Agent skill

Audit Deps

by garfiec in garfiec/Librechat-Mobile

Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.

MITAuto-check: notesDevelopment

Install Audit Deps

skills CLI
$ npx skills add garfiec/Librechat-Mobile --skill audit-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garfiec/Librechat-Mobile audit-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/garfiec/Librechat-Mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-deps .claude/skills/audit-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-deps
GitHub stars
111
Token cost
~2.4k tokens
SKILL.md length
1,151 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.

  • Works in 5 steps: Discovery → Worktree setup → Parallel investigation → …
  • Dependabot has stacked up multiple open PRs and you want a structured pass before merging
  • SKILL.md covers Phase 0 — Discovery, Phase 1 — Worktree setup, Phase 2 — Parallel investigation and Phase 3 — Synthesis and…, plus 2 more sections
  • Calls git and gh

What it does

Audit Deps is an agent skill from garfiec/Librechat-Mobile. Audit open dependabot PRs in this repo. Spawns one investigator per PR (each with a codebase-walk sub-agent), produces a comparison table with per-PR risk + recommendation, and proposes a merge order that minimizes rebase churn. Audit-only — stops at recommendations; user authorizes execution. Use when dependabot has stacked up multiple open PRs and you want a structured pass before merging.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Subagents and Git worktrees. It works with OpenAI and Kotlin. The repository describes itself as: Native Android & iOS client for LibreChat, built with Kotlin Multiplatform and Compose Multiplatform. The licence is MIT.

When your agent uses it

  • Dependabot has stacked up multiple open PRs and you want a structured pass before merging
  • Tasks that involve Dependency management
  • Tasks that involve Subagents

Example prompts

  • “/audit-deps”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Glob, Grep, WebFetch, WebSearch, Agent, TaskCreate, TaskUpdate, TaskList, AskUserQuestion

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Discovery
  2. Worktree setup
  3. Parallel investigation
  4. Synthesis and merge-order proposal
  5. User authorization

What it can do on your machine

Read from SKILL.md and the folder at commit bf2a609. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Glob
    • Grep
    • WebFetch
    • WebSearch
    • Agent
    • TaskCreate
    • TaskUpdate
    • TaskList

    …and 1 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Deps loads about 2.4k tokens when it runs. Until then it costs about 101 tokens; SKILL.md has 1,151 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Glob, Grep, WebFetch, WebSearch, Agent, TaskCreate, TaskUpdate, TaskList, AskUserQuestio

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garfiec/Librechat-Mobile at commit bf2a609, republished under its MIT licence (© garfiec). 1,151 words, ~2,374 tokens.

Download SKILL.mdSave it as .claude/skills/audit-deps/SKILL.md (or your agent's skills folder).
name
audit-deps
description
Audit open dependabot PRs in this repo. Spawns one investigator per PR (each with a codebase-walk sub-agent), produces a comparison table with per-PR risk + recommendation, and proposes a merge order that minimizes rebase churn. Audit-only — stops at recommendations; user authorizes execution. Use when dependabot has stacked up multiple open PRs and you want a structured pass before merging.
allowed-tools
Bash, Read, Glob, Grep, WebFetch, WebSearch, Agent, TaskCreate, TaskUpdate, TaskList, AskUserQuestion
argument-hint
[pr-number ...] (optional, defaults to all open dependabot PRs)

Audit Dependabot PRs

Audit open dependabot PRs and propose a safe merge order.

You are the team lead. You orchestrate. You do NOT read source code or run grep yourself during investigation — every codebase walk goes through a sub-agent inside a per-PR investigator. You handle GitHub queries, worktree setup, synthesis, and the merge-order proposal.

The skill is audit-only. It never merges, pushes, comments on PRs, or removes worktrees. It ends by presenting findings + a proposed sequence and asking the user what to do next.

Phase 0 — Discovery

Args: an optional list of PR numbers (/audit-deps 77 78 79). If omitted, audit every open dependabot PR.

Run once:

bash
gh pr list --state open --json number,title,headRefName,author,createdAt,mergeable,statusCheckRollup \
  --jq '.[] | select(.author.login=="app/dependabot" or (.headRefName | startswith("dependabot/")))'

If args were passed, narrow to those PR numbers. From each PR object extract:

  • PR number, title, head ref
  • mergeable state (MERGEABLE / CONFLICTING / UNKNOWN)
  • statusCheckRollup — count and roll up to "all green" / "N failing"
  • Age in days (today − createdAt)

If the result is empty, exit early with a one-line message — no work to do.

If any PR has CONFLICTING AND age > 7 days, note it as "stale-conflict — rebase candidate" but do NOT trigger a rebase. Rebase decisions belong to Phase 4 (user authorization).

State briefly to the user what you found before moving on:

Found N open dependabot PRs: #77 paging, #78 AGP 9.2.1, #79 kotlinx-datetime. Setting up worktrees.

Phase 1 — Worktree setup

Project worktree convention: .claude/worktrees/deps/pr-<N> on a local branch named pr-<N>.

For each PR:

bash
# fetch dependabot branch as local pr-<N>
git fetch origin <head-ref>:pr-<N>

# create worktree (or refresh if it exists from a prior audit run)
if [ -d ".claude/worktrees/deps/pr-<N>" ]; then
  git -C .claude/worktrees/deps/pr-<N> fetch origin
  git -C .claude/worktrees/deps/pr-<N> reset --hard pr-<N>
else
  git worktree add .claude/worktrees/deps/pr-<N> pr-<N>
fi

Never auto-remove worktrees from prior runs — they may be useful for the user post-audit. Worktree cleanup happens only after Phase 4 if the user approves.

Phase 2 — Parallel investigation

Spawn one investigator per PR in a single message (multiple Agent tool calls together so they run concurrently).

Each investigator is a one-shot Agent call (no team_name — Agent Teams are unnecessary here). The investigator's job has two parts:

  1. Upstream research — the investigator does this itself via WebFetch / WebSearch. Read release notes, changelog, and (if available) the GitHub compare view between the two versions.
  2. Codebase impact — the investigator MUST delegate this to a nested sub-agent via its own Agent call. The sub-agent reads the project root (not the worktree — current develop is the real merge target). The investigator synthesizes upstream + codebase findings into one report.
Investigator prompt template

Pass the investigator everything it needs so it doesn't re-discover:

  • PR number, worktree path, project root path
  • Exact files changed in the PR (extract from gh pr diff <N> --name-only before spawning)
  • CI status rollup from Phase 0 (don't make the investigator re-fetch)
  • Targeted WebFetch URLs — release notes, changelog, GitHub compare view
  • Word cap on the report (250–400 depending on bump complexity)
  • Required report fields:
    • Breaking changes: bullet list, or none — patch
    • Codebase impact: file count + specific call sites with path:line, authored by the sub-agent
    • Sequencing constraints: e.g., "requires Gradle 9.5+ — depends on PR #76", or none
    • Risk: Low / Medium / High + one-line justification
    • Recommendation: merge as-is / merge with caveats (...) / hold (...)

Include these flags in the prompt when applicable:

  • Kotlin/KMP bump (Kotlin, AGP, Compose, KSP, Ktor, Koin, serialization, SKIE, mokkery, anything hooking the K2 compiler): the investigator MUST first enumerate every plugin in gradle/libs.versions.toml that touches the Kotlin compiler or Kotlin/Native, then check each for compatibility. Do NOT pre-list dependencies for the investigator to verify — pre-listing causes blind spots. SKIE specifically has been missed twice this way (2026-04-25, 2026-05-06); check touchlab/SKIE releases and open issues directly, not just variant attributes.
  • Pre-1.0 minor bump (0.x.y → 0.z.0): apply extra scrutiny — pre-1.0 minor bumps can break source/binary API even on green CI. Explicitly check for renamed/relocated symbols that still compile via deprecated aliases.
  • AGP bump: if the release notes touch R8, proguard, manifest merger, or lint, the recommendation must include "release-build smoke test (login → conversations → chat)" as a caveat.
Sub-agent prompt template (codebase walk)

The investigator constructs this and passes it to a nested Agent call:

  • Project root path (the live develop checkout, not the worktree)
  • A grep list specific to the library — symbols, imports, common type names, build-script keys (e.g., for paging: import androidx.paging, PagingSource, Pager(, LazyPagingItems, RemoteMediator, paging-compose)
  • The new API surface and any deprecations from the upstream changelog the investigator just fetched (so the sub-agent knows which call sites are at risk)
  • Report format:
    • File count: how many files touch this library?
    • Call sites: list with file:line
    • Deprecation/removal exposure: which call sites use APIs flagged by the upstream changelog as changed/deprecated/removed, with explicit file:line
    • KMP source-set coverage: does usage live in commonMain, androidMain, iosMain, or tests?
    • Word cap: 200 words

The investigator returns a combined report. Word cap is the investigator's, not the sum.

Show full SKILL.md (397 more words)Show less

Phase 3 — Synthesis and merge-order proposal

After all investigators return, produce two artifacts in the response.

1. Comparison table

One row per PR. Columns:

| # | Bump | CI | Breaking changes | Codebase impact | Sequencing | Risk | Recommendation |

Include every PR Phase 0 enumerated. No silent drops — if an investigator failed, surface the failure rather than omitting the row.

2. Proposed merge order

A numbered list, each entry naming the PR and a one-line rationale. Ordering rules (priority order):

  1. Independent green low-risk first — CI-green + Low risk + no sequencing constraints. These are warm-ups; merging them first reduces rebase churn for everything that follows.
  2. Respect sequencing constraints — if PR B requires PR A (e.g., Gradle ≥ 9.5 → AGP), A goes first.
  3. Config-patch-needed last among non-blocked — PRs that need a small config tweak alongside the bump (detekt rule overrides, proguard addition, etc.) sit at the end of the non-blocked set, so green PRs don't get gated behind config work.
  4. Hold last with a BLOCKED tag — PRs flagged "hold" (CI blocker, breaking change requiring code, awaiting upstream fix) sit at the end with the unblocking condition stated explicitly.

State the why on every line. The user reads the rationale to override the order if needed.

Phase 4 — User authorization

Ask the user via AskUserQuestion what to do. Typical options to offer:

  • Merge all green / merge a subset
  • Push config patch for PR #X (if applicable)
  • Trigger @dependabot rebase on stale-conflict PRs
  • Hold all (leave PRs untouched, exit)
  • Cancel

The skill exits after presenting. Execution happens outside the skill — the user authorizes each action explicitly so per-action control is preserved. This is intentional; don't try to bundle "merge + push patch + comment" behind a single approval inside the skill.

Anti-patterns to avoid

These come from prior runs (sessions 3ae98b8c 2026-05-05 and the 2026-05-11 follow-up):

  • Don't pre-list dependencies for the investigator to check. Make them enumerate from libs.versions.toml. Pre-listing causes blind spots (SKIE missed twice).
  • Don't trust "CI green" to mean "safe" for pre-1.0 minor bumps. Deprecated aliases still compile; flag them anyway.
  • Don't auto-trigger rebases or auto-merge. Both are user-authorized actions even when "the fix is obvious." The cost of pausing is low; the cost of a wrong auto-merge is high.
  • Don't drop a PR from the table if the investigator failed. Surface the failure as a row marked [INVESTIGATOR FAILED] so the user sees it.
  • Don't read source files yourself as the team lead. Codebase walks always go through the per-PR investigator's sub-agent.

© garfiec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-deps of garfiec/Librechat-Mobile.

Open the folder on GitHubat commit bf2a609

Compare with similar skills

Audit Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Deps this skillgarfiec/Librechat-Mobile111—~2.4kAutomated safety check: NotesMIT
Codex CLIkortix-ai/suna20k—~1.6kAutomated safety check: PassCustom licence
DevSpace Manual QA SetupWaishnav/devspace5.2k—~440Automated safety check: PassMIT
Release Candidate Prepopenai/openai-agents-python30k—~4.9kAutomated safety check: PassMIT
Inference Format Optimizera2ui-project/a2ui17k—~985Automated safety check: PassApache-2.0
Live Extension UI Automationqixing-jk/all-api-hub4.9k—~2.6kAutomated safety check: PassAGPL-3.0

Similar skills

  • Codex CLI

    kortix-ai/suna

    Drive OpenAI's Codex CLI (codex exec) as a non-interactive coding sub-agent from inside Claude Code.

    20k GitHub stars~1.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • DevSpace Manual QA Setup

    Waishnav/devspace

    Prepares the current DevSpace checkout or worktree for isolated local manual QA, covering QA state seeding, UI asset builds and snapshot resets.

    5.2k GitHub stars~440 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release Candidate Prep

    openai/openai-agents-python

    Official

    Prepare a local Python SDK release candidate in a dedicated worktree.

    30k GitHub stars~4.9k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Iterative benchmarking, evaluation, and algorithmic optimization of alternative A2UI inference formats (such as Express, Atom, and Elemental).

    17k GitHub stars~985 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Live Extension UI Automation

    qixing-jk/all-api-hub

    Control, debug, and test the live dev browser extension UI (Options, Popup, Sidepanel) via CDP with persistent login states and accounts.

    4.9k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 6 days ago
    DevelopmentAuto-check: notes

More from garfiec/Librechat-Mobile

  • Release Highlights

    garfiec/Librechat-Mobile

    Add a hand-written Highlights section to a GitHub release whose notes were auto-generated, summarizing the release's PRs in user-facing language above the generated changelog.

    111 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Update Web Assets

    garfiec/Librechat-Mobile

    Update the third-party JavaScript vendored into the app for the artifact, diagram, and math WebViews (KaTeX, mermaid, marked, highlight.js, Tailwind, Babel, React).

    111 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • Audit I18n

    garfiec/Librechat-Mobile

    Audit localization / i18n coverage across the compose-resources surface (10 modules x 9 locales).

    111 GitHub stars~7.2k tokensUpdated yesterday
    Auto-check: notes
  • Sync Upstream

    garfiec/Librechat-Mobile

    Sync the Switchboard client with a newer official LibreChat server version — a stable release, a release candidate, or a PARTIAL sync up to an untagged upstream commit (e.g.

    111 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about Audit Deps

What does Audit Deps do?

Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile. Audit Deps is an agent skill from garfiec/Librechat-Mobile. Audit open dependabot PRs in this repo.

When should I use Audit Deps?

Audit Deps fits situations like: dependabot has stacked up multiple open PRs and you want a structured pass before merging; tasks that involve Dependency management; tasks that involve Subagents.

How do I install Audit Deps in Claude Code?

Run `npx skills add garfiec/Librechat-Mobile --skill audit-deps -a claude-code`. Or copy the skill folder (.claude/skills/audit-deps in garfiec/Librechat-Mobile) into .claude/skills/audit-deps in your project. Claude Code loads it when a task matches its description.

How do I install Audit Deps in Codex?

Run `npx skills add garfiec/Librechat-Mobile --skill audit-deps -a codex`. Or copy the skill folder (.claude/skills/audit-deps in garfiec/Librechat-Mobile) into .agents/skills/audit-deps in your project. Codex loads it when a task matches its description.

Can I use Audit Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garfiec/Librechat-Mobile --skill audit-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-deps, .gemini/skills/audit-deps, .github/skills/audit-deps and .opencode/skills/audit-deps in your project.

What does Audit Deps need to run?

Going by SKILL.md and its folder, Audit Deps needs the command-line tools its instructions call (git and gh). Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, WebFetch, WebSearch, Agent, TaskCreate, TaskUpdate, TaskList, AskUserQuestion.

Does Audit Deps access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Audit Deps safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Audit Deps use?

Audit Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Deps use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Deps?

Skills that share tags, products or a category with Audit Deps: Codex CLI (kortix-ai/suna, 20k stars), DevSpace Manual QA Setup (Waishnav/devspace, 5.2k stars), Release Candidate Prep (openai/openai-agents-python, 30k stars) and Inference Format Optimizer (a2ui-project/a2ui, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Deps?

garfiec (a GitHub user) maintains it in garfiec/Librechat-Mobile, which has 111 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 10, 2026.

Source: garfiec/Librechat-Mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.