Agent skill

Dependencies Management

by maread99 in maread99/market_prices

instructions for updating and managing project dependencies (including Github actions).

MITAuto-check: notesDevOps & Cloud

Install Dependencies Management

skills CLI
$ npx skills add maread99/market_prices --skill dependencies-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maread99/market_prices dependencies-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maread99/market_prices.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependencies-management .claude/skills/dependencies-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependencies-management
GitHub stars
106
Token cost
~2.4k tokens
SKILL.md length
1,212 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

instructions for updating and managing project dependencies (including Github actions).

  • Works in 12 steps: Prepare the branch → Update the lock file and environment → Update GitHub Actions versions → …
  • Tasks that involve CI/CD
  • SKILL.md covers Update Dependencies and Adding dependencies
  • Calls uv, curl and sh; reaches github.com and astral.sh; needs GITHUB_TOKEN

What it does

Dependencies Management is an agent skill from maread99/market_prices. instructions for updating and managing project dependencies (including Github actions).

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions, Python, pandas and yfinance. The repository describes itself as: Get meaningful OHLCV datasets. The licence is MIT.

When your agent uses it

  • Tasks that involve CI/CD

Example prompts

  • “Use the dependencies-management skill to instruction for updating and managing project dependencies (including Github actions)”
  • “/dependencies-management”

Requirements

  • Python 3
  • Docker
  • A credential in GITHUB_TOKEN

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Prepare the branch
  2. Update the lock file and environment
  3. Update GitHub Actions versions
  4. Update pre-commit hook versions
  5. Test
  6. Fix
  7. Raise PR
  8. Subscribe to PR activity
  9. Inspect CI results
  10. Fix tests for specific OS/Python configuration
  11. Fallback: raise an issue
  12. Tidy up

What it can do on your machine

Read from SKILL.md and the folder at commit abfb3cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • curl
    • sh
    • pip
    • python
    • pytest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • astral.sh
    • query1.finance.yahoo.com
    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependencies Management loads about 2.4k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 1,212 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePipes a well-known installer script into a shellSKILL.md:27
    curl -LsSf https://astral.sh/uv/install.sh | sh

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maread99/market_prices at commit abfb3cb, republished under its MIT licence (© maread99). 1,212 words, ~2,440 tokens.

Download SKILL.mdSave it as .claude/skills/dependencies-management/SKILL.md (or your agent's skills folder).
name
dependencies-management
description
instructions for updating and managing project dependencies (including Github actions).

Dependencies Management

Update Dependencies

Instructions to update project dependencies (including Github actions used by CI workflows).

1. Prepare the branch

Create a new branch (following the naming convention in @AGENTS.md).

2. Update the lock file and environment

Update uv:

bash
uv self update --token $GITHUB_TOKEN

IMPORTANT: updating uv MUST NOT be skipped. If the above command fails (e.g. due to a GitHub API rate limit), try the following fallbacks in order until uv --version confirms the latest version is active on PATH:

Fallback 1 — official install script (preferred; replaces PATH binary directly):

bash
curl -LsSf https://astral.sh/uv/install.sh | sh
source $HOME/.local/bin/env  # refresh current shell session
uv --version                 # verify PATH binary is now updated

Fallback 2 — pip (use only if curl is unavailable):

bash
pip install --user --upgrade uv
uv --version   # check if PATH binary was updated

Once uv is up to date, run:

bash
uv lock --upgrade  # update the lock file
uv export --format requirements-txt --no-emit-project --no-hashes --no-dev -o requirements.txt  # sync @requirements.txt with @uv.lock
uv sync --inexact  # update environment to match @uv.lock
3. Update GitHub Actions versions

For each uses: <owner>/<repo>@<version> entry across all files in .github/workflows/, retrieve the latest release tag by fetching the releases page with WebFetch:

url:    https://github.com/<owner>/<repo>/releases/latest
prompt: What is the latest release tag for this GitHub action?

In each case update the version pin to any more recent release. Preserve the existing pinning style, so if the current pin is a specific version such as @v3.0.1, update to the full latest version string, whilst if it's a major-version tag such as @v4, update to any new major-version tag (if the project no longer publishes a major-version tag then switch to the full semver).

4. Update pre-commit hook versions

For each repo: entry in .pre-commit-config.yaml, retrieve the latest release tag by fetching the releases page with WebFetch:

url:    https://github.com/<owner>/<repo>/releases/latest
prompt: What is the latest release tag for this pre-commit hook?

In each case update the rev: pin to any more recent release. Preserve the existing pinning style, so if the current pin is a specific version such as v6.0.0, update to the full latest version string, whilst if it's a major-version tag such as @v4, update to any new major-version tag (if the project no longer publishes a major-version tag then switch to the full semver).

5. Test

Before running the tests check whether the test environment has live access to the required network endpoints by running:

bash
python -c "
import urllib.request, sys

for label, url in [
    ('yahoo', 'https://query1.finance.yahoo.com/v8/finance/chart/MSFT?interval=1d&range=1d'),
    ('raw.github.com', 'https://raw.githubusercontent.com/'),
]:
    try:
        urllib.request.urlopen(url, timeout=10)
        print(f'{label}: reachable')
    except Exception as e:
        print(f'{label}: unreachable ({e})')
"

Then, run the test suite with options as determined by the reachability results:

  • If both reachable: run the full test suite:
    bash
    uv run pytest -v
  • otherwise use the pytest --ignore option to exclude the test module(s) correponding with the unreachable service(s):
    • if yahoo unreachable then '--ignore=tests/test_yahoo.py'
    • if raw.github.com unreachable then '--ignore=tests/test_calendar_utils.py' For example, if both yahoo and raw.github.com are unreachable then the command will be:
    bash
    uv run pytest --ignore=tests/test_yahoo.py --ignore=tests/test_calendar_utils.py -v

Interpreting the local test results:

  • All tests pass and no raised warning is fixable (see Fixable warnings section below) → go to step 7 to raise PR.
  • All failing tests are in tests/test_yahoo.py and/or tests/test_calendar_utils.py and no raised warning is fixable → test failures probably due to a transient network issue (see Network tests section below), go to step 7 to raise PR.
  • Failure of any other test or a fixable warning raised → proceed to step 6 to fix.
6. Fix

Any failing tests and fixable warnings will likely have their origin in changes to the dependencies. To provide support for the latest dependencies MAKE REVISIONS to the code base to fix:

  • code causing tests to fail.
  • all fixable warnings (see Fixable warnings section below).

As a general RULE, change the package code to get the tests passing, not the test code! You may make changes to the test code only with good reason and only when this does not impair the test's efficacy.

To facilitate identifying the cause of test failures consider researching the changelogs of updated dependencies for versions released since the previously locked version.

Iterate on this process until:

  • all tests are passing with the exception of any requiring unreachable services.
  • all fixable warnings have been fixed.

IMPORTANT: in this step you should not run the full test suite, rather validate fixes by re-running only the previously failing tests. Example to run a specific test:

bash
pytest tests/test_module.py::test_name
7. Raise PR

Once local tests pass, commit all changes to the branch and raise a PR.

  • PR title: Title the PR as Update Dependencies <MM> <DD> (auto) where:
    • <MM> should be replaced with the first three letters of the current month, the first of which should be capitalized.
    • <DD> should be replaced with the current day of the month as represented by two digits. Example title: Update Dependencies Apr 07 (auto)
  • label: Add the 'dependencies' label to the PR.
  • otherwise comply with the package's 'create-pr' skill.
8. Subscribe to PR activity

By raising the PR a GitHub CI workflow will be triggered. Subscribe to the raised PR's activity.

Proceed to step 9 when you receive an event indicating that the triggered workflow has completed.

Show full SKILL.md (485 more words)Show less
9. Inspect CI results

The CI workflow will have run the full test suite against a matrix of OS and Python versions. Use mcp__github__pull_request_read with the get_check_runs method to read check statuses for all matrix jobs.

Interpreting CI results:

  • All checks green → proceed to step 12.
  • Failures only in tests/test_yahoo.py and/or tests/test_calendar_utils.py → add a comment to the PR identifying the failure as a possible network issue (see Network tests section below) and ask the owner to investigate the test logs and then EITHER re-run the failed jobs if the failure was due to a transient network error OR provide you with a copy of the log for the failing tests in order that you can work on a fix. In this case suspend the session as pending further prompting.
  • Failures in any other test file → proceed to step 10.
10. Fix tests for specific OS/Python configuration

Use the information read from get_check_runs to identify any OS/python version configurations for which the test suite has failed.

If the tests failed on specific matrix combinations (e.g. Windows / Python 3.10) then simulate a local matching environment.

  • If necessary use a Docker container with the target OS. (To specify different Python versions you will be able to run commands with uv run and pass the --python option.)
  • create a new branch against the repository's master branch.
  • update the uv package with uv self update.
  • overwrite uv.lock with the version previously created by step 2.
  • synchronise the environment by running uv sync.

Run the test suite to identify failing tests. For example:

bash
uv run --isolated --python 3.11 python pytest --ignore=tests/test_yahoo.py -v

Then find fixes for the failing tests by following step 6.

Finally commit the necessary changes to your original branch (to which previous commits were made). This will trigger the CI on the PR re-run. Return to step 9 (inspect CI results).

11. Fallback: raise an issue

ONLY if any test failures cannot be resolved, raise an issue that references the PR and details:

  • the failing tests
  • any fixes already attempted
  • any suggested next steps.
12. Tidy up

Perform the following 'tidy up' actions:

  • Call mcp__github__unsubscribe_pr_activity to unscubscribe from the PR activity.
  • Review and if necessary update the PR body to reflect the final circumstances.

Network tests — tests/test_yahoo.py and tests/test_calendar_utils.py

Tests in tests/test_yahoo.py require live network access to the Yahoo Finance API via the yahooquery library.

Tests in tests/test_calendar_utils.py fetch CSV fixture files from raw.githubusercontent.com, which can return HTTP 403 Forbidden when network access is restricted.

  • Local test runs: use the reachability check described in step 5 to decide whether to include or exclude tests in test_yahoo.py and/or test_calendar_utils.py.
  • CI failures in tests/test_yahoo.py or tests/test_calendar_utils.py: the cause of such failures may be a dropped, rate-limited, or blocked network connection although this cannot be assumed.

Fixable warnings The following warnings are considered UNFIXABLE and you should not attempt to fix them.

  • warnings that have their origin in a dependency's code.
  • PricesMissingWarning.

All other warnings are considered fixable.

Adding dependencies

bash
# Add a dependency
uv add <package>

© maread99, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/dependencies-management of maread99/market_prices.

Open the folder on GitHubat commit abfb3cb

Compare with similar skills

Dependencies Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependencies Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependencies Management this skillmaread99/market_prices106—~2.4kAutomated safety check: NotesMIT
Release Evidence WorkflowAli-Marandi/ClimateDataAnalyzer107—~1.6kAutomated safety check: PassMIT
Reproduce macOS Python FlavorsNuitka/Nuitka15k—~1.7kAutomated safety check: PassAGPL-3.0
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
DDNS Build and Release MaintenanceNewFuture/DDNS4.7k—~444Automated safety check: PassMIT
Audit Reviewtestflows/TestFlows-GitHub-Hetzner-Runners102—~2.1kAutomated safety check: PassCustom licence

Similar skills

  • Release Evidence Workflow

    Ali-Marandi/ClimateDataAnalyzer

    Build an auditable release-evidence workflow for a desktop or packaged application.

    107 GitHub stars~1.6k tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.

    15k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Maintains the DDNS project's GitHub Actions, Docker and Nuitka builds, packaging and release preparation without touching publishing credentials.

    4.7k GitHub stars~444 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Audit Review

    testflows/TestFlows-GitHub-Hetzner-Runners

    Perform deep feature audits with transition-matrix and logical fault-injection validation.

    102 GitHub stars~2.1k tokensUpdated 16 days ago
    DevOps & CloudAuto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed

More from maread99/market_prices

  • Writing Tests

    maread99/market_prices

    Instructions and guidance on writing tests. An agent skill from maread99/market_prices.

    106 GitHub stars~315 tokensUpdated 23 days ago
    Auto-check passed

Categories

Questions about Dependencies Management

What does Dependencies Management do?

instructions for updating and managing project dependencies (including Github actions). Dependencies Management is an agent skill from maread99/market_prices. instructions for updating and managing project dependencies (including Github actions).

When should I use Dependencies Management?

Dependencies Management fits situations like: tasks that involve CI/CD.

How do I install Dependencies Management in Claude Code?

Run `npx skills add maread99/market_prices --skill dependencies-management -a claude-code`. Or copy the skill folder (.agents/skills/dependencies-management in maread99/market_prices) into .claude/skills/dependencies-management in your project. Claude Code loads it when a task matches its description.

How do I install Dependencies Management in Codex?

Run `npx skills add maread99/market_prices --skill dependencies-management -a codex`. Or copy the skill folder (.agents/skills/dependencies-management in maread99/market_prices) into .agents/skills/dependencies-management in your project. Codex loads it when a task matches its description.

Can I use Dependencies Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maread99/market_prices --skill dependencies-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependencies-management, .gemini/skills/dependencies-management, .github/skills/dependencies-management and .opencode/skills/dependencies-management in your project.

What does Dependencies Management need to run?

Going by SKILL.md and its folder, Dependencies Management needs the command-line tools its instructions call (uv, curl, sh, pip, python and pytest) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; Docker; A credential in GITHUB_TOKEN.

Does Dependencies Management access the network?

SKILL.md names 4 domains. In commands or code: github.com, astral.sh, query1.finance.yahoo.com and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dependencies Management safe to install?

Our automated static check of SKILL.md found notes only (pipes a well-known installer script into a shell), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dependencies Management use?

Dependencies Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependencies Management use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependencies Management?

Skills that share tags, products or a category with Dependencies Management: Release Evidence Workflow (Ali-Marandi/ClimateDataAnalyzer, 107 stars), Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars) and DDNS Build and Release Maintenance (NewFuture/DDNS, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependencies Management?

maread99 (a GitHub user) maintains it in maread99/market_prices, which has 106 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 15, 2026.

Source: maread99/market_prices on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.