Agent skill

Dependency Maintenance

by foldkit in foldkit/foldkit

Dependency maintenance. An agent skill from foldkit/foldkit.

MITAuto-check passed

Install Dependency Maintenance

skills CLI
$ npx skills add foldkit/foldkit --skill dependency-maintenance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install foldkit/foldkit dependency-maintenance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/repos/effect/.agents/skills/dependency-maintenance .claude/skills/dependency-maintenance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-maintenance
GitHub stars
935
Token cost
~683 tokens
SKILL.md length
321 words
Files
3
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Dependency maintenance. An agent skill from foldkit/foldkit.

  • Works in 5 steps: Read affected manifests and scripts,… → Search for the dependency and every… → Record each match as a development… → …
  • Upgrading dependencies
  • SKILL.md covers Discover, Package-local branch, Coordinated branch and Install and finish
  • Calls pnpm

What it does

Dependency Maintenance is an agent skill from foldkit/foldkit. Dependency maintenance. Use when adding, moving, or upgrading dependencies, changing pnpm or JavaScript runtimes, updating TypeScript or build/test tools, or changing native-build policy, patches, or test images.

Its SKILL.md is about 680 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `coordinated-upgrades.md` and `manifest-roles.md`).

It works with pnpm, JavaScript and TypeScript. The licence is MIT.

When your agent uses it

  • Upgrading dependencies
  • JavaScript runtimes
  • Updating TypeScript
  • Build/test tools

Example prompts

  • “/dependency-maintenance”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read affected manifests and scripts, pnpm-workspace.yaml, setup actions,
  2. Search for the dependency and every current version, range, runtime input,
  3. Record each match as a development version, tested version, peer range,
  4. When adding or moving a manifest entry, read
  5. Select the package-local or coordinated branch and its validation matrix.

What it can do on your machine

Read from SKILL.md and the folder at commit 49dc36e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Maintenance loads about 683 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~683

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from foldkit/foldkit at commit 49dc36e, republished under its MIT licence (© foldkit). 321 words, ~683 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-maintenance/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
dependency-maintenance
description
Dependency maintenance. Use when adding, moving, or upgrading dependencies, changing pnpm or JavaScript runtimes, updating TypeScript or build/test tools, or changing native-build policy, patches, or test images.

Treat an upgrade as a synchronization task, not a lockfile refresh. Derive versions, commands, and compatibility points from the current repository.

Discover

  1. Read affected manifests and scripts, pnpm-workspace.yaml, setup actions, workflows, test configuration, and compatibility documentation.
  2. Search for the dependency and every current version, range, runtime input, image, engine constraint, patch, and compatibility claim.
  3. Record each match as a development version, tested version, peer range, engine minimum, advertised minimum, or intentionally different constraint.
  4. When adding or moving a manifest entry, read manifest-roles.md before selecting its role.
  5. Select the package-local or coordinated branch and its validation matrix.

Discovery is complete when every match and affected validation surface is accounted for.

Package-local branch

Use this branch only for one dependency in one workspace package when runtime, compiler, package-manager, image, patch, native-build, and shared-tooling policy are unchanged.

Update only the owning manifest and keep peer compatibility independent from the development version tested here. If any coordinated surface appears, switch branches.

This branch is complete when the manifest and lockfile agree, focused checks pass, and every search result is intentionally unchanged or package-local.

Coordinated branch

Read coordinated-upgrades.md, select every applicable row, and update all listed synchronization points before installing. Apply root workflow and generated-file requirements before editing those surfaces, then return here to finish matrix and lockfile review.

Install and finish

Run root pnpm install after all selected edits. Inspect warnings and the semantic lockfile diff for specifiers, resolutions, duplicate transitives, peer changes, integrity, patch hashes, lifecycle scripts, and allowBuilds effects. A successful install alone does not complete this review.

Run the narrowest correctness and performance checks that cover every selected matrix row. Apply the root changeset routing after implementation and focused validation.

The task is complete when repeated repository searches find no unclassified synchronization point, manifest roles and compatibility ranges are intentional, the lockfile has no unexplained churn, and every selected check passes or is reported as not runnable.

© foldkit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in repos/effect/.agents/skills/dependency-maintenance of foldkit/foldkit.

  • SKILL.md
  • coordinated-upgrades.md
  • manifest-roles.md

Open the folder on GitHubat commit 49dc36e

Compare with similar skills

Dependency Maintenance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Maintenance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Maintenance this skillfoldkit/foldkit935—~683Automated safety check: PassMIT
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT
AntfuJetBrains/skills3664 repos~1kAutomated safety check: PassNone
Javascript Typescript Typescript Scaffoldaiskillstore/marketplace4307 repos~2kAutomated safety check: NotesNone

Similar skills

  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 8 days ago
    SecurityAuto-check: warnings
  • Antfu

    JetBrains/skills

    Official

    Anthony Fu's opinionated tooling and conventions for JavaScript/TypeScript projects.

    366 GitHub starsUsed in 4 repos~1k tokens
    DevelopmentAuto-check passed
  • You are a TypeScript project architecture expert specializing in scaffolding production-ready Node.js and frontend applications.

    430 GitHub starsUsed in 7 repos~2k tokens
    DevelopmentAuto-check: notes
  • Stryker JS

    mizchi/skills

    Introduce StrykerJS mutation testing or assess JavaScript/TypeScript test quality.

    359 GitHub stars~2.4k tokensUpdated 7 days ago
    Testing & QAAuto-check passed

More from foldkit/foldkit

All 18 skills in this repo
  • Commit Changes

    foldkit/foldkit

    Create a git commit in the Foldkit monorepo with changeset enforcement and formatting.

    935 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Foldkit

    foldkit/foldkit

    A skill your agent uses whenever working with Foldkit. An agent skill from foldkit/foldkit.

    935 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Outline, draft, or revise a Foldkit version release blog post using the repository's announcement style and editorial preferences.

    935 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Audit Program

    foldkit/foldkit

    Audit an existing Foldkit program against the architecture, conventions, and quality bar.

    935 GitHub stars~7.2k tokensUpdated today
    Auto-check passed
  • Generate Program

    foldkit/foldkit

    Generate a complete, idiomatic Foldkit program from a natural language description.

    935 GitHub stars~20k tokensUpdated today
    Auto-check passed
  • Changesets

    foldkit/foldkit

    Concise PR finalization changesets. An agent skill from foldkit/foldkit.

    935 GitHub stars~923 tokensUpdated today
    Auto-check passed

Questions about Dependency Maintenance

What does Dependency Maintenance do?

Dependency maintenance. An agent skill from foldkit/foldkit. Dependency Maintenance is an agent skill from foldkit/foldkit. Dependency maintenance.

When should I use Dependency Maintenance?

Dependency Maintenance fits situations like: upgrading dependencies; javaScript runtimes; updating TypeScript; build/test tools.

How do I install Dependency Maintenance in Claude Code?

Run `npx skills add foldkit/foldkit --skill dependency-maintenance -a claude-code`. Or copy the skill folder (repos/effect/.agents/skills/dependency-maintenance in foldkit/foldkit) into .claude/skills/dependency-maintenance in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Maintenance in Codex?

Run `npx skills add foldkit/foldkit --skill dependency-maintenance -a codex`. Or copy the skill folder (repos/effect/.agents/skills/dependency-maintenance in foldkit/foldkit) into .agents/skills/dependency-maintenance in your project. Codex loads it when a task matches its description.

Can I use Dependency Maintenance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add foldkit/foldkit --skill dependency-maintenance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-maintenance, .gemini/skills/dependency-maintenance, .github/skills/dependency-maintenance and .opencode/skills/dependency-maintenance in your project.

What does Dependency Maintenance need to run?

Going by SKILL.md and its folder, Dependency Maintenance needs the command-line tools its instructions call (pnpm).

Does Dependency Maintenance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dependency Maintenance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Maintenance use?

Dependency Maintenance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Maintenance use?

About 683 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Maintenance?

Skills that share tags, products or a category with Dependency Maintenance: Pnpm Engine (teambit/bit, 18k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars) and Antfu (JetBrains/skills, 366 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Maintenance?

foldkit (a GitHub organization) maintains it in foldkit/foldkit, which has 935 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 9, 2026.

Source: foldkit/foldkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.