Agent skill

Validate Dependencies

by peijun1700 in peijun1700/bluemouse

L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴. An agent skill from peijun1700/bluemouse.

AGPL-3.0Auto-check: notes

Install Validate Dependencies

skills CLI
$ npx skills add peijun1700/bluemouse --skill validate-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install peijun1700/bluemouse validate-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/peijun1700/bluemouse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/validate-dependencies .claude/skills/validate-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-dependencies
GitHub stars
109
Token cost
~1k tokens
SKILL.md length
170 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
AGPL-3.0

At a glance

L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴. An agent skill from peijun1700/bluemouse.

  • Works in 2 steps: AI-Guided Validation → Script Execution
  • SKILL.md covers Two Ways to Use, L9: 導入檢查 (Informational), L10: 標準庫檢查 (Informational) and L11: 第三方庫檢查 (Informational), plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Validate Dependencies is an agent skill from peijun1700/bluemouse. L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴。 BlueMouse 17-Layer Validation Group 3。 Triggers: "dependencies", "imports", "依賴檢查", "circular"

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `validator.py`).

The licence is AGPL-3.0.

Example prompts

  • “dependencies”
  • “imports”
  • “circular”
  • “/validate-dependencies”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Bash, Grep

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. AI-Guided Validation
  2. Script Execution

What it can do on your machine

Read from SKILL.md and the folder at commit 4f32ef0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Dependencies loads about 1k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 170 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from peijun1700/bluemouse at commit 4f32ef0, republished under its AGPL-3.0 licence (© peijun1700). 170 words, ~1,016 tokens.

Download SKILL.mdSave it as .claude/skills/validate-dependencies/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
validate-dependencies
description
L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴。 BlueMouse 17-Layer Validation Group 3。 Triggers: "dependencies", "imports", "依賴檢查", "circular"
allowed-tools
Read, Bash, Grep
user-invocable
true
context
fork

Validate Dependencies Skill (L9-L12)

BlueMouse 17-Layer Validation System - Group 3: 依賴關係驗證

Two Ways to Use

1. AI-Guided Validation

Follow the checklist below to analyze code.

2. Script Execution
bash
python3 .claude/skills/validate-dependencies/validator.py myfile.py
python3 .claude/skills/validate-dependencies/validator.py --verbose myfile.py

L9-L12 Validation Checklist

L9: 導入檢查 (Informational)

What: Count import statements in code

How:

python
imports = [
    node for node in ast.walk(tree)
    if isinstance(node, (ast.Import, ast.ImportFrom))
]

Output: "找到 N 個導入語句" Pass: Always (informational only)


L10: 標準庫檢查 (Informational)

What: Identify Python standard library usage

Known Stdlib:

python
stdlib = {
    'os', 'sys', 'json', 're', 'datetime', 'typing',
    'asyncio', 'time', 'math', 'hashlib', 'collections',
    'functools', 'itertools', 'pathlib', 'subprocess',
    'threading', 'multiprocessing', 'logging', 'unittest',
    'argparse', 'copy', 'io', 'tempfile'
}

How:

python
import_names = []
for node in ast.walk(tree):
    if isinstance(node, ast.Import):
        for n in node.names:
            import_names.append(n.name.split('.')[0])
    elif isinstance(node, ast.ImportFrom):
        if node.module:
            import_names.append(node.module.split('.')[0])

used = [name for name in import_names if name in stdlib]

Output: "精確識別出 N 個標準庫導入" Pass: Always (informational only)


L11: 第三方庫檢查 (Informational)

What: Identify common third-party library usage

Known Third-Party:

python
third_party = {
    'django', 'flask', 'fastapi', 'requests', 'numpy',
    'pandas', 'pytest', 'aiohttp', 'sqlalchemy', 'pydantic',
    'httpx', 'redis', 'celery', 'boto3', 'tensorflow',
    'torch', 'scikit-learn'
}

How:

python
used = []
for module in third_party:
    if f"import {module}" in code or f"from {module}" in code:
        used.append(module)

Output:

  • Found: "使用了 N 個第三方庫"
  • None: "未使用第三方庫"

Pass: Always (informational only)


L12: 循環依賴檢查 ⚠️

What: Detect risky relative imports that may cause circular dependencies

How:

python
for node in ast.walk(tree):
    if isinstance(node, ast.ImportFrom) and node.level > 0:
        has_relative = True

Import Level Explanation:

CodeLevelRisk
import os0✅ Safe
from module import x0✅ Safe
from .sibling import x1⚠️ Risky
from ..parent import x2⚠️ Risky

Pass: No relative imports → "通過 (未檢測到危險的相對導入)" Fail: "檢測到相對導入,可能存在循環依賴風險"

Examples:

python
# ✅ PASS: Absolute imports only
import os
from package.module import func
from typing import Dict

# ❌ FAIL: Relative imports
from .sibling import helper  # level=1
from ..parent import config  # level=2

Why Relative Imports Are Risky:

project/
├── package_a/
│   └── module_a.py  # from ..package_b import func_b
└── package_b/
    └── module_b.py  # from ..package_a import func_a
                     # ❌ Circular dependency!

Output Format

==================================================
L9-L12: 依賴關係驗證
==================================================

Status: ✅ PASSED / ❌ FAILED
Score: X/100 (N/4 layers)

✅ L9: 導入檢查 - 找到 N 個導入語句
✅ L10: 標準庫檢查 - 精確識別出 N 個標準庫導入
✅ L11: 第三方庫檢查 - 使用了 N 個第三方庫
✅/❌ L12: 循環依賴檢查 - [message]

[Verbose mode shows detected libraries]

SkillLayers
/validate-17-layersL1-L17 (完整)
/validate-syntaxL1-L4
/validate-signatureL5-L8
/validate-dependenciesL9-L12
/validate-logicL13-L17

Part of BlueMouse 17-Layer Validation System

© peijun1700, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/validate-dependencies of peijun1700/bluemouse.

  • SKILL.md
  • validator.py

Open the folder on GitHubat commit 4f32ef0

Compare with similar skills

Validate Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Dependencies this skillpeijun1700/bluemouse109—~1kAutomated safety check: NotesAGPL-3.0
Dependency Scanningsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Dependency Checkruvnet/ruflo74k—~258Automated safety check: PassMIT
Dependency Updatecodewhale-hq/Codewhale41k—~142Automated safety check: PassMIT
Bump Sentry Dependencygetsentry/sentry46k—~815Automated safety check: PassCustom licence
Logseq Dependency Upgradelogseq/logseq45k—~1.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • Dependency Scanning

    sickn33/agentic-awesome-skills

    Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

    47k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Dependency Check

    ruvnet/ruflo

    Scan project dependencies for known vulnerabilities and CVEs.

    74k GitHub stars~258 tokensUpdated today
    SecurityAuto-check passed
  • Dependency Update

    codewhale-hq/Codewhale

    Read release notes/changelogs, update a defined dependency scope, handle breaking changes, and verify.

    41k GitHub stars~142 tokensUpdated today
    DevelopmentAuto-check passed
  • Bump Sentry Dependency

    getsentry/sentry

    Official

    Bumps an existing Python dependency in getsentry/sentry through the repository's self-serve GitHub Actions workflow.

    46k GitHub stars~815 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…

    45k GitHub stars~1.1k tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Audit Dependencies

    payloadcms/payload

    A skill your agent uses when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

    45k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed

More from peijun1700/bluemouse

  • Validate Logic

    peijun1700/bluemouse

    L13-L17 類型和邏輯驗證 - 檢查類型一致性、邏輯完整性、錯誤處理、安全性、性能. An agent skill from peijun1700/bluemouse.

    109 GitHub stars~1.5k tokensUpdated 8 mo ago
    Auto-check: notes
  • Validate Signature

    peijun1700/bluemouse

    L5-L8 函數簽名驗證 - 檢查參數、返回值、類型提示、文檔字符串. An agent skill from peijun1700/bluemouse.

    109 GitHub stars~923 tokensUpdated 8 mo ago
    Auto-check: notes
  • Validate Syntax

    peijun1700/bluemouse

    L1-L4 語法和結構驗證 - 檢查 Python 語法、AST 結構、縮進格式、命名規範. An agent skill from peijun1700/bluemouse.

    109 GitHub stars~856 tokensUpdated 8 mo ago
    Auto-check: notes
  • Validate 17 Layers

    peijun1700/bluemouse

    The BlueMouse 17-Layer Alpha Scale (Static Standard). An agent skill from peijun1700/bluemouse.

    109 GitHub stars~546 tokensUpdated 8 mo ago
    Auto-check: notes

Questions about Validate Dependencies

What does Validate Dependencies do?

L9-L12 依賴關係驗證 - 檢查導入語句、標準庫、第三方庫、循環依賴. An agent skill from peijun1700/bluemouse. Validate Dependencies is an agent skill from peijun1700/bluemouse.

How do I install Validate Dependencies in Claude Code?

Run `npx skills add peijun1700/bluemouse --skill validate-dependencies -a claude-code`. Or copy the skill folder (.claude/skills/validate-dependencies in peijun1700/bluemouse) into .claude/skills/validate-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Validate Dependencies in Codex?

Run `npx skills add peijun1700/bluemouse --skill validate-dependencies -a codex`. Or copy the skill folder (.claude/skills/validate-dependencies in peijun1700/bluemouse) into .agents/skills/validate-dependencies in your project. Codex loads it when a task matches its description.

Can I use Validate Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add peijun1700/bluemouse --skill validate-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-dependencies, .gemini/skills/validate-dependencies, .github/skills/validate-dependencies and .opencode/skills/validate-dependencies in your project.

What does Validate Dependencies need to run?

Going by SKILL.md and its folder, Validate Dependencies needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash, Grep.

Does Validate Dependencies access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Validate Dependencies safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Validate Dependencies use?

Validate Dependencies is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Dependencies use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Dependencies?

Skills that share tags, products or a category with Validate Dependencies: Dependency Scanning (sickn33/agentic-awesome-skills, 47k stars), Dependency Check (ruvnet/ruflo, 74k stars), Dependency Update (codewhale-hq/Codewhale, 41k stars) and Bump Sentry Dependency (getsentry/sentry, 46k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Dependencies?

peijun1700 (a GitHub user) maintains it in peijun1700/bluemouse, which has 109 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 29, 2026.

Source: peijun1700/bluemouse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.