Official agent skill

Sponsor Finder

by github in github/awesome-copilot

Find which of a GitHub repository's dependencies are sponsorable via GitHub Sponsors.

OfficialMITAuto-check passedProductivity & Automation

Install Sponsor Finder

skills CLI
$ npx skills add github/awesome-copilot --skill sponsor-finder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot sponsor-finder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sponsor-finder .claude/skills/sponsor-finder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sponsor-finder
GitHub stars
40k
Used in
2 other repos
Token cost
~3k tokens
SKILL.md length
1,288 words
Files
1
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Find which of a GitHub repository's dependencies are sponsorable via GitHub Sponsors.

  • Works in 7 steps: Detect Ecosystem and Package → Get Full Dependency Tree (deps.dev) → Resolve Each Dependency to a GitHub Repo… → …
  • Tasks that involve Health and fitness tracking
  • SKILL.md covers Your Workflow, Step 1: Detect Ecosystem and…, Step 2: Get Full Dependency… and Step 3: Resolve Each…, plus 6 more sections
  • Reaches github.com and api.deps.dev

What it does

Sponsor Finder is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Find which of a GitHub repository's dependencies are sponsorable via GitHub Sponsors. Uses deps.dev API for dependency resolution across npm, PyPI, Cargo, Go, RubyGems, Maven, and NuGet. Checks npm funding metadata, FUNDING.yml files, and web search. Verifies every link. Shows direct and transitive dependencies with OSSF Scorecard health data. Invoke with /sponsor followed by a GitHub owner/repo (e.g. "/sponsor expressjs/express").

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Health and fitness tracking and Web search. It works with GitHub, npm, Ruby and Express. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Tasks that involve Health and fitness tracking
  • Tasks that involve Web search

Example prompts

  • “/sponsor expressjs/express”
  • “/sponsor-finder”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Detect Ecosystem and Package
  2. Get Full Dependency Tree (deps.dev)
  3. Resolve Each Dependency to a GitHub Repo (deps.dev)
  4. Get Project Health Data (deps.dev)
  5. Find Funding Links
  6. Verify Every Link (CRITICAL)
  7. Output the Report

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • api.deps.dev
    • opencollective.com
    • registry.npmjs.org
    • ko-fi.com
    • patreon.com
    • tidelift.com

    Also links to:

    • docs.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sponsor Finder loads about 3k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 1,288 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 1,288 words, ~2,991 tokens.

Download SKILL.mdSave it as .claude/skills/sponsor-finder/SKILL.md (or your agent's skills folder).
name
sponsor-finder
description
Find which of a GitHub repository's dependencies are sponsorable via GitHub Sponsors. Uses deps.dev API for dependency resolution across npm, PyPI, Cargo, Go, RubyGems, Maven, and NuGet. Checks npm funding metadata, FUNDING.yml files, and web search. Verifies every link. Shows direct and transitive dependencies with OSSF Scorecard health data. Invoke with /sponsor followed by a GitHub owner/repo (e.g. "/sponsor expressjs/express").

Sponsor Finder

Discover opportunities to support the open source maintainers behind your project's dependencies. Accepts a GitHub owner/repo (e.g. /sponsor expressjs/express), uses the deps.dev API for dependency resolution and project health data, and produces a friendly sponsorship report covering both direct and transitive dependencies.

Your Workflow

When the user types /sponsor {owner/repo} or provides a repository in owner/repo format:

  1. Parse the input — Extract owner and repo.
  2. Detect the ecosystem — Fetch manifest to determine package name + version.
  3. Get full dependency tree — deps.dev GetDependencies (one call).
  4. Resolve repos — deps.dev GetVersion for each dep → relatedProjects gives GitHub repo.
  5. Get project health — deps.dev GetProject for unique repos → OSSF Scorecard.
  6. Find funding links — npm funding field, FUNDING.yml, web search fallback.
  7. Verify every link — fetch each URL to confirm it's live.
  8. Group and report — by funding destination, sorted by impact.

Step 1: Detect Ecosystem and Package

Use get_file_contents to fetch the manifest from the target repo. Determine the ecosystem and extract the package name + latest version:

FileEcosystemPackage name fromVersion from
package.jsonNPMname fieldversion field
requirements.txtPYPIlist of package namesuse latest (omit version in deps.dev call)
pyproject.tomlPYPI[project.dependencies]use latest
Cargo.tomlCARGO[package] name[package] version
go.modGOmodule pathextract from go.mod
GemfileRUBYGEMSgem namesuse latest
pom.xmlMAVENgroupId:artifactIdversion

Step 2: Get Full Dependency Tree (deps.dev)

This is the key step. Use web_fetch to call the deps.dev API:

https://api.deps.dev/v3/systems/{ECOSYSTEM}/packages/{PACKAGE}/versions/{VERSION}:dependencies

For example:

https://api.deps.dev/v3/systems/npm/packages/express/versions/5.2.1:dependencies

This returns a nodes array where each node has:

  • versionKey.name — package name
  • versionKey.version — resolved version
  • relation — "SELF", "DIRECT", or "INDIRECT"

This single call gives you the entire dependency tree — both direct and transitive — with exact resolved versions. No need to parse lockfiles.

URL encoding

Package names containing special characters must be percent-encoded:

  • @colors/colors → %40colors%2Fcolors
  • Encode @ as %40, / as %2F
For repos without a single root package

If the repo doesn't publish a package (e.g., it's an app not a library), fall back to reading package.json dependencies directly and calling deps.dev GetVersion for each.


Step 3: Resolve Each Dependency to a GitHub Repo (deps.dev)

For each dependency from the tree, call deps.dev GetVersion:

https://api.deps.dev/v3/systems/{ECOSYSTEM}/packages/{NAME}/versions/{VERSION}

From the response, extract:

  • relatedProjects → look for relationType: "SOURCE_REPO" → projectKey.id gives github.com/{owner}/{repo}
  • links → look for label: "SOURCE_REPO" → url field

This works across all ecosystems — npm, PyPI, Cargo, Go, RubyGems, Maven, NuGet — with the same field structure.

Efficiency rules
  • Process in batches of 10 at a time.
  • Deduplicate — multiple packages may map to the same repo.
  • Skip deps where no GitHub project is found (count as "unresolvable").

Step 4: Get Project Health Data (deps.dev)

For each unique GitHub repo, call deps.dev GetProject:

https://api.deps.dev/v3/projects/github.com%2F{owner}%2F{repo}

From the response, extract:

  • scorecard.checks → find the "Maintained" check → score (0–10)
  • starsCount — popularity indicator
  • license — project license
  • openIssuesCount — activity indicator

Use the Maintained score to label project health:

  • Score 7–10 → ⭐ Actively maintained
  • Score 4–6 → ⚠️ Partially maintained
  • Score 0–3 → 💤 Possibly unmaintained
Efficiency rules
  • Only fetch for unique repos (not per-package).
  • Process in batches of 10 at a time.
  • This step is optional — skip if rate-limited and note in output.

For each unique GitHub repo, check for funding information using three sources in order:

5a: npm funding field (npm ecosystem only)

Use web_fetch on https://registry.npmjs.org/{package-name}/latest and check for a funding field:

  • String: "https://github.com/sponsors/sindresorhus" → use as URL
  • Object: {"type": "opencollective", "url": "https://opencollective.com/express"} → use url
  • Array: collect all URLs
5b: .github/FUNDING.yml (repo-level, then org-level fallback)

Step 5b-i — Per-repo check: Use get_file_contents to fetch {owner}/{repo} path .github/FUNDING.yml.

Step 5b-ii — Org/user-level fallback: If 5b-i returned 404 (no FUNDING.yml in the repo itself), check the owner's default community health repo: Use get_file_contents to fetch {owner}/.github path FUNDING.yml.

GitHub supports a default community health files convention: a .github repository at the user/org level provides defaults for all repos that lack their own. For example, isaacs/.github/FUNDING.yml applies to all isaacs/* repos.

Only look up each unique {owner}/.github repo once — reuse the result for all repos under that owner. Process in batches of 10 owners at a time.

Parse the YAML (same for both 5b-i and 5b-ii):

  • github: [username] → https://github.com/sponsors/{username}
  • open_collective: slug → https://opencollective.com/{slug}
  • ko_fi: username → https://ko-fi.com/{username}
  • patreon: username → https://patreon.com/{username}
  • tidelift: platform/package → https://tidelift.com/subscription/pkg/{platform-package}
  • custom: [urls] → use as-is
5c: Web search fallback

For the top 10 unfunded dependencies (by number of transitive dependents), use web_search:

"{package name}" github sponsors OR open collective OR funding

Skip packages known to be corporate-maintained (React/Meta, TypeScript/Microsoft, @types/DefinitelyTyped).

Efficiency rules
  • Check 5a and 5b for all deps. Only use 5c for top unfunded ones.
  • Skip npm registry calls for non-npm ecosystems.
  • Deduplicate repos — check each repo only once.
  • One {owner}/.github check per unique owner — reuse the result for all their repos.
  • Process org-level lookups in batches of 10 owners at a time.

Show full SKILL.md (521 more words)Show less

Before including ANY funding link, verify it exists.

Use web_fetch on each funding URL:

  • Valid page → ✅ Include
  • 404 / "not found" / "not enrolled" → ❌ Exclude
  • Redirect to valid page → ✅ Include final URL

Verify in batches of 5 at a time. Never present unverified links.


Step 7: Output the Report

Output discipline

Minimize intermediate output during data gathering. Do NOT announce each batch ("Batch 3 of 7…", "Now checking funding…"). Instead:

  • Show one brief status line when starting each major phase (e.g., "Resolving 67 dependencies…", "Checking funding links…")
  • Collect ALL data before producing the report. Never drip-feed partial tables.
  • Output the final report as a single cohesive block at the end.
Report template
## 💜 Sponsor Finder Report

**Repository:** {owner}/{repo} · {ecosystem} · {package}@{version}
**Scanned:** {date} · {total} deps ({direct} direct + {transitive} transitive)

---

### 🎯 Ways to Give Back

Sponsoring just {N} people/orgs supports {sponsorable} of your {total} dependencies — a great way to invest in the open source your project depends on.

1. **💜 @{user}** — {N} direct + {M} transitive deps · ⭐ Maintained
   {dep1}, {dep2}, {dep3}, ...
   https://github.com/sponsors/{user}

2. **🟠 Open Collective: {name}** — {N} direct + {M} transitive deps · ⭐ Maintained
   {dep1}, {dep2}, {dep3}, ...
   https://opencollective.com/{name}

3. **💜 @{user2}** — {N} direct dep · 💤 Low activity
   {dep1}
   https://github.com/sponsors/{user2}

---

### 📊 Coverage

- **{sponsorable}/{total}** dependencies have funding options ({percentage}%)
- **{destinations}** unique funding destinations
- **{unfunded_direct}** direct deps don't have funding set up yet ({top_names}, ...)
- All links verified ✅
Report format rules
  • Lead with "🎯 Ways to Give Back" — this is the primary output. Numbered list, sorted by total deps covered (descending).
  • Bare URLs on their own line — not wrapped in markdown link syntax. This ensures they're clickable in any terminal emulator.
  • Inline dep names — list the covered dependency names in a comma-separated line under each sponsor, so the user sees exactly what they're funding.
  • Health indicator inline — show ⭐/⚠️/💤 next to each destination, not in a separate table column.
  • One "📊 Coverage" section — compact stats. No separate "Verified Funding Links" table, no "No Funding Found" table.
  • Unfunded deps as a brief note — just the count + top names. Frame as "don't have funding set up yet" rather than highlighting a gap. Never shame projects for not having funding — many maintainers prefer other forms of contribution.
  • 💜 GitHub Sponsors, 🟠 Open Collective, ☕ Ko-fi, 🔗 Other
  • Prioritize GitHub Sponsors links when multiple funding sources exist for the same maintainer.

Error Handling

  • If deps.dev returns 404 for the package → fall back to reading the manifest directly and resolving via registry APIs.
  • If deps.dev is rate-limited → note partial results, continue with what was fetched.
  • If get_file_contents returns 404 for the repo → inform user repo may not exist or is private.
  • If link verification fails → exclude the link silently.
  • Always produce a report even if partial — never fail silently.

Critical Rules

  1. NEVER present unverified links. Fetch every URL before showing it. 5 verified links > 20 guessed links.
  2. NEVER guess from training knowledge. Always check — funding pages change over time.
  3. Always be encouraging, never shaming. Frame results positively — celebrate what IS funded, and treat unfunded deps as an opportunity, not a failing. Not every project needs or wants financial sponsorship.
  4. Lead with action. The "🎯 Ways to Give Back" section is the primary output — bare clickable URLs, grouped by destination.
  5. Use deps.dev as primary resolver. Fall back to registry APIs only if deps.dev is unavailable.
  6. Always use GitHub MCP tools (get_file_contents), web_fetch, and web_search — never clone or shell out.
  7. Be efficient. Batch API calls, deduplicate repos, check each owner's .github repo only once.
  8. Focus on GitHub Sponsors. Most actionable platform — show others but prioritize GitHub.
  9. Deduplicate by maintainer. Group to show real impact of sponsoring one person.
  10. Show the actionable minimum. Tell users the fewest sponsorships to support the most deps.
  11. Minimize intermediate output. Don't announce each batch. Collect all data, then output one cohesive report.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sponsor-finder of github/awesome-copilot.

Open the folder on GitHubat commit 727ff2e

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in github/awesome-copilot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sponsor Finder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sponsor Finder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sponsor Finder this skillgithub/awesome-copilot40k2 repos~3kAutomated safety check: PassMIT
Review Dependenciestobihagemann/turbo406—~1.5kAutomated safety check: PassMIT
Browser SearchJohell1NS/browser-search528—~2.5kAutomated safety check: PassMIT
Agent ReachEdisonChenAI/agent-reach1041 repos~1.3kAutomated safety check: PassMIT
Mysearchskernelx/MySearch-Proxy159—~1.4kAutomated safety check: NotesMIT
Z.AI CLInumman-ali/zai-cli110—~528Automated safety check: PassMIT

Similar skills

  • Review Dependencies

    tobihagemann/turbo

    Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

    406 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Browser Search

    Johell1NS/browser-search

    Multi-engine web search (SearXNG) + browsing/scraping (Camofox, CloakBrowser).

    528 GitHub stars~2.5k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Agent Reach

    EdisonChenAI/agent-reach

    Use the internet: search, read, and interact with 13+ platforms including Twitter/X, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu (小红书), Douyin (抖音), WeChat Articles (微信公众号), LinkedIn, Boss直聘…

    104 GitHub starsUsed in 1 repo~1.3k tokens
    Productivity & AutomationAuto-check passed
  • Mysearch

    skernelx/MySearch-Proxy

    DEFAULT search skill for OpenClaw. An agent skill from skernelx/MySearch-Proxy.

    159 GitHub stars~1.4k tokensUpdated 6 mo ago
    Productivity & AutomationAuto-check: notes
  • Z.AI CLI

    numman-ali/zai-cli

    Command-line access to Z.AI vision analysis, web search, page reading and GitHub repo exploration through npx zai-cli, using an API key.

    110 GitHub stars~528 tokensUpdated 9 mo ago
    Productivity & AutomationAuto-check passed
  • Pi Web Search

    sickn33/agentic-awesome-skills

    Give Pi Agents a safe web-search and fetch workflow using the installed pi-web-access package.

    47k GitHub starsUsed in 1 repo~925 tokens
    Productivity & AutomationAuto-check passed

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Sponsor Finder

What does Sponsor Finder do?

Find which of a GitHub repository's dependencies are sponsorable via GitHub Sponsors. Sponsor Finder is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Find which of a GitHub repository's dependencies are sponsorable via GitHub Sponsors.

When should I use Sponsor Finder?

Sponsor Finder fits situations like: tasks that involve Health and fitness tracking; tasks that involve Web search.

How do I install Sponsor Finder in Claude Code?

Run `npx skills add github/awesome-copilot --skill sponsor-finder -a claude-code`. Or copy the skill folder (skills/sponsor-finder in github/awesome-copilot) into .claude/skills/sponsor-finder in your project. Claude Code loads it when a task matches its description.

How do I install Sponsor Finder in Codex?

Run `npx skills add github/awesome-copilot --skill sponsor-finder -a codex`. Or copy the skill folder (skills/sponsor-finder in github/awesome-copilot) into .agents/skills/sponsor-finder in your project. Codex loads it when a task matches its description.

Can I use Sponsor Finder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill sponsor-finder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sponsor-finder, .gemini/skills/sponsor-finder, .github/skills/sponsor-finder and .opencode/skills/sponsor-finder in your project.

What does Sponsor Finder need to run?

SKILL.md names no scripts, command-line tools or credentials: Sponsor Finder is instructions for the agent only.

Does Sponsor Finder access the network?

SKILL.md names 8 domains. In commands or code: github.com, api.deps.dev, opencollective.com, registry.npmjs.org, ko-fi.com, patreon.com and tidelift.com; the agent is likely to contact these when it follows the instructions. As links in the text: docs.github.com. This is read from the text; nothing was executed.

Is Sponsor Finder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sponsor Finder use?

Sponsor Finder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sponsor Finder use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sponsor Finder?

Skills that share tags, products or a category with Sponsor Finder: Review Dependencies (tobihagemann/turbo, 406 stars), Browser Search (Johell1NS/browser-search, 528 stars), Agent Reach (EdisonChenAI/agent-reach, 104 stars) and Mysearch (skernelx/MySearch-Proxy, 159 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sponsor Finder?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.