Agent skill

Phx Deps Update

by oliver-kriska in oliver-kriska/claude-elixir-phoenix

Update Hex dependencies safely. An agent skill from oliver-kriska/claude-elixir-phoenix.

MITAuto-check passedAI & LLM Engineering

Install Phx Deps Update

skills CLI
$ npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install oliver-kriska/claude-elixir-phoenix phx-deps-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/oliver-kriska/claude-elixir-phoenix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/targets/codex/skills/phx-deps-update .claude/skills/phx-deps-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phx-deps-update
GitHub stars
565
Token cost
~1.3k tokens
SKILL.md length
525 words
Files
5 (incl. references)
Skills in repo
109
Repo updated
First seen
Licence
MIT

At a glance

Update Hex dependencies safely. An agent skill from oliver-kriska/claude-elixir-phoenix.

  • Works in 8 steps: Discover → Inventory → Scope (AskUserQuestion) → …
  • Use $elixir-phoenix:phx-investigate for deps.get failures
  • SKILL.md covers Usage, Iron Laws, Workflow and Integration, plus 1 more section
  • Calls git, gh and npm; reaches diff.hex.pm

What it does

Phx Deps Update is an agent skill from oliver-kriska/claude-elixir-phoenix. Update Hex dependencies safely. Use for upgrades; use $elixir-phoenix:phx-investigate for deps.get failures.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/changelog-sources.md`, `references/coupled-groups.md` and `references/pr-strategy.md`).

It sits in AI & LLM Engineering, covering LLM observability. It works with Elixir. The repository describes itself as: Claude Code plugin for Elixir/Phoenix/LiveView — 26 specialist agents, Iron Laws enforcement, and Tidewave MCP integration. Plan features with parallel research agents, execute… The licence is MIT.

When your agent uses it

  • Use $elixir-phoenix:phx-investigate for deps.get failures
  • Tasks that involve LLM observability

Example prompts

  • “/phx-deps-update”

Requirements

  • Node.js

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Discover
  2. Inventory
  3. Scope (AskUserQuestion)
  4. Per-Package Update Loop
  5. Verify
  6. Breaking-Change Fixes
  7. Security Handoff
  8. Group, Commit, PR

What it can do on your machine

Read from SKILL.md and the folder at commit 9767a82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • diff.hex.pm

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phx Deps Update loads about 1.3k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 31 tokens; SKILL.md has 525 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from oliver-kriska/claude-elixir-phoenix at commit 9767a82, republished under its MIT licence (© oliver-kriska). 525 words, ~1,304 tokens.

Download SKILL.mdSave it as .claude/skills/phx-deps-update/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
phx-deps-update
description
Update Hex dependencies safely. Use for upgrades; use $elixir-phoenix:phx-investigate for deps.get failures.

Dependency Update (Freshness)

Inventory → update → fix breaks → grouped PRs. This is the only MUTATING deps skill: it edits mix.exs, mix.lock, and source. Security scanning stays in $elixir-phoenix:phx-deps-audit; the vet ledger stays in $elixir-phoenix:phx-deps-vet.

Usage

$elixir-phoenix:phx-deps-update                       # inventory + interactive scope pick
$elixir-phoenix:phx-deps-update --scope patch         # bundle all patch bumps, one PR
$elixir-phoenix:phx-deps-update --pkg phoenix_live_view   # one package (+ coupled group)
$elixir-phoenix:phx-deps-update --dry-run             # inventory only, no changes

Iron Laws

  1. NEVER cross a major version without an explicit mix.exs edit — mix deps.update stays within requirements. Edit the constraint first; add override: true only when mix hex.outdated <pkg> shows a transitive consumer blocking. One major per PR
  2. ALWAYS snapshot the changelog delta BEFORE updating — capture deps/<pkg>/CHANGELOG.md, then delta via mix hex.package diff. Never update blind
  3. NEVER claim an update is safe without verification — run $elixir-phoenix:phx-verify (compile --warnings-as-errors + test). "Compiles" ≠ "works"
  4. ALWAYS move coupled packages together — Phoenix core, Ecto, Ash, Oban, telemetry families update in the SAME step/commit (see references/coupled-groups.md)
  5. NEVER commit a partial bump — mix.lock + mix.exs edits + (for Phoenix-family) assets/package-lock.json in ONE commit
  6. HAND OFF security to $elixir-phoenix:phx-deps-audit — run it on the lock diff before any PR; don't reimplement audit rules
  7. hex.outdated exit 1 is normal — it means "deps are outdated", not failure. Capture with || true

Workflow

Phase 0: Discover

Read mix.exs: deps list, umbrella (apps_path:), git/path deps, private orgs (organization:/repo: in tuples), Phoenix/Ash presence. Create scratch dir .claude/deps-update/{YYYY-MM-DD}/.

Phase 1: Inventory

mix hex.outdated --all || true — parse the text table (no JSON exists; see references/update-mechanics.md). Classify each row patch/minor/major by semver delta; Update not possible = blocked major (mix.exs constraint). Write inventory.md to scratch. Render grouped table: Patch / Minor / Major / Blocked / Git-deps (manual). --dry-run stops here.

Phase 2: Scope (AskUserQuestion)

Present groups with counts and risk. Default recommendation: "Patches (N) — low risk, bundle into one PR". --scope/--pkg flags skip the prompt. When ≥2 members of a coupled group are outdated, force them into one step even under a narrower scope.

Show full SKILL.md (234 more words)Show less
Phase 3: Per-Package Update Loop

For each selected package, in coupled-group order:

  1. Snapshot deps/<pkg>/CHANGELOG.md → scratch/before/
  2. Update — patch/minor: mix deps.update <pkg> [coupled...]; major: edit mix.exs constraint (+ override: true if needed), then mix deps.update <pkg>
  3. git diff mix.lock → the REAL {pkg, old, new} set (hex.outdated says what could change; the lock diff says what did)
  4. Changelog delta: mix hex.package diff <pkg> <old>..<new> — keep the CHANGELOG hunk. Empty → gh api repos/{o}/{r}/releases fallback → compare-URL note (see references/changelog-sources.md)
  5. Write scratch/{pkg}-{old}-{new}.md
  6. Phoenix-family in the diff + assets/package.json exists → npm install --prefix assets, stage assets/package-lock.json with the same commit
Phase 4: Verify

Run $elixir-phoenix:phx-verify. On failure → Phase 5; else Phase 6.

Phase 5: Breaking-Change Fixes

Read the changelog deltas for "breaking"/"removed"/"deprecated" + the compile/test errors. Fix source (apply the sibling-file check). Re-verify.

Phase 6: Security Handoff

Run $elixir-phoenix:phx-deps-audit on the working mix.lock diff (its Mode B default). BLOCK findings → surface and offer $elixir-phoenix:phx-deps-vet <pkg> <ver> for accepted risks. Never skip this before a PR.

Phase 7: Group, Commit, PR

Apply the splitting strategy (references/pr-strategy.md): patches bundled, minors by area, majors solo, coupled groups always together. PR bodies cite the changelog excerpt, the https://diff.hex.pm/diff/<pkg>/<old>..<new> link, verification result, and the deps-audit risk band. Stage lock + mix.exs + package-lock together.

Integration

text
$elixir-phoenix:phx-deps-update (mutating) → $elixir-phoenix:phx-deps-audit (security, Mode B)
        │                              │ BLOCK → $elixir-phoenix:phx-deps-vet (ledger)
        └→ $elixir-phoenix:phx-verify (gate) → grouped commits / PRs

References

  • references/update-mechanics.md — hex.outdated parsing, update vs unlock+get, majors, lock-diff
  • references/changelog-sources.md — hex.package diff, gh fallbacks, private orgs
  • references/coupled-groups.md — must-move-together groups + edge cases
  • references/pr-strategy.md — grouping rules, area buckets, PR template, scratch layout

© oliver-kriska, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in targets/codex/skills/phx-deps-update of oliver-kriska/claude-elixir-phoenix.

  • SKILL.md
  • references/changelog-sources.md
  • references/coupled-groups.md
  • references/pr-strategy.md
  • references/update-mechanics.md

Open the folder on GitHubat commit 9767a82

Compare with similar skills

Phx Deps Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phx Deps Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phx Deps Update this skilloliver-kriska/claude-elixir-phoenix565—~1.3kAutomated safety check: PassMIT
Ash Frameworkpodlove/radiator136—~2.1kAutomated safety check: PassMIT
Sentry Elixir SDKgetsentry/sentry-for-ai268—~3.5kAutomated safety check: PassApache-2.0
Elixirstreamband/hydra-srt147—~804Automated safety check: PassApache-2.0
Change CleanupSimon-Initiative/oli-torus119—~3.7kAutomated safety check: PassMIT
Elixir Expertpass-agent/loomkin1811 repos~796Automated safety check: PassMIT

Similar skills

  • Ash Framework

    podlove/radiator

    Use this skill working with Ash Framework or any of its extensions.

    136 GitHub stars~2.1k tokensUpdated 16 days ago
    AI & LLM EngineeringAuto-check passed
  • Sentry Elixir SDK

    getsentry/sentry-for-ai

    Official

    Full Sentry SDK setup for Elixir. An agent skill from getsentry/sentry-for-ai.

    268 GitHub stars~3.5k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Elixir

    streamband/hydra-srt

    A skill your agent uses for Elixir/Phoenix development in this repo: implementing features, refactors, debugging, tests, Ecto changes, and production-safe fixes.

    147 GitHub stars~804 tokensUpdated 24 days ago
    DevelopmentAuto-check passed
  • Change Cleanup

    Simon-Initiative/oli-torus

    Clean up and harden code introduced by the current branch without drifting into broad refactors.

    119 GitHub stars~3.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Elixir Expert

    pass-agent/loomkin

    Expert in Elixir, Phoenix Framework, and OTP. An agent skill from pass-agent/loomkin.

    181 GitHub starsUsed in 1 repo~796 tokens
    AI & LLM EngineeringAuto-check passed
  • Elixir

    ericrisco/rsc-harness

    A skill your agent uses when writing or refactoring Elixir/OTP on the BEAM — GenServers, supervision trees and restart strategies, pattern matching, mix projects and releases — or when processes…

    180 GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from oliver-kriska/claude-elixir-phoenix

All 109 skills in this repo
  • Codex Ab

    oliver-kriska/claude-elixir-phoenix

    Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value verdict.

    565 GitHub stars~977 tokensUpdated 5 days ago
    Auto-check passed
  • Audit

    oliver-kriska/claude-elixir-phoenix

    Project health audit and health check — architecture, performance, tests, dependencies, code quality.

    565 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with; Use when consulting past solutions…

    565 GitHub stars~528 tokensUpdated 5 days ago
    Auto-check passed
  • Compound Docs

    oliver-kriska/claude-elixir-phoenix

    Searchable Elixir/Phoenix/Ecto solution documentation system with YAML frontmatter.

    565 GitHub stars~547 tokensUpdated 5 days ago
    Auto-check passed
  • Deploy

    oliver-kriska/claude-elixir-phoenix

    Elixir/Phoenix deployment patterns — Dockerfile, fly.toml, runtime.exs, mix release, rel/ overlays.

    565 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Deps Update

    oliver-kriska/claude-elixir-phoenix

    Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo).

    565 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check passed

Works with

Questions about Phx Deps Update

What does Phx Deps Update do?

Update Hex dependencies safely. An agent skill from oliver-kriska/claude-elixir-phoenix. Phx Deps Update is an agent skill from oliver-kriska/claude-elixir-phoenix. Update Hex dependencies safely.

When should I use Phx Deps Update?

Phx Deps Update fits situations like: use $elixir-phoenix:phx-investigate for deps.get failures; tasks that involve LLM observability.

How do I install Phx Deps Update in Claude Code?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-update -a claude-code`. Or copy the skill folder (targets/codex/skills/phx-deps-update in oliver-kriska/claude-elixir-phoenix) into .claude/skills/phx-deps-update in your project. Claude Code loads it when a task matches its description.

How do I install Phx Deps Update in Codex?

Run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-update -a codex`. Or copy the skill folder (targets/codex/skills/phx-deps-update in oliver-kriska/claude-elixir-phoenix) into .agents/skills/phx-deps-update in your project. Codex loads it when a task matches its description.

Can I use Phx Deps Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-deps-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phx-deps-update, .gemini/skills/phx-deps-update, .github/skills/phx-deps-update and .opencode/skills/phx-deps-update in your project.

What does Phx Deps Update need to run?

Going by SKILL.md and its folder, Phx Deps Update needs the command-line tools its instructions call (git, gh and npm). Our summary lists: Node.js.

Does Phx Deps Update access the network?

SKILL.md names 1 domain. In commands or code: diff.hex.pm; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Phx Deps Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phx Deps Update use?

Phx Deps Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phx Deps Update use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Phx Deps Update?

Skills that share tags, products or a category with Phx Deps Update: Ash Framework (podlove/radiator, 136 stars), Sentry Elixir SDK (getsentry/sentry-for-ai, 268 stars), Elixir (streamband/hydra-srt, 147 stars) and Change Cleanup (Simon-Initiative/oli-torus, 119 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phx Deps Update?

oliver-kriska (a GitHub user) maintains it in oliver-kriska/claude-elixir-phoenix, which has 565 GitHub stars. The repository holds 109 skills in this directory. The repository was last updated on October 5, 2026.

Source: oliver-kriska/claude-elixir-phoenix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.