Agent skill

Deps Bump

by lkmeta in lkmeta/txtify

Safely update Txtify dependencies or resolve Dependabot alerts.

Apache-2.0Auto-check passedDevelopment

Install Deps Bump

skills CLI
$ npx skills add lkmeta/txtify --skill deps-bump -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lkmeta/txtify deps-bump --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lkmeta/txtify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/deps-bump .claude/skills/deps-bump && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deps-bump
GitHub stars
135
Token cost
~585 tokens
SKILL.md length
220 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Safely update Txtify dependencies or resolve Dependabot alerts.

  • Works in 5 steps: torch and torchaudio move together, same… → stable-ts ≥ 2.19.1 so pip resolves an… → Before adding any package, and before… → …
  • Asked to bump packages
  • SKILL.md covers Ground rules, Checking alerts and Verification (non-negotiable)
  • Calls gh; reaches youtube.com

What it does

Deps Bump is an agent skill from lkmeta/txtify. Safely update Txtify dependencies or resolve Dependabot alerts. Use when asked to bump packages, fix security alerts, or when a Dependabot PR appears.

Its SKILL.md is about 590 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management and Speech recognition and synthesis. It works with Docker, FastAPI and Python. The repository describes itself as: Web application that converts audio and video to text using AI, supporting various formats and self-hosting. The licence is Apache-2.0.

When your agent uses it

  • Asked to bump packages
  • Fix security alerts
  • A Dependabot PR appears

Example prompts

  • “/deps-bump”

Requirements

  • Python 3
  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. torch and torchaudio move together, same version. A mismatch doesn't fail the build — it crashes the worker at import, and jobs just hang…
  2. stable-ts ≥ 2.19.1 so pip resolves an openai-whisper that builds under modern setuptools (older ones import pkg_resources in setup.py and…
  3. Before adding any package, and before "fixing" an alert on one: check it's actually imported — grep -rn '' src/. Unused packages get…
  4. yt-dlp rots fastest and breaks YouTube downloads silently. After bumping, verify with a real download (host venv is fine)
  5. Runtime deps go in requirements.txt; test-only deps (pytest, httpx, pypdf) in requirements-dev.txt. Don't ship test tooling in the image.

What it can do on your machine

Read from SKILL.md and the folder at commit b54c884. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • youtube.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deps Bump loads about 585 tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~585

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lkmeta/txtify at commit b54c884, republished under its Apache-2.0 licence (© lkmeta). 220 words, ~585 tokens.

Download SKILL.mdSave it as .claude/skills/deps-bump/SKILL.md (or your agent's skills folder).
name
deps-bump
description
Safely update Txtify dependencies or resolve Dependabot alerts. Use when asked to bump packages, fix security alerts, or when a Dependabot PR appears.

Dependency updates for Txtify

Ground rules

  1. torch and torchaudio move together, same version. A mismatch doesn't fail the build — it crashes the worker at import, and jobs just hang at 10%. This is the #1 trap.
  2. stable-ts ≥ 2.19.1 so pip resolves an openai-whisper that builds under modern setuptools (older ones import pkg_resources in setup.py and break the Docker build). Check stable-ts's openai-whisper constraint before bumping torch far ahead.
  3. Before adding any package, and before "fixing" an alert on one: check it's actually imported — grep -rn '<pkg>' src/. Unused packages get deleted, not bumped (transformers/accelerate/srt/webvtt-py died this way).
  4. yt-dlp rots fastest and breaks YouTube downloads silently. After bumping, verify with a real download (host venv is fine):
    python
    import yt_dlp
    opts = {"format": "bestaudio/best", "postprocessors": [{"key": "FFmpegExtractAudio", "preferredcodec": "mp3", "preferredquality": "192"}], "outtmpl": "yt_test.%(ext)s", "quiet": True}
    yt_dlp.YoutubeDL(opts).download(["https://www.youtube.com/watch?v=jNQXAC9IVRw"])  # 19s clip
  5. Runtime deps go in requirements.txt; test-only deps (pytest, httpx, pypdf) in requirements-dev.txt. Don't ship test tooling in the image.

Checking alerts

sh
gh api repos/lkmeta/txtify/dependabot/alerts --paginate \
  --jq '.[] | select(.state=="open") | [.security_advisory.severity, .dependency.package.name, .security_vulnerability.vulnerable_version_range, (.security_vulnerability.first_patched_version.identifier // "none")] | @tsv'

Pick the newest version that is explicitly patched in the alert set rather than blindly taking latest — conservative for the ML stack, current for everything else. Alerts auto-resolve after GitHub rescans the updated manifest (minutes to hours); don't chase the counter.

Verification (non-negotiable)

Any requirements.txt change requires the full Docker E2E — the unit tests stub the ML stack and will pass even when the worker can't import: run the verify skill, Tier 2 (./scripts/docker_e2e.sh → PASS: docker E2E complete).

© lkmeta, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/deps-bump of lkmeta/txtify.

Open the folder on GitHubat commit b54c884

Compare with similar skills

Deps Bump next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deps Bump compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deps Bump this skilllkmeta/txtify135—~585Automated safety check: PassApache-2.0
Flowfile Debugging PlaybookEdwardvaneechoud/Flowfile375—~6.3kAutomated safety check: PassMIT
Sync Dependabot App Depsossf/oss-crs165—~1.7kAutomated safety check: NotesMIT
AzureML Project ScaffoldingKilo-Org/kilo-marketplace190—~3.1kAutomated safety check: NotesMIT
Flowfile Build and Environment SetupEdwardvaneechoud/Flowfile375—~7.3kAutomated safety check: NotesMIT
Pre Pushartcc/freelingo162—~732Automated safety check: PassAGPL-3.0

Similar skills

  • Flowfile Debugging Playbook

    Edwardvaneechoud/Flowfile

    Symptom-to-cause triage playbook for Flowfile (core/worker/kernel/frontend/AI) — covers "no such table" DB cascades (two distinct causes), import-time Alembic migration corruption, silent…

    375 GitHub stars~6.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

    165 GitHub stars~1.7k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes
  • AzureML Project Scaffolding

    Kilo-Org/kilo-marketplace

    Sets up and maintains AzureML-ready Python projects as uv workspaces with devcontainers, a Makefile and job YAML, so local runs match cloud jobs and experiments stay reproducible.

    190 GitHub stars~3.1k tokensUpdated 11 days ago
    DevelopmentAuto-check: notes
  • Flowfile Build and Environment Setup

    Edwardvaneechoud/Flowfile

    Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does.

    375 GitHub stars~7.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Pre Push

    artcc/freelingo

    A skill your agent uses when the user asks to check before pushing, pre-push, verificar antes de pushear, run all checks, or quiere validar que todo pasa antes de hacer push.

    162 GitHub stars~732 tokensUpdated yesterday
    EducationAuto-check passed
  • Code Review Security

    nicepkg/auto-company

    Security-focused code review checklist and automated scanning patterns.

    194 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check passed

More from lkmeta/txtify

  • Verify

    lkmeta/txtify

    Verify a Txtify change end-to-end. An agent skill from lkmeta/txtify.

    135 GitHub stars~583 tokensUpdated 1 mo ago
    Auto-check passed

Questions about Deps Bump

What does Deps Bump do?

Safely update Txtify dependencies or resolve Dependabot alerts. Deps Bump is an agent skill from lkmeta/txtify. Safely update Txtify dependencies or resolve Dependabot alerts.

When should I use Deps Bump?

Deps Bump fits situations like: asked to bump packages; fix security alerts; A Dependabot PR appears.

How do I install Deps Bump in Claude Code?

Run `npx skills add lkmeta/txtify --skill deps-bump -a claude-code`. Or copy the skill folder (.claude/skills/deps-bump in lkmeta/txtify) into .claude/skills/deps-bump in your project. Claude Code loads it when a task matches its description.

How do I install Deps Bump in Codex?

Run `npx skills add lkmeta/txtify --skill deps-bump -a codex`. Or copy the skill folder (.claude/skills/deps-bump in lkmeta/txtify) into .agents/skills/deps-bump in your project. Codex loads it when a task matches its description.

Can I use Deps Bump in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lkmeta/txtify --skill deps-bump -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deps-bump, .gemini/skills/deps-bump, .github/skills/deps-bump and .opencode/skills/deps-bump in your project.

What does Deps Bump need to run?

Going by SKILL.md and its folder, Deps Bump needs the command-line tools its instructions call (gh). Our summary lists: Python 3; Docker.

Does Deps Bump access the network?

SKILL.md names 1 domain. In commands or code: youtube.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Deps Bump safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deps Bump use?

Deps Bump is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deps Bump use?

About 585 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deps Bump?

Skills that share tags, products or a category with Deps Bump: Flowfile Debugging Playbook (Edwardvaneechoud/Flowfile, 375 stars), Sync Dependabot App Deps (ossf/oss-crs, 165 stars), AzureML Project Scaffolding (Kilo-Org/kilo-marketplace, 190 stars) and Flowfile Build and Environment Setup (Edwardvaneechoud/Flowfile, 375 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deps Bump?

lkmeta (a GitHub user) maintains it in lkmeta/txtify, which has 135 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on August 15, 2026.

Source: lkmeta/txtify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.