Agent skill

Bump X402 Dependencies

by coinbase in coinbase/cdp-sdk

Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402…

MITAuto-check passed

Install Bump X402 Dependencies

skills CLI
$ npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coinbase/cdp-sdk bump-x402-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coinbase/cdp-sdk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/bump-x402-dependencies .claude/skills/bump-x402-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bump-x402-dependencies
GitHub stars
203
Token cost
~2.1k tokens
SKILL.md length
852 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402…

  • Works in 9 steps: Resolve the target version. Don't guess… → Find every occurrence. Run → Edit each occurrence. Replace only the… → …
  • The user asks to bump
  • SKILL.md covers Background, Steps and Notes
  • Calls pnpm and npm; needs CDP_API_KEY_ID and CDP_API_KEY_SECRET

What it does

Bump X402 Dependencies is an agent skill from coinbase/cdp-sdk. Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402 example) to the latest lockstep-released version, then verifies the SDK and all examples still build, lint, format, and typecheck. Use when the user asks to bump, update, or sync x402 (or @x402) dependencies/peer dependencies in cdp-sdk, or when a new x402 release needs to be picked up across the repo.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with x402, TypeScript and npm. The repository describes itself as: Client libraries for managing EVM and Solana wallets while relying on CDP to secure private keys. The licence is MIT.

When your agent uses it

  • The user asks to bump
  • Sync x402 (or @x40
  • Dependencies/peer dependencies in cdp-sdk
  • A new x402 release needs to be picked up across the repo

Example prompts

  • “Use the bump-x402-dependencies skill to bump every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev…”
  • “/bump-x402-dependencies”

Requirements

  • A credential in CDP_API_KEY_SECRET
  • A credential in CDP_WALLET_SECRET

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the target version. Don't guess — always resolve it fresh, since
  2. Find every occurrence. Run
  3. Edit each occurrence. Replace only the version number in each
  4. Regenerate lockfiles (non-frozen install; this is expected to modify
  5. Regression-check the SDK
  6. Regression-check the examples
  7. If any regression check fails, don't just move on. An error like
  8. Add a changeset if the SDK's peer dependencies changed. If
  9. Summarize and stop. Report old → new version per file and confirm

What it can do on your machine

Read from SKILL.md and the folder at commit 993de49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CDP_API_KEY_ID
    • CDP_API_KEY_SECRET
    • CDP_WALLET_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bump X402 Dependencies loads about 2.1k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 852 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coinbase/cdp-sdk at commit 993de49, republished under its MIT licence (© coinbase). 852 words, ~2,060 tokens.

Download SKILL.mdSave it as .claude/skills/bump-x402-dependencies/SKILL.md (or your agent's skills folder).
name
bump-x402-dependencies
description
Bumps every @x402/* package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402 example) to the latest lockstep-released version, then verifies the SDK and all examples still build, lint, format, and typecheck. Use when the user asks to bump, update, or sync x402 (or @x402) dependencies/peer dependencies in cdp-sdk, or when a new x402 release needs to be picked up across the repo.

Bump x402 Dependencies

Background

  • @x402/* packages (core, evm, extensions, svm, axios, fetch, mcp, express, hono, next) are released in lockstep: every package publishes the same version number at the same time, always as X.Y.0.
  • typescript/packages/cdp-sdk/package.json declares core/evm/extensions/svm as optional peerDependencies, pinned with ^X.Y.0.
  • typescript/package.json pins the same four packages plus fetch as exact-version devDependencies (no ^) so the SDK's own test suite runs against a known x402 version.
  • Every TypeScript x402 example depends on the subset of @x402/* packages it needs, pinned with ^X.Y.0: examples/typescript/package.json (client examples) and each examples/typescript/x402/servers/{express,hono,mcp,next}/package.json.
  • Why this matters: if these drift out of sync (e.g. extensions at ^2.17.0 while everything else is ^2.16.0), pnpm can install two copies of a package at different versions. TypeScript then treats their exported classes as structurally incompatible, producing errors like Types have separate declarations of a private property 'xyz' in examples that mix a CDP-provided type with an @x402/* type. Keeping every occurrence on the same version avoids/fixes this class of bug.

Steps

  1. Resolve the target version. Don't guess — always resolve it fresh, since this skill is re-run every time x402 publishes a new release:

    bash
    npm view @x402/core dist-tags.latest

    Cross-check 2-3 other @x402/* packages actually in use (e.g. @x402/evm, @x402/extensions) resolve to the same version. If they don't match, stop and ask the user which version to target — the lockstep assumption doesn't hold and blindly bumping could mix incompatible versions.

  2. Find every occurrence. Run:

    bash
    grep -rn '"@x402/' --include=package.json typescript examples 2>/dev/null | grep -v node_modules

    As of writing, this covers exactly these files/keys — but always trust the grep output over this list, since new examples may have been added since:

    FileFieldPrefix
    typescript/packages/cdp-sdk/package.jsonpeerDependencies: core, evm, extensions, svm^
    typescript/package.jsondevDependencies: core, evm, extensions, fetch, svmexact (no ^)
    examples/typescript/package.jsondependencies: axios, core, evm, fetch, mcp, svm^
    examples/typescript/x402/servers/express/package.jsondependencies: core, evm, express, extensions, svm^
    examples/typescript/x402/servers/hono/package.jsondependencies: core, evm, extensions, hono, svm^
    examples/typescript/x402/servers/mcp/package.jsondependencies: core, evm, mcp^
    examples/typescript/x402/servers/next/package.jsondependencies: core, evm, extensions, next, svm^
  3. Edit each occurrence. Replace only the version number in each "@x402/<pkg>": "..." entry and preserve whatever prefix was already there (^ vs. exact). Never touch unrelated dependencies, and never add @x402/* packages to a file that didn't already depend on them.

  4. Regenerate lockfiles (non-frozen install; this is expected to modify both lockfiles):

    bash
    cd typescript && pnpm install
    cd ../examples/typescript && pnpm install
  5. Regression-check the SDK:

    bash
    cd typescript
    pnpm build
    pnpm lint
    pnpm format:check
  6. Regression-check the examples:

    bash
    cd examples/typescript
    pnpm build   # typechecks root examples (evm/, solana/, quickstart/, x402/clients/, etc.)

    The root tsconfig.json excludes x402/servers, so each server workspace has its own tsconfig.json. express, hono, and mcp have a "build": "tsc" script; next has a "typecheck": "tsc --noEmit" script (its "build" is next build). Run each:

    bash
    cd x402/servers/express && pnpm build
    cd ../hono               && pnpm build
    cd ../mcp                && pnpm build
    cd ../next               && pnpm typecheck

    Type-check next rather than next build it: a full next build collects page data, which evaluates the route module and constructs the CDP facilitator via createCdpFacilitatorClient() — that needs real CDP_API_KEY_ID / CDP_API_KEY_SECRET and makes live CDP API calls, which this job (and this skill's local regression check) intentionally avoids — build-examples runs on every PR touching typescript/examples, not just x402 ones, and shouldn't depend on network/CDP availability. tsc --noEmit catches the same type and dependency-version errors without executing module code, and it's what the build-examples CI job runs. (For reference, a real next build also needs PAY_TO set and its next.config.ts sets turbopack.root / outputFileTracingRoot to the repo root so Turbopack can resolve the workspace-linked @coinbase/cdp-sdk — don't remove that config.)

  7. If any regression check fails, don't just move on. An error like Types have separate declarations of a private property '...' means some @x402/* occurrence still doesn't match the rest — re-run step 2's grep and diff versions across all files before investigating further.

  8. Add a changeset if the SDK's peer dependencies changed. If typescript/packages/cdp-sdk/package.json's peerDependencies changed, add a changeset so the bump shows up in the next @coinbase/cdp-sdk release notes:

    markdown
    ---
    "@coinbase/cdp-sdk": patch
    ---
    
    Bump the `@x402/core`, `@x402/evm`, `@x402/extensions`, and `@x402/svm` peer dependencies to `^X.Y.0`.

    Save this as a new file under typescript/.changeset/ (any descriptive filename, e.g. bump-x402-peer-deps.md), with X.Y.0 replaced by the actual version. Use minor/major instead of patch if the x402 release notes call out breaking changes.

  9. Summarize and stop. Report old → new version per file and confirm every regression check passed. Leave all changes uncommitted for the user to review — do not commit or push unless explicitly asked.

Show full SKILL.md (192 more words)Show less

Notes

  • Steps 5-6 above (type-check/build only) mirror what CI's build-examples job runs, and are enough to catch the dependency-version-skew errors this skill exists to fix. They don't require CDP credentials, so they're the right default when you don't have any configured.
  • If you do have CDP credentials (CDP_API_KEY_ID / CDP_API_KEY_SECRET / CDP_WALLET_SECRET) and a funded testnet wallet, also live-test the example servers and clients against each other (pnpm start in each server directory, then run a client example against it) before considering the bump complete. This isn't required by the skill, but it's worth doing: a prior x402 bump introduced a runtime-only regression (an MCP server hanging on a second concurrent client) that type-checking never caught. CI's E2E workflows do have real CDP credentials (a globally-set API key and wallet secret — see .github/workflows/typescript_e2e_test.yml), so this kind of check is reproducible there even without local credentials.
  • If a new x402-consuming example is added later, add its package.json to the table in step 2, give it its own tsconfig.json + "build": "tsc" script (mirroring express/hono/mcp) so it gets type-checked at all, wire that build into the build-examples CI job, and add its regression check to step 6.

© coinbase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .cursor/skills/bump-x402-dependencies of coinbase/cdp-sdk.

Open the folder on GitHubat commit 993de49

Compare with similar skills

Bump X402 Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bump X402 Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bump X402 Dependencies this skillcoinbase/cdp-sdk203—~2.1kAutomated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.4k—~2.2kAutomated safety check: PassMIT
Link Workspace Packagesnomcopter/react-mosaic4.8k6 repos~760Automated safety check: PassCustom licence
Logseq Plugin SDKlogseq/logseq45k—~2.3kAutomated safety check: PassAGPL-3.0
Create Docsvictorgarciaesgi/nuxt-typed-router4132 repos~2.8kAutomated safety check: PassMIT

Similar skills

  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.4k GitHub stars~2.2k tokensUpdated 29 days ago
    DevelopmentAuto-check passed
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 6 repos~760 tokens
    DevelopmentAuto-check passed
  • Logseq Plugin SDK

    logseq/logseq

    Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).

    45k GitHub stars~2.3k tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Create Docs

    victorgarciaesgi/nuxt-typed-router

    Create complete documentation sites for projects. An agent skill from victorgarciaesgi/nuxt-typed-router.

    413 GitHub starsUsed in 2 repos~2.8k tokens
    Frontend & DesignAuto-check passed
  • Run the tests that cover a change in the pnpm repository, in the Rust workspace (pnpm/, pnpr/) or the TypeScript CLI (pnpm11/), and recognize the cases where a scoped run passes without testing…

    37k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed

More from coinbase/cdp-sdk

  • Build X402 Client

    coinbase/cdp-sdk

    Write code that pays for an HTTP API returning 402 Payment Required, using the x402 protocol and a CDP-managed wallet.

    203 GitHub stars~3k tokensUpdated 3 days ago
    Auto-check passed
  • Build X402 Server

    coinbase/cdp-sdk

    Write code that charges for an HTTP route with the x402 protocol and receives USDC in a CDP-managed wallet.

    203 GitHub stars~3.7k tokensUpdated 3 days ago
    Auto-check: notes

Questions about Bump X402 Dependencies

What does Bump X402 Dependencies do?

Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402…. Bump X402 Dependencies is an agent skill from coinbase/cdp-sdk. Bumps every @x402/ package (the optional peer dependencies in the CDP TypeScript SDK, the pinned dev dependencies used to test the SDK against x402, and the dependencies in every TypeScript x402 example) to the latest lockstep-released version, then verifies the SDK and all examples still build, lint, format, and typecheck.

When should I use Bump X402 Dependencies?

Bump X402 Dependencies fits situations like: the user asks to bump; sync x402 (or @x40; dependencies/peer dependencies in cdp-sdk; A new x402 release needs to be picked up across the repo.

How do I install Bump X402 Dependencies in Claude Code?

Run `npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a claude-code`. Or copy the skill folder (.cursor/skills/bump-x402-dependencies in coinbase/cdp-sdk) into .claude/skills/bump-x402-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Bump X402 Dependencies in Codex?

Run `npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a codex`. Or copy the skill folder (.cursor/skills/bump-x402-dependencies in coinbase/cdp-sdk) into .agents/skills/bump-x402-dependencies in your project. Codex loads it when a task matches its description.

Can I use Bump X402 Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coinbase/cdp-sdk --skill bump-x402-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bump-x402-dependencies, .gemini/skills/bump-x402-dependencies, .github/skills/bump-x402-dependencies and .opencode/skills/bump-x402-dependencies in your project.

What does Bump X402 Dependencies need to run?

Going by SKILL.md and its folder, Bump X402 Dependencies needs the command-line tools its instructions call (pnpm and npm) and credentials named CDP_API_KEY_ID, CDP_API_KEY_SECRET and CDP_WALLET_SECRET. Our summary lists: A credential in CDP_API_KEY_SECRET; A credential in CDP_WALLET_SECRET.

Does Bump X402 Dependencies access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bump X402 Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bump X402 Dependencies use?

Bump X402 Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bump X402 Dependencies use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bump X402 Dependencies?

Skills that share tags, products or a category with Bump X402 Dependencies: MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.4k stars), Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars) and Logseq Plugin SDK (logseq/logseq, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bump X402 Dependencies?

coinbase (a GitHub organization) maintains it in coinbase/cdp-sdk, which has 203 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.

Source: coinbase/cdp-sdk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.