Pnpm Engine
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
Dependency maintenance. An agent skill from foldkit/foldkit.
$ npx skills add foldkit/foldkit --skill dependency-maintenance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install foldkit/foldkit dependency-maintenance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/repos/effect/.agents/skills/dependency-maintenance .claude/skills/dependency-maintenance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-maintenance" agent skill from https://github.com/foldkit/foldkit/tree/main/repos/effect/.agents/skills/dependency-maintenance into .claude/skills/dependency-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-maintenance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/foldkit/foldkit/tree/main/repos/effect/.agents/skills/dependency-maintenanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add foldkit/foldkit --skill dependency-maintenance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install foldkit/foldkit dependency-maintenance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/repos/effect/.agents/skills/dependency-maintenance .agents/skills/dependency-maintenance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-maintenance" agent skill from https://github.com/foldkit/foldkit/tree/main/repos/effect/.agents/skills/dependency-maintenance into .agents/skills/dependency-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-maintenance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add foldkit/foldkit --skill dependency-maintenance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install foldkit/foldkit dependency-maintenance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/repos/effect/.agents/skills/dependency-maintenance .cursor/skills/dependency-maintenance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-maintenance" agent skill from https://github.com/foldkit/foldkit/tree/main/repos/effect/.agents/skills/dependency-maintenance into .cursor/skills/dependency-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-maintenance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/foldkit/foldkit.git --path repos/effect/.agents/skills/dependency-maintenance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add foldkit/foldkit --skill dependency-maintenance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install foldkit/foldkit dependency-maintenance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/repos/effect/.agents/skills/dependency-maintenance .gemini/skills/dependency-maintenance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-maintenance" agent skill from https://github.com/foldkit/foldkit/tree/main/repos/effect/.agents/skills/dependency-maintenance into .gemini/skills/dependency-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-maintenance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install foldkit/foldkit dependency-maintenanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add foldkit/foldkit --skill dependency-maintenance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/repos/effect/.agents/skills/dependency-maintenance .github/skills/dependency-maintenance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-maintenance" agent skill from https://github.com/foldkit/foldkit/tree/main/repos/effect/.agents/skills/dependency-maintenance into .github/skills/dependency-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-maintenance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add foldkit/foldkit --skill dependency-maintenance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install foldkit/foldkit dependency-maintenance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/foldkit/foldkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/repos/effect/.agents/skills/dependency-maintenance .opencode/skills/dependency-maintenance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-maintenance" agent skill from https://github.com/foldkit/foldkit/tree/main/repos/effect/.agents/skills/dependency-maintenance into .opencode/skills/dependency-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-maintenance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-maintenanceDependency maintenance. An agent skill from foldkit/foldkit.
Dependency Maintenance is an agent skill from foldkit/foldkit. Dependency maintenance. Use when adding, moving, or upgrading dependencies, changing pnpm or JavaScript runtimes, updating TypeScript or build/test tools, or changing native-build policy, patches, or test images.
Its SKILL.md is about 680 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `coordinated-upgrades.md` and `manifest-roles.md`).
It works with pnpm, JavaScript and TypeScript. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 49dc36e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Maintenance loads about 683 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 321 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from foldkit/foldkit at commit 49dc36e, republished under its MIT licence (© foldkit). 321 words, ~683 tokens.
.claude/skills/dependency-maintenance/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Treat an upgrade as a synchronization task, not a lockfile refresh. Derive versions, commands, and compatibility points from the current repository.
pnpm-workspace.yaml, setup actions,
workflows, test configuration, and compatibility documentation.Discovery is complete when every match and affected validation surface is accounted for.
Use this branch only for one dependency in one workspace package when runtime, compiler, package-manager, image, patch, native-build, and shared-tooling policy are unchanged.
Update only the owning manifest and keep peer compatibility independent from the development version tested here. If any coordinated surface appears, switch branches.
This branch is complete when the manifest and lockfile agree, focused checks pass, and every search result is intentionally unchanged or package-local.
Read coordinated-upgrades.md, select every applicable row, and update all listed synchronization points before installing. Apply root workflow and generated-file requirements before editing those surfaces, then return here to finish matrix and lockfile review.
Run root pnpm install after all selected edits. Inspect warnings and the
semantic lockfile diff for specifiers, resolutions, duplicate transitives, peer
changes, integrity, patch hashes, lifecycle scripts, and allowBuilds effects.
A successful install alone does not complete this review.
Run the narrowest correctness and performance checks that cover every selected matrix row. Apply the root changeset routing after implementation and focused validation.
The task is complete when repeated repository searches find no unclassified synchronization point, manifest roles and compatibility ranges are intentional, the lockfile has no unexplained churn, and every selected check passes or is reported as not runnable.
© foldkit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files in repos/effect/.agents/skills/dependency-maintenance of foldkit/foldkit.
Open the folder on GitHubat commit 49dc36e
Dependency Maintenance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Maintenance this skillfoldkit/foldkit | 935 | — | ~683 | Automated safety check: Pass | MIT | |
| Pnpm Engineteambit/bit | 18k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| npm Supply Chain Securitybodadotsh/npm-security-best-practices | 858 | — | ~1k | Automated safety check: Warn | MIT | |
| AntfuJetBrains/skills | 366 | 4 repos | ~1k | Automated safety check: Pass | None | |
| Javascript Typescript Typescript Scaffoldaiskillstore/marketplace | 430 | 7 repos | ~2k | Automated safety check: Notes | None |
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
JetBrains/skills
Anthony Fu's opinionated tooling and conventions for JavaScript/TypeScript projects.
aiskillstore/marketplace
You are a TypeScript project architecture expert specializing in scaffolding production-ready Node.js and frontend applications.
mizchi/skills
Introduce StrykerJS mutation testing or assess JavaScript/TypeScript test quality.
foldkit/foldkit
Create a git commit in the Foldkit monorepo with changeset enforcement and formatting.
foldkit/foldkit
A skill your agent uses whenever working with Foldkit. An agent skill from foldkit/foldkit.
foldkit/foldkit
Outline, draft, or revise a Foldkit version release blog post using the repository's announcement style and editorial preferences.
foldkit/foldkit
Audit an existing Foldkit program against the architecture, conventions, and quality bar.
foldkit/foldkit
Generate a complete, idiomatic Foldkit program from a natural language description.
foldkit/foldkit
Concise PR finalization changesets. An agent skill from foldkit/foldkit.
Works with
Dependency maintenance. An agent skill from foldkit/foldkit. Dependency Maintenance is an agent skill from foldkit/foldkit. Dependency maintenance.
Dependency Maintenance fits situations like: upgrading dependencies; javaScript runtimes; updating TypeScript; build/test tools.
Run `npx skills add foldkit/foldkit --skill dependency-maintenance -a claude-code`. Or copy the skill folder (repos/effect/.agents/skills/dependency-maintenance in foldkit/foldkit) into .claude/skills/dependency-maintenance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add foldkit/foldkit --skill dependency-maintenance -a codex`. Or copy the skill folder (repos/effect/.agents/skills/dependency-maintenance in foldkit/foldkit) into .agents/skills/dependency-maintenance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add foldkit/foldkit --skill dependency-maintenance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-maintenance, .gemini/skills/dependency-maintenance, .github/skills/dependency-maintenance and .opencode/skills/dependency-maintenance in your project.
Going by SKILL.md and its folder, Dependency Maintenance needs the command-line tools its instructions call (pnpm).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependency Maintenance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 683 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependency Maintenance: Pnpm Engine (teambit/bit, 18k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), npm Supply Chain Security (bodadotsh/npm-security-best-practices, 858 stars) and Antfu (JetBrains/skills, 366 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
foldkit (a GitHub organization) maintains it in foldkit/foldkit, which has 935 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 9, 2026.
Source: foldkit/foldkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.