Agent skill

Native Dependency Update

by mono in mono/SkiaSharp

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

MITAuto-check passedSecurity

Install Native Dependency Update

skills CLI
$ npx skills add mono/SkiaSharp --skill native-dependency-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mono/SkiaSharp native-dependency-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/native-dependency-update .claude/skills/native-dependency-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
native-dependency-update
GitHub stars
5.6k
Token cost
~4.1k tokens
SKILL.md length
1,752 words
Files
3 (incl. scripts, references)
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

  • User asks to: - Bump/update a native dependency (libpng
  • SKILL.md covers Key References, ⚠️ MANDATORY: Follow Every Phase, Critical Rules and Phase 0: Environment Setup…, plus 2 more sections
  • Runs Shell scripts from its folder; calls git, gh and dotnet; reaches github.com; needs GH_TOKEN
  • Etc.) - Fix a CVE

What it does

Native Dependency Update is an agent skill from mono/SkiaSharp. Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. Handles security CVE fixes, bug fixes, and version bumps. Use when user asks to: - Bump/update a native dependency (libpng, zlib, expat, webp, etc.) - Fix a CVE or security vulnerability in a native library - Update Skia's DEPS file - Check what version of a dependency is currently used - Analyze breaking changes between dependency versions Triggers: "bump libpng", "update zlib", "fix…

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/breaking-changes.md` and `scripts/setup.sh`).

It sits in Security, covering Vulnerability scanning, Security review and Dependency management. The repository describes itself as: SkiaSharp is a cross-platform 2D graphics API for .NET platforms based on Google's Skia Graphics Library. It provides a comprehensive 2D API that can be used across mobile… The licence is MIT.

When your agent uses it

  • User asks to: - Bump/update a native dependency (libpng
  • Etc.) - Fix a CVE
  • Fix CVE in expat
  • Update native deps

Example prompts

  • “bump libpng”
  • “update zlib”
  • “fix CVE in expat”
  • “/native-dependency-update”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit a74f7f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • gh
    • dotnet
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Native Dependency Update loads about 4.1k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 183 tokens; SKILL.md has 1,752 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~183
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mono/SkiaSharp at commit a74f7f9, republished under its MIT licence (© mono). 1,752 words, ~4,110 tokens.

Download SKILL.mdSave it as .claude/skills/native-dependency-update/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
native-dependency-update
description
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. Handles security CVE fixes, bug fixes, and version bumps. Use when user asks to: - Bump/update a native dependency (libpng, zlib, expat, webp, etc.) - Fix a CVE or security vulnerability in a native library - Update Skia's DEPS file - Check what version of a dependency is currently used - Analyze breaking changes between dependency versions Triggers: "bump libpng", "update zlib", "fix CVE in expat", "update native deps", "what version of libpng", "check for breaking changes". For security audits (finding CVEs, checking PR coverage), use the `security-audit` skill instead.

Native Dependency Update Skill

Update native dependencies in SkiaSharp's Skia fork (mono/skia).

Key References

⚠️ MANDATORY: Follow Every Phase

You MUST complete ALL phases in order. Do not skip phases to save time.

Pre-Flight Checklist

Before starting, confirm you will:

  • Complete Phase 0-8 in order
  • Update DEPS, externals/skia submodule, cgmanifest.json, AND scripts/VERSIONS.txt (for independently-versioned deps — e.g. harfbuzz)
  • Build and test locally before any PR
  • Create PRs (never push directly to protected branches)
  • Stop and ask at every 🛑 checkpoint

Critical Rules

🛑 STOP AND ASK before: Creating PRs, Merging PRs, Force pushing, Any destructive git operations

🚫 BRANCH PROTECTION (MANDATORY COMPLIANCE)

⛔ POLICY VIOLATION: Direct commits to protected branches are prohibited.

This rule applies to BOTH repositories:

RepositoryProtected BranchesAction Required
mono/SkiaSharp (parent repo)main, release/*Create feature branch first
mono/skia (externals/skia submodule)main, skiasharpCreate feature branch first

Before ANY commit in either repository:

  1. Create a feature branch — Use naming convention: dev/update-{dep}
  2. Never commit directly to protected branches — All changes require a PR
  3. This is a compliance requirement — Direct commits bypass review, CI, and audit trails
🔒 Security Rules (ALWAYS — not just for CVE bumps)

All dependency updates are assumed security-sensitive. These rules apply to EVERY bump:

Commit message: Update {dep} to {version} — NOTHING else (plus Co-authored-by trailer) PR title: Update {dep} to {version} PR body: Version numbers, file changes, build verification results ONLY Branch name: dev/update-{dep} — NEVER include CVE IDs

Prohibited in ALL public artifacts (PRs, commits, branches, PR comments):

  • ❌ CVE IDs (e.g., CVE-2026-XXXXX)
  • ❌ Severity ratings or CVSS scores
  • ❌ Words: "security", "vulnerability", "exploit", "fix CVE", "security bump"
  • ❌ Version ranges like "from X to Y" in commit messages
  • ❌ Branch context like "(release/3.119.x)" in commit messages

Security analysis goes in the session conversation ONLY — report to the user:

  1. Which CVEs are fixed, severity, CVSS scores
  2. Which CVEs affect SkiaSharp's code paths and which don't (with reasoning)
  3. Behavior changes that may need test coverage
  4. Upstream issues that remain unfixed
❌ NEVER Do These
ShortcutWhy It's Wrong
Push directly to protected branchesBypasses PR review and CI
Skip native build phaseCI is too slow; must verify locally first
Manually close issuesBreaks audit trail; PR merge auto-closes
Skip cgmanifest.json updateSecurity compliance requires it
Skip scripts/VERSIONS.txt for an independently-versioned dep (harfbuzz)Native soname, DLL FileVersion, and NuGet version drift out of sync with the actual binary
Skip externals/skia submodule updateSkiaSharp won't use the new dependency version
Revert/undo pushed commitsFix forward with new commit instead
Merge both PRs without updating submodule in betweenSquash-merge creates new SHA; submodule points to orphaned commit; BREAKS USERS
Include security details in public artifactsLeaks vulnerability info before users can update
Environment Reminders

These do NOT persist across bash tool calls. Prefix every relevant command:

CommandPrefix
dotnetexport PATH="/usr/local/share/dotnet:/opt/homebrew/bin:$PATH" &&
gh pr create, gh pr edit, etc.unset GH_TOKEN &&
grep (pattern matching)Use grep -E not grep -P (BSD grep on macOS)

Phase 0: Environment Setup (MANDATORY FIRST STEP)

Run the setup script before any other work. It initializes submodules, unshallows the dependency, creates the skia feature branch, and verifies the environment:

bash
bash .agents/skills/native-dependency-update/scripts/setup.sh {dep} {skia_target_branch} {skiasharp_target_branch}

Arguments:

ArgDefaultExamples
dep(required)libpng, expat, zlib, libwebp, freetype
skia_target_branchskiasharpskiasharp, release/3.119.x
skiasharp_target_branchmainmain, release/3.119.x
Determining the skia target branch

⚠️ NEVER assume the skia target branch. It depends on what the user is asking:

User requestskiasharp_target_branchskia_target_branch
Update on mainmainskiasharp
Backport to release branchrelease/3.119.xAsk the user

If you're unsure which skia branch to target, ask the user. Do not guess.

After the script completes, proceed to Phase 1.


Workflow

Phase 1: Discovery
  1. Check for existing PRs in mono/SkiaSharp and mono/skia
  2. Check current version in externals/skia/DEPS
  3. Find target version — get commit hash with git rev-parse {tag}^{commit}
Phase 2: Analysis

Source File Verification (MANDATORY):

bash
cd externals/skia/third_party/externals/{dep}
git diff {old}..{new} --diff-filter=AD --name-only  # Added/Deleted files

Cross-reference against externals/skia/third_party/{dep}/BUILD.gn — new source files may need to be added.

👉 See references/breaking-changes.md for risk assessment.

Phase 3: Local Changes
  1. Edit externals/skia/DEPS with new commit hash
  2. Update BUILD.gn if needed (rare)
  3. Update cgmanifest.json with new version (required for CVE detection)
  4. Update scripts/VERSIONS.txt — only for deps that ship their own native library / NuGet package. Among the bumpable deps this is currently only harfbuzz (libpng, zlib, expat, libwebp, freetype, libjpeg-turbo are statically linked into libSkiaSharp and have NO VERSIONS.txt entry — skip this step for them). See VERSIONS.txt updates below.
  5. Checkout new version in dependency directory

👉 See documentation/dev/dependencies.md for the cgmanifest format.

VERSIONS.txt updates (harfbuzz)

When bumping harfbuzz to {major}.{minor}.{micro}, update ALL of these lines in scripts/VERSIONS.txt (they otherwise drift out of sync with the binary — the soname/file lines drive the actual native .so soname and DLL FileVersion):

EntryLine formatValue for X.Y.Z
harfbuzzreleaseX.Y.Z
HarfBuzzsoname0.<60000 + X*100 + Y*10 + Z>.0 (e.g. 14.2.1 → 0.61421.0)
HarfBuzzSharpfileX.Y.Z (N = 0)
HarfBuzzSharp + all HarfBuzzSharp.NativeAssets.*nugetX.Y.Z (N = 0, ≈10 lines)

HarfBuzz upgrades are made on main and are not backported to older release lines. The upgrade resets package revision N to zero and makes the current Skia milestone the base for X.Y.Z; the normalized 3-part form represents X.Y.Z.0.

If later Skia milestones continue using the same native HarfBuzz version, each milestone adds 100 to the bucket base. For example, if M152 adopts 14.3.1, M152 uses revisions 0–99, M153 uses 100–199, and M154 uses 200–299.

The soname formula and package bucket formula are documented in comments next to their lines. Verify the result with grep -E "harfbuzz|HarfBuzz" scripts/VERSIONS.txt: the native release and soname must match X.Y.Z, while every HarfBuzzSharp file/NuGet entry must reset to the same X.Y.Z package version.

Phase 4: Build & Test

🛑 MANDATORY: Build locally before creating PRs.

See documentation/dev/building.md for platform-specific build commands.

bash
dotnet cake --target=externals-macos --arch=arm64  # Example

# Run all tests (core + Vulkan + Direct3D). GPU backends are required per
# GpuPolicy — a backend that cannot come up fails.
dotnet test tests/SkiaSharp.Tests.Console.slnx

Use the unfiltered solution for initial and final validation. If it identifies a failure, use the owning core, singleton, Vulkan, or Direct3D test project for filtered diagnostic iterations; filtering the .slnx fails the other projects with zero matches. Rerun the unfiltered solution after the focused test passes.

Build Retry Strategy

Common transient failure: HTTP 429 from chromium.googlesource.com

When running dotnet cake --target=externals-macos, the git-sync-deps step fetches 10+ dependencies from Google's mirrors in parallel. If multiple sessions run concurrently, you'll hit rate limits:

error: RPC failed; HTTP 429 curl 22 The requested URL returned error: 429
Exception: Thread failure detected

Strategy:

  1. Wait a short while (rate limits are transient)
  2. Retry the build command
  3. If it still fails after 3 retries, stop and ask for help

Do NOT attempt to manually clone dependencies from other repos — you may pick wrong versions or SHAs.

Other common build issues:

  • fetch-gn network abort → retry (transient)
  • --no-restore flag on dotnet test → remove it, let NuGet restore run
  • Test TTY noise → pipe to file or use tail -50 to read results
Show full SKILL.md (671 more words)Show less
cgmanifest.json Schema

The cgmanifest.json uses different structures per component type:

  • Type "other": component.other.name, component.other.version
  • Type "git": component.git.repositoryUrl, component.git.commitHash

Do NOT assume all entries use the same schema. Check component.type first.

Phase 5: Create PRs

🛑 STOP AND ASK FOR APPROVAL before creating PRs.

Both PRs must be created together — CI requires both.

Both repos use branch name dev/update-{dep}. The skia branch was already created by the setup script.

Step 1: Create mono/skia PR

The branch dev/update-{dep} already exists in externals/skia (created by setup script).

  1. Stage ALL changes before committing (DEPS, BUILD.gn if changed)
  2. Commit ONCE with this exact format:
    Update {dep} to {version}
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
  3. Push ONCE and create a PR targeting {skia_target_branch}:
    bash
    unset GH_TOKEN && gh pr create --repo mono/skia --base {skia_target_branch} --title "Update {dep} to {version}" --body "..."

Do NOT commit-then-amend. Every amend requires a force-push which re-triggers CI (wasting 2+ hours of compute).

Step 2: Create SkiaSharp PR

⚠️ CRITICAL: You MUST update the submodule reference, not just cgmanifest.json

  1. Update the submodule — In externals/skia, fetch and checkout the branch you just pushed in Step 1
  2. Stage both changes — git add externals/skia cgmanifest.json (the submodule AND the manifest)
  3. Commit ONCE with the same format as Step 1
  4. Push and create PR targeting {skiasharp_target_branch}:
    • If targeting main: use the create_pull_request tool
    • If targeting a release branch: use the create_pull_request tool, then immediately fix the base:
      bash
      unset GH_TOKEN && gh pr edit {number} --repo mono/SkiaSharp --base {skiasharp_target_branch}

Edit both PRs to reference each other:

bash
unset GH_TOKEN && gh pr edit {skia_pr_number} --repo mono/skia --body "...Required SkiaSharp PR: https://github.com/mono/SkiaSharp/pull/{number}..."
unset GH_TOKEN && gh pr edit {skiasharp_pr_number} --repo mono/SkiaSharp --body "...Required skia PR: https://github.com/mono/skia/pull/{number}..."
Phase 5 Completion Checklist

Before proceeding, verify ALL of these:

  • Branch names follow dev/update-{dep} convention
  • mono/skia PR targets {skia_target_branch} branch
  • mono/SkiaSharp PR targets {skiasharp_target_branch} branch
  • SkiaSharp's externals/skia submodule points to the mono/skia PR branch (check with git submodule status)
  • cgmanifest.json updated with new version
  • scripts/VERSIONS.txt updated for independently-versioned deps (harfbuzz: release, soname, file, all nuget lines) — N/A for statically-linked deps
  • Both PRs cross-reference each other
  • No security details in any public artifact (see Security Rules above)
Phase 6: Monitor CI

SkiaSharp uses Azure DevOps. mono/skia has no CI — relies on SkiaSharp's.

Phase 7: Merge

🛑 STOP AND ASK FOR APPROVAL before each merge.

🚨 CRITICAL: SQUASH MERGE CREATES NEW COMMITS

When you squash-merge mono/skia PR, GitHub creates a NEW commit SHA on the target branch. The original commits on dev/update-{dep} become orphaned when the branch is deleted.

If SkiaSharp's submodule still points to the old (orphaned) commit, it will BREAK:

  • New clones will fail
  • Submodule updates will fail
  • Users cannot build SkiaSharp

YOU MUST UPDATE THE SUBMODULE BEFORE MERGING SKIASHARP PR.

Merge Sequence (MANDATORY)
  1. Merge mono/skia PR first — This creates a new squashed commit on {skia_target_branch}
  2. Fetch the updated {skia_target_branch} and note the new commit SHA
  3. Update the SkiaSharp submodule to point to the new squashed commit (not the old branch commit)
  4. Push the updated submodule reference to the SkiaSharp PR branch
  5. Only then merge the SkiaSharp PR
Merge Checklist

Before proceeding past each step, verify:

  • mono/skia PR merged
  • Fetched {skia_target_branch} to get new SHA
  • Updated SkiaSharp submodule to new SHA (cd externals/skia && git checkout {new-sha})
  • Pushed submodule update to SkiaSharp PR branch
  • SkiaSharp PR merged

❌ NEVER merge both PRs in quick succession without updating the submodule in between. ❌ NEVER assume the submodule reference is correct after squash-merging mono/skia.

If You Must Amend a Pushed Commit

If you must amend a commit in externals/skia:

  1. Amend the skia commit
  2. Force-push the skia branch
  3. In SkiaSharp root: git add externals/skia (picks up new SHA)
  4. git commit --amend --no-edit
  5. Force-push the SkiaSharp branch

⚠️ NEVER amend the skia commit without also updating the parent submodule reference. The old SHA becomes orphaned after force-push.

Phase 8: Verify
  • Related issues auto-closed
  • Both PRs merged
  • No failures on {skiasharp_target_branch}
  • Submodule points to a commit on {skia_target_branch} — fetch the target branch, check that externals/skia commit exists on it (not orphaned)

Common Dependencies

DependencyDEPS Key
libpngthird_party/externals/libpng
libexpatthird_party/externals/expat
zlibthird_party/externals/zlib
libwebpthird_party/externals/libwebp
harfbuzzthird_party/externals/harfbuzz
freetypethird_party/externals/freetype
libjpeg-turbothird_party/externals/libjpeg-turbo

For cgmanifest names and upstream URLs, see documentation/dev/dependencies.md.

© mono, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in .agents/skills/native-dependency-update of mono/SkiaSharp.

  • SKILL.md
  • references/breaking-changes.md
  • scripts/setup.sh

Open the folder on GitHubat commit a74f7f9

Compare with similar skills

Native Dependency Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Native Dependency Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Native Dependency Update this skillmono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Security Analysismicrosoft/haste106—~1kAutomated safety check: PassMIT
Ghost Scan Depsghostsecurity/skills408—~1.3kAutomated safety check: NotesApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Dependency Update BotVarnan-Tech/opendirectory672—~3kAutomated safety check: NotesMIT

Similar skills

  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    106 GitHub stars~1k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Ghost Scan Deps

    ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner.

    408 GitHub stars~1.3k tokensUpdated 9 days ago
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Dependency Update Bot

    Varnan-Tech/opendirectory

    Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

    672 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Security Check

    gocronx-team/gocron

    Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

    808 GitHub stars~690 tokensUpdated 4 days ago
    SecurityAuto-check passed

More from mono/SkiaSharp

All 23 skills in this repo
  • Issue Fix

    mono/SkiaSharp

    Fix bugs in SkiaSharp C bindings. An agent skill from mono/SkiaSharp.

    5.6k GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Issue Repro

    mono/SkiaSharp

    Reproduce a SkiaSharp issue systematically and capture structured reproduction results.

    5.6k GitHub stars~4.7k tokensUpdated today
    Auto-check passed
  • Issue Triage

    mono/SkiaSharp

    Triage a SkiaSharp GitHub issue or PR into structured JSON with classification (type, area, platform, severity), suggested response, automatable actions, and companion Markdown/HTML reports.

    5.6k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Review Skia Update

    mono/SkiaSharp

    Review a Skia upstream merge PR in mono/skia. An agent skill from mono/SkiaSharp.

    5.6k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Sample Scout

    mono/SkiaSharp

    Scout Skia GM (golden master) samples in the externals/skia submodule to find demos worth porting to the SkiaSharp Gallery.

    5.6k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Skia Analyst

    mono/SkiaSharp

    Analyze Skia features for SkiaSharp - produces a unified analysis of what shipped (upstream engine benefits, PR links, migration guides) and what's missing (impact/priority/effort scoring, hidden…

    5.6k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Questions about Native Dependency Update

What does Native Dependency Update do?

Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. Native Dependency Update is an agent skill from mono/SkiaSharp.) in SkiaSharp's Skia fork.

When should I use Native Dependency Update?

Native Dependency Update fits situations like: user asks to: - Bump/update a native dependency (libpng; etc.) - Fix a CVE; fix CVE in expat; update native deps.

How do I install Native Dependency Update in Claude Code?

Run `npx skills add mono/SkiaSharp --skill native-dependency-update -a claude-code`. Or copy the skill folder (.agents/skills/native-dependency-update in mono/SkiaSharp) into .claude/skills/native-dependency-update in your project. Claude Code loads it when a task matches its description.

How do I install Native Dependency Update in Codex?

Run `npx skills add mono/SkiaSharp --skill native-dependency-update -a codex`. Or copy the skill folder (.agents/skills/native-dependency-update in mono/SkiaSharp) into .agents/skills/native-dependency-update in your project. Codex loads it when a task matches its description.

Can I use Native Dependency Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mono/SkiaSharp --skill native-dependency-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/native-dependency-update, .gemini/skills/native-dependency-update, .github/skills/native-dependency-update and .opencode/skills/native-dependency-update in your project.

What does Native Dependency Update need to run?

Going by SKILL.md and its folder, Native Dependency Update needs a shell for the scripts in its folder, the command-line tools its instructions call (git, gh, dotnet and bash) and credentials named GH_TOKEN. Our summary lists: A Bash shell.

Does Native Dependency Update access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Native Dependency Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Native Dependency Update use?

Native Dependency Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Native Dependency Update use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Native Dependency Update?

Skills that share tags, products or a category with Native Dependency Update: Cyberowlai (karimhabush/cyberowl, 263 stars), Security Analysis (microsoft/haste, 106 stars), Ghost Scan Deps (ghostsecurity/skills, 408 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Native Dependency Update?

mono (a GitHub organization) maintains it in mono/SkiaSharp, which has 5,585 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.

Source: mono/SkiaSharp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.