Agent skill

Update Dependencies

by heypinchy in heypinchy/pinchy

A skill your agent uses when bumping general npm/pnpm dependencies across the Pinchy workspace (root, packages/web, packages/plugins/, docs), when the user asks to "update dependencies," "check for…

AGPL-3.0Auto-check passedDevelopment

Install Update Dependencies

skills CLI
$ npx skills add heypinchy/pinchy --skill update-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install heypinchy/pinchy update-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/heypinchy/pinchy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/update-dependencies .claude/skills/update-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-dependencies
GitHub stars
182
Token cost
~1.5k tokens
SKILL.md length
624 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
AGPL-3.0

At a glance

A skill your agent uses when bumping general npm/pnpm dependencies across the Pinchy workspace (root, packages/web, packages/plugins/, docs), when the user asks to "update dependencies," "check for…

  • Works in 3 steps: Bucket every outdated package into one… → Apply the safe-bump and paired-bump… → Report, don't auto-commit. This touches…
  • Bumping general npm/pnpm dependencies across the Pinchy workspace (root
  • SKILL.md covers Overview, Scope, Procedure and Quick Reference
  • Calls pnpm, git and npm

What it does

Update Dependencies is an agent skill from heypinchy/pinchy. Use when bumping general npm/pnpm dependencies across the Pinchy workspace (root, packages/web, packages/plugins/, docs), when the user asks to "update dependencies," "check for outdated packages," or run "pnpm outdated" / "npm update". Not for the pinned OpenClaw core version or openclaw-node — see update-openclaw for those.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with pnpm, npm and ESLint. The repository describes itself as: Self-hosted AI agent platform built on OpenClaw. Enterprise-ready, offline-capable, open source. 🦞. The licence is AGPL-3.0.

When your agent uses it

  • Bumping general npm/pnpm dependencies across the Pinchy workspace (root
  • Packages/plugins/
  • The user asks to update dependencies
  • Check for outdated packages

Example prompts

  • “update dependencies,”
  • “check for outdated packages,”
  • “pnpm outdated”
  • “/update-dependencies”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Bucket every outdated package into one of three groups before touching
  2. Apply the safe-bump and paired-bump groups, then verify
  3. Report, don't auto-commit. This touches runtime dependencies, not

What it can do on your machine

Read from SKILL.md and the folder at commit 5159959. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • git
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Dependencies loads about 1.5k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 624 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from heypinchy/pinchy at commit 5159959, republished under its AGPL-3.0 licence (© heypinchy). 624 words, ~1,526 tokens.

Download SKILL.mdSave it as .claude/skills/update-dependencies/SKILL.md (or your agent's skills folder).
name
update-dependencies
description
Use when bumping general npm/pnpm dependencies across the Pinchy workspace (root, packages/web, packages/plugins/*, docs), when the user asks to "update dependencies," "check for outdated packages," or run "pnpm outdated" / "npm update". Not for the pinned OpenClaw core version or openclaw-node — see update-openclaw for those.

Update npm/pnpm Dependencies

Overview

Pinchy is a pnpm workspace with several independent package.jsons (root, packages/web, each packages/plugins/*, plus the standalone docs/ package). A blind "bump everything to latest" misses two kinds of traps: packages that are pinned together and packages that are pinned apart for a documented reason.

Scope

Excluded from this skill — use update-openclaw instead: openclaw (dev dependency, the pinned core runtime) and openclaw-node (our own client library). OpenClaw upgrades have repeatedly broken Pinchy in ways pnpm test/tsc don't catch (session keys, tools.allow semantics, config.apply timing) — bumping them needs the dedicated release-notes review procedure, not a routine sweep. If pnpm outdated shows a newer openclaw/openclaw-node, list it in your report but do not touch it here; tell the user to run update-openclaw separately.

Procedure

  1. Enumerate outdated packages per workspace, not just root:

    bash
    pnpm outdated                              # root
    pnpm -C packages/web outdated
    for d in packages/plugins/*/; do pnpm -C "$d" outdated; done
    cd docs && pnpm outdated                    # standalone package.json/lockfile

    If node_modules isn't installed in the current worktree, every row shows "missing (wanted X)" — that's not a signal, ignore it. The wanted → latest columns are what matter.

  2. Bucket every outdated package into one of three groups before touching any file:

    • Safe patch/minor bump. Same major version, no known pairing constraint. Bump directly.
    • Paired — must move together, or not at all. Check before bumping:
      • next + eslint-config-next (Next.js ships them in lockstep; eslint-config-next also gates the eslint-v10 blocker below).
      • Any two packages from the same vendor that render/parse together (e.g. an avatar/icon library split into a core + style package) — if only one has a newer major, leave both pinned until the other catches up.
      • Any package listed in pnpm.patchedDependencies (root package.json) — a local patch is pinned to an exact version. Bumping needs its own step: verify the patch still applies after the bump (pnpm install fails loudly if it doesn't), and if it no longer applies, regenerate it and confirm the behavior it exists for still works (check pnpm patch history / memory for why the patch exists before assuming it's obsolete).
    • Known blocker or deliberately deferred — do not bump, state why:
      • eslint 9 → 10 is blocked: eslint-config-next pulls in eslint-plugin-react, whose peer range caps ESLint below 10; forcing it past that crashes pnpm lint at runtime. Recheck when eslint-config-next ships a major that drops this constraint.
      • A dependency's major version just became latest days/weeks ago (check npm view <pkg> time or the dist-tags) — prefer the newest release within the previous major and flag the fresh major as a separate, deliberate follow-up once it has real-world mileage.
      • A dependency that's a hand-rolled integration point, not a thin passthrough (e.g. a PDF/document engine used directly by our own extraction/render code) — a major bump there needs its own PR with the relevant test suite run against real sample data, not a bundled sweep.
  3. Apply the safe-bump and paired-bump groups, then verify:

    bash
    pnpm install
    pnpm -C packages/web lint
    pnpm test                      # root script fans out to workspaces
    pnpm -C packages/web test:db
    pnpm test:scripts
    pnpm build
    pnpm format
    cd docs && pnpm build           # if docs/ package.json changed

    Run the relevant pnpm -C packages/web test:e2e:<suffix> for any plugin whose external-API client library was bumped (e.g. googleapis → test:e2e:email).

  4. Report, don't auto-commit. This touches runtime dependencies, not just app code — present the diff (git status --short, git diff --stat per workspace) and the three buckets (bumped / paired-and-bumped / deliberately-skipped-with-reason) and let the user decide to commit. Give majors you deliberately skipped their own follow-up mention so nobody re-attempts them blind next sweep.

Show full SKILL.md (100 more words)Show less

Quick Reference

SituationAction
openclaw / openclaw-node outdatedDon't bump here — use update-openclaw
eslint 9 → 10 availableSkip, known peer-dep blocker via eslint-config-next
Package in pnpm.patchedDependenciesBump in its own commit, re-verify the patch applies
Two packages from one vendor, only one has a new majorLeave both pinned until the pair catches up
Major version is brand new (days/weeks old)Take the latest previous-major patch instead, flag the major separately
Hand-rolled integration (PDF, parsing engine, etc.) major bumpOwn PR, run its specific test suite against real data
Any dependency bump at allNever auto-commit — report the diff and ask

© heypinchy, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/update-dependencies of heypinchy/pinchy.

Open the folder on GitHubat commit 5159959

Compare with similar skills

Update Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Dependencies this skillheypinchy/pinchy182—~1.5kAutomated safety check: PassAGPL-3.0
Antfuoyjt/uniapp-vue3-template627—~1.3kAutomated safety check: PassMIT
Testingtrieb-work/nextjs-turbo-redis-cache151—~1.1kAutomated safety check: PassMIT
JS Security Auditc0x12c/ai-toolkit106—~1.6kAutomated safety check: WarnNone
Link Workspace Packagesnomcopter/react-mosaic4.8k6 repos~760Automated safety check: PassCustom licence
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Antfu

    oyjt/uniapp-vue3-template

    Anthony Fu's {Opinionated} preferences and best practices for web development

    627 GitHub stars~1.3k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Testing

    trieb-work/nextjs-turbo-redis-cache

    Run tests and add Next.js version coverage for the cache handler.

    151 GitHub stars~1.1k tokensUpdated 15 days ago
    Testing & QAAuto-check passed
  • JS Security Audit

    c0x12c/ai-toolkit

    Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

    106 GitHub stars~1.6k tokensUpdated 3 mo ago
    SecurityAuto-check: warnings
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 6 repos~760 tokens
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Run the tests that cover a change in the pnpm repository, in the Rust workspace (pnpm/, pnpr/) or the TypeScript CLI (pnpm11/), and recognize the cases where a scoped run passes without testing…

    37k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed

More from heypinchy/pinchy

All 18 skills in this repo
  • Knowledge Search

    heypinchy/pinchy

    Answer questions from the organization's indexed documents using knowledgesearch, and cite every claim back to a retrieved passage.

    182 GitHub stars~1.4k tokensUpdated 18 days ago
    Auto-check passed
  • Odoo Read

    heypinchy/pinchy

    Query and summarize data from a connected Odoo instance with the odoo read tools (describe, count, read, aggregate).

    182 GitHub stars~965 tokensUpdated 18 days ago
    Auto-check passed
  • Review Docs

    heypinchy/pinchy

    Use before opening a PR that changes docs/ or a user-visible surface (an API route, the tool registry, an agent template, the audit event catalogue, the settings navigation, plugin tools), and when…

    182 GitHub stars~1.3k tokensUpdated 18 days ago
    Auto-check passed
  • A skill your agent uses when a new Ollama Cloud model is announced or available (e.g.

    182 GitHub stars~3.9k tokensUpdated 18 days ago
    Auto-check: notes
  • Update Openclaw

    heypinchy/pinchy

    A skill your agent uses when bumping the pinned OpenClaw core version (openclaw npm package), when preparing a Pinchy release, or when the user asks to "update OpenClaw" / "upgrade OpenClaw" / check…

    182 GitHub stars~2.8k tokensUpdated 18 days ago
    Auto-check passed
  • Cut Pinchy Release

    heypinchy/pinchy

    A skill your agent uses when cutting, tagging, or publishing a new Pinchy version — e.g.

    182 GitHub stars~11k tokensUpdated 18 days ago
    Auto-check: notes

Works with

Categories

Questions about Update Dependencies

What does Update Dependencies do?

A skill your agent uses when bumping general npm/pnpm dependencies across the Pinchy workspace (root, packages/web, packages/plugins/, docs), when the user asks to "update dependencies," "check for…. Update Dependencies is an agent skill from heypinchy/pinchy. Use when bumping general npm/pnpm dependencies across the Pinchy workspace (root, packages/web, packages/plugins/, docs), when the user asks to "update dependencies," "check for outdated packages," or run "pnpm outdated" / "npm update".

When should I use Update Dependencies?

Update Dependencies fits situations like: bumping general npm/pnpm dependencies across the Pinchy workspace (root; packages/plugins/; the user asks to update dependencies; check for outdated packages.

How do I install Update Dependencies in Claude Code?

Run `npx skills add heypinchy/pinchy --skill update-dependencies -a claude-code`. Or copy the skill folder (.claude/skills/update-dependencies in heypinchy/pinchy) into .claude/skills/update-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Update Dependencies in Codex?

Run `npx skills add heypinchy/pinchy --skill update-dependencies -a codex`. Or copy the skill folder (.claude/skills/update-dependencies in heypinchy/pinchy) into .agents/skills/update-dependencies in your project. Codex loads it when a task matches its description.

Can I use Update Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add heypinchy/pinchy --skill update-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-dependencies, .gemini/skills/update-dependencies, .github/skills/update-dependencies and .opencode/skills/update-dependencies in your project.

What does Update Dependencies need to run?

Going by SKILL.md and its folder, Update Dependencies needs the command-line tools its instructions call (pnpm, git and npm).

Does Update Dependencies access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Dependencies use?

Update Dependencies is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Dependencies use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Dependencies?

Skills that share tags, products or a category with Update Dependencies: Antfu (oyjt/uniapp-vue3-template, 627 stars), Testing (trieb-work/nextjs-turbo-redis-cache, 151 stars), JS Security Audit (c0x12c/ai-toolkit, 106 stars) and Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Dependencies?

heypinchy (a GitHub organization) maintains it in heypinchy/pinchy, which has 182 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 21, 2026.

Source: heypinchy/pinchy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.