Agent skill

Review Dependencies

by tobihagemann in tobihagemann/turbo

Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

MITAuto-check passedDevOps & Cloud

Install Review Dependencies

skills CLI
$ npx skills add tobihagemann/turbo --skill review-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tobihagemann/turbo review-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tobihagemann/turbo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/codex/skills/review-dependencies .claude/skills/review-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-dependencies
GitHub stars
408
Token cost
~1.5k tokens
SKILL.md length
648 words
Files
1
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

  • Works in 3 steps: Detect Package Managers → Discovery → Report Findings
  • The user asks to review dependencies
  • SKILL.md covers Step 1: Detect Package Managers, Step 2: Discovery, Step 3: Report Findings and Output Format, plus 1 more section
  • Calls gh, npm and yarn

What it does

Review Dependencies is an agent skill from tobihagemann/turbo. Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. Returns structured findings without upgrading. Use when the user asks to "review dependencies", "check for outdated packages", "check dependencies", "scan dependencies", "dependency review", "check for outdated GitHub Actions", or "are my workflow actions up to date".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Vulnerability scanning and CI/CD. It works with GitHub Actions, Gradle, npm and Ruby. The repository describes itself as: Reusable workflows for planning, building, reviewing, and shipping with Claude Code and Codex. The licence is MIT.

When your agent uses it

  • The user asks to review dependencies
  • Check for outdated packages
  • Check dependencies
  • Scan dependencies

Example prompts

  • “review dependencies”
  • “check for outdated packages”
  • “check dependencies”
  • “/review-dependencies”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Detect Package Managers
  2. Discovery
  3. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 931eda5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • yarn
    • pnpm
    • pip
    • poetry
    • uv
    • cargo
    • go
    • bundle
    • mvn
    • gradle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm, yarn, pnpm, pip and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Dependencies loads about 1.5k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 648 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tobihagemann/turbo at commit 931eda5, republished under its MIT licence (© tobihagemann). 648 words, ~1,494 tokens.

Download SKILL.mdSave it as .claude/skills/review-dependencies/SKILL.md (or your agent's skills folder).
name
review-dependencies
description
Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. Returns structured findings without upgrading. Use when the user asks to "review dependencies", "check for outdated packages", "check dependencies", "scan dependencies", "dependency review", "check for outdated GitHub Actions", or "are my workflow actions up to date".

Review Dependencies

Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. Analysis only. Does not upgrade.

Step 1: Detect Package Managers

Identify which package managers are in use by searching for config files:

Config filePackage managerLockfileEcosystem
package.jsonnpm / yarn / pnpmpackage-lock.json / yarn.lock / pnpm-lock.yamlNode.js
Package.swift, *.xcodeprojSwift Package ManagerPackage.resolvedSwift
pyproject.toml, requirements.txt, setup.pypip / poetry / uvpoetry.lock, uv.lockPython
Cargo.tomlcargoCargo.lockRust
go.modGo modulesgo.sumGo
GemfileBundlerGemfile.lockRuby
pom.xmlMaven—Java
build.gradle, build.gradle.ktsGradlegradle.lockfileJava/Kotlin
.github/workflows/*.yml / .yaml, action.yml / .yamlGitHub Actions—CI

Swift dependencies can live in Package.swift or be configured directly in the Xcode project file (.xcodeproj/.xcworkspace). For Xcode-managed dependencies, inspect the project's package references.

Detection steps:

  1. Search for config files in the project root and subdirectories (exclude vendored directories)
  2. If a lockfile exists, use the corresponding package manager variant (e.g., yarn.lock → yarn, pnpm-lock.yaml → pnpm)
  3. When the repo declares a dependency automation config (.github/dependabot.yml / .yaml, renovate.json, .github/renovate.json), read it and add every ecosystem it declares to the set found by the config-file search
  4. When the repo has a GitHub remote, list open dependency PRs with gh pr list --author app/dependabot (or app/renovate), and mark each upgrade one of them already proposes
  5. If multiple instances of the same package manager found (e.g., monorepo with several package.json files): use request_user_input to let the user pick one (Codex request_user_input choices are mutually exclusive). For an "all of them" workflow, ask follow-up free-form input or run the review per instance.
  6. If multiple package managers found: use request_user_input to let the user pick one. Exclude the CI ecosystem from that choice and review it alongside whichever the user picks
  7. If none found across every step above: inform user and stop
Show full SKILL.md (352 more words)Show less

Step 2: Discovery

Run the appropriate discovery command to find available updates:

Package managerDiscovery commandNotes
npmncu --format groupRequires npm-check-updates. Suggest npm install -g npm-check-updates if missing.
yarnncu --format group or yarn upgrade-interactive
pnpmncu --format group or pnpm outdated
Swift PMCheck resolved versions in Package.resolved against latest releases via web searchNo built-in outdated command. Read Package.swift or inspect the Xcode project to identify dependencies and their current version constraints.
pippip list --outdated
poetrypoetry show --outdated
uvuv pip list --outdated
cargocargo outdatedRequires cargo-outdated. Fall back to comparing Cargo.toml versions via web search.
Go modulesgo list -m -u all
Bundlerbundle outdated
Mavenmvn versions:display-dependency-updates
Gradlegradle dependencyUpdatesRequires com.github.ben-manes.versions plugin.
GitHub Actionsgh api repos/<owner>/<repo>/releases/latest --jq .tag_name, compared against each uses: refNo outdated command. Take <owner>/<repo> from the ref's first two path segments. Read a SHA-pinned ref's version from its trailing comment (uses: <owner>/<action>@<sha> # v1.2.3). Compare only the components the ref pins, so @v7 is current against v7.0.1. Fall back to repos/<owner>/<repo>/tags when the release 404s or its tag namespace differs from the ref's, and to web search when the action is not hosted on GitHub. Exclude local (./…), <repo-relative> ($/…), and Docker (docker://…) refs, which pin no release.

Categorize updates:

  • Major (breaking changes) — requires migration research
  • Minor (new features, backward compatible)
  • Patch (bug fixes)

Step 3: Report Findings

If the discovery tool is not installed, suggest the installation command (see Step 2 notes column). If no tool exists for the ecosystem, fall back to manual version checking via web search.

If no updates are available, report that dependencies are up to date. Otherwise, report each update in the output format below, followed by the Overall Verdict.

Then call update_plan to mark this step completed and continue with the next step of the active workflow.

Output Format

Format each finding as:

### [P<N>] <title (imperative, <=80 chars)>

**Package:** `<name>` <current> -> <latest>
**Manager:** <npm/pip/cargo/etc.>
**Proposed:** <open automation PR already covering this upgrade, when one exists>

<one paragraph: why this matters, known vulnerabilities if any, major version gap>

After all findings, add:

## Overall Verdict

**Dependencies:** <up to date | updates available>

<summary with counts: N major, N minor, N patch>

Priority Levels

  • P0 — Known security vulnerability (CVE) in the current version
  • P1 — Multiple major versions behind (e.g., React 17 → 19)
  • P2 — One major version behind or significantly outdated minor versions
  • P3 — Minor or patch updates available

© tobihagemann, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in codex/skills/review-dependencies of tobihagemann/turbo.

Open the folder on GitHubat commit 931eda5

Compare with similar skills

Review Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Dependencies this skilltobihagemann/turbo408—~1.5kAutomated safety check: PassMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Dsh Web UI Releaseningbainb/deepseek-harness-desktop789—~1.4kAutomated safety check: WarnBSD-3-Clause
ReleaseWebMCP-org/npm-packages104—~1.6kAutomated safety check: NotesMIT
Upgrade Notesgetknit/knit133—~1.2kAutomated safety check: PassGPL-3.0

Similar skills

  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Dsh Web UI Release

    ningbainb/deepseek-harness-desktop

    Release and publish the dsh-web-ui monorepo (DSH Web GUI plugin family + skin collection) — bump all packages to one unified version, commit and tag, push the vX.Y.Z tag that triggers the GitHub…

    789 GitHub stars~1.4k tokensUpdated 4 days ago
    DevelopmentAuto-check: warnings
  • Release

    WebMCP-org/npm-packages

    Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

    104 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Upgrade Notes

    getknit/knit

    Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

    133 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…

    871 GitHub stars~2.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from tobihagemann/turbo

All 81 skills in this repo
  • Consult Oracle

    tobihagemann/turbo

    Consult ChatGPT Pro via ChatGPT browser automation for problems that resist standard approaches.

    408 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Fetch PR Comments

    tobihagemann/turbo

    Fetch and summarize review feedback and conversation from a GitHub PR (unresolved review threads, review bodies, and PR conversation comments) without making changes.

    408 GitHub stars~967 tokensUpdated 2 days ago
    Auto-check passed
  • Recall Rationale

    tobihagemann/turbo

    Recall why a past change was made by locating the Claude Code transcript that produced it.

    408 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Resolve PR Comments

    tobihagemann/turbo

    Evaluate, fix, answer, and reply to GitHub pull request review comments and conversation comments.

    408 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check passed
  • Resolve PR Comments

    tobihagemann/turbo

    Evaluate, fix, answer, and reply to GitHub pull request review comments and conversation comments.

    408 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check passed
  • Assess Technical Debt

    tobihagemann/turbo

    Assess project-wide structural technical debt: complexity hotspots, deprecated API usage, duplication clusters, architecture rot, and low-value tests.

    408 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed

Questions about Review Dependencies

What does Review Dependencies do?

Detect package managers and CI action pins, then discover outdated or vulnerable dependencies. Review Dependencies is an agent skill from tobihagemann/turbo. Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

When should I use Review Dependencies?

Review Dependencies fits situations like: the user asks to review dependencies; check for outdated packages; check dependencies; scan dependencies.

How do I install Review Dependencies in Claude Code?

Run `npx skills add tobihagemann/turbo --skill review-dependencies -a claude-code`. Or copy the skill folder (codex/skills/review-dependencies in tobihagemann/turbo) into .claude/skills/review-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Review Dependencies in Codex?

Run `npx skills add tobihagemann/turbo --skill review-dependencies -a codex`. Or copy the skill folder (codex/skills/review-dependencies in tobihagemann/turbo) into .agents/skills/review-dependencies in your project. Codex loads it when a task matches its description.

Can I use Review Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tobihagemann/turbo --skill review-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-dependencies, .gemini/skills/review-dependencies, .github/skills/review-dependencies and .opencode/skills/review-dependencies in your project.

What does Review Dependencies need to run?

Going by SKILL.md and its folder, Review Dependencies needs the command-line tools its instructions call (gh, npm, yarn, pnpm, pip and poetry). Our summary lists: Python 3; Node.js; Docker.

Does Review Dependencies access the network?

SKILL.md contains no URLs. Its commands use gh, npm, pip and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Dependencies use?

Review Dependencies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Dependencies use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Dependencies?

Skills that share tags, products or a category with Review Dependencies: GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Dsh Web UI Release (ningbainb/deepseek-harness-desktop, 789 stars) and Release (WebMCP-org/npm-packages, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Dependencies?

tobihagemann (a GitHub user) maintains it in tobihagemann/turbo, which has 408 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 9, 2026.

Source: tobihagemann/turbo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.