Agent skill

Wrap Third Party Libs

by LedgerHQ in LedgerHQ/ledger-live

Apps do not depend on third-party libraries directly: the lowest valid package owns each one.

MITAuto-check passed

Install Wrap Third Party Libs

skills CLI
$ npx skills add LedgerHQ/ledger-live --skill wrap-third-party-libs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LedgerHQ/ledger-live wrap-third-party-libs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LedgerHQ/ledger-live.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/wrap-third-party-libs .claude/skills/wrap-third-party-libs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wrap-third-party-libs
GitHub stars
622
Token cost
~839 tokens
SKILL.md length
441 words
Files
1
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Apps do not depend on third-party libraries directly: the lowest valid package owns each one.

  • Works in 5 steps: Before adding a dependency to apps/*,… → Place the owner in the lowest valid… → The package declares the third-party lib… → …
  • SKILL.md covers Why, Rule, Examples and Exceptions, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Wrap Third Party Libs is an agent skill from LedgerHQ/ledger-live. Apps do not depend on third-party libraries directly: the lowest valid package owns each one. Read before adding a dependency to apps//package.json, importing a new npm package from an app, or bumping a library the apps use.

Its SKILL.md is about 840 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm. The repository describes itself as: Mono-repository for Ledger Wallet apps and related packages. The licence is MIT.

Example prompts

  • “/wrap-third-party-libs”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Before adding a dependency to apps/*, look for an existing owner package. If none, create one.
  2. Place the owner in the lowest valid layer of the structure-flow table (shared, domain, features/platform, features/flow), for example
  3. The package declares the third-party lib in its own dependencies (catalog: when a catalog entry exists). Apps and other packages import…
  4. The public API hides the lib: no lib types or instances in exports, so the lib can be replaced without touching callers.
  5. Add a test in the package that exercises the real lib, including the success path.

What it can do on your machine

Read from SKILL.md and the folder at commit 46bd13a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wrap Third Party Libs loads about 839 tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 441 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~839

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LedgerHQ/ledger-live at commit 46bd13a, republished under its MIT licence (© LedgerHQ). 441 words, ~839 tokens.

Download SKILL.mdSave it as .claude/skills/wrap-third-party-libs/SKILL.md (or your agent's skills folder).
name
wrap-third-party-libs
description
Apps do not depend on third-party libraries directly: the lowest valid package owns each one. Read before adding a dependency to apps/*/package.json, importing a new npm package from an app, or bumping a library the apps use.

Wrap third-party libs below the apps

An app's package.json lists workspace packages and the exceptions below (framework singletons, the design system, tooling). A library that serves one capability (QR code, signature check, storage, id generation) belongs to a package below the app, which exposes a small API of our own.

Why

  • Every direct app dependency is a potential silent override. The renderer's resolve.modules puts the app's node_modules first, so the app's copy wins over the version a library declared for itself (@noble/curves v1 forced onto a v2 consumer crashed Desktop at boot).
  • Desktop and mobile each pick a different lib for the same job (qrcode vs react-native-qrcode-svg). One owner gives one behaviour and one test.
  • Bumping or swapping a lib touches one package, not two apps.

Rule

  1. Before adding a dependency to apps/*, look for an existing owner package. If none, create one.
  2. Place the owner in the lowest valid layer of the structure-flow table (shared, domain, features/platform, features/flow), for example:
    • business-agnostic (QR code, clipboard, linking, list reorder): shared/<name>, e.g. @shared/ui-qr-code
    • capability shared across flows or apps: features/platform/<name>
    • used by one flow or one domain: that features/flow or domain package
  3. The package declares the third-party lib in its own dependencies (catalog: when a catalog entry exists). Apps and other packages import the package by name, never the lib.
  4. The public API hides the lib: no lib types or instances in exports, so the lib can be replaced without touching callers.
  5. Add a test in the package that exercises the real lib, including the success path.
Show full SKILL.md (181 more words)Show less

Examples

Existing app dependencies predate this rule and are migrated over time; do not add new ones.

  • shared/ui-qr-code (intent of the pattern; its API and placement are still under platform review): owns qrcode; apps render <QrCode /> (Desktop still declares qrcode until migrated).
  • #23097: @noble/curves and @trust/keyto moved out of Desktop into @features/platform-app-update; sslHelper.verify became a wrapper. Precedent for isolating a lib an app used once; the package is Desktop-only today, so it is not a placement model for new packages.

Exceptions

Keep a direct app dependency for libraries that must be a singleton across the bundle (react, react-dom, redux, react-router, styled-components, i18next), for the design system (@ledgerhq/lumen-*), and for build or tooling packages. Anything else goes behind a package; if you think it is an exception, ask in the PR before adding it.

Review

  • Does the PR add a runtime dependency to apps/*/package.json? Ask which package should own it.
  • Does an app import a library that a shared/ or features/platform/ package already wraps? Use the package.
  • Do two apps use different libs for the same job? Move both behind one package.

© LedgerHQ, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/wrap-third-party-libs of LedgerHQ/ledger-live.

Open the folder on GitHubat commit 46bd13a

Compare with similar skills

Wrap Third Party Libs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wrap Third Party Libs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wrap Third Party Libs this skillLedgerHQ/ledger-live622—~839Automated safety check: PassMIT
Defuddlekepano/obsidian-skills49k11 repos~208Automated safety check: PassMIT
Vercel Deploybytedance/deer-flow84k10 repos~797Automated safety check: PassMIT
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
Nx Run Tasksnomcopter/react-mosaic4.8k8 repos~613Automated safety check: PassCustom licence

Similar skills

  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 11 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    84k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 8 repos~613 tokens
    DevelopmentAuto-check passed
  • Validates OpenHarness features by running real multi-turn agent loops with live LLM calls against an unfamiliar codebase, checking actual tool execution.

    16k GitHub starsUsed in 1 repo~2.1k tokens
    Testing & QAAuto-check: notes

More from LedgerHQ/ledger-live

All 51 skills in this repo
  • Impacting PRs

    LedgerHQ/ledger-live

    Find which open PRs are impacted by a migration/sunset/refactor and notify their authors — blocking review when the old path is already gone from develop, heads-up comment when it is only deprecated…

    622 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Cloud Sync Module

    LedgerHQ/ledger-live

    Write, review or debug a cloudSyncModule.ts — a CloudSyncDataManager that syncs one slice of user data through Ledger Sync (Cloud Sync).

    622 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Codeownership

    LedgerHQ/ledger-live

    Maintain CODEOWNERS file and team directories. An agent skill from LedgerHQ/ledger-live.

    622 GitHub stars~687 tokensUpdated yesterday
    Auto-check passed
  • Coin Families Contract

    LedgerHQ/ledger-live

    Coin-specific families logic must live in families/. An agent skill from LedgerHQ/ledger-live.

    622 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Data Layer Advanced

    LedgerHQ/ledger-live

    Structure a Ledger Wallet data layer where one API response serves several entities.

    622 GitHub stars~509 tokensUpdated yesterday
    Auto-check passed
  • Debug Rn Native Crash

    LedgerHQ/ledger-live

    Investigate native React Native crashes (Fabric/Hermes/iOS) in ledger-live-mobile when JS error logs are missing or unhelpful.

    622 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Wrap Third Party Libs

What does Wrap Third Party Libs do?

Apps do not depend on third-party libraries directly: the lowest valid package owns each one. Wrap Third Party Libs is an agent skill from LedgerHQ/ledger-live. Apps do not depend on third-party libraries directly: the lowest valid package owns each one.

How do I install Wrap Third Party Libs in Claude Code?

Run `npx skills add LedgerHQ/ledger-live --skill wrap-third-party-libs -a claude-code`. Or copy the skill folder (.agents/skills/wrap-third-party-libs in LedgerHQ/ledger-live) into .claude/skills/wrap-third-party-libs in your project. Claude Code loads it when a task matches its description.

How do I install Wrap Third Party Libs in Codex?

Run `npx skills add LedgerHQ/ledger-live --skill wrap-third-party-libs -a codex`. Or copy the skill folder (.agents/skills/wrap-third-party-libs in LedgerHQ/ledger-live) into .agents/skills/wrap-third-party-libs in your project. Codex loads it when a task matches its description.

Can I use Wrap Third Party Libs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LedgerHQ/ledger-live --skill wrap-third-party-libs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wrap-third-party-libs, .gemini/skills/wrap-third-party-libs, .github/skills/wrap-third-party-libs and .opencode/skills/wrap-third-party-libs in your project.

What does Wrap Third Party Libs need to run?

SKILL.md names no scripts, command-line tools or credentials: Wrap Third Party Libs is instructions for the agent only.

Does Wrap Third Party Libs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wrap Third Party Libs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wrap Third Party Libs use?

Wrap Third Party Libs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wrap Third Party Libs use?

About 839 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Wrap Third Party Libs?

Skills that share tags, products or a category with Wrap Third Party Libs: Defuddle (kepano/obsidian-skills, 49k stars), Vercel Deploy (bytedance/deer-flow, 84k stars), Knap Markdown Templates (kepano/obsidian-skills, 49k stars) and MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wrap Third Party Libs?

LedgerHQ (a GitHub organization) maintains it in LedgerHQ/ledger-live, which has 622 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 10, 2026.

Source: LedgerHQ/ledger-live on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.