Cyberowlai
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
$ npx skills add mono/SkiaSharp --skill native-dependency-update -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mono/SkiaSharp native-dependency-update --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/native-dependency-update .claude/skills/native-dependency-update && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "native-dependency-update" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/native-dependency-update into .claude/skills/native-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-dependency-update", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mono/SkiaSharp/tree/main/.agents/skills/native-dependency-updateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mono/SkiaSharp --skill native-dependency-update -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mono/SkiaSharp native-dependency-update --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/native-dependency-update .agents/skills/native-dependency-update && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "native-dependency-update" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/native-dependency-update into .agents/skills/native-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-dependency-update", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mono/SkiaSharp --skill native-dependency-update -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mono/SkiaSharp native-dependency-update --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/native-dependency-update .cursor/skills/native-dependency-update && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "native-dependency-update" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/native-dependency-update into .cursor/skills/native-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-dependency-update", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mono/SkiaSharp.git --path .agents/skills/native-dependency-update--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mono/SkiaSharp --skill native-dependency-update -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mono/SkiaSharp native-dependency-update --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/native-dependency-update .gemini/skills/native-dependency-update && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "native-dependency-update" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/native-dependency-update into .gemini/skills/native-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-dependency-update", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mono/SkiaSharp native-dependency-updateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mono/SkiaSharp --skill native-dependency-update -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/native-dependency-update .github/skills/native-dependency-update && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "native-dependency-update" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/native-dependency-update into .github/skills/native-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-dependency-update", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mono/SkiaSharp --skill native-dependency-update -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mono/SkiaSharp native-dependency-update --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/native-dependency-update .opencode/skills/native-dependency-update && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "native-dependency-update" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/native-dependency-update into .opencode/skills/native-dependency-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-dependency-update", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
native-dependency-updateUpdate native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
Native Dependency Update is an agent skill from mono/SkiaSharp. Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. Handles security CVE fixes, bug fixes, and version bumps. Use when user asks to: - Bump/update a native dependency (libpng, zlib, expat, webp, etc.) - Fix a CVE or security vulnerability in a native library - Update Skia's DEPS file - Check what version of a dependency is currently used - Analyze breaking changes between dependency versions Triggers: "bump libpng", "update zlib", "fix…
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/breaking-changes.md` and `scripts/setup.sh`).
It sits in Security, covering Vulnerability scanning, Security review and Dependency management. The repository describes itself as: SkiaSharp is a cross-platform 2D graphics API for .NET platforms based on Google's Skia Graphics Library. It provides a comprehensive 2D API that can be used across mobile… The licence is MIT.
Read from SKILL.md and the folder at commit a74f7f9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitghdotnetbashFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Native Dependency Update loads about 4.1k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 183 tokens; SKILL.md has 1,752 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mono/SkiaSharp at commit a74f7f9, republished under its MIT licence (© mono). 1,752 words, ~4,110 tokens.
.claude/skills/native-dependency-update/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Update native dependencies in SkiaSharp's Skia fork (mono/skia).
You MUST complete ALL phases in order. Do not skip phases to save time.
Before starting, confirm you will:
externals/skia submodule, cgmanifest.json, AND scripts/VERSIONS.txt (for independently-versioned deps — e.g. harfbuzz)🛑 STOP AND ASK before: Creating PRs, Merging PRs, Force pushing, Any destructive git operations
⛔ POLICY VIOLATION: Direct commits to protected branches are prohibited.
This rule applies to BOTH repositories:
| Repository | Protected Branches | Action Required |
|---|---|---|
| mono/SkiaSharp (parent repo) | main, release/* | Create feature branch first |
mono/skia (externals/skia submodule) | main, skiasharp | Create feature branch first |
Before ANY commit in either repository:
dev/update-{dep}All dependency updates are assumed security-sensitive. These rules apply to EVERY bump:
Commit message: Update {dep} to {version} — NOTHING else (plus Co-authored-by trailer)
PR title: Update {dep} to {version}
PR body: Version numbers, file changes, build verification results ONLY
Branch name: dev/update-{dep} — NEVER include CVE IDs
Prohibited in ALL public artifacts (PRs, commits, branches, PR comments):
Security analysis goes in the session conversation ONLY — report to the user:
| Shortcut | Why It's Wrong |
|---|---|
| Push directly to protected branches | Bypasses PR review and CI |
| Skip native build phase | CI is too slow; must verify locally first |
| Manually close issues | Breaks audit trail; PR merge auto-closes |
Skip cgmanifest.json update | Security compliance requires it |
Skip scripts/VERSIONS.txt for an independently-versioned dep (harfbuzz) | Native soname, DLL FileVersion, and NuGet version drift out of sync with the actual binary |
Skip externals/skia submodule update | SkiaSharp won't use the new dependency version |
| Revert/undo pushed commits | Fix forward with new commit instead |
| Merge both PRs without updating submodule in between | Squash-merge creates new SHA; submodule points to orphaned commit; BREAKS USERS |
| Include security details in public artifacts | Leaks vulnerability info before users can update |
These do NOT persist across bash tool calls. Prefix every relevant command:
| Command | Prefix |
|---|---|
dotnet | export PATH="/usr/local/share/dotnet:/opt/homebrew/bin:$PATH" && |
gh pr create, gh pr edit, etc. | unset GH_TOKEN && |
grep (pattern matching) | Use grep -E not grep -P (BSD grep on macOS) |
Run the setup script before any other work. It initializes submodules, unshallows the dependency, creates the skia feature branch, and verifies the environment:
bash .agents/skills/native-dependency-update/scripts/setup.sh {dep} {skia_target_branch} {skiasharp_target_branch}Arguments:
| Arg | Default | Examples |
|---|---|---|
dep | (required) | libpng, expat, zlib, libwebp, freetype |
skia_target_branch | skiasharp | skiasharp, release/3.119.x |
skiasharp_target_branch | main | main, release/3.119.x |
⚠️ NEVER assume the skia target branch. It depends on what the user is asking:
| User request | skiasharp_target_branch | skia_target_branch |
|---|---|---|
| Update on main | main | skiasharp |
| Backport to release branch | release/3.119.x | Ask the user |
If you're unsure which skia branch to target, ask the user. Do not guess.
After the script completes, proceed to Phase 1.
externals/skia/DEPSgit rev-parse {tag}^{commit}Source File Verification (MANDATORY):
cd externals/skia/third_party/externals/{dep}
git diff {old}..{new} --diff-filter=AD --name-only # Added/Deleted filesCross-reference against externals/skia/third_party/{dep}/BUILD.gn — new source files may need to be added.
👉 See references/breaking-changes.md for risk assessment.
externals/skia/DEPS with new commit hashcgmanifest.json with new version (required for CVE detection)scripts/VERSIONS.txt — only for deps that ship their own native library / NuGet package. Among the bumpable deps this is currently only harfbuzz (libpng, zlib, expat, libwebp, freetype, libjpeg-turbo are statically linked into libSkiaSharp and have NO VERSIONS.txt entry — skip this step for them). See VERSIONS.txt updates below.👉 See documentation/dev/dependencies.md for the cgmanifest format.
When bumping harfbuzz to {major}.{minor}.{micro}, update ALL of these
lines in scripts/VERSIONS.txt (they otherwise drift out of sync with the
binary — the soname/file lines drive the actual native .so soname and DLL
FileVersion):
| Entry | Line format | Value for X.Y.Z |
|---|---|---|
harfbuzz | release | X.Y.Z |
HarfBuzz | soname | 0.<60000 + X*100 + Y*10 + Z>.0 (e.g. 14.2.1 → 0.61421.0) |
HarfBuzzSharp | file | X.Y.Z (N = 0) |
HarfBuzzSharp + all HarfBuzzSharp.NativeAssets.* | nuget | X.Y.Z (N = 0, ≈10 lines) |
HarfBuzz upgrades are made on main and are not backported to older release
lines. The upgrade resets package revision N to zero and makes the current
Skia milestone the base for X.Y.Z; the normalized 3-part form represents
X.Y.Z.0.
If later Skia milestones continue using the same native HarfBuzz version, each milestone adds 100 to the bucket base. For example, if M152 adopts 14.3.1, M152 uses revisions 0–99, M153 uses 100–199, and M154 uses 200–299.
The soname formula and package bucket formula are documented in comments next
to their lines. Verify the result with
grep -E "harfbuzz|HarfBuzz" scripts/VERSIONS.txt: the native release and
soname must match X.Y.Z, while every HarfBuzzSharp file/NuGet entry must
reset to the same X.Y.Z package version.
🛑 MANDATORY: Build locally before creating PRs.
See documentation/dev/building.md for platform-specific build commands.
dotnet cake --target=externals-macos --arch=arm64 # Example
# Run all tests (core + Vulkan + Direct3D). GPU backends are required per
# GpuPolicy — a backend that cannot come up fails.
dotnet test tests/SkiaSharp.Tests.Console.slnxUse the unfiltered solution for initial and final validation. If it identifies a failure,
use the owning core, singleton, Vulkan, or Direct3D test project for filtered diagnostic
iterations; filtering the .slnx fails the other projects with zero matches. Rerun the
unfiltered solution after the focused test passes.
Common transient failure: HTTP 429 from chromium.googlesource.com
When running dotnet cake --target=externals-macos, the git-sync-deps step fetches 10+ dependencies from Google's mirrors in parallel. If multiple sessions run concurrently, you'll hit rate limits:
error: RPC failed; HTTP 429 curl 22 The requested URL returned error: 429
Exception: Thread failure detectedStrategy:
Do NOT attempt to manually clone dependencies from other repos — you may pick wrong versions or SHAs.
Other common build issues:
fetch-gn network abort → retry (transient)--no-restore flag on dotnet test → remove it, let NuGet restore runtail -50 to read resultsThe cgmanifest.json uses different structures per component type:
"other": component.other.name, component.other.version"git": component.git.repositoryUrl, component.git.commitHashDo NOT assume all entries use the same schema. Check component.type first.
🛑 STOP AND ASK FOR APPROVAL before creating PRs.
Both PRs must be created together — CI requires both.
Both repos use branch name dev/update-{dep}. The skia branch was already created by the setup script.
The branch dev/update-{dep} already exists in externals/skia (created by setup script).
Update {dep} to {version}
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>{skia_target_branch}:unset GH_TOKEN && gh pr create --repo mono/skia --base {skia_target_branch} --title "Update {dep} to {version}" --body "..."Do NOT commit-then-amend. Every amend requires a force-push which re-triggers CI (wasting 2+ hours of compute).
⚠️ CRITICAL: You MUST update the submodule reference, not just cgmanifest.json
externals/skia, fetch and checkout the branch you just pushed in Step 1git add externals/skia cgmanifest.json (the submodule AND the manifest){skiasharp_target_branch}:main: use the create_pull_request toolcreate_pull_request tool, then immediately fix the base:unset GH_TOKEN && gh pr edit {number} --repo mono/SkiaSharp --base {skiasharp_target_branch}Edit both PRs to reference each other:
unset GH_TOKEN && gh pr edit {skia_pr_number} --repo mono/skia --body "...Required SkiaSharp PR: https://github.com/mono/SkiaSharp/pull/{number}..."
unset GH_TOKEN && gh pr edit {skiasharp_pr_number} --repo mono/SkiaSharp --body "...Required skia PR: https://github.com/mono/skia/pull/{number}..."Before proceeding, verify ALL of these:
dev/update-{dep} convention{skia_target_branch} branch{skiasharp_target_branch} branchexternals/skia submodule points to the mono/skia PR branch (check with git submodule status)cgmanifest.json updated with new versionscripts/VERSIONS.txt updated for independently-versioned deps (harfbuzz: release, soname, file, all nuget lines) — N/A for statically-linked depsSkiaSharp uses Azure DevOps. mono/skia has no CI — relies on SkiaSharp's.
🛑 STOP AND ASK FOR APPROVAL before each merge.
🚨 CRITICAL: SQUASH MERGE CREATES NEW COMMITS
When you squash-merge mono/skia PR, GitHub creates a NEW commit SHA on the target branch. The original commits on
dev/update-{dep}become orphaned when the branch is deleted.If SkiaSharp's submodule still points to the old (orphaned) commit, it will BREAK:
- New clones will fail
- Submodule updates will fail
- Users cannot build SkiaSharp
YOU MUST UPDATE THE SUBMODULE BEFORE MERGING SKIASHARP PR.
{skia_target_branch}{skia_target_branch} and note the new commit SHABefore proceeding past each step, verify:
{skia_target_branch} to get new SHAcd externals/skia && git checkout {new-sha})❌ NEVER merge both PRs in quick succession without updating the submodule in between. ❌ NEVER assume the submodule reference is correct after squash-merging mono/skia.
If you must amend a commit in externals/skia:
git add externals/skia (picks up new SHA)git commit --amend --no-edit⚠️ NEVER amend the skia commit without also updating the parent submodule reference. The old SHA becomes orphaned after force-push.
{skiasharp_target_branch}{skia_target_branch} — fetch the target branch, check that externals/skia commit exists on it (not orphaned)| Dependency | DEPS Key |
|---|---|
| libpng | third_party/externals/libpng |
| libexpat | third_party/externals/expat |
| zlib | third_party/externals/zlib |
| libwebp | third_party/externals/libwebp |
| harfbuzz | third_party/externals/harfbuzz |
| freetype | third_party/externals/freetype |
| libjpeg-turbo | third_party/externals/libjpeg-turbo |
For cgmanifest names and upstream URLs, see documentation/dev/dependencies.md.
© mono, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in .agents/skills/native-dependency-update of mono/SkiaSharp.
Open the folder on GitHubat commit a74f7f9
Native Dependency Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Native Dependency Update this skillmono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Security Analysismicrosoft/haste | 106 | — | ~1k | Automated safety check: Pass | MIT | |
| Ghost Scan Depsghostsecurity/skills | 408 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Dependency Update BotVarnan-Tech/opendirectory | 672 | — | ~3k | Automated safety check: Notes | MIT |
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
microsoft/haste
Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.
ghostsecurity/skills
Ghost Security - Software Composition Analysis (SCA) scanner.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
Varnan-Tech/opendirectory
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
gocronx-team/gocron
Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.
mono/SkiaSharp
Fix bugs in SkiaSharp C bindings. An agent skill from mono/SkiaSharp.
mono/SkiaSharp
Reproduce a SkiaSharp issue systematically and capture structured reproduction results.
mono/SkiaSharp
Triage a SkiaSharp GitHub issue or PR into structured JSON with classification (type, area, platform, severity), suggested response, automatable actions, and companion Markdown/HTML reports.
mono/SkiaSharp
Review a Skia upstream merge PR in mono/skia. An agent skill from mono/SkiaSharp.
mono/SkiaSharp
Scout Skia GM (golden master) samples in the externals/skia submodule to find demos worth porting to the SkiaSharp Gallery.
mono/SkiaSharp
Analyze Skia features for SkiaSharp - produces a unified analysis of what shipped (upstream engine benefits, PR links, migration guides) and what's missing (impact/priority/effort scoring, hidden…
Categories
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. Native Dependency Update is an agent skill from mono/SkiaSharp.) in SkiaSharp's Skia fork.
Native Dependency Update fits situations like: user asks to: - Bump/update a native dependency (libpng; etc.) - Fix a CVE; fix CVE in expat; update native deps.
Run `npx skills add mono/SkiaSharp --skill native-dependency-update -a claude-code`. Or copy the skill folder (.agents/skills/native-dependency-update in mono/SkiaSharp) into .claude/skills/native-dependency-update in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mono/SkiaSharp --skill native-dependency-update -a codex`. Or copy the skill folder (.agents/skills/native-dependency-update in mono/SkiaSharp) into .agents/skills/native-dependency-update in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mono/SkiaSharp --skill native-dependency-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/native-dependency-update, .gemini/skills/native-dependency-update, .github/skills/native-dependency-update and .opencode/skills/native-dependency-update in your project.
Going by SKILL.md and its folder, Native Dependency Update needs a shell for the scripts in its folder, the command-line tools its instructions call (git, gh, dotnet and bash) and credentials named GH_TOKEN. Our summary lists: A Bash shell.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Native Dependency Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Native Dependency Update: Cyberowlai (karimhabush/cyberowl, 263 stars), Security Analysis (microsoft/haste, 106 stars), Ghost Scan Deps (ghostsecurity/skills, 408 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mono (a GitHub organization) maintains it in mono/SkiaSharp, which has 5,585 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.
Source: mono/SkiaSharp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.