Agent skill

Windsurf Dependency Management

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Analyze and update dependencies with vulnerability scanning.

MITAuto-check passedDevelopment

Install Windsurf Dependency Management

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-dependency-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace windsurf-dependency-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/windsurf-dependency-management .claude/skills/windsurf-dependency-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windsurf-dependency-management
GitHub stars
2.8k
Token cost
~510 tokens
SKILL.md length
132 words
Files
5 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Analyze and update dependencies with vulnerability scanning.

  • Works in 5 steps: Run Initial Audit → Analyze Update Paths → Plan Updates → …
  • S mention update dependencies
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windsurf Dependency Management is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze and update dependencies with vulnerability scanning. Activate when users mention "update dependencies", "security audit", "npm audit", "vulnerability scan", or "dependency updates". Handles dependency analysis and updates. Use when working with windsurf dependency management functionality. Trigger with phrases like "windsurf dependency management", "windsurf management", "windsurf".

Its SKILL.md is about 510 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/directory-structure.md`, `references/errors.md` and `references/examples.md`). Compatibility notes: Designed for Claude Code

It sits in Development, covering Dependency management. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • S mention update dependencies
  • Vulnerability scan
  • Dependency updates
  • Working with windsurf dependency management functionality

Example prompts

  • “update dependencies”
  • “security audit”
  • “npm audit”
  • “/windsurf-dependency-management”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(cmd:*), Grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run Initial Audit
  2. Analyze Update Paths
  3. Plan Updates
  4. Apply and Verify
  5. Establish Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(cmd:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.windsurf.ai
    • docs.npmjs.com
    • semver.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Windsurf Dependency Management loads about 510 tokens when it runs, and up to ~1.5k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 132 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~510
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 132 words, ~510 tokens.

Download SKILL.mdSave it as .claude/skills/windsurf-dependency-management/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
windsurf-dependency-management
description
Analyze and update dependencies with vulnerability scanning. Activate when users mention "update dependencies", "security audit", "npm audit", "vulnerability scan", or "dependency updates". Handles dependency analysis and updates. Use when working with windsurf dependency management functionality. Trigger with phrases like "windsurf dependency management", "windsurf management", "windsurf".
allowed-tools
Read, Write, Edit, Bash(cmd:*), Grep
compatibility
Designed for Claude Code
version
1.0.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, skill-databases, security, audit

Windsurf Dependency Management

Overview

This skill enables comprehensive dependency management within Windsurf projects. Cascade analyzes your dependency tree, identifies security vulnerabilities, suggests safe updates, and helps plan migration paths for major version upgrades.

Prerequisites

  • Windsurf IDE with Cascade enabled
  • Package manager installed (npm, yarn, pnpm, pip)
  • Project with package.json, requirements.txt, or equivalent
  • Understanding of semantic versioning
  • CI/CD pipeline for testing updates (recommended)

Instructions

  1. Run Initial Audit
  2. Analyze Update Paths
  3. Plan Updates
  4. Apply and Verify
  5. Establish Monitoring

See ${CLAUDE_SKILL_DIR}/references/implementation.md for detailed implementation guide.

Output

  • Security audit report with findings
  • Update plan with prioritized changes
  • Compatibility matrix for version combinations
  • Migration guides for breaking changes

Error Handling

See ${CLAUDE_SKILL_DIR}/references/errors.md for comprehensive error handling.

Examples

See ${CLAUDE_SKILL_DIR}/references/examples.md for detailed examples.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/.curated/windsurf-dependency-management of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/directory-structure.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Windsurf Dependency Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windsurf Dependency Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windsurf Dependency Management this skilljeremylongshore/tons-of-skills-marketplace2.8k—~510Automated safety check: PassMIT
Triage Dependabot Alertsactivepieces/activepieces25k—~2.9kAutomated safety check: PassCustom licence
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT
Golang Continuous Integrationcontext-labs/whip1.1k—~3.5kAutomated safety check: PassMIT
Gem Dependency Managementruby-git/ruby-git1.8k—~806Automated safety check: PassMIT
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT

Similar skills

  • Triage Dependabot Alerts

    activepieces/activepieces

    Triage Dependabot dependency vulnerability alerts for the Activepieces repo — pull open alerts, dedupe to distinct (package, advisory), confirm the vulnerable package + API is actually used, and…

    25k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Gem Dependency Management

    ruby-git/ruby-git

    Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

    1.8k GitHub stars~806 tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated yesterday
    DevelopmentAuto-check: warnings
  • Dependency Upgrade Protocol

    dralgorhythm/claude-agentic-framework

    Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

    125 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Windsurf Dependency Management

What does Windsurf Dependency Management do?

Analyze and update dependencies with vulnerability scanning. Windsurf Dependency Management is an agent skill from jeremylongshore/tons-of-skills-marketplace. Analyze and update dependencies with vulnerability scanning.

When should I use Windsurf Dependency Management?

Windsurf Dependency Management fits situations like: S mention update dependencies; vulnerability scan; dependency updates; working with windsurf dependency management functionality.

How do I install Windsurf Dependency Management in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-dependency-management -a claude-code`. Or copy the skill folder (skills/.curated/windsurf-dependency-management in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/windsurf-dependency-management in your project. Claude Code loads it when a task matches its description.

How do I install Windsurf Dependency Management in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-dependency-management -a codex`. Or copy the skill folder (skills/.curated/windsurf-dependency-management in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/windsurf-dependency-management in your project. Codex loads it when a task matches its description.

Can I use Windsurf Dependency Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill windsurf-dependency-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windsurf-dependency-management, .gemini/skills/windsurf-dependency-management, .github/skills/windsurf-dependency-management and .opencode/skills/windsurf-dependency-management in your project.

What does Windsurf Dependency Management need to run?

SKILL.md names no scripts, command-line tools or credentials: Windsurf Dependency Management is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(cmd:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Windsurf Dependency Management access the network?

SKILL.md names 3 domains. As links in the text: docs.windsurf.ai, docs.npmjs.com and semver.org. This is read from the text; nothing was executed.

Is Windsurf Dependency Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windsurf Dependency Management use?

Windsurf Dependency Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windsurf Dependency Management use?

About 510 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 954 tokens, read only when the agent opens those files.

What are the alternatives to Windsurf Dependency Management?

Skills that share tags, products or a category with Windsurf Dependency Management: Triage Dependabot Alerts (activepieces/activepieces, 25k stars), Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars), Golang Continuous Integration (context-labs/whip, 1.1k stars) and Gem Dependency Management (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windsurf Dependency Management?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.