Agent skill

Package Search

by davepoon in davepoon/buildwithclaude

Search for packages and assess security risk before adding as dependencies

MITAuto-check: notesDevelopment

Install Package Search

skills CLI
$ npx skills add davepoon/buildwithclaude --skill package-search -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davepoon/buildwithclaude package-search --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnetix/skills/package-search .claude/skills/package-search && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
package-search
GitHub stars
3.6k
Token cost
~4.3k tokens
SKILL.md length
1,968 words
Files
1
Skills in repo
246
Repo updated
First seen
Licence
MIT

At a glance

Search for packages and assess security risk before adding as dependencies

  • Works in 6 steps: Detect Repository Ecosystems → Search Packages → Filter Results → …
  • Development work in your project
  • SKILL.md covers Output & Analysis Guidelines, Vulnerability Memory…, Dependabot Integration and Code Scanning (CodeQL)…, plus 4 more sections
  • Calls gh, pip and go; reaches github.com

What it does

Package Search is an agent skill from davepoon/buildwithclaude. Search for packages and assess security risk before adding as dependencies

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with Python and Mermaid. The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/package-search”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Bash, Read, Glob, Grep, Edit, Write

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect Repository Ecosystems
  2. Search Packages
  3. Filter Results
  4. Risk Assessment
  5. Propose Dependency Addition
  6. Planning Interview

What it can do on your machine

Read from SKILL.md and the folder at commit 616deb5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Glob
    • Grep
    • Edit
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • pip
    • go
    • uv
    • cargo
    • python3
    • python
    • gem
    • composer
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Package Search loads about 4.3k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 1,968 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Glob, Grep, Edit, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davepoon/buildwithclaude at commit 616deb5, republished under its MIT licence (© davepoon). 1,968 words, ~4,276 tokens.

Download SKILL.mdSave it as .claude/skills/package-search/SKILL.md (or your agent's skills folder).
name
package-search
description
Search for packages and assess security risk before adding as dependencies
allowed-tools
Bash, Read, Glob, Grep, Edit, Write
argument-hint
<package-name>
user-invocable
true
model
sonnet

Vulnetix Package Search Skill

This skill searches for packages across ecosystems and provides a comprehensive security risk assessment before adding them as dependencies.

Output & Analysis Guidelines

Primary output format: Markdown. All reports, tables, summaries, and diffs MUST be presented as formatted markdown text directly — never generate scripts or programs to produce output that can be expressed as markdown.

Visual data — use Mermaid diagrams to display data visually when it aids comprehension. Mermaid renders natively in markdown and requires no external tools. Use it for:

  • Dependency trees / upgrade paths → graph TD or graph LR
  • Version comparison timelines → timeline
  • Risk breakdowns → pie or quadrantChart
  • Decision flow (add/skip/alternatives) → flowchart

Example — vulnerability distribution for a package:

markdown
```mermaid
pie title Vulnerability Severity
    "Critical" : 1
    "High" : 2
    "Medium" : 5
    "Low" : 3
```

If uv is available, richer visualizations can be generated with Python (matplotlib, plotly) and saved to .vulnetix/:

bash
command -v uv &>/dev/null && uv run --with matplotlib python3 -c '
import matplotlib.pyplot as plt
# ... generate chart ...
plt.savefig(".vulnetix/chart.png", dpi=150, bbox_inches="tight")
'

When Python charts are generated, display them inline and keep the Mermaid version as a text fallback.

Data processing — tooling cascade (strict order):

  1. jq / yq + bash builtins (preferred) — jq for JSON, yq for YAML. Pipe to head, tail, cut, sed, grep, sort, uniq, wc for shaping.
  2. uv (for complex analysis or charts) — If aggregation, statistics, or visualization beyond Mermaid are needed, check uv first:
    bash
    command -v uv &>/dev/null && uv run --with pandas,matplotlib python3 -c '...'
  3. python3 stdlib (last resort) — Only if uv is unavailable. Use json, csv, collections, statistics modules — no pip dependencies:
    bash
    command -v python3 &>/dev/null && python3 -c 'import json, sys; ...'

Never assume any runtime is available — always check with command -v before use. If all programmatic tools are unavailable, analyze manually with the Read tool and present results as markdown with Mermaid diagrams.

Version detection commands (pip show, go list -m, cargo pkgid, etc.) are exempt — they query package managers directly and are tried as-available per the version detection priority in Step 1b.

Vulnerability Memory (.vulnetix/memory.yaml)

This skill reads the .vulnetix/memory.yaml file in the repository root to surface prior vulnerability history for packages being searched. This file is shared with /vulnetix:fix and /vulnetix:exploits.

At the start of every invocation:

  1. Use Glob to check if .vulnetix/memory.yaml exists in the repo root
  2. If it exists, use Read to load it
  3. Use Glob for .vulnetix/scans/*.cdx.json — if CycloneDX SBOMs exist from prior scans (pre-commit hook or fix skill), cross-reference package names against SBOM component lists for additional vulnerability context

During risk assessment (Step 4):

  1. For each package in the search results, check if any vulnerabilities in the memory file reference that package name
  2. If prior entries exist, add a Known History column or section to the output:
    • List each vuln ID, its current status (in developer-friendly language), decision date, and CWSS priority if available
    • Example: CVE-2021-44228 — Fixed (2024-01-15), CVE-2023-1234 — Risk accepted (2024-03-01), P3 (52.0)
    • If pocs exist for a vuln, note: N PoC(s) on file — do not display PoC URLs or paths in package search output
  3. If a package has unresolved vulnerabilities (affected or under_investigation), flag this prominently in the risk assessment. If CWSS priority is P1 or P2, add a warning: "Active exploit intelligence available — run /vulnetix:exploits <vuln-id> for details"

After completing the search:

  1. If the search reveals new vulnerabilities (from vulnerabilityCount or maxSeverity in the API response) that are NOT already tracked in the memory file, record them as new entries with:
    • status: under_investigation
    • discovery.source: scan
    • discovery.sbom: path to the relevant .vulnetix/scans/*.cdx.json if one exists for this package's manifest
    • decision.choice: investigating
    • decision.reason: "Discovered via /vulnetix:package-search"
  2. Append to history: event: discovered, detail: "Found via package search for <query>"

VEX-to-developer-language: When surfacing prior decisions, use developer-friendly language:

  • not_affected → "Not affected", affected → "Vulnerable", fixed → "Fixed", under_investigation → "Investigating"

Dependabot Integration

When gh CLI is available (check with gh auth status 2>/dev/null), query Dependabot alerts for packages in the search results to enrich the risk assessment.

During Step 4 (Risk Assessment):

  1. For each package in the results, check for open Dependabot alerts:
    bash
    gh api repos/{owner}/{repo}/dependabot/alerts?state=open --jq '[.[] | select(.dependency.package.name == "'"$PACKAGE_NAME"'")] | length'
  2. If alerts exist, add a Dependabot Alerts column to the comparison table showing the count and highest severity
  3. If a Dependabot PR exists for the package, note it: "Dependabot PR #N open for <package> upgrade"
  4. If a prior memory entry for this package has a dependabot section, surface it in the Known History output:
    • Example: CVE-2021-44228 — Fixed (2024-01-15, Dependabot: merged PR #187)

During Step 5 (Propose Dependency Addition):

  • If a Dependabot PR already proposes the same version upgrade, suggest reviewing and merging that PR instead of manual editing: "Dependabot PR #N already proposes this upgrade — consider merging it instead"

This avoids duplicate work and leverages Dependabot's existing CI validation.

Code Scanning (CodeQL) Integration

When gh CLI is available, check if CodeQL has flagged issues related to packages being searched. The canonical state-to-VEX mapping is defined in /vulnetix:fix.

During Step 4 (Risk Assessment):

  1. For each package with known vulnerabilities, check if CodeQL alerts match the associated CWEs:
    bash
    gh api repos/{owner}/{repo}/code-scanning/alerts --jq '[.[] | select(.rule.tags[]? | test("CWE-<NUMBER>"; "i"))] | length'
  2. If matching alerts exist, add a CodeQL Alerts column to the comparison table showing count and states
  3. If a prior memory entry for this package has a code_scanning section, surface it in Known History:
    • Example: CVE-2021-44228 — Fixed (2024-01-15, CodeQL: alert #15 fixed)
  4. If CodeQL default setup is not configured, note: "CodeQL not enabled — consider enabling for code-level detection"

During Step 5 (Propose Dependency Addition):

  • If a CodeQL autofix is available for related alerts, mention it: "CodeQL also has an AI-suggested code fix for the related code pattern"

Secret Scanning Integration

When gh CLI is available, check for secret scanning alerts relevant to packages handling authentication or credentials.

During Step 4 (Risk Assessment):

  1. If a package being evaluated handles auth/secrets (e.g., jsonwebtoken, bcrypt, passport, oauth2, crypto, keyring), check for open secret scanning alerts:
    bash
    gh api repos/{owner}/{repo}/secret-scanning/alerts?state=open --jq 'length'
  2. If active secrets exist alongside a package that handles credentials, flag: "Active secrets detected in this repo — adding/upgrading this package should include a secret rotation review"
  3. If a prior memory entry has a secret_scanning section, surface it in Known History

Workflow

Step 1: Detect Repository Ecosystems

Check cached manifest data first: If .vulnetix/memory.yaml has a manifests section, use it to identify previously detected ecosystems and their scan dates. This avoids re-globbing for manifests that are already tracked. If the manifests section exists and is recent (< 24h), use the cached ecosystem list as a starting point.

Then verify with Glob to catch any new manifest files:

  • package.json, package-lock.json, yarn.lock, pnpm-lock.yaml → npm
  • go.mod, go.sum → go
  • Cargo.toml, Cargo.lock → cargo
  • requirements.txt, pyproject.toml, Pipfile, poetry.lock, uv.lock → pypi
  • Gemfile, Gemfile.lock → rubygems
  • pom.xml, build.gradle, gradle.lockfile → maven
  • composer.json, composer.lock → packagist

Determine which ecosystems this repository uses. If new manifest files are discovered that aren't in the manifests section of .vulnetix/memory.yaml, add them with ecosystem, path, and scan_source: package-search (without sbom_generated: true since this skill doesn't generate SBOMs).

Show full SKILL.md (883 more words)Show less
Step 1b: Detect Currently Installed Version

For the package being searched, determine if it is already installed and what version is in use. You MUST resolve the current version using one of these methods (in priority order) and always disclose the source in your output:

  1. User-supplied version — the user explicitly stated the version in their message
  2. Lockfile — the most authoritative filesystem source:
    • npm: Read package-lock.json or yarn.lock or pnpm-lock.yaml for the resolved version
    • pypi: Read poetry.lock, Pipfile.lock, or uv.lock
    • go: Read go.sum for the recorded version
    • cargo: Read Cargo.lock for the resolved version
    • rubygems: Read Gemfile.lock
    • maven: Read gradle.lockfile if present
    • packagist: Read composer.lock
  3. Manifest file — the declared version constraint (less precise than lockfile):
    • npm: package.json → dependencies / devDependencies
    • pypi: requirements.txt (pkg==1.2.3), pyproject.toml
    • go: go.mod (require pkg v1.2.3)
    • cargo: Cargo.toml [dependencies]
    • rubygems: Gemfile
    • maven: pom.xml <version>, build.gradle
    • packagist: composer.json
  4. Installed artifacts — query the actual installed state:
    • npm: Read node_modules/<package>/package.json → version field
    • pypi: Run pip show <package> or python -c "import <pkg>; print(<pkg>.__version__)"
    • go: Run go list -m <package>
    • cargo: Run cargo pkgid <package>
    • rubygems: Run gem list <package> --local
    • system binaries: Run <binary> --version or which <binary>

If the package is not currently installed (not found in any of the above), explicitly state: "Not currently installed — no existing version detected."

Version Source Label: In all outputs, tag the version with its source, e.g.:

  • 1.2.3 (from lockfile: package-lock.json)
  • ^1.2.0 (from manifest: package.json — constraint, not exact)
  • 1.2.3 (from node_modules)
  • 1.2.3 (user-supplied)
  • Not installed
Step 2: Search Packages

Run the Vulnetix VDB package search command:

bash
vulnetix vdb packages search "$ARGUMENTS" -o json

If you detected a single ecosystem, add the --ecosystem <ecosystem> flag to filter results.

For example:

bash
vulnetix vdb packages search "express" --ecosystem npm -o json

The output is JSON with this structure:

json
{
  "packages": [
    {
      "name": "express",
      "ecosystem": "npm",
      "description": "Fast, unopinionated, minimalist web framework",
      "latestVersion": "4.18.2",
      "vulnerabilityCount": 3,
      "maxSeverity": "high",
      "safeHarbourScore": 85,
      "repository": "https://github.com/expressjs/express"
    }
  ]
}

Version enrichment: After receiving results, enrich each package with the current version detected in Step 1b. The API returns latestVersion — you must pair this with the currentVersion you resolved from the filesystem.

Step 3: Filter Results

Discard packages from ecosystems not present in the repository. For example, if the repo only has package.json, filter out PyPI and Cargo results.

Step 4: Risk Assessment

Present the matching packages in a comparison table with these columns:

PackageEcosystemCurrent VersionLatest VersionVulnerabilitiesMax SeveritySafe HarbourConfidenceRepository
expressnpm4.17.1 (lockfile)4.18.23high0.85High[link]

Column definitions:

  • Current Version: The version currently in use in this repository, with its source in parentheses (e.g., 4.17.1 (lockfile), ^4.17.0 (manifest), Not installed). This is resolved from Step 1b.
  • Latest Version: The latest available version from the ecosystem registry (from API response).
  • Vulnerability Count: Total known vulnerabilities across all versions.
  • Max Severity: Highest severity rating (critical/high/medium/low).
  • Safe Harbour: The API returns a 0–100 integer score. Convert to a 0–1 decimal by dividing by 100 (e.g., API returns 85 → display 0.85). This represents a safety confidence percentage where 1.0 = 100% confidence in safety.
  • Confidence: A human-readable label derived from the Safe Harbour value:
    • High: Safe Harbour > 0.90 — excellent security posture, strong track record
    • Reasonable: Safe Harbour 0.35–0.90 — acceptable risk, minor or moderate issues
    • Low: Safe Harbour < 0.35 — significant risk, use with extreme caution

Below the table, always include a Version Context summary:

Version Context:
- express: 4.17.1 → 4.18.2 (patch upgrade available) — source: package-lock.json
- lodash: Not installed — no existing version detected

This gives the user full transparency on where version information was derived and what upgrade path exists.

Step 5: Propose Dependency Addition

For the best candidate (lowest vuln count, highest Safe Harbour value):

  1. Identify the manifest file to edit based on ecosystem
  2. State the version change clearly: If upgrading, show currentVersion → latestVersion. If new, show (new) latestVersion.
  3. Show the concrete edit that would add or update this dependency:
    • npm: Add/update in dependencies in package.json
    • pypi: Add/update in requirements.txt or pyproject.toml
    • go: Provide go get command with version
    • cargo: Add/update in [dependencies] in Cargo.toml
    • maven: Provide <dependency> XML with version
    • rubygems: Add/update in Gemfile with version
    • packagist: Provide composer require command with version

Use the Edit tool to show the proposed change, but DO NOT apply it yet.

Example for npm (new dependency):

diff
{
  "dependencies": {
+   "express": "^4.18.2",
    "other-package": "1.0.0"
  }
}

Example for npm (upgrade):

diff
{
  "dependencies": {
-   "express": "^4.17.1",
+   "express": "^4.18.2",
    "other-package": "1.0.0"
  }
}

Always include the specific version in the proposed edit — never use * or latest.

Step 6: Planning Interview

Ask the user:

  1. Would you like me to add this package to your project? (If yes, apply the edit and suggest running npm install, pip install, etc.)
  2. Search for alternatives? (Suggest 2-3 alternative package names based on repository context and the search query)
  3. Run deeper vulnerability check? (Suggest /vulnetix:exploits <vuln-id> for any critical/high severity vulnerabilities found)

If the user requests alternatives, repeat steps 2-6 with the suggested names.

Error Handling

  • If vulnetix vdb packages search fails, inform the user to check vulnetix vdb status
  • If no packages match repo ecosystems, suggest broadening the search or checking alternative ecosystems
  • If manifest file structure is unfamiliar, ask the user which file to edit

Security Notes

  • Always recommend the latest stable version unless there are known vulnerabilities in it
  • If the latest version has critical vulnerabilities, warn the user and recommend holding off until a patch is available
  • Never silently add dependencies — always get explicit user approval first
  • All outputs MUST include package versions — both current (if installed) and latest. Never omit version numbers from tables, diffs, or recommendations.
  • Version source transparency is mandatory — always disclose how the current version was determined (lockfile, manifest, node_modules, user-supplied, or not installed). If version detection fails for a source, note what was attempted.

© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/vulnetix/skills/package-search of davepoon/buildwithclaude.

Open the folder on GitHubat commit 616deb5

Compare with similar skills

Package Search next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Package Search compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Package Search this skilldavepoon/buildwithclaude3.6k—~4.3kAutomated safety check: NotesMIT
Code Graph Mermaid Diagramstrailofbits/skills7.4k—~1.7kAutomated safety check: PassCC-BY-SA-4.0
Design Doc MermaidSpillwaveSolutions/design-doc-mermaid1761 repos~5.6kAutomated safety check: PassNone
Markdown Mermaid Writingneflibata-feng/MyArxiv-Agent1265 repos~3.8kAutomated safety check: NotesApache-2.0
Code To Diagramzebbern/claude-code-guide4.7k—~972Automated safety check: PassMIT
Generate Readmedivar-ir/ai-doc-gen767—~996Automated safety check: PassMIT

Similar skills

  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Design Doc Mermaid

    SpillwaveSolutions/design-doc-mermaid

    Create Mermaid diagrams (flowchart, sequence, class, ER, state, C4, architecture) from text or source code.

    176 GitHub starsUsed in 1 repo~5.6k tokens
    DevelopmentAuto-check passed
  • Markdown Mermaid Writing

    neflibata-feng/MyArxiv-Agent

    Comprehensive markdown and Mermaid diagram writing skill that establishes text-based diagrams as the DEFAULT documentation standard.

    126 GitHub starsUsed in 5 repos~3.8k tokens
    DevelopmentAuto-check: notes
  • Code To Diagram

    zebbern/claude-code-guide

    Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.

    4.7k GitHub stars~972 tokensUpdated today
    DevelopmentAuto-check passed
  • Generate Readme

    divar-ir/ai-doc-gen

    Generate or refresh a comprehensive, professional README.md for a repository, with architecture overview, mermaid and optional C4 diagrams, repository structure, dependencies, and API documentation.

    767 GitHub stars~996 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Book Writer

    aospbooks/aosp-internal-book

    Patterns for writing technical book chapters in Markdown with Mermaid diagrams, served via ProperDocs (a MkDocs fork).

    139 GitHub stars~3.1k tokensUpdated 4 days ago
    DevelopmentAuto-check passed

More from davepoon/buildwithclaude

All 246 skills in this repo
  • iOS Hig Design Guide

    davepoon/buildwithclaude

    Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.

    3.6k GitHub stars~735 tokensUpdated today
    Auto-check passed
  • Video Downloader

    davepoon/buildwithclaude

    Download YouTube videos with customizable quality and format options.

    3.6k GitHub starsUsed in 1 repo~871 tokens
    Auto-check passed
  • Qwen Vision

    davepoon/buildwithclaude

    A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…

    3.6k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Atlas Cloud Media

    davepoon/buildwithclaude

    Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.

    3.6k GitHub stars~852 tokensUpdated today
    Auto-check passed
  • Browser Extension Launch

    davepoon/buildwithclaude

    面向没有编程经验的用户,把想法做成可试用的浏览器插件,并完成检查、商店材料、审核提交和上线验证;也用于继续已有插件、排错和发布新版。用户说“帮我做个插件”“把插件上架”“继续我的插件”时使用。普通网站开发、仅查询插件知识不触发。

    3.6k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Slack Gif Creator

    davepoon/buildwithclaude

    Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.

    3.6k GitHub starsUsed in 12 repos~4.3k tokens
    Auto-check passed

Works with

Questions about Package Search

What does Package Search do?

Search for packages and assess security risk before adding as dependencies. Package Search is an agent skill from davepoon/buildwithclaude.

When should I use Package Search?

Package Search fits situations like: development work in your project.

How do I install Package Search in Claude Code?

Run `npx skills add davepoon/buildwithclaude --skill package-search -a claude-code`. Or copy the skill folder (plugins/vulnetix/skills/package-search in davepoon/buildwithclaude) into .claude/skills/package-search in your project. Claude Code loads it when a task matches its description.

How do I install Package Search in Codex?

Run `npx skills add davepoon/buildwithclaude --skill package-search -a codex`. Or copy the skill folder (plugins/vulnetix/skills/package-search in davepoon/buildwithclaude) into .agents/skills/package-search in your project. Codex loads it when a task matches its description.

Can I use Package Search in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill package-search -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/package-search, .gemini/skills/package-search, .github/skills/package-search and .opencode/skills/package-search in your project.

What does Package Search need to run?

Going by SKILL.md and its folder, Package Search needs the command-line tools its instructions call (gh, pip, go, uv, cargo and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, Edit, Write.

Does Package Search access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Package Search safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Package Search use?

Package Search is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Package Search use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Package Search?

Skills that share tags, products or a category with Package Search: Code Graph Mermaid Diagrams (trailofbits/skills, 7.4k stars), Design Doc Mermaid (SpillwaveSolutions/design-doc-mermaid, 176 stars), Markdown Mermaid Writing (neflibata-feng/MyArxiv-Agent, 126 stars) and Code To Diagram (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Package Search?

davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,605 GitHub stars. The repository holds 246 skills in this directory. The repository was last updated on October 9, 2026.

Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.