Agent skill

Os Eco Dep Sync

by jayminwest in jayminwest/warren

Bump warren onto the latest published @os-eco/ versions across package.json + bun.lock and the Dockerfile CLI pins, then run the gates and open a PR.

MITAuto-check passedDevOps & Cloud

Install Os Eco Dep Sync

skills CLI
$ npx skills add jayminwest/warren --skill os-eco-dep-sync -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jayminwest/warren os-eco-dep-sync --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jayminwest/warren.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/os-eco-dep-sync .claude/skills/os-eco-dep-sync && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
os-eco-dep-sync
GitHub stars
481
Token cost
~1.9k tokens
SKILL.md length
794 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Bump warren onto the latest published @os-eco/ versions across package.json + bun.lock and the Dockerfile CLI pins, then run the gates and open a PR.

  • Works in 6 steps: Discover the latest published version of… → Bump the npm dependencies (package.json… → Bump the Dockerfile global pins → …
  • Checking if warren is on the newest burrow/plot/canopy/seeds/mulch/sapling
  • SKILL.md covers Pre-flight, Procedure, Acceptance and Failure modes, plus 1 more section
  • Calls bun, git and npm

What it does

Os Eco Dep Sync is an agent skill from jayminwest/warren. Bump warren onto the latest published @os-eco/ versions across package.json + bun.lock and the Dockerfile CLI pins, then run the gates and open a PR. Use when checking if warren is on the newest burrow/plot/canopy/seeds/mulch/sapling.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Pull requests. It works with npm and Docker. The repository describes itself as: Run coding agents like infrastructure, not terminal sessions. Warren manages isolation, lifecycle, spend, recovery, and Git delivery on compute you control. The licence is MIT.

When your agent uses it

  • Checking if warren is on the newest burrow/plot/canopy/seeds/mulch/sapling
  • Tasks that involve Containers
  • Tasks that involve Pull requests

Example prompts

  • “/os-eco-dep-sync”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Discover the latest published version of each tool
  2. Bump the npm dependencies (package.json + bun.lock)
  3. Bump the Dockerfile global pins
  4. Keep warren's own VERSION in sync and ship the bump
  5. Run the gates
  6. Commit to main

What it can do on your machine

Read from SKILL.md and the folder at commit 9595340. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • git
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Os Eco Dep Sync loads about 1.9k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 794 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jayminwest/warren at commit 9595340, republished under its MIT licence (© jayminwest). 794 words, ~1,853 tokens.

Download SKILL.mdSave it as .claude/skills/os-eco-dep-sync/SKILL.md (or your agent's skills folder).
name
os-eco-dep-sync
description
Bump warren onto the latest published @os-eco/* versions across package.json + bun.lock and the Dockerfile CLI pins, then run the gates and open a PR. Use when checking if warren is on the newest burrow/plot/canopy/seeds/mulch/sapling.
tools
bun, npm, git, gh
inputs
package (optional) — restrict to one os-eco tool, e.g. burrow; default is all
outputs
updated package.json + regenerated bun.lock with caret ranges on latest, updated Dockerfile global-install pins on latest, a focused commit on main (gates…

os-eco-dep-sync

Use this skill inside the warren repo when you need to confirm warren is running the newest published versions of the other os-eco tools and bump it if not. Warren is the only ecosystem consumer, and it tracks the rest of os-eco across two surfaces that must stay in lockstep:

  1. npm dependencies in package.json (+ bun.lock): @os-eco/burrow-cli and @os-eco/plot-cli. These are what warren builds and imports against — consumed as published registry packages, not links.
  2. Global CLI pins in the Dockerfile bun install -g block: all six bundled CLIs — @os-eco/burrow-cli, @os-eco/plot-cli, @os-eco/canopy-cli, @os-eco/seeds-cli, @os-eco/mulch-cli, @os-eco/sapling-cli — that back warren's opt-in features at runtime.

"Latest" always means the published npm version (npm view ... version), never the local sibling working tree.

The burrow double-pin invariant. @os-eco/burrow-cli (and plot-cli) appears in both surfaces. Bun.spawn resolves ./node_modules/.bin/burrow before PATH, so bumping only the Dockerfile is a silent no-op — the supervisor keeps running the lockfile copy. The two pins MUST be identical. See CLAUDE.md → "Relationship to burrow".

Pre-flight

bash
cd warren                         # this skill operates only on the warren repo
git status                        # MUST be clean before you start
command -v bun npm git gh         # gh optional (only for the PR step)

If the tree is dirty, stop and let the user commit or stash first — this skill ends in a focused, reviewable commit and a noisy tree defeats that.

Read the current pins so you know the starting point:

bash
grep '@os-eco/' package.json
grep '@os-eco/' Dockerfile

Procedure

1. Discover the latest published version of each tool
bash
for t in burrow plot canopy seeds mulch sapling; do
  printf '%-8s %s\n' "$t" "$(npm view @os-eco/$t-cli version)"
done

If inputs.package was given, restrict the loop to that one tool. Record each latest. Compare against the pins printed in pre-flight; anything behind is a bump target. If every surface already matches latest, report "warren is up to date" and stop — do not create an empty commit.

2. Bump the npm dependencies (package.json + bun.lock)

For each lagging entry in dependencies (burrow-cli, plot-cli only), set the caret range to the latest published version, then regenerate the lockfile:

bash
# edit package.json: "@os-eco/burrow-cli": "^<latest>", "@os-eco/plot-cli": "^<latest>"
bun install                       # regenerates bun.lock to resolve the new range
grep -A1 '@os-eco/burrow-cli' bun.lock   # confirm the resolved version == latest

Edit package.json with the editor, not by hand-piping into the file. Keep the existing caret (^) style — match the surrounding manifest.

3. Bump the Dockerfile global pins

In the RUN bun install -g block, update every lagging @os-eco/<tool>-cli@X.Y.Z to its latest published version (exact pin, no caret — that block is deliberately pinned). Cover all six tools, not just the two npm deps:

bash
grep -n '@os-eco/.*-cli@' Dockerfile     # verify each line now reads the latest version

Enforce the double-pin invariant: the burrow-cli and plot-cli versions in the Dockerfile MUST equal the versions bun.lock resolved in step 2. If they disagree, the supervisor and the bundled CLI diverge at runtime.

4. Keep warren's own VERSION in sync and ship the bump

A dependency bump is a release, so bump warren's own patch version. Use the script — it rewrites every version site at once and rolls back on failure:

bash
bun run version:bump patch
grep '"version"' package.json
grep 'export const VERSION' src/index.ts   # the two strings MUST match —
                                           # release.yml fails the job otherwise

Add a CHANGELOG.md entry for the new version describing the os-eco bumps (the release workflow pulls notes from the matching section).

5. Run the gates
bash
bun run check:all                 # the full suite CI enforces; warnings fail

If burrow/plot shipped a breaking change, this is where typecheck or tests catch it. Fix forward against the new version or, if the break is real and out of scope, stop and report it rather than pinning back silently.

Show full SKILL.md (311 more words)Show less
6. Commit to main

Commit directly to main — do not create a feature branch or open a PR for this sync. Stage only the touched surfaces and write one focused commit:

bash
git add package.json bun.lock Dockerfile src/index.ts CHANGELOG.md docs/openapi.yaml
git commit -m "chore: sync os-eco deps to latest published versions"

(docs/openapi.yaml only changes if the VERSION bump in step 4 re-baselined it via bun run gen:openapi; include it when it shows in git status.)

Do not git push unless the user asked for it — leave the commit local and report that it's on main.

Acceptance

  • npm view @os-eco/<tool>-cli version equals the pin for that tool in both package.json (for burrow/plot) and the Dockerfile (for all six).
  • bun.lock resolves burrow-cli/plot-cli to those same versions, and the Dockerfile's burrow-cli/plot-cli pins match the lockfile (double-pin held).
  • package.json "version" equals src/index.ts VERSION.
  • bun run check:all exits 0.
  • One focused commit on main (no feature branch, no PR); tree otherwise clean.

Failure modes

SymptomCauseRemedy
Supervisor runs an old burrow despite a Dockerfile bumpBun.spawn resolves the local node_modules/.bin/burrow firstBump burrow in package.json + bun.lock too; keep both pins equal (step 2 + 3)
release.yml fails "Verify version sync"package.json version ≠ src/index.ts VERSIONEdit both to the same string (step 4)
npm view returns empty / errorstool not published, typo'd name, or offlineConfirm the exact @os-eco/<tool>-cli name; skip tools with no published release
check:all fails on typecheck after a bumpupstream shipped a breaking changeAdapt warren to the new API, or report and hold the bump for that tool only
bun install leaves bun.lock unchangedcaret range already admitted the latestConfirm whether a manifest bump is actually needed; the lockfile may already be current

Further reading

  • CLAUDE.md → "Relationship to burrow" and "Version Management" — the double-pin rule and the two-place version contract.
  • Dockerfile — the bun install -g block that bundles the six os-eco CLIs.
  • .github/workflows/release.yml — the version-sync gate, tag, and GitHub release. Deploy is decoupled: .github/workflows/deploy-gke.yml rolls GKE forward on a published release.

© jayminwest, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/os-eco-dep-sync of jayminwest/warren.

Open the folder on GitHubat commit 9595340

Compare with similar skills

Os Eco Dep Sync next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Os Eco Dep Sync compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Os Eco Dep Sync this skilljayminwest/warren481—~1.9kAutomated safety check: PassMIT
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0
PR Reviewkimdre/doco-cd1.7k—~311Automated safety check: PassApache-2.0
Ddevhaxtheweb/haxcms-php130—~1.6kAutomated safety check: PassApache-2.0
Data Processingaiskillstore/marketplace4331 repos~720Automated safety check: NotesMIT
Tokf Runmpecan/tokf199—~571Automated safety check: PassMIT

Similar skills

  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • PR Review

    kimdre/doco-cd

    Review pull request diffs for correctness and regressions, and provide actionable feedback when asked to review a PR.

    1.7k GitHub stars~311 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Ddev

    haxtheweb/haxcms-php

    DDEV local development environment guidance for Docker-based PHP/Node projects.

    130 GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 1 repo~720 tokens
    DevOps & CloudAuto-check: notes
  • Tokf Run

    mpecan/tokf

    Compress verbose CLI output with tokf before returning results.

    199 GitHub stars~571 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    A skill your agent uses when writing, reviewing, or optimizing Dockerfiles, even if the user just says their image is too large, their build is slow, or they need to harden a container for production.

    552 GitHub stars~3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: warnings

More from jayminwest/warren

  • Good First Issue Batch

    jayminwest/warren

    File a batch of contributor-ready GitHub issues from the seeds backlog, re-verifying every candidate against HEAD first so no dead issue reaches a contributor.

    481 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Release

    jayminwest/warren

    Prepare, cut, and verify a warren release — tracker audits, version bump, CHANGELOG curation, ROADMAP update, push, then watch the pipeline through to published artifacts.

    481 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Seeds Issue Audit

    jayminwest/warren

    Audit and triage open Seeds (sd) issues — find which can be closed, auto-close high-confidence completed ones, and report borderline cases.

    481 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • UI Design Review

    jayminwest/warren

    Independent design review of a warren web-UI change. An agent skill from jayminwest/warren.

    481 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Warren Dogfood Pipeline

    jayminwest/warren

    Full prioritize → dispatch → shepherd → track pipeline against the live warren instance.

    481 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Os Eco Dep Sync

What does Os Eco Dep Sync do?

Bump warren onto the latest published @os-eco/ versions across package.json + bun.lock and the Dockerfile CLI pins, then run the gates and open a PR. Os Eco Dep Sync is an agent skill from jayminwest/warren.lock and the Dockerfile CLI pins, then run the gates and open a PR.

When should I use Os Eco Dep Sync?

Os Eco Dep Sync fits situations like: checking if warren is on the newest burrow/plot/canopy/seeds/mulch/sapling; tasks that involve Containers; tasks that involve Pull requests.

How do I install Os Eco Dep Sync in Claude Code?

Run `npx skills add jayminwest/warren --skill os-eco-dep-sync -a claude-code`. Or copy the skill folder (.agents/skills/os-eco-dep-sync in jayminwest/warren) into .claude/skills/os-eco-dep-sync in your project. Claude Code loads it when a task matches its description.

How do I install Os Eco Dep Sync in Codex?

Run `npx skills add jayminwest/warren --skill os-eco-dep-sync -a codex`. Or copy the skill folder (.agents/skills/os-eco-dep-sync in jayminwest/warren) into .agents/skills/os-eco-dep-sync in your project. Codex loads it when a task matches its description.

Can I use Os Eco Dep Sync in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jayminwest/warren --skill os-eco-dep-sync -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/os-eco-dep-sync, .gemini/skills/os-eco-dep-sync, .github/skills/os-eco-dep-sync and .opencode/skills/os-eco-dep-sync in your project.

What does Os Eco Dep Sync need to run?

Going by SKILL.md and its folder, Os Eco Dep Sync needs the command-line tools its instructions call (bun, git and npm).

Does Os Eco Dep Sync access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Os Eco Dep Sync safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Os Eco Dep Sync use?

Os Eco Dep Sync is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Os Eco Dep Sync use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Os Eco Dep Sync?

Skills that share tags, products or a category with Os Eco Dep Sync: Reflexo Release (Myriad-Dreamin/typst.ts, 1.2k stars), PR Review (kimdre/doco-cd, 1.7k stars), Ddev (haxtheweb/haxcms-php, 130 stars) and Data Processing (aiskillstore/marketplace, 433 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Os Eco Dep Sync?

jayminwest (a GitHub user) maintains it in jayminwest/warren, which has 481 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: jayminwest/warren on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.