Official agent skill

Audit And Reduce Dependencies

by grafana in grafana/skills

Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

OfficialApache-2.0Auto-check: warningsDevOps & Cloud

Install Audit And Reduce Dependencies

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add grafana/skills --skill audit-and-reduce-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills audit-and-reduce-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-plugins/audit-and-reduce-dependencies .claude/skills/audit-and-reduce-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-and-reduce-dependencies
GitHub stars
282
Token cost
~3.6k tokens
SKILL.md length
1,680 words
Files
1
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

  • Works in 8 steps: Hardening gate (/check-npm) → Baseline → Remove unused direct dependencies → …
  • Cleaning up pnpm dependencies
  • SKILL.md covers Workflow, Step 0: Hardening gate…, Dependency triage and pnpm & supply-chain, plus 9 more sections
  • Calls pnpm, git and curl; reaches registry.npmjs.org

What it does

Audit And Reduce Dependencies is an agent skill from grafana/skills, published by the product's own GitHub organization. Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style. Runs /check-npm first, then removes unused deps, dedupes versions, ranks transitive closure, and reports Keep/Replace/Remove triage. Use when cleaning up pnpm dependencies, reducing lockfile size, or shrinking nodemodules in Grafana plugins; not for Go modules or full GitHub Actions workflow audits.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Monitoring and alerting, Dependency management and CI/CD. It works with Grafana, pnpm, npm and GitHub Actions. The licence is Apache-2.0.

When your agent uses it

  • Cleaning up pnpm dependencies
  • Reducing lockfile size
  • Shrinking nodemodules in Grafana plugins
  • Not for Go modules

Example prompts

  • “Use the audit-and-reduce-dependencies skill to reduce JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and…”
  • “/audit-and-reduce-dependencies”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Hardening gate (/check-npm)
  2. Baseline
  3. Remove unused direct dependencies
  4. Deduplicate monorepo direct versions
  5. Rank transitive lockfile closure
  6. Find low-risk high-impact upgrades
  7. Inline trivial usage
  8. Apply e18e guidance

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • git
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org

    Also links to:

    • e18e.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit And Reduce Dependencies loads about 3.6k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 1,680 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:35
    do not weaken** `pnpm-workspace.yaml`, `.npmrc`, CI install flags, or Renovate age gates during cleanup.
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:39
    icy live in `pnpm-workspace.yaml`, not `.npmrc` or `package.json#pnpm` (pnpm 11 no longer reads the `package.json#pnpm`
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:106
    `allowBuilds`), and install policy in `.npmrc` / CI flags (e.g. `--frozen-lockfile`, `--ignore-scripts`).

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 1,680 words, ~3,563 tokens.

Download SKILL.mdSave it as .claude/skills/audit-and-reduce-dependencies/SKILL.md (or your agent's skills folder).
name
audit-and-reduce-dependencies
description
Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style. Runs /check-npm first, then removes unused deps, dedupes versions, ranks transitive closure, and reports Keep/Replace/Remove triage. Use when cleaning up pnpm dependencies, reducing lockfile size, or shrinking node_modules in Grafana plugins; not for Go modules or full GitHub Actions workflow audits.
license
Apache-2.0

Audit and reduce dependencies

Reduce JavaScript dependency footprint. Use pnpm only. Preserve the lockfile, workspace layout, and dependency range style unless there is a concrete reason to change them.

For GitHub Actions workflow triage (action choice, permissions, pinning), use a dedicated workflow audit — not the reporting format below (workflow file + step only when the finding is pnpm install policy).

Workflow

  1. Hardening gate: run /check-npm (read-only). See check-npm.
  2. Establish the baseline.
  3. Remove unused direct dependencies.
  4. Deduplicate direct dependency versions in monorepos.
  5. Rank direct dependencies by transitive lockfile closure.
  6. Use closure data to find low-risk minor/patch upgrades.
  7. Use closure data to find trivial dependencies worth inlining.
  8. Check e18e recommendations for replacements/removals.
  9. Reinstall, verify, and report measured impact.

Step 0: Hardening gate (/check-npm)

Run /check-npm before mutating manifests or lockfiles.

  • If any check FAILs: report the table and fix snippets; do not weaken pnpm-workspace.yaml, .npmrc, CI install flags, or Renovate age gates during cleanup.
  • Do not paste full hardening config into this workflow — /check-npm owns version thresholds, script policy, git-dep protocols, and min release age.
  • If the user only asked for hardening (not reduction), stop after /check-npm unless they also want cleanup.

pnpm 11+: script and release-age policy live in pnpm-workspace.yaml, not .npmrc or package.json#pnpm (pnpm 11 no longer reads the package.json#pnpm field). Verify each key against the installed pnpm major before suggesting config. Never add unsupported keys. Do not lower an existing minimumReleaseAge (or org equivalent) during cleanup.

Dependency triage

For each non-trivial direct dependency (especially after Steps 4–7), assign one label:

LabelMeaning
KeepRequired; worthwhile transitive cost; well maintained.
Replace-with-BetterRequired; better-maintained or safer alternative exists.
Replace-with-InternalRequired; external risk warrants internal implementation.
RemoveCan drop or inline (Step 6).
Needs-user-reviewAmbiguous usage, policy tradeoff, or change needing human verification.

Replacements and new direct deps

  • No new direct dependencies (including swaps) without explicit user approval.
  • Prefer Remove (inline/native APIs) over Replace-with-Better when equivalent.
  • For Replace-with-Better: state why (maintenance, security, smaller tree); prefer actively maintained, widely adopted packages from trusted maintainers.
  • Respect repo minimumReleaseAge / Renovate gates; command-level 72h freshness is a floor, not permission to bypass stricter config.

pnpm & supply-chain

Confirm the repo uses pnpm: pnpm-lock.yaml, pnpm-workspace.yaml, and/or packageManager / devEngines.packageManager.name set to pnpm in root package.json. If not on pnpm, stop — do not migrate package managers as part of cleanup.

Respect repo install policy when present (e.g. pnpm install --frozen-lockfile --ignore-scripts).

ActionCommand
Install/update lockfilepnpm install --ignore-scripts (+ repo flags, e.g. --frozen-lockfile)
Remove direct dependencypnpm remove <pkg> --ignore-scripts
Add/update direct dependencypnpm add <pkg>@<version> --ignore-scripts
Explain dependencypnpm why <pkg>
Dedupe lockfilepnpm dedupe (then pnpm install --ignore-scripts if lockfile changed)
Outdated / version infopnpm outdated <pkg>
One-off toolspnpm --config.ignore-scripts=true dlx <pkg>@<version> <args...> (pin version; prefer pnpm exec when in lockfile)

Lifecycle scripts: Always --ignore-scripts on pnpm install, pnpm add, and pnpm remove unless the user explicitly writes allow scripts in the same message (state which scripts would run and the risk). For pnpm dlx, dlx does not accept --ignore-scripts directly — use pnpm --config.ignore-scripts=true dlx (flags after dlx are forwarded to the executed binary). If a dependency legitimately needs a build script (native modules, etc.), finish without scripts, then ask whether to run a specific manual rebuild (e.g. pnpm rebuild <pkg>).

Freshness check (≥ 72 hours) — required before any command that adds or upgrades a named package version (pnpm add, pnpm dlx with new/upgraded direct version). Not required for plain pnpm install / pnpm remove with no new package argument.

For each directly named package:

  1. curl -s https://registry.npmjs.org/<package-name>
  2. Resolve version: pinned pkg@1.2.3 → that version; range/latest/unspecified → dist-tags.latest
  3. Read time["<version>"]
  4. If published less than 72 hours ago → stop. Tell the user package, version, and exact age. Suggest an older known-good pin unless they write override freshness check.
  5. @grafana/* scoped packages are exempt from the freshness check; --ignore-scripts still applies.

After a failed freshness check, do not substitute a different version without user approval.

Safety rules

  • Work in small batches so lockfile diffs remain reviewable.
  • Never trust unused-dependency tools blindly; verify imports, config files, scripts, generated code hooks, framework conventions, plugin names, CLIs, and dynamic imports.
  • You may write scripting and parsing to verify package.json and lockfile dependency accounts.
  • Treat peerDependencies, optionalDependencies, package bin usage, test fixtures, and published package manifests as higher risk.
  • Do not remove or inline dependencies used for security, parsing, crypto, Unicode, URL handling, date/time, i18n, or platform compatibility unless the replacement is proven equivalent.
  • Do not switch package managers, delete pnpm-lock.yaml, or rewrite workspace structure as part of cleanup.
  • Treat pnpm dedupe as potentially behavior-changing; inspect lockfile diffs and run focused verification before keeping the result.
  • Measure before and after: direct dependency count, lockfile line count or entry count, package count, and estimated node_modules size when available.

Step 1: Baseline

Collect:

  • All package.json files and workspace boundaries (pnpm-workspace.yaml).
  • pnpm-lock.yaml, pnpm-workspace.yaml security settings (minimumReleaseAge, strictDepBuilds, blockExoticSubdeps, allowBuilds), and install policy in .npmrc / CI flags (e.g. --frozen-lockfile, --ignore-scripts).
  • Direct dependency names by manifest section: dependencies, devDependencies, peerDependencies, optionalDependencies.
  • Existing verification commands from scripts, CI, or repo docs.
  • CI spot-check (.github/workflows or equivalent): installs should use pnpm install --frozen-lockfile and script blocking consistent with workspace config. Flag workflows that regenerate lockfiles on every run.
  • Renovate / Dependabot (if present): note minimumReleaseAge for npm packages; do not reduce it during cleanup.

Record baseline metrics: git status --short, wc -l pnpm-lock.yaml. If node_modules is installed, estimate footprint with platform-appropriate tools. Lockfile reductions are the primary metric — do not depend on node_modules being present.

Step 2: Remove unused direct dependencies

Unsafe direct dependency protocols — scan all workspace package.json dependency sections. Flag values that are not: semver range, workspace:, patch:, or npm: alias to semver. Flag git: / github: / tarball URLs / user/repo shorthand / file: / link: / exec: / etc. (same allow-list as /check-npm). Do not remove flagged entries silently; report for a separate hardening PR unless the user asked to fix them.

Use a static analyzer as a starting point, not as proof (knip, depcheck, or repo-native tooling). Run with pinned pnpm --config.ignore-scripts=true dlx <tool>@<version> <args...> when not installed (freshness-check the pin first).

For each candidate:

  • Search code, configs, package scripts, build tooling, tests, and docs for the package name and known import paths.
  • Check whether required by a published package manifest, peer contract, plugin loader, CLI command, or dynamic require/import.
  • Remove only when no real usage remains.
  • Run pnpm install --ignore-scripts (+ repo flags) and focused verification.

If usage is only in a script or config, consider moving between dependencies and devDependencies instead of removing.

Show full SKILL.md (601 more words)Show less

Step 3: Deduplicate monorepo direct versions

Look for the same direct dependency declared with multiple versions/ranges across package manifests. Use existing policy first: exact pins, caret ranges, catalog/protocol usage, workspace protocol, or central constraints.

  • Use syncpack list-mismatches or equivalent for discovery.
  • Standardize direct ranges when packages can share the same compatible version.
  • Prefer manifest-level consistency before adding pnpm.overrides.
  • Use pnpm.overrides only for transitive convergence or security fixes, and document why.

After deduping, run pnpm install --ignore-scripts (+ repo flags) and inspect manifest and lockfile diffs. Then consider pnpm dedupe — apply carefully; may change transitive resolution.

Step 4: Rank transitive lockfile closure

For each important direct dependency, estimate closure: transitive lockfile entries reachable from that dependency.

Report both:

  • Total closure: all packages reachable from the dependency.
  • Exclusive closure: packages that disappear if this dependency is removed and are not retained by other direct dependencies.

Prefer deterministic measurement:

  1. Save baseline lockfile metrics.
  2. Temporarily remove one direct dependency from the owning manifest.
  3. Run pnpm install --ignore-scripts (+ repo flags).
  4. Measure lockfile line/entry reduction and package count reduction.
  5. Revert the manifest and pnpm-lock.yaml (e.g., git checkout -- <manifest> pnpm-lock.yaml) before measuring the next dependency.

Use pnpm why <pkg> for large transitive packages. Rank by impact and risk, not just raw size.

Step 5: Find low-risk high-impact upgrades

Use closure rankings to target direct dependencies whose newer minor/patch versions reduce transitive dependencies.

For each candidate:

  • Check available non-major versions with pnpm outdated.
  • Review changelog/release notes for dependency tree changes.
  • Freshness-check the target version, then upgrade one dependency or tight cluster at a time (pnpm add <pkg>@<version> --ignore-scripts).
  • Run pnpm install --ignore-scripts (+ repo flags) and compare closure metrics.
  • Run focused tests and relevant build/typecheck commands.

Avoid major upgrades unless the user explicitly accepts the migration risk.

Step 6: Inline trivial usage

Use closure rankings to find direct dependencies with small, obvious usage but large transitive cost.

Inline only when all are true:

  • Usage is tiny and easy to fully characterize.
  • Equivalent code is shorter or clearer than retaining the dependency.
  • Behavior is covered by tests or can be covered with small characterization tests.
  • The dependency is not solving cross-platform, security, parsing, Unicode, locale, or spec-compliance edge cases.

Prefer native APIs over new replacement dependencies when the required behavior is simple.

Step 7: Apply e18e guidance

bash
# Pin @e18e/cli@<version> after freshness check; disable scripts on the dlx install
pnpm --config.ignore-scripts=true dlx @e18e/cli@<version> analyze
pnpm --config.ignore-scripts=true dlx @e18e/cli@<version> migrate --dry-run

Also check https://e18e.dev/docs/replacements/. Treat recommendations as candidates, not mandates; verify bundle/runtime behavior and run tests. Map e18e swaps to Replace-with-Better only after user approval.

Reporting

Summarize outcomes with measured impact:

  • /check-npm result (PASS/FAIL summary; link fixes if FAIL).
  • Direct dependencies removed or moved.
  • Direct versions deduplicated.
  • Lockfile line/entry reduction.
  • Estimated package or node_modules reduction when available.
  • High-impact candidates deferred and why (including replacements awaiting approval).
  • Unsafe protocol / CI / Renovate findings from baseline (if any).
  • Verification commands run and results.
  • Supply-chain: versions freshness-checked (or exempted), --ignore-scripts on all installs/adds, --config.ignore-scripts=true on pnpm dlx.

Call out risk explicitly when a removal depends on static analysis rather than runtime coverage.

Reporting format

Use for dependency cleanup findings only — not GitHub Actions workflow triage.

For each finding:

  • Evidence: package name and version/range; manifest path and section; supporting signal (import site, pnpm why, knip/depcheck hit, closure measurement, /check-npm row, or workflow file + step only for pnpm install policy).
  • Decision: one of Dependency triage labels.
  • Proposed change: exact manifest/lockfile command or edit. If not applied yet, state that explicitly.
  • Rationale: footprint (exclusive/total closure), supply-chain, maintenance, or verification risk.
  • User review required: tests/build/typecheck to run; peer/plugin/CLI consumers; published-package or dynamic-import risk; approval before Replace-with-Better or any new direct dependency.

Use one block per package (or per protocol/CI finding), not a single-line summary, when the finding is non-trivial.

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/grafana-plugins/audit-and-reduce-dependencies of grafana/skills.

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Audit And Reduce Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit And Reduce Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit And Reduce Dependencies this skillgrafana/skills282—~3.6kAutomated safety check: WarnApache-2.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
Check Deps SyncHyk260/PureChat546—~594Automated safety check: PassMIT
Kubelb Dependency Updateskubermatic/kubelb148—~1.3kAutomated safety check: PassApache-2.0
Bump Sentry Dependencygetsentry/sentry46k—~815Automated safety check: PassCustom licence

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Check Deps Sync

    Hyk260/PureChat

    Check if package.json files are in sync with pnpm-lock.yaml.

    546 GitHub stars~594 tokensUpdated 24 days ago
    DevOps & CloudAuto-check passed
  • Kubelb Dependency Updates

    kubermatic/kubelb

    Sweep and update every dependency surface in the kubelb repo (go.mod, Makefile tool versions, prow images, GitHub Actions, hack/ci pins, addon Helm charts, pinned container images) and split the…

    148 GitHub stars~1.3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Bump Sentry Dependency

    getsentry/sentry

    Official

    Bumps an existing Python dependency in getsentry/sentry through the repository's self-serve GitHub Actions workflow.

    46k GitHub stars~815 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Uv Workflow

    Aedelon/claude-code-blueprint

    Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    282 GitHub stars~678 tokensUpdated 2 days ago
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    282 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    282 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    282 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    282 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    282 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Audit And Reduce Dependencies

What does Audit And Reduce Dependencies do?

Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style. Audit And Reduce Dependencies is an agent skill from grafana/skills, published by the product's own GitHub organization. Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

When should I use Audit And Reduce Dependencies?

Audit And Reduce Dependencies fits situations like: cleaning up pnpm dependencies; reducing lockfile size; shrinking nodemodules in Grafana plugins; not for Go modules.

How do I install Audit And Reduce Dependencies in Claude Code?

Run `npx skills add grafana/skills --skill audit-and-reduce-dependencies -a claude-code`. Or copy the skill folder (skills/grafana-plugins/audit-and-reduce-dependencies in grafana/skills) into .claude/skills/audit-and-reduce-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Audit And Reduce Dependencies in Codex?

Run `npx skills add grafana/skills --skill audit-and-reduce-dependencies -a codex`. Or copy the skill folder (skills/grafana-plugins/audit-and-reduce-dependencies in grafana/skills) into .agents/skills/audit-and-reduce-dependencies in your project. Codex loads it when a task matches its description.

Can I use Audit And Reduce Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill audit-and-reduce-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-and-reduce-dependencies, .gemini/skills/audit-and-reduce-dependencies, .github/skills/audit-and-reduce-dependencies and .opencode/skills/audit-and-reduce-dependencies in your project.

What does Audit And Reduce Dependencies need to run?

Going by SKILL.md and its folder, Audit And Reduce Dependencies needs the command-line tools its instructions call (pnpm, git and curl).

Does Audit And Reduce Dependencies access the network?

SKILL.md names 2 domains. In commands or code: registry.npmjs.org; the agent is likely to contact it when it follows the instructions. As links in the text: e18e.dev. This is read from the text; nothing was executed.

Is Audit And Reduce Dependencies safe to install?

Our automated static check of SKILL.md flagged 3 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Audit And Reduce Dependencies use?

Audit And Reduce Dependencies is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit And Reduce Dependencies use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit And Reduce Dependencies?

Skills that share tags, products or a category with Audit And Reduce Dependencies: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Check Deps Sync (Hyk260/PureChat, 546 stars) and Kubelb Dependency Updates (kubermatic/kubelb, 148 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit And Reduce Dependencies?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 282 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.