Agent skill

Dependency Safety

by doorkeeper-gem in doorkeeper-gem/doorkeeper

Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper.

MITAuto-check passedBackend & APIs

Install Dependency Safety

skills CLI
$ npx skills add doorkeeper-gem/doorkeeper --skill dependency-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install doorkeeper-gem/doorkeeper dependency-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/doorkeeper-gem/doorkeeper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-safety .claude/skills/dependency-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-safety
GitHub stars
5.5k
Token cost
~931 tokens
SKILL.md length
389 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper.

  • Works in 4 steps: Is the functionality available in Ruby… → Can it be an optional dependency… → Is the gem well-maintained (recent… → …
  • Modifying Gemfile
  • SKILL.md covers Runtime Dependencies, Checking for Vulnerabilities, Version Constraints and Adding a New Development…, plus 3 more sections
  • Calls bundle and gem

What it does

Dependency Safety is an agent skill from doorkeeper-gem/doorkeeper. Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper. Use when modifying Gemfile, doorkeeper.gemspec, or gemfiles/.gemfile.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Ruby and Ruby on Rails. The repository describes itself as: Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. The licence is MIT.

When your agent uses it

  • Modifying Gemfile
  • Doorkeeper.gemspec
  • Gemfiles/.gemfile

Example prompts

  • “/dependency-safety”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Is the functionality available in Ruby stdlib or Rails already?
  2. Can it be an optional dependency (required only if the host app includes it)?
  3. Is the gem well-maintained (recent releases, multiple maintainers, good test coverage)?
  4. Does it introduce native extensions that complicate installation?

What it can do on your machine

Read from SKILL.md and the folder at commit 80f4eba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bundle
    • gem

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Safety loads about 931 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 389 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~931

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from doorkeeper-gem/doorkeeper at commit 80f4eba, republished under its MIT licence (© doorkeeper-gem). 389 words, ~931 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-safety/SKILL.md (or your agent's skills folder).
name
dependency-safety
description
Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper. Use when modifying Gemfile, doorkeeper.gemspec, or gemfiles/*.gemfile.

Dependency Safety

When adding, updating, or reviewing dependencies in Doorkeeper, use this skill to ensure gems are safe, necessary, and properly constrained.

Runtime Dependencies

Doorkeeper has a single runtime dependency: railties >= 5. This is intentional — a library should minimize its dependency footprint.

Before adding a new runtime dependency, ask:

  1. Is the functionality available in Ruby stdlib or Rails already?
  2. Can it be an optional dependency (required only if the host app includes it)?
  3. Is the gem well-maintained (recent releases, multiple maintainers, good test coverage)?
  4. Does it introduce native extensions that complicate installation?

Prefer optional dependencies over hard requirements. Example: jwt is optional — only needed for private_key_jwt client authentication. Check lib/doorkeeper.rb for the autoload pattern.

Checking for Vulnerabilities

bash
gem install bundler-audit
bundle-audit update
bundle-audit check

Severity mapping:

  • Critical/High CVE in a runtime dependency → must fix immediately
  • Critical/High CVE in a dev dependency → fix when convenient (doesn't affect users)
  • Medium/Low → assess whether exploitable in Doorkeeper's context

Version Constraints

In doorkeeper.gemspec (runtime):
  • Use permissive constraints: gem.add_dependency "railties", ">= 5"
  • Doorkeeper supports a wide range of Rails versions — don't over-constrain
In Gemfile (development):
  • Pin major versions with pessimistic operator: gem "rspec-rails", "~> 8.0"
  • Gemfile.lock is gitignored (standard for gems — host apps control the resolved versions)
In gemfiles/*.gemfile (CI matrix):
  • Each file tests a specific Rails version
  • Keep in sync with CI matrix in .github/workflows/ci.yml
  • Lockfiles (gemfiles/*.lock) are also gitignored
Show full SKILL.md (169 more words)Show less

Adding a New Development Dependency

  1. Add to doorkeeper.gemspec under add_development_dependency with a version constraint
  2. Add to Gemfile if it needs a specific version or group
  3. Run bundle install to verify resolution succeeds
  4. Verify CI still passes across the gemfile matrix

Adding an Optional Runtime Dependency

Pattern from existing code (jwt gem in lib/doorkeeper/oauth/client_authentication/private_key_jwt.rb):

ruby
# Defined as a private class method, called at the point the dependency is needed:
def self.require_jwt!
  require "jwt"
rescue LoadError
  raise LoadError,
        "private_key_jwt client authentication requires the 'jwt' gem (>= 2.7); " \
        "add it to your Gemfile to use this method"
end
private_class_method :require_jwt!

The re-raised LoadError keeps the diagnosis in server logs rather than leaking it to the OAuth client as an error response. Call the method at the point the dependency is first needed, not at file load time.

Dependency Health Indicators

SignalGoodConcerning
Last release< 6 months ago> 2 years ago
Open issues/PRsActively triagedHundreds unaddressed
MaintainersMultipleSingle individual
DownloadsEstablished usageVery low
LicenseMIT, Apache, BSDGPL (viral), None
DependenciesFew, well-knownDeep tree, obscure gems

Verification

After dependency changes:

  1. bundle install succeeds
  2. bundle exec rake spec passes
  3. bundle-audit check shows no new vulnerabilities
  4. bundle exec rubocop passes
  5. Check CI gemfiles still resolve

© doorkeeper-gem, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/dependency-safety of doorkeeper-gem/doorkeeper.

Open the folder on GitHubat commit 80f4eba

Compare with similar skills

Dependency Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Safety this skilldoorkeeper-gem/doorkeeper5.5k—~931Automated safety check: PassMIT
New AppRailsEventStore/ecommerce507—~3.1kAutomated safety check: PassMIT
Rails ExpertJeffallan/claude-skills12k—~1.4kAutomated safety check: PassMIT
Rails Patternsaffaan-m/ECC276k—~4.1kAutomated safety check: PassMIT
Ruby Patternssoftspark/ai-toolkit179—~2.3kAutomated safety check: PassApache-2.0
Railsericrisco/rsc-harness174—~3.1kAutomated safety check: PassMIT

Similar skills

  • New App

    RailsEventStore/ecommerce

    Scaffold a new Rails app with event sourcing, following project conventions (todomvc as reference)

    507 GitHub stars~3.1k tokensUpdated 18 days ago
    Backend & APIsAuto-check passed
  • Rails Expert

    Jeffallan/claude-skills

    Builds Rails 7+ apps with Hotwire Turbo Frames and Streams, Active Record tuning, Action Cable, Sidekiq jobs and RSpec specs, with migration and N+1 checks.

    12k GitHub stars~1.4k tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Rails Patterns

    affaan-m/ECC

    Ruby on Rails framework patterns for Rails 7.1+ and 8.x apps.

    276k GitHub stars~4.1k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Ruby Patterns

    softspark/ai-toolkit

    Ruby/Rails: blocks, metaprogramming, ActiveRecord, Sidekiq, RSpec, Sorbet, Hanami.

    179 GitHub stars~2.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Rails

    ericrisco/rsc-harness

    A skill your agent uses when building or maintaining a Ruby on Rails app — models, controllers, views, routes and migrations; ActiveRecord associations, scopes and query performance; Hotwire (Turbo…

    174 GitHub stars~3.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Ruby Rules

    softspark/ai-toolkit

    Ruby coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from doorkeeper-gem/doorkeeper

  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Code Quality

    doorkeeper-gem/doorkeeper

    Maintain code health and architecture standards when implementing features or refactoring Doorkeeper.

    5.5k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Testing

    doorkeeper-gem/doorkeeper

    Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper.

    5.5k GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Rfc Compliance

    doorkeeper-gem/doorkeeper

    Verify OAuth protocol implementations stay aligned with relevant RFCs.

    5.5k GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Dependency Safety

What does Dependency Safety do?

Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper. Dependency Safety is an agent skill from doorkeeper-gem/doorkeeper. Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper.

When should I use Dependency Safety?

Dependency Safety fits situations like: modifying Gemfile; doorkeeper.gemspec; gemfiles/.gemfile.

How do I install Dependency Safety in Claude Code?

Run `npx skills add doorkeeper-gem/doorkeeper --skill dependency-safety -a claude-code`. Or copy the skill folder (.agents/skills/dependency-safety in doorkeeper-gem/doorkeeper) into .claude/skills/dependency-safety in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Safety in Codex?

Run `npx skills add doorkeeper-gem/doorkeeper --skill dependency-safety -a codex`. Or copy the skill folder (.agents/skills/dependency-safety in doorkeeper-gem/doorkeeper) into .agents/skills/dependency-safety in your project. Codex loads it when a task matches its description.

Can I use Dependency Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add doorkeeper-gem/doorkeeper --skill dependency-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-safety, .gemini/skills/dependency-safety, .github/skills/dependency-safety and .opencode/skills/dependency-safety in your project.

What does Dependency Safety need to run?

Going by SKILL.md and its folder, Dependency Safety needs the command-line tools its instructions call (bundle and gem).

Does Dependency Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dependency Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Safety use?

Dependency Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Safety use?

About 931 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Safety?

Skills that share tags, products or a category with Dependency Safety: New App (RailsEventStore/ecommerce, 507 stars), Rails Expert (Jeffallan/claude-skills, 12k stars), Rails Patterns (affaan-m/ECC, 276k stars) and Ruby Patterns (softspark/ai-toolkit, 179 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Safety?

doorkeeper-gem (a GitHub organization) maintains it in doorkeeper-gem/doorkeeper, which has 5,523 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: doorkeeper-gem/doorkeeper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.