Install the "update-deps" agent skill from https://github.com/github/rust-gems/tree/main/.github/skills/update-deps into .claude/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add github/rust-gems --skill update-deps -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "update-deps" agent skill from https://github.com/github/rust-gems/tree/main/.github/skills/update-deps into .agents/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add github/rust-gems --skill update-deps -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "update-deps" agent skill from https://github.com/github/rust-gems/tree/main/.github/skills/update-deps into .cursor/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add github/rust-gems --skill update-deps -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "update-deps" agent skill from https://github.com/github/rust-gems/tree/main/.github/skills/update-deps into .gemini/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
GitHub CLI
$ gh skill install github/rust-gems update-deps
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add github/rust-gems --skill update-deps -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "update-deps" agent skill from https://github.com/github/rust-gems/tree/main/.github/skills/update-deps into .github/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add github/rust-gems --skill update-deps -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "update-deps" agent skill from https://github.com/github/rust-gems/tree/main/.github/skills/update-deps into .opencode/skills/update-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-deps", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
update-deps
GitHub stars
134
Token cost
~2.7k tokens
SKILL.md length
1,058 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT
At a glance
Keep dependencies up-to-date. An agent skill from github/rust-gems.
Works in 9 steps: Assess repo state → Gather dependency intelligence → Create branch and apply updates → …
Tasks that involve Dependency management
SKILL.md covers Repository context, Workflow, Guidelines and Edge cases
Calls git, make and gh; reaches github.com
What it does
Update Deps is an agent skill from github/rust-gems, published by the product's own GitHub organization. Keep dependencies up-to-date. Discovers outdated deps via dependabot alerts/PRs, creates one PR per ecosystem, iterates until CI is green, then assigns for review.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. It works with GitHub and npm. The repository describes itself as: A collection of rust algorithms and data structures. The licence is MIT.
When your agent uses it
Tasks that involve Dependency management
Example prompts
“/update-deps”
Requirements
Node.js
Workflow steps
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 24cec2c. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
git
make
gh
cargo
npm
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
github.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Update Deps loads about 2.7k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 1,058 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~44
When it runs· the whole SKILL.md, loaded when a task matches
~2.7k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/update-deps/SKILL.md (or your agent's skills folder).
name
update-deps
description
Keep dependencies up-to-date. Discovers outdated deps via dependabot alerts/PRs, creates one PR per ecosystem, iterates until CI is green, then assigns for review.
user-invocable
true
Update Dependencies
Automate the full dependency update lifecycle: discover what's outdated, apply updates grouped by ecosystem, fix breakage, get CI green, and hand off for human review.
Repository context
This is a Rust workspace containing utility crates published to crates.io. All dependency update PRs target the main branch.
Dependabot is configured (.github/dependabot.yaml) to open PRs against main on the 2nd of each month. This skill gathers individual dependabot PRs, combines updates by ecosystem, fixes any breakage, gets CI green, and creates consolidated PRs for human review.
Crates in this workspace
Crate
Description
bpe
Fast byte-pair encoding
bpe-openai
OpenAI tokenizers built on bpe
geo_filters
Probabilistic cardinality estimation
string-offsets
UTF-8/UTF-16/Unicode position conversion (with WASM/JS bindings)
Deps declared per-crate; Cargo.lock at workspace root pins versions
github-actions
.github/workflows/
CI and publish workflows
npm
crates/string-offsets/js/
JS bindings for string-offsets (WASM)
Build and validation commands
bash
make build # cargo build --all-targets --all-features
make build-js # npm run compile in crates/string-offsets/js
make lint # cargo fmt --check + cargo clippy (deny warnings, forbid unwrap_used)
make test # cargo test + doc tests
CI runs on ubuntu-latest with the mold linker. The lint job depends on build.
Workflow
1. Assess repo state
Determine the repo identity and confirm the target branch.
For ecosystems without dependabot coverage or when running ad-hoc, use native tooling:
cargo:cargo update --dry-run
npm: find directories containing package.json, then run npm outdated --json || true in each (npm exits non-zero when updates exist)
Also fetch the advisory URLs for any security-related updates. Individual alert details are at https://github.com/{owner}/{repo}/security/dependabot/{alert_number}. Fetch alert numbers and GHSA IDs via:
Include both open and auto_dismissed/dismissed alerts — the update may resolve alerts in any state.
Cross-reference and group all updates by ecosystem. Present a summary to the user:
How many updates per ecosystem
Which have security alerts (with severity, GHSA IDs, and advisory links)
Which dependabot PRs already exist
Flag high-risk upgrades. Before proceeding, explicitly call out upgrades that carry elevated risk:
Major version bumps — likely contain breaking API changes
Packages with wide blast radius — for this repo, pay special attention to: serde, itertools, regex-automata, wasm-bindgen, criterion, and the Rust toolchain itself
Multiple major bumps in the same PR — each major bump multiplies the risk; consider splitting them
Present the risk assessment to the user and recommend which upgrades to include vs. defer. When in doubt, prefer a smaller, safe update over an ambitious one that might break.
3. Create branch and apply updates
For each selected ecosystem, starting from main:
bash
git checkout main
git pull origin main
git checkout -b deps/{ecosystem}-updates-$(date +%Y-%m-%d)
Apply updates using ecosystem-appropriate tooling:
cargo:
bash
cargo update
# For major bumps, edit Cargo.toml version constraints then:
cargo check
This is a Cargo workspace — always run from the repo root. All crate Cargo.toml files are in crates/. The Cargo.lock at the root is the single source of truth.
npm:
bash
cd crates/string-offsets/js
npm update
npm install
github-actions:
Parse workflow YAML files in .github/workflows/ for uses: directives
For each action with an outdated version (from dependabot PRs/alerts), update the SHA or version tag
Be careful to preserve comments and formatting
4. Build, lint, and test locally
Always run:
bash
make lint # cargo fmt --check + clippy with deny warnings
make test # cargo test with backtrace
make build # full workspace build (all targets, all features)
If npm dependencies changed:
bash
make build-js # npm compile for string-offsets JS binding
If the build/lint/test fails:
Read the error output carefully
Analyze what broke — likely API changes, type errors, or deprecation removals
Make the necessary code changes to fix the breakage
Run the pipeline again
Repeat up to 3 times
If still failing after 3 iterations, report the situation to the user and ask for guidance. Do not push broken code.
5. Commit and push
Stage all changes and commit with a descriptive message:
bash
git add -A
git commit -m "chore(deps): update {ecosystem} dependencies
Updated packages:
- package-a: 1.0.0 → 2.0.0
- package-b: 3.1.0 → 3.2.0
{If code changes were needed:}
Fixed breaking changes:
- Updated X API usage for package-a v2
Supersedes: #{dependabot_pr_1}, #{dependabot_pr_2}
"
List of updated dependencies with version changes (old → new)
Any security alerts resolved — for each, link to the specific dependabot alert (https://github.com/{owner}/{repo}/security/dependabot/{alert_number}) and the GHSA advisory (https://github.com/advisories/GHSA-xxxx-xxxx-xxxx), along with severity and summary
High-risk changes flagged for reviewer attention (major version bumps, wide-blast-radius packages)
Code changes made to fix breakage (if any)
References to superseded dependabot PRs
Note that this was generated by the update-deps skill
Write the body to a temp file and create the PR targeting main:
gh run list --branch {branch} --status failure --json databaseId,name --limit 1
gh run view {run_id} --log-failed
Analyze the failure — CI runs on ubuntu-latest with mold linker, which may differ from local builds.
Fix the issue locally, commit, and push:
bash
git add -A
git commit -m "fix: resolve CI failure in {ecosystem} dep update
{Brief description of what failed and why}"
git push
Monitor again. Repeat up to 3 iterations total.
If still failing after 3 pushes, report to the user with the failure details and ask for help.
8. Close superseded dependabot PRs
For each dependabot PR that this update supersedes:
bash
gh pr close {dependabot_pr_number} --comment "Superseded by #{new_pr_number} which includes this update along with other {ecosystem} dependency updates."
9. Assign for review
Request review from CODEOWNERS or a user-provided reviewer (not the PR author):
Report the final PR URL and a summary of what was done.
Guidelines
All PRs target main. There is no separate dev branch.
Never push to main directly. Always work on a feature branch.
Never push code that doesn't pass make lint and make test. If you can't fix it in 3 tries, stop and ask.
Be conservative with major version bumps. If a major version update breaks things and the fix isn't obvious, skip that package and note it in the PR description.
Regenerate lockfiles. Always regenerate Cargo.lock and package-lock.json after updating — don't just edit manifests.
One ecosystem at a time. Complete the full cycle (update → build → push → PR → CI green) for one ecosystem before moving to the next.
If no updates are needed for an ecosystem, skip it and tell the user.
Security alerts take priority. Address security alerts first within each ecosystem.
Clippy is strict. This repo forbids unwrap_used outside tests and denies all warnings. New dependency versions may trigger new clippy lints — fix them.
Edge cases
Cargo workspace: Dependencies are declared per-crate but share a single Cargo.lock at the workspace root. Always run cargo update and cargo check from the repo root.
npm: Look for package.json files to discover npm packages rather than hardcoding paths — the repo layout may change.
WASM builds: After updating wasm-bindgen or related deps, verify make build-js still works — WASM toolchain version mismatches are common.
Rate limits: If gh api hits rate limits, wait and retry. Report to user if persistent.
Nothing to update: Report cleanly and move to the next ecosystem (or exit).
Merge conflicts on push: Rebase on main and retry: git fetch origin main && git rebase origin/main.
Branch already exists: If deps/{ecosystem}-updates-{date} already exists, append a counter or ask user.
Update Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
Keep dependencies up-to-date. An agent skill from github/rust-gems. Update Deps is an agent skill from github/rust-gems, published by the product's own GitHub organization. Keep dependencies up-to-date.
When should I use Update Deps?
Update Deps fits situations like: tasks that involve Dependency management.
How do I install Update Deps in Claude Code?
Run `npx skills add github/rust-gems --skill update-deps -a claude-code`. Or copy the skill folder (.github/skills/update-deps in github/rust-gems) into .claude/skills/update-deps in your project. Claude Code loads it when a task matches its description.
How do I install Update Deps in Codex?
Run `npx skills add github/rust-gems --skill update-deps -a codex`. Or copy the skill folder (.github/skills/update-deps in github/rust-gems) into .agents/skills/update-deps in your project. Codex loads it when a task matches its description.
Can I use Update Deps in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/rust-gems --skill update-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-deps, .gemini/skills/update-deps, .github/skills/update-deps and .opencode/skills/update-deps in your project.
What does Update Deps need to run?
Going by SKILL.md and its folder, Update Deps needs the command-line tools its instructions call (git, make, gh, cargo and npm). Our summary lists: Node.js.
Does Update Deps access the network?
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Is Update Deps safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Update Deps use?
Update Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Update Deps use?
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Update Deps?
Skills that share tags, products or a category with Update Deps: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Dependabot Alerts Update (livesession/xyd, 114 stars), Fix Security PR (unional/typescript-blackbook, 133 stars) and Stash Supply Chain Security (cipherstash/stack, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Update Deps?
github (a GitHub organization, an official publisher) maintains it in github/rust-gems, which has 134 GitHub stars. The repository was last updated on October 6, 2026.
Source: github/rust-gems on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.