Agent skill

Check Deps Sync

by Hyk260 in Hyk260/PureChat

Check if package.json files are in sync with pnpm-lock.yaml.

MITAuto-check passedDevOps & Cloud

Install Check Deps Sync

skills CLI
$ npx skills add Hyk260/PureChat --skill check-deps-sync -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hyk260/PureChat check-deps-sync --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hyk260/PureChat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/check-deps-sync .claude/skills/check-deps-sync && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
check-deps-sync
GitHub stars
546
Token cost
~594 tokens
SKILL.md length
209 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Check if package.json files are in sync with pnpm-lock.yaml.

  • Works in 5 steps: Identify All Package Files → Run Sync Check → Alternative Check Method → …
  • User wants to verify dependency synchronization
  • SKILL.md covers Workflow, Common Issues, Best Practices and Quick Commands
  • Calls pnpm

What it does

Check Deps Sync is an agent skill from Hyk260/PureChat. Check if package.json files are in sync with pnpm-lock.yaml. Use when user wants to verify dependency synchronization, before pushing to CI/CD, or when encountering build failures due to lockfile mismatches.

Its SKILL.md is about 590 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Dependency management, CI/CD and LLM inference and serving. It works with npm, pnpm, OpenAI and Vercel. The repository describes itself as: PureChat 是一款全面的聊天应用程序,它将传统的即时消息与高级 AI 功能集成在一起。其模块化架构、可扩展的 AI 集成系统和灵活的配置选项使其成为强大的应用程序,也是 AI 增强通信应用程序的坚实基础。支持OpenAI,Ollama,DeepSeek等大语言模型,Markdown 渲染,聊天记录生成截图,主题切换,助力开发者快速掌握现代技术。 The licence is MIT.

When your agent uses it

  • User wants to verify dependency synchronization
  • Before pushing to CI/CD
  • Encountering build failures due to lockfile mismatches

Example prompts

  • “/check-deps-sync”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify All Package Files
  2. Run Sync Check
  3. Alternative Check Method
  4. Fix Sync Issues
  5. Verify Fix

What it can do on your machine

Read from SKILL.md and the folder at commit abb2ec1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Check Deps Sync loads about 594 tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 209 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~594

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hyk260/PureChat at commit abb2ec1, republished under its MIT licence (© Hyk260). 209 words, ~594 tokens.

Download SKILL.mdSave it as .claude/skills/check-deps-sync/SKILL.md (or your agent's skills folder).
name
check-deps-sync
description
Check if package.json files are in sync with pnpm-lock.yaml. Use when user wants to verify dependency synchronization, before pushing to CI/CD, or when encountering build failures due to lockfile mismatches.

Check Dependencies Sync

检查 package.json 文件与 pnpm-lock.yaml 是否同步,防止因忘记更新依赖导致 Vercel 构建失败。

Workflow

Step 1: Identify All Package Files

Find all package.json files in the workspace:

  • Root: package.json
  • Packages: packages/*/package.json
Step 2: Run Sync Check

Execute the following command to check synchronization:

bash
pnpm install --frozen-lockfile --dry-run

If this fails, it means pnpm-lock.yaml is out of sync with package.json files.

Step 3: Alternative Check Method

For a more detailed check, run:

bash
pnpm ls --depth=0

This will list all dependencies and show if there are any issues.

Step 4: Fix Sync Issues

If sync issues are found:

  1. To update lockfile (safe - preserves existing versions):

    bash
    pnpm install --no-frozen-lockfile
  2. To clean install (if issues persist):

    bash
    rm -rf node_modules pnpm-lock.yaml
    pnpm install
Step 5: Verify Fix

After fixing, verify by running:

bash
pnpm install --frozen-lockfile

This should complete without errors.

Common Issues

IssueCauseSolution
ERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILEpackage.json changed but lockfile not updatedRun pnpm install to update lockfile
ERR_PNPM_FROZEN_LOCKFILE_MISSING_DEPENDENCYNew dependency added without installRun pnpm install
Version mismatchManual version change in package.jsonRun pnpm install to sync

Best Practices

  1. Before pushing to Vercel/GitHub: Always run pnpm install --frozen-lockfile locally to verify sync
  2. After modifying package.json: Immediately run pnpm install to update lockfile
  3. Commit both files together: Always commit package.json and pnpm-lock.yaml in the same commit
  4. Use exact versions: Prefer exact versions in dependencies for reproducible builds

Quick Commands

bash
# Check sync (fails if out of sync)
pnpm install --frozen-lockfile

# Fix sync issues
pnpm install

# Full reset (nuclear option)
rm -rf node_modules pnpm-lock.yaml && pnpm install

© Hyk260, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/check-deps-sync of Hyk260/PureChat.

Open the folder on GitHubat commit abb2ec1

Compare with similar skills

Check Deps Sync next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Check Deps Sync compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Check Deps Sync this skillHyk260/PureChat546—~594Automated safety check: PassMIT
Uv WorkflowAedelon/claude-code-blueprint120—~1.2kAutomated safety check: NotesCustom licence
Upgrade Runtime StackPackmindHub/packmind317—~2.2kAutomated safety check: PassApache-2.0
JS Security Auditc0x12c/ai-toolkit106—~1.6kAutomated safety check: WarnNone
Audit And Reduce Dependenciesgrafana/skills281—~3.6kAutomated safety check: WarnApache-2.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT

Similar skills

  • Uv Workflow

    Aedelon/claude-code-blueprint

    Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Upgrade Runtime Stack

    PackmindHub/packmind

    Check whether newer stable versions of Node.js (24.x line), Nx, or Vite are available and, if so, generate a detailed upgrade plan markdown file at the repo root.

    317 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • JS Security Audit

    c0x12c/ai-toolkit

    Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

    106 GitHub stars~1.6k tokensUpdated 3 mo ago
    SecurityAuto-check: warnings
  • Official

    Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

    281 GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Deploy

    noskillish/bankmcp

    Deploy BankMCP™ to a small server so it works in claude.ai and on the phone: Railway or Fly.io, volume, domain, setup page, connector.

    277 GitHub stars~744 tokensUpdated 11 days ago
    DevOps & CloudAuto-check passed

More from Hyk260/PureChat

  • Create Skill

    Hyk260/PureChat

    Create a new skill in the current repository. An agent skill from Hyk260/PureChat.

    546 GitHub starsUsed in 1 repo~823 tokens
    Auto-check passed
  • Code Review

    Hyk260/PureChat

    Perform code reviews (CR) for changed files in the current repository.

    546 GitHub stars~645 tokensUpdated 22 days ago
    Auto-check passed

Questions about Check Deps Sync

What does Check Deps Sync do?

Check if package.json files are in sync with pnpm-lock.yaml. Check Deps Sync is an agent skill from Hyk260/PureChat.yaml.

When should I use Check Deps Sync?

Check Deps Sync fits situations like: user wants to verify dependency synchronization; before pushing to CI/CD; encountering build failures due to lockfile mismatches.

How do I install Check Deps Sync in Claude Code?

Run `npx skills add Hyk260/PureChat --skill check-deps-sync -a claude-code`. Or copy the skill folder (.agents/skills/check-deps-sync in Hyk260/PureChat) into .claude/skills/check-deps-sync in your project. Claude Code loads it when a task matches its description.

How do I install Check Deps Sync in Codex?

Run `npx skills add Hyk260/PureChat --skill check-deps-sync -a codex`. Or copy the skill folder (.agents/skills/check-deps-sync in Hyk260/PureChat) into .agents/skills/check-deps-sync in your project. Codex loads it when a task matches its description.

Can I use Check Deps Sync in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hyk260/PureChat --skill check-deps-sync -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/check-deps-sync, .gemini/skills/check-deps-sync, .github/skills/check-deps-sync and .opencode/skills/check-deps-sync in your project.

What does Check Deps Sync need to run?

Going by SKILL.md and its folder, Check Deps Sync needs the command-line tools its instructions call (pnpm).

Does Check Deps Sync access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Check Deps Sync safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Check Deps Sync use?

Check Deps Sync is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Check Deps Sync use?

About 594 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Check Deps Sync?

Skills that share tags, products or a category with Check Deps Sync: Uv Workflow (Aedelon/claude-code-blueprint, 120 stars), Upgrade Runtime Stack (PackmindHub/packmind, 317 stars), JS Security Audit (c0x12c/ai-toolkit, 106 stars) and Audit And Reduce Dependencies (grafana/skills, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Check Deps Sync?

Hyk260 (a GitHub user) maintains it in Hyk260/PureChat, which has 546 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 17, 2026.

Source: Hyk260/PureChat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.