Auto-check passed
  • Loop Token Budget Guard

    cobusgreyling/loop-engineering

    Check token budget and run-log spend before and after a loop run. Enforces early exit when over budget or when there is no actionable work.

    11k GitHub starsUsed in 1 repo~376 tokens
    Auto-check passed

Works with

Questions about Dependency Triage

What does Dependency Triage do?

Scan package manifests and lockfiles for outdated and vulnerable dependencies. Dependency Triage is an agent skill from cobusgreyling/loop-engineering. Scan package manifests and lockfiles for outdated and vulnerable dependencies.

When should I use Dependency Triage?

Dependency Triage fits situations like: tasks that involve Dependency management; tasks that involve Vulnerability scanning.

How do I install Dependency Triage in Claude Code?

Run `npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a claude-code`. Or copy the skill folder (starters/dependency-sweeper-opencode/skills/dependency-triage in cobusgreyling/loop-engineering) into .claude/skills/dependency-triage in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Triage in Codex?

Run `npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a codex`. Or copy the skill folder (starters/dependency-sweeper-opencode/skills/dependency-triage in cobusgreyling/loop-engineering) into .agents/skills/dependency-triage in your project. Codex loads it when a task matches its description.

Can I use Dependency Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-triage, .gemini/skills/dependency-triage, .github/skills/dependency-triage and .opencode/skills/dependency-triage in your project.

What does Dependency Triage need to run?

Going by SKILL.md and its folder, Dependency Triage needs the command-line tools its instructions call (npm, cargo and pip).

Does Dependency Triage access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Triage use?

Dependency Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Triage use?

About 206 tokens (SKILL.md is roughly 824 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Triage?

Skills that share tags, products or a category with Dependency Triage: npm Supply Chain Check (majiayu000/spellbook, 287 stars), Dep Security (tinyfish-io/tinyfish-cookbook, 2.2k stars), Cve Scan (softspark/ai-toolkit, 179 stars) and Dependency Update Bot (Varnan-Tech/opendirectory, 674 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Triage?

cobusgreyling (a GitHub user) maintains it in cobusgreyling/loop-engineering, which has 11,444 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 9, 2026.

Source: cobusgreyling/loop-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.