Agent skill

Polylith Libs

by DavidVujic in DavidVujic/python-polylith

Inspect third-party libraries used per Polylith project with poly libs.

MITAuto-check passed

Install Polylith Libs

skills CLI
$ npx skills add DavidVujic/python-polylith --skill polylith-libs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DavidVujic/python-polylith polylith-libs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DavidVujic/python-polylith.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/polylith/polylith-libs .claude/skills/polylith-libs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
polylith-libs
GitHub stars
553
Token cost
~656 tokens
SKILL.md length
213 words
Files
1
Skills in repo
37
Repo updated
First seen
Licence
MIT

At a glance

Inspect third-party libraries used per Polylith project with poly libs.

  • The user wants to see dependency usage
  • SKILL.md covers Quick command, Prerequisites, Command reference and Examples, plus 2 more sections
  • Calls uv and poetry
  • Audit version drift across projects

What it does

Polylith Libs is an agent skill from DavidVujic/python-polylith. Inspect third-party libraries used per Polylith project with poly libs. Use when the user wants to see dependency usage, audit version drift across projects, find which projects use a given library, or compare library declarations vs. the lock file. Read-only — for a CI gate use polylith-check instead.

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Tooling support for the Polylith Architecture in Python. The licence is MIT.

When your agent uses it

  • The user wants to see dependency usage
  • Audit version drift across projects
  • Find which projects use a given library
  • Compare library declarations vs

Example prompts

  • “/polylith-libs”

What it can do on your machine

Read from SKILL.md and the folder at commit a7a80f2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • poetry

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Polylith Libs loads about 656 tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 213 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~656

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DavidVujic/python-polylith at commit a7a80f2, republished under its MIT licence (© DavidVujic). 213 words, ~656 tokens.

Download SKILL.mdSave it as .claude/skills/polylith-libs/SKILL.md (or your agent's skills folder).
name
polylith-libs
description
Inspect third-party libraries used per Polylith project with `poly libs`. Use when the user wants to see dependency usage, audit version drift across projects, find which projects use a given library, or compare library declarations vs. the lock file. Read-only — for a CI gate use `polylith-check` instead.

Libs Skill

Quick command

bash
uv run poly libs

Command prefix: If you do not know the package manager, list lock files with ls uv.lock poetry.lock pdm.lock 2>/dev/null (a pyproject.toml is always present, so it tells you nothing on its own). Use uv run poly (uv), poetry poly (poetry), pdm run poly (pdm), hatch run poly (hatch), or poly (activated venv). Examples below use uv run.

poly libs reports; poly check fails the build. Use libs for inspection, check for CI (load polylith-check).

Prerequisites

  • A Polylith workspace with at least one project.
  • A lock file at the root (uv.lock, poetry.lock, or pdm.lock).

Command reference

OptionDefaultDescription
--strictfalseStricter matching of names and versions across projects.
--directorycwdLimit output to projects whose path matches this directory.
--alias—Comma-separated import_name=package_name aliases.
--shortfalseCompact view — useful for wide workspaces.
--savefalsePersist the report to a file under the workspace's output dir.

Examples

bash
# Full library × project matrix
uv run poly libs

# Strict version-drift detection
uv run poly libs --strict

# Compact view for many projects
uv run poly libs --short

How to read it

  • Rows are third-party libraries; columns are projects.
  • ✔ = the library is used by that project.
  • A library used by multiple projects with different versions = version drift. Fix by aligning versions in the relevant project pyproject.tomls, or by relying on a central lock file (uv workspaces).

Notes for the agent

  • poly libs is read-only — it never modifies pyproject.toml or the lock file.

© DavidVujic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/polylith/polylith-libs of DavidVujic/python-polylith.

Open the folder on GitHubat commit a7a80f2

Compare with similar skills

Polylith Libs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Polylith Libs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Polylith Libs this skillDavidVujic/python-polylith553—~656Automated safety check: PassMIT
Third Party Cookiesthedaviddias/Front-End-Checklist74k—~580Automated safety check: PassMIT
Third Party Scriptsthedaviddias/Front-End-Checklist74k—~417Automated safety check: PassMIT
Managing Third Party Vendor Riskmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Audit Third Party Contractsben-manes/caffeine18k—~943Automated safety check: PassApache-2.0
Libraryasgeirtj/system_prompts_leaks69k—~4kAutomated safety check: PassCC0-1.0

Similar skills

  • Third Party Cookies

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing a website for privacy compliance, third-party resource loading, or cookie consent implementation.

    74k GitHub stars~580 tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Third Party Scripts

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing slow page loads, heavy assets, or rendering delays related to Optimize third-party script loading.

    74k GitHub stars~417 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Managing Third Party Vendor Risk

    mukul975/Anthropic-Cybersecurity-Skills

    Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Audit Third Party Contracts

    ben-manes/caffeine

    Verify every third-party and sharp-edged JDK API usage against the contract the upstream documentation actually states

    18k GitHub stars~943 tokensUpdated yesterday
    Auto-check passed
  • Library

    asgeirtj/system_prompts_leaks

    Use ChatGPT Library when the user mentions their Library, asks to find or work with a Library-backed file, Site, or named file that may be in the Library, or wants to organize Library folders…

    69k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • Third Party Code

    open-edge-platform/anomalib

    Review/generate third-party code attribution, licensing, and notice requirements

    6.2k GitHub stars~599 tokensUpdated today
    Auto-check passed

More from DavidVujic/python-polylith

All 37 skills in this repo
  • Polylith Base Creation

    DavidVujic/python-polylith

    Create a Polylith base with poly create base — the entry point of a deployable application (HTTP API, CLI, message-queue consumer, AWS Lambda handler, GCP Cloud Function, scheduled job).

    553 GitHub stars~757 tokensUpdated 3 days ago
    Auto-check passed
  • Polylith Check

    DavidVujic/python-polylith

    Validate a Polylith workspace with poly check — the canonical CI gate.

    553 GitHub stars~972 tokensUpdated 3 days ago
    Auto-check passed
  • Polylith Component Creation

    DavidVujic/python-polylith

    Create a Polylith component with poly create component — a reusable, isolated brick implementing business logic, a feature, a domain module, or a capability.

    553 GitHub stars~800 tokensUpdated 3 days ago
    Auto-check passed
  • Polylith Dependency Management

    DavidVujic/python-polylith

    Add or manage third-party dependencies in a Polylith workspace.

    553 GitHub stars~643 tokensUpdated 3 days ago
    Auto-check passed
  • Polylith Dependency Visualization

    DavidVujic/python-polylith

    Visualize brick × brick dependencies with poly deps — find circular dependencies, inspect a brick's public interface, and detect interface-bypass violations.

    553 GitHub stars~906 tokensUpdated 3 days ago
    Auto-check passed
  • Polylith Diff

    DavidVujic/python-polylith

    List Polylith bricks whose implementation changed since a git tag using poly diff.

    553 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed

Questions about Polylith Libs

What does Polylith Libs do?

Inspect third-party libraries used per Polylith project with poly libs. Polylith Libs is an agent skill from DavidVujic/python-polylith. Inspect third-party libraries used per Polylith project with poly libs.

When should I use Polylith Libs?

Polylith Libs fits situations like: the user wants to see dependency usage; audit version drift across projects; find which projects use a given library; compare library declarations vs.

How do I install Polylith Libs in Claude Code?

Run `npx skills add DavidVujic/python-polylith --skill polylith-libs -a claude-code`. Or copy the skill folder (.agents/skills/polylith/polylith-libs in DavidVujic/python-polylith) into .claude/skills/polylith-libs in your project. Claude Code loads it when a task matches its description.

How do I install Polylith Libs in Codex?

Run `npx skills add DavidVujic/python-polylith --skill polylith-libs -a codex`. Or copy the skill folder (.agents/skills/polylith/polylith-libs in DavidVujic/python-polylith) into .agents/skills/polylith-libs in your project. Codex loads it when a task matches its description.

Can I use Polylith Libs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DavidVujic/python-polylith --skill polylith-libs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/polylith-libs, .gemini/skills/polylith-libs, .github/skills/polylith-libs and .opencode/skills/polylith-libs in your project.

What does Polylith Libs need to run?

Going by SKILL.md and its folder, Polylith Libs needs the command-line tools its instructions call (uv and poetry).

Does Polylith Libs access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Polylith Libs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Polylith Libs use?

Polylith Libs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Polylith Libs use?

About 656 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Polylith Libs?

Skills that share tags, products or a category with Polylith Libs: Third Party Cookies (thedaviddias/Front-End-Checklist, 74k stars), Third Party Scripts (thedaviddias/Front-End-Checklist, 74k stars), Managing Third Party Vendor Risk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Audit Third Party Contracts (ben-manes/caffeine, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Polylith Libs?

DavidVujic (a GitHub user) maintains it in DavidVujic/python-polylith, which has 553 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 4, 2026.

Source: DavidVujic/python-polylith on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.