Agent skill

Dependency Triage

by cobusgreyling in cobusgreyling/loop-engineering

Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop.

MITAuto-check passedSecurity

Install Dependency Triage

skills CLI
$ npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cobusgreyling/loop-engineering dependency-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cobusgreyling/loop-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/starters/dependency-sweeper/.grok/skills/dependency-triage .claude/skills/dependency-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-triage
GitHub stars
11k
Token cost
~300 tokens
SKILL.md length
84 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop.

  • Scanning a project's lockfile for outdated packages and known CVEs
  • SKILL.md covers Output per package, Classification Rules and Rules
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Sorting pending dependency updates into patch, minor and major risk groups

What it does

For each outdated package the skill outputs a short Markdown block giving the current and suggested version. Classification rules sort updates into patch for a semver patch or lockfile-only security fix with no API change, minor for a semver minor bump that still needs a cautious verifier, and major for anything that always escalates to a human unless already pre-approved in the sweeper's saved state. A package on a denylist in that state always escalates without being auto-touched, and a high-severity CVE escalates whenever its fix would require a major or breaking change.

Operating rules say to prefer the smallest safe version bump that resolves the advisory, never bundle unrelated package updates into one change, record any human overrides read from dependency-sweeper-state.md on every run, and escalate to a human whenever a lockfile conflict or peer dependency warning appears.

When your agent uses it

  • Scanning a project's lockfile for outdated packages and known CVEs
  • Sorting pending dependency updates into patch, minor and major risk groups
  • Running one pass of an automated dependency sweeper loop

Example prompts

  • “Scan package.json and the lockfile for outdated packages and CVEs.”
  • “Classify these pending updates into patch, minor and major risk.”
  • “Check the denylist and escalate any package that's on it.”

Requirements

  • A dependency-sweeper-state.md file recording prior overrides and denylist entries

What it can do on your machine

Read from SKILL.md and the folder at commit d25c2f4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Triage loads about 300 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 84 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~300

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cobusgreyling/loop-engineering at commit d25c2f4, republished under its MIT licence (© cobusgreyling). 84 words, ~300 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-triage/SKILL.md (or your agent's skills folder).
name
dependency-triage
description
Scan package manifests and lockfiles for outdated packages and known CVEs. Groups updates by risk (patch, minor, major). Use in dependency sweeper loops.
user_invocable
true

Dependency Triage Skill

Output per package

markdown
### package-name (ecosystem: npm|pip|go|etc.)
- Current: x.y.z
- Suggested: x.y.z
- Risk: patch | minor | major
- CVE: none | CVE-XXXX (severity)
- Actionable: yes | no (denylist / human gate)
- Suggested loop action: patch-in-worktree | escalate-human | skip

Classification Rules

  • patch: semver patch or lockfile-only security fix with no API change
  • minor: semver minor — cautious, verifier required
  • major: always escalate-human unless explicitly pre-approved in state
  • denylist: packages in state denylist → escalate-human, no auto-touch
  • high-severity CVE: escalate if fix requires major or breaking change

Rules

  • Prefer the smallest safe bump that resolves the advisory.
  • Never bundle unrelated package updates in one change.
  • Record human overrides from dependency-sweeper-state.md every run.
  • If lockfile conflict or peer dependency warning → escalate-human.

© cobusgreyling, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in starters/dependency-sweeper/.grok/skills/dependency-triage of cobusgreyling/loop-engineering.

Open the folder on GitHubat commit d25c2f4

Compare with similar skills

Dependency Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Triage this skillcobusgreyling/loop-engineering11k—~300Automated safety check: PassMIT
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Dependency Auditbriiirussell/cybersecurity-skills413—~3.2kAutomated safety check: WarnMIT
Reviewing Dependenciesbitwarden/ai-plugins154—~2kAutomated safety check: PassCustom licence
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Vulnerability Scanningsecondsky/claude-skills227—~799Automated safety check: PassMIT

Similar skills

  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Dependency Audit

    briiirussell/cybersecurity-skills

    Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

    413 GitHub stars~3.2k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • Reviewing Dependencies

    bitwarden/ai-plugins

    Official

    This skill should be used when the user asks to "review Dependabot alerts", "check for vulnerable dependencies", "audit third-party packages", "assess supply chain risk", "run an Aikido scan", or…

    154 GitHub stars~2k tokensUpdated yesterday
    SecurityAuto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Vulnerability Scanning

    secondsky/claude-skills

    Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

    227 GitHub stars~799 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed

More from cobusgreyling/loop-engineering

All 21 skills in this repo
  • Install Loop Engineering

    cobusgreyling/loop-engineering

    Installs Loop Engineering into a project through the single @cobusgreyling/loop CLI, scaffolding a report-only loop and a readiness score.

    11k GitHub starsUsed in 1 repo~648 tokens
    Auto-check passed
  • Loop Constraints Enforcer

    cobusgreyling/loop-engineering

    Loads a project's loop-constraints.md before any other action and blocks pushes, edits or merges that violate the rules it defines.

    11k GitHub starsUsed in 1 repo~475 tokens
    Auto-check: notes
  • Release Notes Drafter

    cobusgreyling/loop-engineering

    Turns a structured list of changes from changelog-scan into a categorized, user-facing release notes draft file, and never publishes anything.

    11k GitHub stars~555 tokensUpdated yesterday
    Auto-check passed
  • Issue Triage Loop

    cobusgreyling/loop-engineering

    Scans open GitHub issues and discussions, flags duplicates, scores priority and proposes labels into issue-triage-state.md without ever labeling or closing.

    11k GitHub stars~522 tokensUpdated yesterday
    Auto-check passed
  • Loop Triage Report

    cobusgreyling/loop-engineering

    Turns CI failures, open issues, recent commits and chat threads into a prioritized markdown report that an automation loop can act on without inventing architecture work.

    11k GitHub stars~500 tokensUpdated yesterday
    Auto-check passed
  • Loop Token Budget Guard

    cobusgreyling/loop-engineering

    Check token budget and run-log spend before and after a loop run. Enforces early exit when over budget or when there is no actionable work.

    11k GitHub starsUsed in 1 repo~376 tokens
    Auto-check passed

Questions about Dependency Triage

What does Dependency Triage do?

Scans package manifests and lockfiles for outdated packages and known CVEs, then classifies each possible update as patch, minor, major or escalate-human for a dependency sweeper loop. For each outdated package the skill outputs a short Markdown block giving the current and suggested version. Classification rules sort updates into patch for a semver patch or lockfile-only security fix with no API change, minor for a semver minor bump that still needs a cautious verifier, and major for anything that always escalates to a human unless already pre-approved in the sweeper's saved state.

When should I use Dependency Triage?

Dependency Triage fits situations like: scanning a project's lockfile for outdated packages and known CVEs; sorting pending dependency updates into patch, minor and major risk groups; running one pass of an automated dependency sweeper loop.

How do I install Dependency Triage in Claude Code?

Run `npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a claude-code`. Or copy the skill folder (starters/dependency-sweeper/.grok/skills/dependency-triage in cobusgreyling/loop-engineering) into .claude/skills/dependency-triage in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Triage in Codex?

Run `npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a codex`. Or copy the skill folder (starters/dependency-sweeper/.grok/skills/dependency-triage in cobusgreyling/loop-engineering) into .agents/skills/dependency-triage in your project. Codex loads it when a task matches its description.

Can I use Dependency Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cobusgreyling/loop-engineering --skill dependency-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-triage, .gemini/skills/dependency-triage, .github/skills/dependency-triage and .opencode/skills/dependency-triage in your project.

What does Dependency Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Dependency Triage is instructions for the agent only. Our summary lists: A dependency-sweeper-state.md file recording prior overrides and denylist entries.

Does Dependency Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dependency Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Triage use?

Dependency Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Triage use?

About 300 tokens (SKILL.md is roughly 1.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Triage?

Skills that share tags, products or a category with Dependency Triage: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Dependency Audit (briiirussell/cybersecurity-skills, 413 stars), Reviewing Dependencies (bitwarden/ai-plugins, 154 stars) and npm Supply Chain Check (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Triage?

cobusgreyling (a GitHub user) maintains it in cobusgreyling/loop-engineering, which has 11,444 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 9, 2026.

Source: cobusgreyling/loop-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.