Codex CLI
kortix-ai/suna
Drive OpenAI's Codex CLI (codex exec) as a non-interactive coding sub-agent from inside Claude Code.
Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.
$ npx skills add garfiec/Librechat-Mobile --skill audit-deps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install garfiec/Librechat-Mobile audit-deps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/garfiec/Librechat-Mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-deps .claude/skills/audit-deps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-deps" agent skill from https://github.com/garfiec/Librechat-Mobile/tree/develop/.claude/skills/audit-deps into .claude/skills/audit-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-deps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/garfiec/Librechat-Mobile/tree/develop/.claude/skills/audit-depsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add garfiec/Librechat-Mobile --skill audit-deps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install garfiec/Librechat-Mobile audit-deps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garfiec/Librechat-Mobile.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/audit-deps .agents/skills/audit-deps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-deps" agent skill from https://github.com/garfiec/Librechat-Mobile/tree/develop/.claude/skills/audit-deps into .agents/skills/audit-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-deps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garfiec/Librechat-Mobile --skill audit-deps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install garfiec/Librechat-Mobile audit-deps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garfiec/Librechat-Mobile.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/audit-deps .cursor/skills/audit-deps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-deps" agent skill from https://github.com/garfiec/Librechat-Mobile/tree/develop/.claude/skills/audit-deps into .cursor/skills/audit-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-deps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/garfiec/Librechat-Mobile.git --path .claude/skills/audit-deps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add garfiec/Librechat-Mobile --skill audit-deps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install garfiec/Librechat-Mobile audit-deps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garfiec/Librechat-Mobile.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/audit-deps .gemini/skills/audit-deps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-deps" agent skill from https://github.com/garfiec/Librechat-Mobile/tree/develop/.claude/skills/audit-deps into .gemini/skills/audit-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-deps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install garfiec/Librechat-Mobile audit-depsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add garfiec/Librechat-Mobile --skill audit-deps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/garfiec/Librechat-Mobile.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/audit-deps .github/skills/audit-deps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-deps" agent skill from https://github.com/garfiec/Librechat-Mobile/tree/develop/.claude/skills/audit-deps into .github/skills/audit-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-deps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garfiec/Librechat-Mobile --skill audit-deps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install garfiec/Librechat-Mobile audit-deps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garfiec/Librechat-Mobile.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/audit-deps .opencode/skills/audit-deps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-deps" agent skill from https://github.com/garfiec/Librechat-Mobile/tree/develop/.claude/skills/audit-deps into .opencode/skills/audit-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-deps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-depsAudit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.
Audit Deps is an agent skill from garfiec/Librechat-Mobile. Audit open dependabot PRs in this repo. Spawns one investigator per PR (each with a codebase-walk sub-agent), produces a comparison table with per-PR risk + recommendation, and proposes a merge order that minimizes rebase churn. Audit-only — stops at recommendations; user authorizes execution. Use when dependabot has stacked up multiple open PRs and you want a structured pass before merging.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management, Subagents and Git worktrees. It works with OpenAI and Kotlin. The repository describes itself as: Native Android & iOS client for LibreChat, built with Kotlin Multiplatform and Compose Multiplatform. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit bf2a609. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGlobGrepWebFetchWebSearchAgentTaskCreateTaskUpdateTaskList…and 1 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Deps loads about 2.4k tokens when it runs. Until then it costs about 101 tokens; SKILL.md has 1,151 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Glob, Grep, WebFetch, WebSearch, Agent, TaskCreate, TaskUpdate, TaskList, AskUserQuestioAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from garfiec/Librechat-Mobile at commit bf2a609, republished under its MIT licence (© garfiec). 1,151 words, ~2,374 tokens.
.claude/skills/audit-deps/SKILL.md (or your agent's skills folder).Audit open dependabot PRs and propose a safe merge order.
You are the team lead. You orchestrate. You do NOT read source code or run grep yourself during investigation — every codebase walk goes through a sub-agent inside a per-PR investigator. You handle GitHub queries, worktree setup, synthesis, and the merge-order proposal.
The skill is audit-only. It never merges, pushes, comments on PRs, or removes worktrees. It ends by presenting findings + a proposed sequence and asking the user what to do next.
Args: an optional list of PR numbers (/audit-deps 77 78 79). If omitted, audit every open
dependabot PR.
Run once:
gh pr list --state open --json number,title,headRefName,author,createdAt,mergeable,statusCheckRollup \
--jq '.[] | select(.author.login=="app/dependabot" or (.headRefName | startswith("dependabot/")))'If args were passed, narrow to those PR numbers. From each PR object extract:
mergeable state (MERGEABLE / CONFLICTING / UNKNOWN)statusCheckRollup — count and roll up to "all green" / "N failing"createdAt)If the result is empty, exit early with a one-line message — no work to do.
If any PR has CONFLICTING AND age > 7 days, note it as "stale-conflict — rebase candidate" but do
NOT trigger a rebase. Rebase decisions belong to Phase 4 (user authorization).
State briefly to the user what you found before moving on:
Found N open dependabot PRs: #77 paging, #78 AGP 9.2.1, #79 kotlinx-datetime. Setting up worktrees.
Project worktree convention: .claude/worktrees/deps/pr-<N> on a local branch named pr-<N>.
For each PR:
# fetch dependabot branch as local pr-<N>
git fetch origin <head-ref>:pr-<N>
# create worktree (or refresh if it exists from a prior audit run)
if [ -d ".claude/worktrees/deps/pr-<N>" ]; then
git -C .claude/worktrees/deps/pr-<N> fetch origin
git -C .claude/worktrees/deps/pr-<N> reset --hard pr-<N>
else
git worktree add .claude/worktrees/deps/pr-<N> pr-<N>
fiNever auto-remove worktrees from prior runs — they may be useful for the user post-audit. Worktree cleanup happens only after Phase 4 if the user approves.
Spawn one investigator per PR in a single message (multiple Agent tool calls together so
they run concurrently).
Each investigator is a one-shot Agent call (no team_name — Agent Teams are unnecessary here).
The investigator's job has two parts:
WebFetch / WebSearch. Read
release notes, changelog, and (if available) the GitHub compare view between the two versions.Agent call. The sub-agent reads the project root (not the worktree — current develop is the
real merge target). The investigator synthesizes upstream + codebase findings into one report.Pass the investigator everything it needs so it doesn't re-discover:
gh pr diff <N> --name-only before spawning)none — patchpath:line, authored by the sub-agentnoneLow / Medium / High + one-line justificationmerge as-is / merge with caveats (...) / hold (...)Include these flags in the prompt when applicable:
gradle/libs.versions.toml that touches the Kotlin compiler or Kotlin/Native, then check each
for compatibility. Do NOT pre-list dependencies for the investigator to verify — pre-listing
causes blind spots. SKIE specifically has been missed twice this way (2026-04-25, 2026-05-06);
check touchlab/SKIE releases and open issues
directly, not just variant attributes.0.x.y → 0.z.0): apply extra scrutiny — pre-1.0 minor bumps can break
source/binary API even on green CI. Explicitly check for renamed/relocated symbols that still
compile via deprecated aliases.The investigator constructs this and passes it to a nested Agent call:
develop checkout, not the worktree)import androidx.paging, PagingSource, Pager(, LazyPagingItems,
RemoteMediator, paging-compose)file:linefile:lineThe investigator returns a combined report. Word cap is the investigator's, not the sum.
After all investigators return, produce two artifacts in the response.
One row per PR. Columns:
| # | Bump | CI | Breaking changes | Codebase impact | Sequencing | Risk | Recommendation |Include every PR Phase 0 enumerated. No silent drops — if an investigator failed, surface the failure rather than omitting the row.
A numbered list, each entry naming the PR and a one-line rationale. Ordering rules (priority order):
BLOCKED tag — PRs flagged "hold" (CI blocker, breaking change requiring
code, awaiting upstream fix) sit at the end with the unblocking condition stated explicitly.State the why on every line. The user reads the rationale to override the order if needed.
Ask the user via AskUserQuestion what to do. Typical options to offer:
@dependabot rebase on stale-conflict PRsThe skill exits after presenting. Execution happens outside the skill — the user authorizes each action explicitly so per-action control is preserved. This is intentional; don't try to bundle "merge + push patch + comment" behind a single approval inside the skill.
These come from prior runs (sessions 3ae98b8c 2026-05-05 and the 2026-05-11 follow-up):
libs.versions.toml. Pre-listing causes blind spots (SKIE missed twice).[INVESTIGATOR FAILED] so the user sees it.© garfiec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/audit-deps of garfiec/Librechat-Mobile.
Open the folder on GitHubat commit bf2a609
Audit Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Deps this skillgarfiec/Librechat-Mobile | 111 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Codex CLIkortix-ai/suna | 20k | — | ~1.6k | Automated safety check: Pass | Custom licence | |
| DevSpace Manual QA SetupWaishnav/devspace | 5.2k | — | ~440 | Automated safety check: Pass | MIT | |
| Release Candidate Prepopenai/openai-agents-python | 30k | — | ~4.9k | Automated safety check: Pass | MIT | |
| Inference Format Optimizera2ui-project/a2ui | 17k | — | ~985 | Automated safety check: Pass | Apache-2.0 | |
| Live Extension UI Automationqixing-jk/all-api-hub | 4.9k | — | ~2.6k | Automated safety check: Pass | AGPL-3.0 |
kortix-ai/suna
Drive OpenAI's Codex CLI (codex exec) as a non-interactive coding sub-agent from inside Claude Code.
Waishnav/devspace
Prepares the current DevSpace checkout or worktree for isolated local manual QA, covering QA state seeding, UI asset builds and snapshot resets.
openai/openai-agents-python
Prepare a local Python SDK release candidate in a dedicated worktree.
a2ui-project/a2ui
Iterative benchmarking, evaluation, and algorithmic optimization of alternative A2UI inference formats (such as Express, Atom, and Elemental).
qixing-jk/all-api-hub
Control, debug, and test the live dev browser extension UI (Options, Popup, Sidepanel) via CDP with persistent login states and accounts.
Chachamaru127/claude-code-harness
Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.
garfiec/Librechat-Mobile
Add a hand-written Highlights section to a GitHub release whose notes were auto-generated, summarizing the release's PRs in user-facing language above the generated changelog.
garfiec/Librechat-Mobile
Update the third-party JavaScript vendored into the app for the artifact, diagram, and math WebViews (KaTeX, mermaid, marked, highlight.js, Tailwind, Babel, React).
garfiec/Librechat-Mobile
Audit localization / i18n coverage across the compose-resources surface (10 modules x 9 locales).
garfiec/Librechat-Mobile
Sync the Switchboard client with a newer official LibreChat server version — a stable release, a release candidate, or a PARTIAL sync up to an untagged upstream commit (e.g.
Categories
Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile. Audit Deps is an agent skill from garfiec/Librechat-Mobile. Audit open dependabot PRs in this repo.
Audit Deps fits situations like: dependabot has stacked up multiple open PRs and you want a structured pass before merging; tasks that involve Dependency management; tasks that involve Subagents.
Run `npx skills add garfiec/Librechat-Mobile --skill audit-deps -a claude-code`. Or copy the skill folder (.claude/skills/audit-deps in garfiec/Librechat-Mobile) into .claude/skills/audit-deps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add garfiec/Librechat-Mobile --skill audit-deps -a codex`. Or copy the skill folder (.claude/skills/audit-deps in garfiec/Librechat-Mobile) into .agents/skills/audit-deps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garfiec/Librechat-Mobile --skill audit-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-deps, .gemini/skills/audit-deps, .github/skills/audit-deps and .opencode/skills/audit-deps in your project.
Going by SKILL.md and its folder, Audit Deps needs the command-line tools its instructions call (git and gh). Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, WebFetch, WebSearch, Agent, TaskCreate, TaskUpdate, TaskList, AskUserQuestion.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Audit Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Deps: Codex CLI (kortix-ai/suna, 20k stars), DevSpace Manual QA Setup (Waishnav/devspace, 5.2k stars), Release Candidate Prep (openai/openai-agents-python, 30k stars) and Inference Format Optimizer (a2ui-project/a2ui, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
garfiec (a GitHub user) maintains it in garfiec/Librechat-Mobile, which has 111 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 10, 2026.
Source: garfiec/Librechat-Mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.