Agent skill

Dependency Update

by gocronx-team in gocronx-team/gocron

Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.

MITAuto-check passedDevelopment

Install Dependency Update

skills CLI
$ npx skills add gocronx-team/gocron --skill dependency-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gocronx-team/gocron dependency-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gocronx-team/gocron.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-update .claude/skills/dependency-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-update
GitHub stars
808
Token cost
~891 tokens
SKILL.md length
439 words
Files
2
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.

  • Root/admin/docs pnpm packages
  • SKILL.md covers Assess before changing, Apply the smallest update, Verify by ecosystem and Decide and report
  • Calls pnpm and go
  • Docker base images

What it does

Dependency Update is an agent skill from gocronx-team/gocron. Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests. Use for Go modules, root/admin/docs pnpm packages, GitHub Actions, Docker base images, security advisories, lockfile conflicts, or dependency update pull requests.

Its SKILL.md is about 890 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Dependency management. It works with Go, pnpm, Docker and GitHub Actions. The repository describes itself as: distributed scheduled task management system. The licence is MIT.

When your agent uses it

  • Root/admin/docs pnpm packages
  • Docker base images
  • Security advisories
  • Lockfile conflicts

Example prompts

  • “/dependency-update”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit e76e9da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Update loads about 891 tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 439 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~891

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gocronx-team/gocron at commit e76e9da, republished under its MIT licence (© gocronx-team). 439 words, ~891 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-update/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
dependency-update
description
Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests. Use for Go modules, root/admin/docs pnpm packages, GitHub Actions, Docker base images, security advisories, lockfile conflicts, or dependency update pull requests.

Update gocron dependencies

Handle one dependency group and ecosystem at a time unless a security fix requires coordinated versions. A request to inspect a PR or alert is read-only; merge, dismiss, commit, and push only when explicitly requested.

Assess before changing

  • Inspect the manifest and lockfile diff, release notes, advisory, dependency graph, and current CI status. Use primary upstream documentation.
  • Classify the update as patch, minor, major, security, development-only, build tooling, GitHub Action, or runtime/container.
  • Determine whether the dependency is direct, transitive, bundled into the frontend, shipped in the image, or used only in tests.
  • For security alerts, record the vulnerable range, fixed version, severity, reachable code path, and whether every affected workspace is updated.
  • Treat major updates, Go/toolchain changes, framework upgrades, database drivers, schedulers, RPC libraries, auth/crypto packages, and container bases as high risk even when the diff is small.

Never edit a lockfile by hand. Use the repository package manager and preserve its existing lockfile format. Do not silence peer dependency failures or add blanket advisory ignores to make a check green.

Apply the smallest update

Use the narrowest ecosystem command that updates the requested package and its required peers. Review the resulting diff for unrelated upgrades, install scripts, new transitive packages, license changes, and unexpected engine or Go version changes. Revert unrelated generated churn without discarding pre-existing user changes.

For a Dependabot PR, prefer checking out or updating its branch rather than reconstructing a different lockfile locally. If the branch is stale, rebase or regenerate only when the user authorized changes to that PR.

Show full SKILL.md (182 more words)Show less

Verify by ecosystem

  • Go runtime dependency: run go mod tidy, ensure go.mod and go.sum contain only expected changes, then run affected package tests with -race, go vet ./..., and govulncheck ./... when available.
  • Admin frontend: run pnpm --dir web/gocronx-admin build-only, pnpm --dir web/gocronx-admin exec vue-tsc --noEmit, and pnpm --dir web/gocronx-admin lint.
  • Docs: run pnpm --dir docs docs:build.
  • Root tooling: run the affected commit/lint hook command and verify the admin workspace lockfile was not unintentionally changed.
  • GitHub Action: validate YAML and inspect the referenced action's changelog and immutable tag/SHA policy.
  • Docker/base image: build Dockerfile.gocron and inspect architecture, runtime user, binary/library compatibility, and vulnerability scan results.

Run the relevant package tests even if the dependency is marked dev-only. Invoke $verify before merge for every code or lockfile update.

Decide and report

State the exact old/new versions, why the update is needed, runtime exposure, breaking-change review, manifest/lockfiles changed, audit result, checks run, and remaining risk. Recommend merge only when required checks are green and the diff contains no unexplained dependency churn.

If committing, use one single-line Conventional Commit subject under 100 characters and no Co-Authored-By, for example:

text
chore(deps): update vue to 3.6.0

© gocronx-team, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/dependency-update of gocronx-team/gocron.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit e76e9da

Compare with similar skills

Dependency Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Update this skillgocronx-team/gocron808—~891Automated safety check: PassMIT
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT
Audit And Reduce Dependenciesgrafana/skills279—~3.6kAutomated safety check: WarnApache-2.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Golang Continuous Integrationcontext-labs/whip1.1k—~3.5kAutomated safety check: PassMIT
Sync Dependabot App Depsossf/oss-crs165—~1.7kAutomated safety check: NotesMIT

Similar skills

  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Official

    Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

    279 GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

    165 GitHub stars~1.7k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Dependabot

    github/awesome-copilot

    Official

    Comprehensive guide for configuring and managing GitHub Dependabot.

    40k GitHub starsUsed in 1 repo~3.4k tokens
    DevelopmentAuto-check passed

More from gocronx-team/gocron

All 8 skills in this repo
  • Migration

    gocronx-team/gocron

    Create, review, or verify gocron database migrations across SQLite, MySQL, and PostgreSQL.

    808 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Security Check

    gocronx-team/gocron

    Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

    808 GitHub stars~690 tokensUpdated 5 days ago
    Auto-check passed
  • Scheduler Change

    gocronx-team/gocron

    Safely implement, diagnose, or review changes to gocron scheduling and task execution.

    808 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • API Feature

    gocronx-team/gocron

    Implement or review an end-to-end gocron HTTP API change. An agent skill from gocronx-team/gocron.

    808 GitHub stars~1.2k tokensUpdated 5 days ago
    Auto-check passed
  • Release

    gocronx-team/gocron

    Prepare or publish a safe gocron release by choosing a SemVer bump, updating AppVersion and migrations, invoking the complete verification gate, committing, checking CI, and creating an annotated tag.

    808 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Release

    gocronx-team/gocron

    Cut a gocron release — bump AppVersion, align the migration version id, run the full CI check locally, and tag only when everything is green.

    808 GitHub stars~586 tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Dependency Update

What does Dependency Update do?

Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests. Dependency Update is an agent skill from gocronx-team/gocron. Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.

When should I use Dependency Update?

Dependency Update fits situations like: root/admin/docs pnpm packages; Docker base images; security advisories; lockfile conflicts.

How do I install Dependency Update in Claude Code?

Run `npx skills add gocronx-team/gocron --skill dependency-update -a claude-code`. Or copy the skill folder (.agents/skills/dependency-update in gocronx-team/gocron) into .claude/skills/dependency-update in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Update in Codex?

Run `npx skills add gocronx-team/gocron --skill dependency-update -a codex`. Or copy the skill folder (.agents/skills/dependency-update in gocronx-team/gocron) into .agents/skills/dependency-update in your project. Codex loads it when a task matches its description.

Can I use Dependency Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gocronx-team/gocron --skill dependency-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-update, .gemini/skills/dependency-update, .github/skills/dependency-update and .opencode/skills/dependency-update in your project.

What does Dependency Update need to run?

Going by SKILL.md and its folder, Dependency Update needs the command-line tools its instructions call (pnpm and go). Our summary lists: Docker.

Does Dependency Update access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dependency Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Update use?

Dependency Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Update use?

About 891 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Update?

Skills that share tags, products or a category with Dependency Update: Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars), Audit And Reduce Dependencies (grafana/skills, 279 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Golang Continuous Integration (context-labs/whip, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Update?

gocronx-team (a GitHub organization) maintains it in gocronx-team/gocron, which has 808 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 2, 2026.

Source: gocronx-team/gocron on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.