Agent skill

Dependency Patches

by LedgerHQ in LedgerHQ/ledger-live

Read before creating or changing patches/.patch, pnpm.patchedDependencies, or using pnpm patch to modify third-party dependency source.

MITAuto-check passed

Install Dependency Patches

skills CLI
$ npx skills add LedgerHQ/ledger-live --skill dependency-patches -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LedgerHQ/ledger-live dependency-patches --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-patches .claude/skills/dependency-patches && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-patches
GitHub stars
622
Token cost
~491 tokens
SKILL.md length
256 words
Files
1
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Read before creating or changing patches/.patch, pnpm.patchedDependencies, or using pnpm patch to modify third-party dependency source.

  • Works in 4 steps: Check the upstream issue tracker, pull… → Assess whether the dependency is… → Do not put Ledger product logic in a… → …
  • SKILL.md covers Before creating a patch and Every patch requires
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dependency Patches is an agent skill from LedgerHQ/ledger-live. Read before creating or changing patches/.patch, pnpm.patchedDependencies, or using pnpm patch to modify third-party dependency source.

Its SKILL.md is about 490 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with pnpm. The repository describes itself as: Mono-repository for Ledger Wallet apps and related packages. The licence is MIT.

Example prompts

  • “/dependency-patches”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Check the upstream issue tracker, pull requests, and releases for the fix. Use an available upstream release instead of a patch.
  2. Assess whether the dependency is outdated, still needed, and has a maintained alternative. Prefer replacing an unmaintained or unnecessary…
  3. Do not put Ledger product logic in a dependency. A small generic, opt-in hook may be patched only when it is suitable for upstreaming.
  4. Use a local patch only when the equivalent upstream fix is open or merged but unreleased. Otherwise, a patch is an exception: a revert, an…

What it can do on your machine

Read from SKILL.md and the folder at commit 46bd13a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • ledgerhq.atlassian.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Patches loads about 491 tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 256 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~491

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LedgerHQ/ledger-live at commit 46bd13a, republished under its MIT licence (© LedgerHQ). 256 words, ~491 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-patches/SKILL.md (or your agent's skills folder).
name
dependency-patches
description
Read before creating or changing `patches/*.patch`, `pnpm.patchedDependencies`, or using `pnpm patch` to modify third-party dependency source.

Dependency patches

A pnpm patch is a content fork of a third-party dependency. Do not choose one casually: prefer an upstream release, configuration, or application-side workaround. This policy applies to new patches; existing patches require a migration/removal decision before being expanded or carried to a new version.

Before creating a patch

  1. Check the upstream issue tracker, pull requests, and releases for the fix. Use an available upstream release instead of a patch.
  2. Assess whether the dependency is outdated, still needed, and has a maintained alternative. Prefer replacing an unmaintained or unnecessary dependency over carrying a patch.
  3. Do not put Ledger product logic in a dependency. A small generic, opt-in hook may be patched only when it is suitable for upstreaming.
  4. Use a local patch only when the equivalent upstream fix is open or merged but unreleased. Otherwise, a patch is an exception: a revert, an unmaintained dependency, or an urgent production/CI fix. Record the justification and the removal plan in the tracking ticket, and still open the upstream PR when one applies.

Every patch requires

  • A tech-debt backlog ticket linking the upstream PR/reference (when applicable), naming an owner, and stating the removal condition, such as “remove after upstream version X.Y.Z”.
  • An adjacent comment in the patched file using that file's native comment syntax, with the upstream reference and removal condition. For formats without comments (for example JSON), put those details in the tracking ticket.
  • Minimal, generic changes that can be removed cleanly. Never use a patch to inject undeclared dependencies; see pnpm-resolution.

© LedgerHQ, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/dependency-patches of LedgerHQ/ledger-live.

Open the folder on GitHubat commit 46bd13a

Compare with similar skills

Dependency Patches next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Patches compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Patches this skillLedgerHQ/ledger-live622—~491Automated safety check: PassMIT
DeerFlow Smoke Testbytedance/deer-flow84k—~2.5kAutomated safety check: NotesMIT
@pierre/diffs Code Renderingpierrecomputer/pierre6.3k2 repos~803Automated safety check: PassApache-2.0
Vuetify Playgroundvuetifyjs/vuetify41k—~730Automated safety check: PassCustom licence
React Router Release Notes Prepremix-run/react-router57k—~1.1kAutomated safety check: PassMIT
React Syncvercel/next.js143k—~486Automated safety check: PassMIT

Similar skills

  • DeerFlow Smoke Test

    bytedance/deer-flow

    Walks through an end-to-end smoke test of a DeerFlow deployment: pull the latest code, deploy with Docker or locally, verify services, run health checks and write a report.

    84k GitHub stars~2.5k tokensUpdated today
    Testing & QAAuto-check: notes
  • @pierre/diffs Code Rendering

    pierrecomputer/pierre

    Guides an agent through using @pierre/diffs to render syntax-highlighted files and diffs, and to build editing and review surfaces in React or plain JavaScript.

    6.3k GitHub starsUsed in 2 repos~803 tokens
    DevelopmentAuto-check passed
  • Vuetify Playground

    vuetifyjs/vuetify

    Maintains the Vuetify repo's local Playground.vue so contributors get a realistic reproduction and a short demo they can paste into a pull request description.

    41k GitHub stars~730 tokensUpdated today
    Frontend & DesignAuto-check passed
  • React Router Release Notes Prep

    remix-run/react-router

    Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.

    57k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • React Sync

    vercel/next.js

    Official

    Build local React changes in the bundle variants consumed by Next.js, sync them into a local Next.js checkout, and test the resulting integration.

    143k GitHub stars~486 tokensUpdated today
    Auto-check passed
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 6 repos~760 tokens
    DevelopmentAuto-check passed

More from LedgerHQ/ledger-live

All 51 skills in this repo
  • Impacting PRs

    LedgerHQ/ledger-live

    Find which open PRs are impacted by a migration/sunset/refactor and notify their authors — blocking review when the old path is already gone from develop, heads-up comment when it is only deprecated…

    622 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Cloud Sync Module

    LedgerHQ/ledger-live

    Write, review or debug a cloudSyncModule.ts — a CloudSyncDataManager that syncs one slice of user data through Ledger Sync (Cloud Sync).

    622 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Codeownership

    LedgerHQ/ledger-live

    Maintain CODEOWNERS file and team directories. An agent skill from LedgerHQ/ledger-live.

    622 GitHub stars~687 tokensUpdated today
    Auto-check passed
  • Coin Families Contract

    LedgerHQ/ledger-live

    Coin-specific families logic must live in families/. An agent skill from LedgerHQ/ledger-live.

    622 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Data Layer Advanced

    LedgerHQ/ledger-live

    Structure a Ledger Wallet data layer where one API response serves several entities.

    622 GitHub stars~509 tokensUpdated today
    Auto-check passed
  • Debug Rn Native Crash

    LedgerHQ/ledger-live

    Investigate native React Native crashes (Fabric/Hermes/iOS) in ledger-live-mobile when JS error logs are missing or unhelpful.

    622 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Works with

Questions about Dependency Patches

What does Dependency Patches do?

Read before creating or changing patches/.patch, pnpm.patchedDependencies, or using pnpm patch to modify third-party dependency source. Dependency Patches is an agent skill from LedgerHQ/ledger-live.patchedDependencies, or using pnpm patch to modify third-party dependency source.

How do I install Dependency Patches in Claude Code?

Run `npx skills add LedgerHQ/ledger-live --skill dependency-patches -a claude-code`. Or copy the skill folder (.agents/skills/dependency-patches in LedgerHQ/ledger-live) into .claude/skills/dependency-patches in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Patches in Codex?

Run `npx skills add LedgerHQ/ledger-live --skill dependency-patches -a codex`. Or copy the skill folder (.agents/skills/dependency-patches in LedgerHQ/ledger-live) into .agents/skills/dependency-patches in your project. Codex loads it when a task matches its description.

Can I use Dependency Patches in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LedgerHQ/ledger-live --skill dependency-patches -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-patches, .gemini/skills/dependency-patches, .github/skills/dependency-patches and .opencode/skills/dependency-patches in your project.

What does Dependency Patches need to run?

SKILL.md names no scripts, command-line tools or credentials: Dependency Patches is instructions for the agent only.

Does Dependency Patches access the network?

SKILL.md names 1 domain. As links in the text: ledgerhq.atlassian.net. This is read from the text; nothing was executed.

Is Dependency Patches safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Patches use?

Dependency Patches is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Patches use?

About 491 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependency Patches?

Skills that share tags, products or a category with Dependency Patches: DeerFlow Smoke Test (bytedance/deer-flow, 84k stars), @pierre/diffs Code Rendering (pierrecomputer/pierre, 6.3k stars), Vuetify Playground (vuetifyjs/vuetify, 41k stars) and React Router Release Notes Prep (remix-run/react-router, 57k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Patches?

LedgerHQ (a GitHub organization) maintains it in LedgerHQ/ledger-live, which has 622 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 10, 2026.

Source: LedgerHQ/ledger-live on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.