Release Evidence Workflow
Ali-Marandi/ClimateDataAnalyzer
Build an auditable release-evidence workflow for a desktop or packaged application.
instructions for updating and managing project dependencies (including Github actions).
$ npx skills add maread99/market_prices --skill dependencies-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install maread99/market_prices dependencies-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/maread99/market_prices.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependencies-management .claude/skills/dependencies-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependencies-management" agent skill from https://github.com/maread99/market_prices/tree/master/.agents/skills/dependencies-management into .claude/skills/dependencies-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependencies-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/maread99/market_prices/tree/master/.agents/skills/dependencies-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add maread99/market_prices --skill dependencies-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install maread99/market_prices dependencies-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maread99/market_prices.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dependencies-management .agents/skills/dependencies-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependencies-management" agent skill from https://github.com/maread99/market_prices/tree/master/.agents/skills/dependencies-management into .agents/skills/dependencies-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependencies-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maread99/market_prices --skill dependencies-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install maread99/market_prices dependencies-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maread99/market_prices.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dependencies-management .cursor/skills/dependencies-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependencies-management" agent skill from https://github.com/maread99/market_prices/tree/master/.agents/skills/dependencies-management into .cursor/skills/dependencies-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependencies-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/maread99/market_prices.git --path .agents/skills/dependencies-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add maread99/market_prices --skill dependencies-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install maread99/market_prices dependencies-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maread99/market_prices.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dependencies-management .gemini/skills/dependencies-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependencies-management" agent skill from https://github.com/maread99/market_prices/tree/master/.agents/skills/dependencies-management into .gemini/skills/dependencies-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependencies-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install maread99/market_prices dependencies-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add maread99/market_prices --skill dependencies-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/maread99/market_prices.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dependencies-management .github/skills/dependencies-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependencies-management" agent skill from https://github.com/maread99/market_prices/tree/master/.agents/skills/dependencies-management into .github/skills/dependencies-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependencies-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maread99/market_prices --skill dependencies-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install maread99/market_prices dependencies-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maread99/market_prices.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dependencies-management .opencode/skills/dependencies-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependencies-management" agent skill from https://github.com/maread99/market_prices/tree/master/.agents/skills/dependencies-management into .opencode/skills/dependencies-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependencies-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependencies-managementinstructions for updating and managing project dependencies (including Github actions).
Dependencies Management is an agent skill from maread99/market_prices. instructions for updating and managing project dependencies (including Github actions).
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions, Python, pandas and yfinance. The repository describes itself as: Get meaningful OHLCV datasets. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit abfb3cb. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvcurlshpippythonpytestFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comastral.shquery1.finance.yahoo.comraw.githubusercontent.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependencies Management loads about 2.4k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 1,212 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
curl -LsSf https://astral.sh/uv/install.sh | shAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from maread99/market_prices at commit abfb3cb, republished under its MIT licence (© maread99). 1,212 words, ~2,440 tokens.
.claude/skills/dependencies-management/SKILL.md (or your agent's skills folder).Instructions to update project dependencies (including Github actions used by CI workflows).
Create a new branch (following the naming convention in @AGENTS.md).
Update uv:
uv self update --token $GITHUB_TOKENIMPORTANT: updating uv MUST NOT be skipped. If the above command fails (e.g. due to a GitHub API rate limit), try the following fallbacks in order until uv --version confirms the latest version is active on PATH:
Fallback 1 — official install script (preferred; replaces PATH binary directly):
curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env # refresh current shell session
uv --version # verify PATH binary is now updatedFallback 2 — pip (use only if curl is unavailable):
pip install --user --upgrade uv
uv --version # check if PATH binary was updatedOnce uv is up to date, run:
uv lock --upgrade # update the lock file
uv export --format requirements-txt --no-emit-project --no-hashes --no-dev -o requirements.txt # sync @requirements.txt with @uv.lock
uv sync --inexact # update environment to match @uv.lockFor each uses: <owner>/<repo>@<version> entry across all files in .github/workflows/, retrieve the latest release tag by fetching the releases page with WebFetch:
url: https://github.com/<owner>/<repo>/releases/latest
prompt: What is the latest release tag for this GitHub action?In each case update the version pin to any more recent release. Preserve the existing pinning style, so if the current pin is a specific version such as @v3.0.1, update to the full latest version string, whilst if it's a major-version tag such as @v4, update to any new major-version tag (if the project no longer publishes a major-version tag then switch to the full semver).
For each repo: entry in .pre-commit-config.yaml, retrieve the latest release tag by fetching the releases page with WebFetch:
url: https://github.com/<owner>/<repo>/releases/latest
prompt: What is the latest release tag for this pre-commit hook?In each case update the rev: pin to any more recent release. Preserve the existing pinning style, so if the current pin is a specific version such as v6.0.0, update to the full latest version string, whilst if it's a major-version tag such as @v4, update to any new major-version tag (if the project no longer publishes a major-version tag then switch to the full semver).
Before running the tests check whether the test environment has live access to the required network endpoints by running:
python -c "
import urllib.request, sys
for label, url in [
('yahoo', 'https://query1.finance.yahoo.com/v8/finance/chart/MSFT?interval=1d&range=1d'),
('raw.github.com', 'https://raw.githubusercontent.com/'),
]:
try:
urllib.request.urlopen(url, timeout=10)
print(f'{label}: reachable')
except Exception as e:
print(f'{label}: unreachable ({e})')
"Then, run the test suite with options as determined by the reachability results:
uv run pytest -vuv run pytest --ignore=tests/test_yahoo.py --ignore=tests/test_calendar_utils.py -vInterpreting the local test results:
tests/test_yahoo.py and/or tests/test_calendar_utils.py and no raised warning is fixable → test failures probably due to a transient network issue (see Network tests section below), go to step 7 to raise PR.Any failing tests and fixable warnings will likely have their origin in changes to the dependencies. To provide support for the latest dependencies MAKE REVISIONS to the code base to fix:
As a general RULE, change the package code to get the tests passing, not the test code! You may make changes to the test code only with good reason and only when this does not impair the test's efficacy.
To facilitate identifying the cause of test failures consider researching the changelogs of updated dependencies for versions released since the previously locked version.
Iterate on this process until:
IMPORTANT: in this step you should not run the full test suite, rather validate fixes by re-running only the previously failing tests. Example to run a specific test:
pytest tests/test_module.py::test_nameOnce local tests pass, commit all changes to the branch and raise a PR.
Update Dependencies <MM> <DD> (auto) where:<MM> should be replaced with the first three letters of the current month, the first of which should be capitalized.<DD> should be replaced with the current day of the month as represented by two digits.
Example title: Update Dependencies Apr 07 (auto)By raising the PR a GitHub CI workflow will be triggered. Subscribe to the raised PR's activity.
Proceed to step 9 when you receive an event indicating that the triggered workflow has completed.
The CI workflow will have run the full test suite against a matrix of OS and Python versions. Use mcp__github__pull_request_read with the get_check_runs method to read check statuses for all matrix jobs.
Interpreting CI results:
tests/test_yahoo.py and/or tests/test_calendar_utils.py → add a comment to the PR identifying the failure as a possible network issue (see Network tests section below) and ask the owner to investigate the test logs and then EITHER re-run the failed jobs if the failure was due to a transient network error OR provide you with a copy of the log for the failing tests in order that you can work on a fix. In this case suspend the session as pending further prompting.Use the information read from get_check_runs to identify any OS/python version configurations for which the test suite has failed.
If the tests failed on specific matrix combinations (e.g. Windows / Python 3.10) then simulate a local matching environment.
uv run and pass the --python option.)uv package with uv self update.uv.lock with the version previously created by step 2.uv sync.Run the test suite to identify failing tests. For example:
uv run --isolated --python 3.11 python pytest --ignore=tests/test_yahoo.py -vThen find fixes for the failing tests by following step 6.
Finally commit the necessary changes to your original branch (to which previous commits were made). This will trigger the CI on the PR re-run. Return to step 9 (inspect CI results).
ONLY if any test failures cannot be resolved, raise an issue that references the PR and details:
Perform the following 'tidy up' actions:
mcp__github__unsubscribe_pr_activity to unscubscribe from the PR activity.Network tests — tests/test_yahoo.py and tests/test_calendar_utils.py
Tests in tests/test_yahoo.py require live network access to the Yahoo Finance API via the yahooquery library.
Tests in tests/test_calendar_utils.py fetch CSV fixture files from raw.githubusercontent.com, which can return HTTP 403 Forbidden when network access is restricted.
test_yahoo.py and/or test_calendar_utils.py.tests/test_yahoo.py or tests/test_calendar_utils.py: the cause of such failures may be a dropped, rate-limited, or blocked network connection although this cannot be assumed.Fixable warnings The following warnings are considered UNFIXABLE and you should not attempt to fix them.
PricesMissingWarning.All other warnings are considered fixable.
# Add a dependency
uv add <package>© maread99, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/dependencies-management of maread99/market_prices.
Open the folder on GitHubat commit abfb3cb
Dependencies Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependencies Management this skillmaread99/market_prices | 106 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Release Evidence WorkflowAli-Marandi/ClimateDataAnalyzer | 107 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Reproduce macOS Python FlavorsNuitka/Nuitka | 15k | — | ~1.7k | Automated safety check: Pass | AGPL-3.0 | |
| CI Pipeline Synthesizerkajisho5/ffmpeg-skill | 1.9k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| DDNS Build and Release MaintenanceNewFuture/DDNS | 4.7k | — | ~444 | Automated safety check: Pass | MIT | |
| Audit Reviewtestflows/TestFlows-GitHub-Hetzner-Runners | 102 | — | ~2.1k | Automated safety check: Pass | Custom licence |
Ali-Marandi/ClimateDataAnalyzer
Build an auditable release-evidence workflow for a desktop or packaged application.
Nuitka/Nuitka
Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
NewFuture/DDNS
Maintains the DDNS project's GitHub Actions, Docker and Nuitka builds, packaging and release preparation without touching publishing credentials.
testflows/TestFlows-GitHub-Hetzner-Runners
Perform deep feature audits with transition-matrix and logical fault-injection validation.
Aedelon/claude-code-blueprint
Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.
maread99/market_prices
Instructions and guidance on writing tests. An agent skill from maread99/market_prices.
Categories
instructions for updating and managing project dependencies (including Github actions). Dependencies Management is an agent skill from maread99/market_prices. instructions for updating and managing project dependencies (including Github actions).
Dependencies Management fits situations like: tasks that involve CI/CD.
Run `npx skills add maread99/market_prices --skill dependencies-management -a claude-code`. Or copy the skill folder (.agents/skills/dependencies-management in maread99/market_prices) into .claude/skills/dependencies-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add maread99/market_prices --skill dependencies-management -a codex`. Or copy the skill folder (.agents/skills/dependencies-management in maread99/market_prices) into .agents/skills/dependencies-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maread99/market_prices --skill dependencies-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependencies-management, .gemini/skills/dependencies-management, .github/skills/dependencies-management and .opencode/skills/dependencies-management in your project.
Going by SKILL.md and its folder, Dependencies Management needs the command-line tools its instructions call (uv, curl, sh, pip, python and pytest) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Docker; A credential in GITHUB_TOKEN.
SKILL.md names 4 domains. In commands or code: github.com, astral.sh, query1.finance.yahoo.com and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pipes a well-known installer script into a shell), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Dependencies Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependencies Management: Release Evidence Workflow (Ali-Marandi/ClimateDataAnalyzer, 107 stars), Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars) and DDNS Build and Release Maintenance (NewFuture/DDNS, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
maread99 (a GitHub user) maintains it in maread99/market_prices, which has 106 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 15, 2026.
Source: maread99/market_prices on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.