Agent skill

Update Deps

by joshukraine in joshukraine/dotfiles

Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR.

MITAuto-check passedDevelopment

Install Update Deps

skills CLI
$ npx skills add joshukraine/dotfiles --skill update-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install joshukraine/dotfiles update-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/joshukraine/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude/.claude/skills/update-deps .claude/skills/update-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-deps
GitHub stars
429
Token cost
~2.2k tokens
SKILL.md length
1,065 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR.

  • Works in 7 steps: Detect the environment (do not hardcode) → Reconcile open Dependabot PRs → Update incrementally → …
  • Tasks that involve Dependency management
  • SKILL.md covers Command Options, Workflow at a glance, Your task and Design principles, plus 5 more sections
  • Calls gh, npm and cargo

What it does

Update Deps is an agent skill from joshukraine/dotfiles. Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. Framework-agnostic.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management and Security review. It works with npm. The repository describes itself as: :roundpushpin: My dotfiles for macOS using Neovim, Zsh, and Ghostty + Tmux. The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Security review

Example prompts

  • “/update-deps”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Detect the environment (do not hardcode)
  2. Reconcile open Dependabot PRs
  3. Update incrementally
  4. Run the security audit
  5. Validate boot-affecting changes on the real CI
  6. Open a unified PR
  7. Verify Dependabot auto-close (don't race it)

What it can do on your machine

Read from SKILL.md and the folder at commit b59ad5b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • cargo
    • bundle
    • poetry
    • go
    • pip
    • yarn
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm, pip, yarn and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Deps loads about 2.2k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 1,065 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from joshukraine/dotfiles at commit b59ad5b, republished under its MIT licence (© joshukraine). 1,065 words, ~2,192 tokens.

Download SKILL.mdSave it as .claude/skills/update-deps/SKILL.md (or your agent's skills folder).
name
update-deps
description
Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. Framework-agnostic.
disable-model-invocation
true

Update Dependencies

Update project dependencies safely: reconcile open Dependabot PRs into one unified change, run the project's security audit, validate boot-affecting changes against the real CI environment, and open a single PR — instead of stopping at local commits.

This skill is framework-agnostic. It detects the project's package manager, test/lint commands, audit suite, and CI workflow rather than assuming a stack.

Command Options

  • --dry-run: Show what would be updated without making changes
  • --major: Include major version updates (default: minor/patch only)
  • --package <name>: Update specific package only
  • --skip-tests: Skip running tests between updates

Workflow at a glance

text
Detect → Reconcile Dependabot → Update → Audit → Validate on real CI → Open PR → Verify auto-close

Each stage feeds the next. Don't skip the audit or the real-CI validation for boot-affecting changes — those are the two stages that catch what local tests can't.

Your task

1. Detect the environment (do not hardcode)

Detect both the package manager and the project's real entry points. The runners below are common defaults, not assumptions — always confirm against what the repo actually uses.

  • Package manager:
    • package.json (npm/yarn/pnpm) — check the lockfile to disambiguate
    • Gemfile (bundler)
    • requirements.txt / pyproject.toml (pip/poetry/uv)
    • Cargo.toml (cargo)
    • go.mod (go modules)
  • Test/lint/CI entry points — prefer a single project gate over assumed runners:
    • A wrapper script like bin/ci, bin/test, script/test, or a Makefile/Justfile target is the canonical gate — use it if present.
    • Otherwise detect the real tools: Minitest vs RSpec, StandardRB vs RuboCop, Herb, Biome vs ESLint, Prettier, tsc, mypy, etc.
    • Detect the CI workflow itself: list .github/workflows/*.yml and identify the workflow that runs on the default branch and the jobs it contains.
  • Audit suite (see step 4) — detect, don't assume.
2. Reconcile open Dependabot PRs

Before making any changes, find out what Dependabot already has in flight:

bash
gh pr list --app dependabot --state open --json number,title,headRefName,body
  • If open Dependabot PRs exist, fold their bumps into one unified branch rather than running in parallel and leaving stale PRs behind.
  • Land the exact target versions or newer for every bump a Dependabot PR covers. Dependabot auto-closes a PR once its target versions (or higher) land on the base branch — landing a lower version defeats that and leaves the PR open.
  • Note which PRs you expect to be superseded; you'll verify their auto-close in step 7.
3. Update incrementally

Keep the safe, category-by-category loop:

  • Security updates first (always include), then patch, then minor.
  • Major updates only with --major. Isolate a risky major into its own commit — or its own PR — so it can be rolled back cleanly without reverting the safe bumps.
  • Run the detected test gate after each category. If --skip-tests: skip test execution.
  • For major bumps, flag soft-dependency and default-behavior changes explicitly — a newly pulled-in transitive dependency, a changed default load/eager-load behavior (e.g. Bundler's require:), a renamed config key. These are where "the tests pass but boot breaks" lives.
  • Stop and report if the gate fails; offer to revert the specific update that caused it.
4. Run the security audit

This is the highest-value stage on a dependency PR — not an afterthought. After updates, run the project's detected audit suite and fold any newly surfaced fix into this PR (a fresh advisory is in-scope, not a separate task):

EcosystemAudit tools (detect what's present)
Rubybundler-audit; plus brakeman and importmap audit on Rails
Nodenpm audit, yarn npm audit, pnpm audit
Pythonpip-audit, safety
Rustcargo audit
Gogovulncheck

If the project's CI gate (e.g. bin/ci) already runs these, run that gate rather than invoking each tool separately.

5. Validate boot-affecting changes on the real CI

A change that touches the manifest (the Gemfile, package.json, pyproject.toml — not just the lockfile) can alter what loads at boot. Local gates cannot catch a failure caused by a system library that happens to be installed on the dev machine but missing on one CI job. Validate those changes on the actual CI environment before recommending merge:

bash
gh workflow run <ci-workflow> --ref <branch>
gh run watch   # or: gh run list --branch <branch>

Do this when:

  • The manifest changed (new dependency, changed require:/load behavior, version constraint change), and/or
  • A bump pulls in a native/system-backed library (image processing, crypto, database drivers).

Lockfile-only patch bumps with a green local gate generally don't need a dedicated CI run.

Show full SKILL.md (404 more words)Show less
6. Open a unified PR

Stop-at-commits is not the finish line. Open one PR for the reconciled set, following the project's PR conventions — hand off to the /create-pr skill (it generates the description, links issues, and updates the ROADMAP). Summarize in the PR body: the bumps grouped by category, the Dependabot PRs this supersedes, any CVE fixed, and the result of the real-CI run.

7. Verify Dependabot auto-close (don't race it)

After the PR merges, expect Dependabot to auto-close the superseded PRs on its own — verify it did rather than pre-emptively closing them:

bash
gh pr list --app dependabot --state open
  • If a superseded PR closed automatically: done.
  • Fallback only: if a PR is still open after Dependabot's next rebase cycle — the edge where a lower/different version landed and Dependabot just rebases instead of closing (see dependabot/dependabot-core#13606) — close it manually with a note. Don't duplicate Dependabot's behavior or race its rebase.

Design principles

The lessons this workflow encodes, worth keeping in mind when a situation doesn't fit the steps above:

  • "Passes locally, fails on one CI job" is a real failure class. A local gate can't see a system library that's present on your machine but absent on a specific CI job. Boot-affecting dependency changes need real-CI validation, not just local tests.
  • Don't fight Dependabot. It already reconciles bumps and auto-closes superseded PRs. The skill's job is to expect and verify that behavior, not re-implement it.
  • Security audits are the highest-value step, not an afterthought. A plain update can ship a live CVE that only the audit catches.

Package manager commands

npm/yarn/pnpm
bash
npm outdated        # check
npm update <pkg>    # update
Ruby (Bundler)
bash
bundle outdated
bundle update <gem>
Python (pip/poetry)
bash
pip list --outdated
poetry show --outdated && poetry update <pkg>
Rust (Cargo)
bash
cargo outdated
cargo update <pkg>
Go
bash
go list -u -m all
go get -u <pkg>

Update categories

  1. Security updates (always applied) — packages with known vulnerabilities.
  2. Patch updates (default) — bug fixes, e.g. 1.2.3 → 1.2.4.
  3. Minor updates (default) — backwards-compatible features, e.g. 1.2.3 → 1.3.0.
  4. Major updates (only with --major) — breaking changes, e.g. 1.2.3 → 2.0.0. Isolate for clean rollback.

Commit message format

Use Conventional Commits format from global CLAUDE.md:

text
chore(deps): update dependencies

Security updates:
- erb: 6.0.1 → 6.0.3 (CVE-2026-41316)

Patch updates:
- rails: 7.1.3 → 7.1.5

Minor updates:
- image_processing: 1.12 → 2.0

Breaking changes:
- image_processing 2.0 requires ruby-vips; added with require: false
  so a missing libvips does not crash boot.

Error handling

  • No package manager detected: "No supported package manager found"
  • No outdated packages and no open Dependabot PRs: "All dependencies are up to date"
  • Test or audit failure: identify the culprit update, offer to revert it
  • Real-CI run fails: report the failing job; do not recommend merge
  • Lock file conflicts: guide through resolution

Integration with global standards

Follow dependency best practices from global CLAUDE.md:

  • Pin versions, use lock files for consistent environments
  • Test breaking changes thoroughly; document system requirements
  • Treat security advisories as in-scope for the dependency PR

© joshukraine, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude/.claude/skills/update-deps of joshukraine/dotfiles.

Open the folder on GitHubat commit b59ad5b

Compare with similar skills

Update Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Deps this skilljoshukraine/dotfiles429—~2.2kAutomated safety check: PassMIT
Dependency Update BotVarnan-Tech/opendirectory674—~3kAutomated safety check: NotesMIT
JS Security Auditc0x12c/ai-toolkit106—~1.6kAutomated safety check: WarnNone
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT
Dependency Upgrade Protocoldralgorhythm/claude-agentic-framework125—~1.5kAutomated safety check: PassNone

Similar skills

  • Dependency Update Bot

    Varnan-Tech/opendirectory

    Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

    674 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • JS Security Audit

    c0x12c/ai-toolkit

    Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

    106 GitHub stars~1.6k tokensUpdated 3 mo ago
    SecurityAuto-check: warnings
  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Dependency Upgrade Protocol

    dralgorhythm/claude-agentic-framework

    Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

    125 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Detecting Malicious npm Packages

    mukul975/Anthropic-Cybersecurity-Skills

    Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    DevelopmentAuto-check: warnings

More from joshukraine/dotfiles

All 24 skills in this repo
  • Todoist CLI

    joshukraine/dotfiles

    Manage Todoist tasks, projects, labels, filters, sections, comments, reminders, and workspaces via the td CLI.

    429 GitHub starsUsed in 1 repo~6.9k tokens
    Auto-check passed
  • Autopilot Triage

    joshukraine/dotfiles

    Vet open issues for autonomous resolution and queue the qualifying ones with the autopilot-queued label — the start-of-day "fill the queue" half of the triage → run split.

    429 GitHub stars~2.1k tokensUpdated 4 days ago
    Auto-check passed
  • Checkpoint

    joshukraine/dotfiles

    Quick 2-minute status update on current phase, completed work, blockers, and health check.

    429 GitHub stars~600 tokensUpdated 4 days ago
    Auto-check passed
  • Create PR

    joshukraine/dotfiles

    Create a pull request with auto-generated description, issue linking, ROADMAP updates, and PR-metadata validation.

    429 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed
  • Debrief

    joshukraine/dotfiles

    Detailed technical walkthrough covering architecture, test coverage, product tour, and key design decisions.

    429 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Drift Check

    joshukraine/dotfiles

    Pre-PR advisory check for deviations from the project spec. An agent skill from joshukraine/dotfiles.

    429 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about Update Deps

What does Update Deps do?

Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. Update Deps is an agent skill from joshukraine/dotfiles. Dependabot-aware dependency updates with security audit, real-CI validation, and a unified PR.

When should I use Update Deps?

Update Deps fits situations like: tasks that involve Dependency management; tasks that involve Security review.

How do I install Update Deps in Claude Code?

Run `npx skills add joshukraine/dotfiles --skill update-deps -a claude-code`. Or copy the skill folder (claude/.claude/skills/update-deps in joshukraine/dotfiles) into .claude/skills/update-deps in your project. Claude Code loads it when a task matches its description.

How do I install Update Deps in Codex?

Run `npx skills add joshukraine/dotfiles --skill update-deps -a codex`. Or copy the skill folder (claude/.claude/skills/update-deps in joshukraine/dotfiles) into .agents/skills/update-deps in your project. Codex loads it when a task matches its description.

Can I use Update Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add joshukraine/dotfiles --skill update-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-deps, .gemini/skills/update-deps, .github/skills/update-deps and .opencode/skills/update-deps in your project.

What does Update Deps need to run?

Going by SKILL.md and its folder, Update Deps needs the command-line tools its instructions call (gh, npm, cargo, bundle, poetry and go). Our summary lists: Python 3.

Does Update Deps access the network?

SKILL.md contains no URLs. Its commands use gh, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Deps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Deps use?

Update Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Deps use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Deps?

Skills that share tags, products or a category with Update Deps: Dependency Update Bot (Varnan-Tech/opendirectory, 674 stars), JS Security Audit (c0x12c/ai-toolkit, 106 stars), Verdaccio Code Review (verdaccio/verdaccio, 18k stars) and Stash Supply Chain Security (cipherstash/stack, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Deps?

joshukraine (a GitHub user) maintains it in joshukraine/dotfiles, which has 429 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: joshukraine/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.