Agent skill

Dependency Update

by codewhale-hq in codewhale-hq/Codewhale

Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.

MITAuto-check passedDevelopment

Install Dependency Update

skills CLI
$ npx skills add codewhale-hq/Codewhale --skill dependency-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codewhale-hq/Codewhale dependency-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/codewhale-hq/Codewhale.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/tui/assets/skills/dependency-update .claude/skills/dependency-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-update
GitHub stars
41k
Token cost
~142 tokens
SKILL.md length
42 words
Files
1
Skills in repo
63
Repo updated
First seen
Licence
MIT

At a glance

Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.

  • Works in 4 steps: Identify the dependency set and current… → Read release notes/changelogs. → Apply updates and fix breakages. → …
  • Tasks that involve Changelog and release notes
  • SKILL.md covers Invocation, Non-goals and Workflow
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dependency Update is an agent skill from codewhale-hq/Codewhale. Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify. Explicit-only; no broad update-everything by inference.

Its SKILL.md is about 140 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes and Dependency management. The repository describes itself as: Open-source coding agent for your terminal, built in Rust and on a journey of continuous community improvement. Issues and PRs welcome. The licence is MIT.

When your agent uses it

  • Tasks that involve Changelog and release notes
  • Tasks that involve Dependency management

Example prompts

  • “/dependency-update”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the dependency set and current versions.
  2. Read release notes/changelogs.
  3. Apply updates and fix breakages.
  4. Verify with the project’s test/build gates.

What it can do on your machine

Read from SKILL.md and the folder at commit ad333fd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Update loads about 142 tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 42 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~142

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from codewhale-hq/Codewhale at commit ad333fd, republished under its MIT licence (© codewhale-hq). 42 words, ~142 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-update/SKILL.md (or your agent's skills folder).
name
dependency-update
description
Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify. Explicit-only; no broad update-everything by inference.
invocation
explicit-only

Dependency Update

Invocation

Explicit-only with a defined dependency scope.

Non-goals

  • No inferred “update everything”.
  • No publish/release.

Workflow

  1. Identify the dependency set and current versions.
  2. Read release notes/changelogs.
  3. Apply updates and fix breakages.
  4. Verify with the project’s test/build gates.

© codewhale-hq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/tui/assets/skills/dependency-update of codewhale-hq/Codewhale.

Open the folder on GitHubat commit ad333fd

Compare with similar skills

Dependency Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Update this skillcodewhale-hq/Codewhale41k—~142Automated safety check: PassMIT
Claude Code Version Checkykdojo/claude-code-tips10k—~1.8kAutomated safety check: PassCustom licence
Bestie FeaturesJuliaBesties/BestieTemplate.jl128—~2.5kAutomated safety check: PassMPL-2.0
Dependabot PR Reviewkernitus/BukkitOldCombatMechanics223—~882Automated safety check: PassMPL-2.0
Sake CI Releasekattouf/Sake116—~731Automated safety check: PassMIT
Update Depsviclafouch/meme-studio110—~2.6kAutomated safety check: PassNone

Similar skills

  • Claude Code Version Check

    ykdojo/claude-code-tips

    Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.

    10k GitHub stars~1.8k tokensUpdated 12 days ago
    DevelopmentAuto-check passed
  • Bestie Features

    JuliaBesties/BestieTemplate.jl

    Add BestieTemplate features (AGENTS.md, changelog, dependabot, pre-commit, lint workflow, testitem runner) to a Julia package with the bestie CLI — no Julia needed.

    128 GitHub stars~2.5k tokensUpdated 19 days ago
    DevelopmentAuto-check passed
  • Dependabot PR Review

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and…

    223 GitHub stars~882 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Sake CI Release

    kattouf/Sake

    A skill your agent uses when working on CI workflows, GitHub Actions, release process, changelog generation (git-cliff), or dependabot configuration.

    116 GitHub stars~731 tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Update Deps

    viclafouch/meme-studio

    Audit all outdated dependencies with detailed research on changelogs, breaking changes, bug fixes, and deprecations.

    110 GitHub stars~2.6k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Es X Node Support Update

    eslint-community/eslint-plugin-es-x

    Update eslint-plugin-es-x Node.js support in its own dedicated PR.

    157 GitHub stars~980 tokensUpdated 11 days ago
    DevelopmentAuto-check passed

More from codewhale-hq/Codewhale

All 63 skills in this repo
  • Codewhale Dogfood Install

    codewhale-hq/Codewhale

    Proves a Codewhale change in the real product: a stamped release build, an atomic local install, fresh-shell verification and manual QA that automated gates cannot cover.

    41k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Codewhale Session Handoff

    codewhale-hq/Codewhale

    Writes a paste-ready handoff for the next agent session, opening with a state-check command block and separating done, suspected and blocked work.

    41k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Codewhale Landing Workflow

    codewhale-hq/Codewhale

    Decides how verified work should reach main, directly, in a worktree or on an integration branch, while keeping contributor credit and respecting merge gates.

    41k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Sub-Agent Delegation

    codewhale-hq/Codewhale

    Guides when and how to split multi-step coding, research or verification work into focused sub-agent runs while the parent keeps integration and final checks.

    41k GitHub stars~790 tokensUpdated today
    Auto-check passed
  • Codewhale Fleet Manager

    codewhale-hq/Codewhale

    Triages and manages Codewhale fleet runs and workers with typed commands, classifying failures and choosing a safe restart, resume or escalation.

    41k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • GitHub Issue Bulk Assigner

    codewhale-hq/Codewhale

    Moves a list of GitHub issues into a milestone or assigns them to owners with the gh CLI, checking each one before and after the change.

    41k GitHub stars~953 tokensUpdated today
    Auto-check passed

Categories

Questions about Dependency Update

What does Dependency Update do?

Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify. Dependency Update is an agent skill from codewhale-hq/Codewhale. Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.

When should I use Dependency Update?

Dependency Update fits situations like: tasks that involve Changelog and release notes; tasks that involve Dependency management.

How do I install Dependency Update in Claude Code?

Run `npx skills add codewhale-hq/Codewhale --skill dependency-update -a claude-code`. Or copy the skill folder (crates/tui/assets/skills/dependency-update in codewhale-hq/Codewhale) into .claude/skills/dependency-update in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Update in Codex?

Run `npx skills add codewhale-hq/Codewhale --skill dependency-update -a codex`. Or copy the skill folder (crates/tui/assets/skills/dependency-update in codewhale-hq/Codewhale) into .agents/skills/dependency-update in your project. Codex loads it when a task matches its description.

Can I use Dependency Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewhale-hq/Codewhale --skill dependency-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-update, .gemini/skills/dependency-update, .github/skills/dependency-update and .opencode/skills/dependency-update in your project.

What does Dependency Update need to run?

SKILL.md names no scripts, command-line tools or credentials: Dependency Update is instructions for the agent only.

Does Dependency Update access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dependency Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Update use?

Dependency Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Update use?

About 142 tokens (SKILL.md is roughly 568 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Update?

Skills that share tags, products or a category with Dependency Update: Claude Code Version Check (ykdojo/claude-code-tips, 10k stars), Bestie Features (JuliaBesties/BestieTemplate.jl, 128 stars), Dependabot PR Review (kernitus/BukkitOldCombatMechanics, 223 stars) and Sake CI Release (kattouf/Sake, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Update?

codewhale-hq (a GitHub organization) maintains it in codewhale-hq/Codewhale, which has 41,067 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on October 7, 2026.

Source: codewhale-hq/Codewhale on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.