Agent skill

Dependency Management

by rampstackco in rampstackco/claude-skills

Manage third-party libraries, runtimes, and SaaS dependencies.

MITAuto-check passedDevelopment

Install Dependency Management

skills CLI
$ npx skills add rampstackco/claude-skills --skill dependency-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rampstackco/claude-skills dependency-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rampstackco/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-management .claude/skills/dependency-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-management
GitHub stars
935
Token cost
~2.8k tokens
SKILL.md length
1,361 words
Files
3 (incl. references)
Skills in repo
103
Repo updated
First seen
Licence
MIT

At a glance

Manage third-party libraries, runtimes, and SaaS dependencies.

  • Works in 8 steps: Inventory → Audit → Categorize and prioritize → …
  • Setting an update cadence
  • SKILL.md covers When to use, When NOT to use, Required inputs and The framework: 4 categories of…, plus 7 more sections
  • Calls npm, bundle and pip

What it does

Dependency Management is an agent skill from rampstackco/claude-skills. Manage third-party libraries, runtimes, and SaaS dependencies. Use this skill when setting an update cadence, responding to security advisories, dealing with deprecated dependencies, evaluating new dependencies, auditing what's installed, or unblocking a dependency upgrade. Triggers on dependency, package update, security patch, lockfile, deprecated, breaking change, supply chain, dependency audit, npm audit, dependabot, renovate. Also triggers when a build breaks after an update or when an advisory is published…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/upgrade-checklist.md`).

It sits in Development, covering Dependency management. The repository describes itself as: Stack-agnostic Claude Skills covering the full website lifecycle: brand, design, content, SEO, dev, ops, growth, and research. Build, ship, audit, optimize. The licence is MIT.

When your agent uses it

  • Setting an update cadence
  • Responding to security advisories
  • Dealing with deprecated dependencies
  • Evaluating new dependencies

Example prompts

  • “/dependency-management”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Inventory
  2. Audit
  3. Categorize and prioritize
  4. Test before merging fixes
  5. Plan major version upgrades
  6. Set the policy
  7. Automate
  8. Audit usage periodically

What it can do on your machine

Read from SKILL.md and the folder at commit 482c9bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • bundle
    • pip
    • yarn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pip and yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependency Management loads about 2.8k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 1,361 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rampstackco/claude-skills at commit 482c9bf, republished under its MIT licence (© rampstackco). 1,361 words, ~2,751 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-management/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
dependency-management
description
Manage third-party libraries, runtimes, and SaaS dependencies. Use this skill when setting an update cadence, responding to security advisories, dealing with deprecated dependencies, evaluating new dependencies, auditing what's installed, or unblocking a dependency upgrade. Triggers on dependency, package update, security patch, lockfile, deprecated, breaking change, supply chain, dependency audit, npm audit, dependabot, renovate. Also triggers when a build breaks after an update or when an advisory is published for a used package.
category
cross-cutting
catalog_summary
Package updates, security patches, lockfile hygiene
display_order
4

Dependency Management

Decide what to depend on, keep dependencies current, respond to advisories, and reduce supply chain risk. Stack-agnostic principles; specifics vary by package manager.


When to use

  • Setting up dependency hygiene for a new or existing project
  • Responding to a security advisory
  • Major version upgrade of a key dependency
  • Adding a new dependency (evaluation, decision)
  • Removing a dependency (cleanup)
  • Audit of what's installed and what's actually used
  • Setting an update cadence and policy
  • Diagnosing a broken build after an update

When NOT to use

  • General code review (use code-review-web)
  • Vulnerability scanning of infrastructure (use security-baseline)
  • Pinning vendor or service contracts (use vendor-evaluation)
  • Performance impact of dependencies (use performance-optimization)

Required inputs

  • Package manager and lockfile in use (npm, yarn, pnpm, pip, gem, composer, etc.)
  • Current dependency list (production and dev)
  • Current advisories (run audit; check service like Snyk, Dependabot)
  • Update history (when were major dependencies last updated)
  • Risk profile (production criticality, change tolerance)

The framework: 4 categories of dependency

Every dependency falls into one of these. The category drives the policy.

Category 1: Critical runtime

Code that runs in production and would break the system if it failed.

Examples: framework, database driver, payment SDK, authentication library.

Policy:

  • Update cadence: monthly minor, quarterly major (with planning)
  • Security: patch within 24-72 hours of advisory, 24h for critical
  • Pinning: exact version pins or narrow ranges
  • Vetting: thoroughly evaluated before adoption
Category 2: Supporting runtime

Code that runs in production but is replaceable or non-critical.

Examples: utility libraries, formatting, non-core integrations.

Policy:

  • Update cadence: monthly together with critical
  • Security: patch within a week of advisory
  • Pinning: narrow ranges acceptable (e.g., ^1.2.3)
  • Vetting: moderate evaluation; alternatives considered
Category 3: Dev/build

Code that runs only during development or build, not in production.

Examples: bundlers, linters, test frameworks, type checkers.

Policy:

  • Update cadence: quarterly
  • Security: patch within a week (still matters; supply chain attacks target build tools)
  • Pinning: ranges acceptable
  • Vetting: lighter; broken dev tools surface fast
Category 4: Optional/dev-only-personal

Tools individual developers use that aren't part of shared dev environment.

Not really managed at the project level. Mentioned for completeness.


The framework: 5 risk dimensions

When evaluating a dependency, consider:

Dimension 1: Maintenance health
  • Last commit date (months ago is concerning)
  • Open issue count and age
  • Number of maintainers
  • Sponsorship or commercial backing
  • Roadmap visibility

A dependency abandoned a year ago is a liability waiting to surface.

Dimension 2: Surface area
  • Size of the package
  • Number of transitive dependencies
  • Footprint in the bundle (for client-side)
  • Privileges required (file system, network, etc.)

A small dependency that pulls in 50 transitive packages has the surface area of all 50.

Dimension 3: Replaceability
  • How hard would it be to remove?
  • Are there alternatives?
  • Could the functionality be implemented in-house?
  • Is the API standard or idiomatic?

A dependency you can't replace is leverage you've granted to its maintainer.

Dimension 4: Trust
  • Reputation of the maintainer or organization
  • Code quality (skim the source)
  • License (GPL, MIT, BSD, proprietary, none)
  • History of security issues
  • Supply chain practices (signed releases, 2FA on publishes)
Dimension 5: Cost
  • Time to evaluate, integrate, maintain
  • Risk of breaking changes
  • Lockfile entropy
  • Potential security exposure
  • Bundle size impact (for client-side)

Every dependency has a cost. Free packages aren't free.


Workflow

Step 1: Inventory

Run a dependency listing:

bash
# npm/yarn/pnpm
npm ls --all --json

# pip
pip list

# gem  
bundle list

For each top-level dependency, categorize (critical / supporting / dev). For transitives, you generally don't manage individually unless one becomes a problem.

Step 2: Audit

Run the security audit:

bash
npm audit
yarn npm audit  # Yarn 2+; "yarn audit" on Yarn 1 Classic
pip-audit
bundle audit

For each finding:

  • Severity (critical, high, medium, low)
  • Package and version
  • Fix available?
  • Used directly or transitively?
Step 3: Categorize and prioritize
SeverityDirect depIndirect dep
CriticalPatch todayPatch this week (if a fix exists; track if not)
HighPatch this weekPatch this month
MediumPatch this monthTrack; patch with next round
LowTrackTrack

Critical and high in production code are emergencies. Low and medium are scheduled work.

Step 4: Test before merging fixes

Even patch-level updates can break things. For critical dependencies:

  • Run the full test suite
  • Smoke-test in staging
  • Watch the monitoring after rollout

For supporting and dev:

  • Run the test suite
  • A failed test is OK to investigate; don't merge a known-broken update
Step 5: Plan major version upgrades

Major versions break things. Plan rather than rush.

For each major upgrade:

  • Read the changelog and migration guide
  • Estimate the migration effort
  • Schedule the work (don't do it under deadline pressure)
  • Branch and test thoroughly
  • Plan a staged rollout if it's a critical dependency

Don't sit on major versions indefinitely. The longer you wait, the more painful the upgrade.

Step 6: Set the policy

Document:

  • Update cadence (e.g., monthly review, quarterly upgrades)
  • Security response SLA (e.g., critical within 24h)
  • Approval for new dependencies (who signs off)
  • Removal criteria (when do we drop a dependency)
  • Pinning strategy (exact, narrow range, broad range)

The policy is what survives team turnover. Without it, dependency management becomes chaotic ad hoc work.

Show full SKILL.md (551 more words)Show less
Step 7: Automate
  • Renovate or Dependabot for automatic update PRs
  • CI runs audit on every PR
  • Block merges on critical advisories (with override path for false positives)
  • Notify on advisories for installed packages
  • Lockfile diff in PR review

Automation reduces toil. Manual checking doesn't scale.

Step 8: Audit usage periodically

Quarterly:

  • Dependencies installed but not imported anywhere (run a tool like depcheck)
  • Major versions behind (more than 1-2 majors behind = upgrade plan needed)
  • Unmaintained packages (last commit over a year ago = consider replacing)
  • License audit (anything that's changed terms?)

Remove what's not used. Replace what's unmaintained.


New dependency evaluation

Before adding a new dependency, answer:

  • What problem does this solve?
  • Could we solve it without a dependency? (Often yes for small problems.)
  • What alternatives exist?
  • Is the package actively maintained?
  • What's the install size and bundle impact?
  • What are the transitive dependencies? (Worth a quick scan.)
  • What's the license?
  • What's the security history?
  • How replaceable is it?

Default: don't add. Add only when the value clearly exceeds the cost. The cost includes ongoing maintenance, not just installation.


Dependency removal

When removing a dependency:

  • Identify all usages (search the codebase)
  • Replace each usage (with native code, another dependency, or a no-op)
  • Remove from package.json or equivalent
  • Update lockfile (run install)
  • Verify tests pass
  • Verify build size went down (or stayed the same)
  • Document the removal in the changelog

Removed dependencies sometimes leave config files, CI hooks, or imports behind. Search broadly.


Failure patterns

No update cadence. Dependencies drift. When you finally upgrade, it's painful. Set a cadence.

Audit disabled in CI. "Too noisy." Tune the audit, don't disable it. Whitelist known false positives explicitly.

Pinning everything to exact versions. Stops automatic patches. Misses security fixes. Use narrow ranges with a lockfile.

Unpinned floating versions. latest in production. Builds aren't reproducible. Lockfile required.

Adding dependencies without review. "I just needed a quick utility." Now there are 50 unused dependencies. Require review for new dependencies.

Ignoring transitive dependencies. A direct dependency pulls in 50 indirect ones. Each is supply chain surface. Audit the tree, not just the top level.

Patching with major version bumps. "Updating to fix a bug" but the update is a major version. Now you have unrelated breaking changes too. Be deliberate about the version of the fix.

Vendor-bundled libraries. Some dependencies vendor copies of other dependencies. They're not visible to the audit. Periodically check.

Build-time dependencies treated as zero-risk. Build tools have access to your code and credentials. Supply chain attacks target them. Treat with appropriate care.

Fork without rebase plan. Forking a dependency to fix something. Then you own it. Plan how to rebase or merge upstream changes, or commit to maintaining the fork.

No license audit. Project ships with a GPL dependency in a commercial product. Compliance issue. Audit licenses on add and quarterly.

Update PRs piling up. Dependabot PRs go unmerged for months. Either tune to fewer PRs or commit time to merging them.


Output format

A dependency policy document includes:

  • Inventory: current dependencies by category
  • Audit status: open advisories, severity, plan
  • Policies: cadence, SLA, pinning, approval
  • Tooling: what's automated (Renovate, Dependabot, audit in CI)
  • License audit: any concerns
  • Quarterly review schedule: when this gets revisited

Reference files

  • references/upgrade-checklist.md: Step-by-step checklist for performing a major version upgrade of a critical dependency, from changelog reading to staged rollout.

© rampstackco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/dependency-management of rampstackco/claude-skills.

  • SKILL.md
  • README.md
  • references/upgrade-checklist.md

Open the folder on GitHubat commit 482c9bf

Compare with similar skills

Dependency Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Management this skillrampstackco/claude-skills935—~2.8kAutomated safety check: PassMIT
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Add TTS Engine to Voiceboxjamiepine/voicebox57k—~1.3kAutomated safety check: PassMIT
Merge Dependabot PRsonyx-dot-app/onyx32k1 repos~2.2kAutomated safety check: PassMIT
Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit2597 repos~1.2kAutomated safety check: NotesCustom licence
Update .NET OS Packagesdotnet/core22k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Add TTS Engine to Voicebox

    jamiepine/voicebox

    Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.

    57k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Merge Dependabot PRs

    onyx-dot-app/onyx

    Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…

    32k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Senior Architect Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…

    259 GitHub starsUsed in 7 repos~1.2k tokens
    DevelopmentAuto-check: notes
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed

More from rampstackco/claude-skills

All 103 skills in this repo
  • After Action Report

    rampstackco/claude-skills

    Run a structured after-action review (postmortem, retrospective) on a launch, incident, or completed project to capture timeline, root cause analysis, contributing factors, and actionable lessons.

    935 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Analytics Strategy

    rampstackco/claude-skills

    Design measurement frameworks including event taxonomy, KPI hierarchy, dashboard architecture, attribution models, and analytics implementation strategy.

    935 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Brand Style Guide

    rampstackco/claude-skills

    Build or audit a comprehensive brand style guide that documents the full brand system including story, logo system, color, typography, imagery, voice, applications, and dos/don'ts.

    935 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Brand Voice

    rampstackco/claude-skills

    Develop or document a complete brand voice and tone system covering voice attributes, tone shifts by context, vocabulary preferences, grammar rules, and copy examples.

    935 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Content And Copy

    rampstackco/claude-skills

    Write or edit website copy, blog content, and editorial pieces with attention to voice, structure, and goal.

    935 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Content Strategy

    rampstackco/claude-skills

    Develop a content strategy covering editorial positioning, content pillars, formats, calendar, governance, and topical authority planning.

    935 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Dependency Management

What does Dependency Management do?

Manage third-party libraries, runtimes, and SaaS dependencies. Dependency Management is an agent skill from rampstackco/claude-skills. Manage third-party libraries, runtimes, and SaaS dependencies.

When should I use Dependency Management?

Dependency Management fits situations like: setting an update cadence; responding to security advisories; dealing with deprecated dependencies; evaluating new dependencies.

How do I install Dependency Management in Claude Code?

Run `npx skills add rampstackco/claude-skills --skill dependency-management -a claude-code`. Or copy the skill folder (skills/dependency-management in rampstackco/claude-skills) into .claude/skills/dependency-management in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Management in Codex?

Run `npx skills add rampstackco/claude-skills --skill dependency-management -a codex`. Or copy the skill folder (skills/dependency-management in rampstackco/claude-skills) into .agents/skills/dependency-management in your project. Codex loads it when a task matches its description.

Can I use Dependency Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rampstackco/claude-skills --skill dependency-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-management, .gemini/skills/dependency-management, .github/skills/dependency-management and .opencode/skills/dependency-management in your project.

What does Dependency Management need to run?

Going by SKILL.md and its folder, Dependency Management needs the command-line tools its instructions call (npm, bundle, pip and yarn).

Does Dependency Management access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependency Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependency Management use?

Dependency Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Management use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Dependency Management?

Skills that share tags, products or a category with Dependency Management: Dep Updates (trufflesecurity/trufflehog, 28k stars), Add TTS Engine to Voicebox (jamiepine/voicebox, 57k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Senior Architect Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Management?

rampstackco (a GitHub organization) maintains it in rampstackco/claude-skills, which has 935 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 7, 2026.

Source: rampstackco/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.