Triage Dependabot Alerts
activepieces/activepieces
Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…
Looks up a third-party library's current documentation through the context7 MCP server instead of relying on the agent's possibly outdated training data.
$ npx skills add duckbugio/flock --skill library-docs-lookup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install duckbugio/flock library-docs-lookup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/duckbugio/flock.git skills-src && mkdir -p .claude/skills && cp -r skills-src/core/skills/library-docs-lookup .claude/skills/library-docs-lookup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "library-docs-lookup" agent skill from https://github.com/duckbugio/flock/tree/main/core/skills/library-docs-lookup into .claude/skills/library-docs-lookup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "library-docs-lookup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/duckbugio/flock/tree/main/core/skills/library-docs-lookupType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add duckbugio/flock --skill library-docs-lookup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install duckbugio/flock library-docs-lookup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duckbugio/flock.git skills-src && mkdir -p .agents/skills && cp -r skills-src/core/skills/library-docs-lookup .agents/skills/library-docs-lookup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "library-docs-lookup" agent skill from https://github.com/duckbugio/flock/tree/main/core/skills/library-docs-lookup into .agents/skills/library-docs-lookup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "library-docs-lookup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add duckbugio/flock --skill library-docs-lookup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install duckbugio/flock library-docs-lookup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duckbugio/flock.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/core/skills/library-docs-lookup .cursor/skills/library-docs-lookup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "library-docs-lookup" agent skill from https://github.com/duckbugio/flock/tree/main/core/skills/library-docs-lookup into .cursor/skills/library-docs-lookup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "library-docs-lookup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/duckbugio/flock.git --path core/skills/library-docs-lookup--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add duckbugio/flock --skill library-docs-lookup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install duckbugio/flock library-docs-lookup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duckbugio/flock.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/core/skills/library-docs-lookup .gemini/skills/library-docs-lookup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "library-docs-lookup" agent skill from https://github.com/duckbugio/flock/tree/main/core/skills/library-docs-lookup into .gemini/skills/library-docs-lookup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "library-docs-lookup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install duckbugio/flock library-docs-lookupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add duckbugio/flock --skill library-docs-lookup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/duckbugio/flock.git skills-src && mkdir -p .github/skills && cp -r skills-src/core/skills/library-docs-lookup .github/skills/library-docs-lookup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "library-docs-lookup" agent skill from https://github.com/duckbugio/flock/tree/main/core/skills/library-docs-lookup into .github/skills/library-docs-lookup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "library-docs-lookup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add duckbugio/flock --skill library-docs-lookup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install duckbugio/flock library-docs-lookup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duckbugio/flock.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/core/skills/library-docs-lookup .opencode/skills/library-docs-lookup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "library-docs-lookup" agent skill from https://github.com/duckbugio/flock/tree/main/core/skills/library-docs-lookup into .opencode/skills/library-docs-lookup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "library-docs-lookup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
library-docs-lookupLooks up a third-party library's current documentation through the context7 MCP server instead of relying on the agent's possibly outdated training data.
Training data goes stale as library APIs, method signatures, config keys and best practices change between versions, so guessing them is called a top source of subtly wrong code. The skill resolves a library name to its context7 id, then fetches the up-to-date docs for that id scoped to the specific hook, method or config option needed, and pulls the version the project actually depends on by checking its manifest file rather than assuming the latest release when the two differ.
It applies when calling a method or option that may not exist in the installed version, wiring up a new dependency or framework feature, working with an unfamiliar or fast-moving library such as a cloud SDK or web framework, or chasing a compile or runtime error that looks like an API mismatch. It explicitly does not bother with the standard library or a small, stable utility already known cold, or with pure project-internal code, which should be read from the repo instead of looked up externally. The guiding rule is to prefer one focused docs lookup over a wrong guess that then has to be debugged.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 19c82dd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Library Docs Lookup via Context7 loads about 408 tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 195 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from duckbugio/flock at commit 19c82dd, republished under its MIT licence (© duckbugio). 195 words, ~408 tokens.
.claude/skills/library-docs-lookup/SKILL.md (or your agent's skills folder).Training data goes stale: library APIs, method signatures, config keys, and best practices change between versions. Guessing them is a top source of subtly-wrong code. When you touch an external library/framework/SDK/API, get the CURRENT docs.
The context7 MCP server is available. Use its tools:
resolve-library-id — resolve the library name (e.g. "tauri",
"centrifuge-go", "react-query") to its context7 id.get-library-docs — fetch the up-to-date docs for that id, scoped to the
topic/symbol you need (the specific hook, method, or config option).Pull the version the project actually depends on — check go.mod /
package.json / Cargo.toml / requirements.txt — not "latest", when they
differ.
Prefer one focused docs lookup over a wrong guess you then have to debug.
© duckbugio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in core/skills/library-docs-lookup of duckbugio/flock.
Open the folder on GitHubat commit 19c82dd
Library Docs Lookup via Context7 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Library Docs Lookup via Context7 this skillduckbugio/flock | 502 | — | ~408 | Automated safety check: Pass | MIT | |
| Triage Dependabot Alertsactivepieces/activepieces | 25k | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Self Healingpskoett/pskoett-ai-skills | 314 | — | ~5.3k | Automated safety check: Notes | None | |
| Dependabotgithub/awesome-copilot | 40k | 1 repos | ~3.4k | Automated safety check: Pass | MIT | |
| Maintenancecyanheads/pubmed-mcp-server | 156 | — | ~5.9k | Automated safety check: Pass | Apache-2.0 | |
| OpenStoryline Install HelperFireRedTeam/FireRed-OpenStoryline | 3.5k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 |
activepieces/activepieces
Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…
pskoett/pskoett-ai-skills
Active runtime recovery for coding agents: when something breaks mid-task, diagnose the root cause, write a fix, VERIFY by re-running the broken thing, then file a HEAL- entry to .learnings/HEALS.md…
github/awesome-copilot
Comprehensive guide for configuring and managing GitHub Dependabot.
cyanheads/pubmed-mcp-server
Investigate, adopt, and verify dependency updates — with special handling for @cyanheads/mcp-ts-core.
FireRedTeam/FireRed-OpenStoryline
Installs, repairs and starts a local source checkout of FireRed-OpenStoryline, from prerequisites and a venv to resources, config and the MCP and web servers.
activepieces/activepieces
Triage the GitHub privately-reported vulnerability backlog for Activepieces — pull repository security advisories from the Security tab, scope-check against SECURITY.md, deeply validate each…
duckbugio/flock
Has the agent build, test and lint a change, re-read the request and check for regressions before it says a coding task is done, then report exactly what it ran.
duckbugio/flock
Answer questions about the owner's services and domain using the approved DuckBug knowledge base through configured MCP tools.
Works with
Categories
Looks up a third-party library's current documentation through the context7 MCP server instead of relying on the agent's possibly outdated training data. Training data goes stale as library APIs, method signatures, config keys and best practices change between versions, so guessing them is called a top source of subtly wrong code. The skill resolves a library name to its context7 id, then fetches the up-to-date docs for that id scoped to the specific hook, method or config option needed, and pulls the version the project actually depends on by checking its manifest file rather than assuming the latest release when the two differ.
Library Docs Lookup via Context7 fits situations like: calling a method or option that might not exist in the installed library version; wiring up a new SDK client or framework feature for the first time; working with a fast-moving cloud SDK or web framework; debugging an error that looks like an API mismatch with a dependency.
Run `npx skills add duckbugio/flock --skill library-docs-lookup -a claude-code`. Or copy the skill folder (core/skills/library-docs-lookup in duckbugio/flock) into .claude/skills/library-docs-lookup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add duckbugio/flock --skill library-docs-lookup -a codex`. Or copy the skill folder (core/skills/library-docs-lookup in duckbugio/flock) into .agents/skills/library-docs-lookup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add duckbugio/flock --skill library-docs-lookup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/library-docs-lookup, .gemini/skills/library-docs-lookup, .github/skills/library-docs-lookup and .opencode/skills/library-docs-lookup in your project.
SKILL.md names no scripts, command-line tools or credentials: Library Docs Lookup via Context7 is instructions for the agent only. Our summary lists: The context7 MCP server.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Library Docs Lookup via Context7 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 408 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Library Docs Lookup via Context7: Triage Dependabot Alerts (activepieces/activepieces, 25k stars), Self Healing (pskoett/pskoett-ai-skills, 314 stars), Dependabot (github/awesome-copilot, 40k stars) and Maintenance (cyanheads/pubmed-mcp-server, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
duckbugio (a GitHub organization) maintains it in duckbugio/flock, which has 502 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.
Source: duckbugio/flock on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.