Agent skill

Dependency Update Bot

by Varnan-Tech in Varnan-Tech/opendirectory

Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

MITAuto-check: notesDevelopment

Install Dependency Update Bot

skills CLI
$ npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Varnan-Tech/opendirectory dependency-update-bot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Varnan-Tech/opendirectory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-update-bot .claude/skills/dependency-update-bot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependency-update-bot
GitHub stars
674
Token cost
~3k tokens
SKILL.md length
503 words
Files
5 (incl. references)
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

  • Works in 9 steps: Setup Check → Detect Outdated Packages → Classify by Risk Level → …
  • Asked to update dependencies
  • SKILL.md covers Step 1: Setup Check, Step 2: Detect Outdated Packages, Step 3: Classify by Risk Level and Step 4: Security Audit, plus 5 more sections
  • Calls python3, npm and curl; reaches registry.npmjs.org and pypi.org; needs GEMINI_API_KEY and GITHUB_TOKEN

What it does

Dependency Update Bot is an agent skill from Varnan-Tech/opendirectory. Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. Runs a CVE security audit. Fetches changelogs, summarizes breaking changes with Gemini, and opens one PR per risk group (patch, minor, major). Includes Diagnosis Mode for install conflicts. Use when asked to update dependencies, check for outdated packages, open dependency PRs, scan for package updates, audit for CVEs, or flag breaking changes in upgrades. Trigger when a user says "check for outdated packages", "update my dependencies", "open…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `README.md`, `evals/evals.json` and `references/changelog-patterns.md`). Compatibility notes: ["claude-code","gemini-cli","github-copilot"]

It sits in Development, covering Dependency management, Vulnerability scanning and Changelog and release notes. It works with npm and Ruby. The repository describes itself as: AI Agent Skills built for Founders who hate Marketing. The licence is MIT.

When your agent uses it

  • Asked to update dependencies
  • Check for outdated packages
  • Open dependency PRs
  • Scan for package updates

Example prompts

  • “check for outdated packages”
  • “update my dependencies”
  • “open PRs for dependency updates”
  • “/dependency-update-bot”

Requirements

  • Python 3
  • Node.js
  • A credential in GEMINI_API_KEY
  • A credential in GITHUB_TOKEN
  • Compatibility (from SKILL.md): ["claude-code","gemini-cli","github-copilot"]

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Setup Check
  2. Detect Outdated Packages
  3. Classify by Risk Level
  4. Security Audit
  5. Fetch Changelogs
  6. Summarize with Gemini
  7. Create PRs
  8. Diagnosis Mode
  9. Output Summary

What it can do on your machine

Read from SKILL.md and the folder at commit 62e437a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • npm
    • curl
    • cargo
    • git
    • go
    • gh
    • bundle
    • pip
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org
    • pypi.org
    • api.github.com
    • generativelanguage.googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GEMINI_API_KEY
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    ["claude-code","gemini-cli","github-copilot"]

    From compatibility in the SKILL.md frontmatter.

Context cost

Dependency Update Bot loads about 3k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 155 tokens; SKILL.md has 503 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:27
    t at aistudio.google.com. Add it to your .env file."

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Varnan-Tech/opendirectory at commit 62e437a, republished under its MIT licence (© Varnan-Tech). 503 words, ~3,000 tokens.

Download SKILL.mdSave it as .claude/skills/dependency-update-bot/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
dependency-update-bot
description
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. Runs a CVE security audit. Fetches changelogs, summarizes breaking changes with Gemini, and opens one PR per risk group (patch, minor, major). Includes Diagnosis Mode for install conflicts. Use when asked to update dependencies, check for outdated packages, open dependency PRs, scan for package updates, audit for CVEs, or flag breaking changes in upgrades. Trigger when a user says "check for outdated packages", "update my dependencies", "open PRs for dependency updates", "scan for CVEs", or "which packages need upgrading".
compatibility
["claude-code","gemini-cli","github-copilot"]
author
OpenDirectory
version
1.0.0

Dependency Update Bot

Scan for outdated packages. Run a security audit. Fetch changelogs. Summarize breaking changes. Open one PR per risk group.


Critical rule: Only update packages that the package manager's outdated command actually reports. Never guess or invent version numbers. If a changelog cannot be fetched, note the gap rather than inventing content.


Step 1: Setup Check

bash
echo "GEMINI_API_KEY: ${GEMINI_API_KEY:+set}"
echo "GITHUB_TOKEN: ${GITHUB_TOKEN:-not set, changelog fetching rate-limited to 60/hour}"
gh auth status 2>/dev/null | head -1 || echo "gh: not authenticated"

If GEMINI_API_KEY is missing: Stop. Tell the user: "GEMINI_API_KEY is required. Get it at aistudio.google.com. Add it to your .env file."

If gh is not authenticated: Stop. Tell the user: "GitHub CLI must be authenticated. Run: gh auth login"

Detect package manager(s):

bash
ls package.json 2>/dev/null && echo "npm"
ls requirements.txt pyproject.toml 2>/dev/null && echo "pip"
ls Cargo.toml 2>/dev/null && echo "cargo"
ls go.mod 2>/dev/null && echo "go"
ls Gemfile 2>/dev/null && echo "ruby"

If multiple are found, ask: "Found [list]. Which should I scan? (all / npm / pip / cargo / go / ruby)"


Step 2: Detect Outdated Packages

npm:

bash
npm outdated --json --long 2>/dev/null | python3 -c "
import sys, json
data = json.load(sys.stdin)
for name, info in data.items():
    print(json.dumps({'name': name, 'current': info.get('current','?'), 'latest': info.get('latest','?'), 'dep_type': info.get('type','dependencies')}))
"

pip:

bash
pip list --outdated --format=json 2>/dev/null | python3 -c "
import sys, json
for p in json.load(sys.stdin):
    print(json.dumps({'name': p['name'], 'current': p['version'], 'latest': p['latest_version']}))
"

Cargo (Rust):

bash
cargo outdated --format json 2>/dev/null || \
  cargo outdated 2>/dev/null | grep -v "^---" | tail -n +3 | head -30
# If cargo-outdated not installed: cargo install cargo-outdated

Go modules:

bash
go list -u -m -json all 2>/dev/null | python3 -c "
import sys, json
decoder = json.JSONDecoder()
buf = sys.stdin.read()
pos = 0
while pos < len(buf):
    try:
        obj, idx = decoder.raw_decode(buf, pos)
        if obj.get('Update'):
            print(json.dumps({'name': obj['Path'], 'current': obj['Version'], 'latest': obj['Update']['Version']}))
        pos += idx
    except: break
"

Ruby (Bundler):

bash
bundle outdated --parseable 2>/dev/null | python3 -c "
import sys
for line in sys.stdin:
    parts = line.strip().split()
    if len(parts) >= 4:
        print('{\"name\":\"' + parts[0] + '\",\"current\":\"' + parts[3].strip('()') + '\",\"latest\":\"' + parts[1] + '\"}')
"

If all return empty: "All packages are up to date." Stop.

State count before proceeding: "Found X outdated packages."


Step 3: Classify by Risk Level

Parse version bump (current → latest):

  • MAJOR: first digit changed (1.x.x → 2.x.x)
  • MINOR: second digit changed (1.2.x → 1.3.x)
  • PATCH: third digit changed (1.2.3 → 1.2.4)
bash
python3 -c "
def classify(current, latest):
    try:
        c = [int(x) for x in current.lstrip('v').split('.')[:3]]
        l = [int(x) for x in latest.lstrip('v').split('.')[:3]]
        if l[0] > c[0]: return 'major'
        if len(l) > 1 and len(c) > 1 and l[1] > c[1]: return 'minor'
        return 'patch'
    except: return 'unknown'
"

State the breakdown: "Patch: X packages. Minor: Y packages. Major: Z packages."


Step 4: Security Audit

Run a CVE scan before creating any PRs. This determines urgency.

npm:

bash
npm audit --json 2>/dev/null | python3 -c "
import sys, json
d = json.load(sys.stdin)
vulns = d.get('vulnerabilities', {})
for pkg, info in vulns.items():
    sev = info.get('severity', 'unknown')
    via = [v.get('title','') for v in info.get('via',[]) if isinstance(v, dict)]
    print(f'  [{sev.upper()}] {pkg}: {via[0] if via else \"see npm audit\"}')
" 2>/dev/null || echo "No vulnerabilities found or npm audit not available"

pip:

bash
pip-audit --format=json 2>/dev/null | python3 -c "
import sys, json
for vuln in json.load(sys.stdin):
    print(f'  [{vuln.get(\"aliases\",[\"\"])[0]}] {vuln[\"name\"]} {vuln[\"version\"]}: {vuln[\"description\"][:80]}')
" 2>/dev/null || echo "pip-audit not installed. Run: pip install pip-audit"

Cargo:

bash
cargo audit 2>/dev/null | grep -E "^(ID|Package|Severity|URL)" | head -30 \
  || echo "cargo-audit not installed. Run: cargo install cargo-audit"

Escalation rule: If a PATCH or MINOR update has a Critical or High CVE, promote it to MAJOR priority: it gets its own PR and the CVE details go in the PR body.

Report security findings before proceeding:

Security audit: [N] vulnerabilities found
  [CRITICAL] lodash 4.17.19: Prototype Pollution (CVE-2021-23337)
  [HIGH] axios 0.21.1: Server-Side Request Forgery (CVE-2021-3749)

If no vulnerabilities: "Security audit: clean."


Step 5: Fetch Changelogs

For each package, try sources in order. Stop at first that returns content.

Source 1: GitHub Releases API

Get repo URL from registry:

bash
# npm
curl -s "https://registry.npmjs.org/{PACKAGE}/latest" \
  | python3 -c "import sys,json; d=json.load(sys.stdin); r=d.get('repository',{}); print(r.get('url','') if isinstance(r,dict) else str(r))"

# pip
curl -s "https://pypi.org/pypi/{PACKAGE}/json" \
  | python3 -c "import sys,json; d=json.load(sys.stdin); print(d.get('info',{}).get('home_page','') or d.get('info',{}).get('project_urls',{}).get('Source',''))"

Fetch last 5 releases:

bash
AUTH_HEADER=""
[ -n "$GITHUB_TOKEN" ] && AUTH_HEADER="-H \"Authorization: Bearer $GITHUB_TOKEN\""
curl -s $AUTH_HEADER \
  "https://api.github.com/repos/{OWNER}/{REPO}/releases?per_page=5" \
  | python3 -c "import sys,json; [print(json.dumps({'tag':r.get('tag_name',''),'body':r.get('body','')[:1500]})) for r in json.load(sys.stdin)]"

Keep releases between current and latest version only.

Source 2: npm registry README (fallback)

bash
curl -s "https://registry.npmjs.org/{PACKAGE}" \
  | python3 -c "import sys,json; print(json.load(sys.stdin).get('readme','')[:3000])"

Source 3: PyPI description (last resort for pip)

bash
curl -s "https://pypi.org/pypi/{PACKAGE}/json" \
  | python3 -c "import sys,json; print(json.load(sys.stdin).get('info',{}).get('description','')[:2000])"

If no source returns content: note "No changelog found" and continue.


Show full SKILL.md (187 more words)Show less

Step 6: Summarize with Gemini

One request per risk group. Include security findings for any CVE-affected packages:

bash
cat > /tmp/deps-summary-request.json << 'ENDJSON'
{
  "system_instruction": {
    "parts": [{
      "text": "You are a developer writing a GitHub PR description for a dependency update. Given a list of packages being updated and their raw changelog content, write a concise PR body in Markdown. Rules: For each package, list only what changed between the OLD version and the NEW version. Use bullet points. Flag breaking changes with a BREAKING prefix. Flag CVE fixes with a SECURITY prefix and include the CVE ID. Keep each package section to 3-5 bullets maximum. If no changelog was found for a package, write 'No changelog available.' Do not use em dashes. Do not use these words: seamless, robust, leverage, transform, innovative. Output only the Markdown PR body, no commentary."
    }]
  },
  "contents": [{
    "parts": [{
      "text": "PACKAGES_AND_CHANGELOGS_HERE"
    }]
  }],
  "generationConfig": {
    "temperature": 0.2,
    "maxOutputTokens": 2048
  }
}
ENDJSON

curl -s -X POST \
  "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.0-flash:generateContent?key=$GEMINI_API_KEY" \
  -H "Content-Type: application/json" \
  -d @/tmp/deps-summary-request.json \
  | python3 -c "import sys,json; d=json.load(sys.stdin); print(d['candidates'][0]['content']['parts'][0]['text'])"

Step 7: Create PRs

One PR per non-empty risk group. One PR per package for major updates (individual review required).

1. Create branch:

bash
BRANCH="deps/{RISK}-updates-$(date +%Y%m%d)"
git checkout -b "$BRANCH"

2. Update package file:

npm:

bash
npm install {package}@{latest_version} --save-exact
# devDependencies:
npm install {package}@{latest_version} --save-dev --save-exact

pip:

bash
python3 -c "
import re, sys
pkg, version, filename = sys.argv[1], sys.argv[2], sys.argv[3]
with open(filename) as f: content = f.read()
pattern = rf'^{re.escape(pkg)}[>=<!\s].*$'
new_content = re.sub(pattern, f'{pkg}=={version}', content, flags=re.MULTILINE|re.IGNORECASE)
if new_content == content: new_content = content + f'\n{pkg}=={version}'
open(filename, 'w').write(new_content)
" "{PACKAGE}" "{LATEST}" "requirements.txt"

Cargo:

bash
# Edit Cargo.toml version field for the package, then:
cargo update {package}

Go:

bash
go get {module}@{latest_version}
go mod tidy

Ruby:

bash
bundle update {gem_name}

3. Commit:

bash
git add -A
git commit -m "chore(deps): update {RISK} dependencies $(date +%Y-%m-%d)"

4. Create PR:

bash
cat > /tmp/dep-pr-body-{RISK}.md << 'ENDMD'
PR_BODY_FROM_GEMINI
ENDMD

gh pr create \
  --title "chore(deps): update {RISK} dependencies" \
  --body-file /tmp/dep-pr-body-{RISK}.md \
  --label "dependencies" \
  --base main

Major updates get label dependencies,breaking-change. CVE-fixing updates get label dependencies,security.

After each PR, return to main: git checkout main


Step 8: Diagnosis Mode

Trigger: If any package install command fails mid-run, enter Diagnosis Mode instead of stopping.

Detect the failure type:

Error patternLikely causeSuggested fix
peer dep conflictPeer dependency incompatibilityShow conflicting pair, suggest --legacy-peer-deps flag or downgrade
ERESOLVEnpm resolution conflictRun npm install --legacy-peer-deps for the affected package only
version not foundVersion does not exist in registryCheck registry with npm view {pkg} versions
python requiresPython version incompatibilityNote required Python version, skip package
cargo E0463Rust edition incompatibilityFlag for manual review

Present a diagnosis summary:

Install failed for {package}: {error type}
Likely cause: {explanation}
Suggested fix: {specific command or action}
Remaining packages: proceeding with {N} that succeeded.

Do not stop the entire run when one package fails. Continue with packages that succeed.


Step 9: Output Summary

## Dependency Update Summary: [YYYY-MM-DD]

### Security
[CRITICAL] lodash: CVE-2021-23337 fixed in 4.17.21: PR #42
[HIGH] axios: CVE-2021-3749 fixed in 0.21.4: PR #42

| Risk Level | Packages | PR |
|------------|----------|-----|
| Patch | lodash 4.17.19→4.17.21, axios 0.21.1→0.21.4 | #42 |
| Minor | express 4.17.1→4.18.2 | #43 |
| Major | react 17.0.2→18.2.0 | #44 |

PRs opened: 3

Packages with no changelog: some-obscure-pkg (no GitHub repo in registry)
Install failures: none

Next action: Review major update PRs individually before merging.

© Varnan-Tech, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/dependency-update-bot of Varnan-Tech/opendirectory.

  • SKILL.md
  • .env.example
  • README.md
  • evals/evals.json
  • references/changelog-patterns.md

Open the folder on GitHubat commit 62e437a

Compare with similar skills

Dependency Update Bot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependency Update Bot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependency Update Bot this skillVarnan-Tech/opendirectory674—~3kAutomated safety check: NotesMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Ghost Scan Depsghostsecurity/skills408—~1.3kAutomated safety check: NotesApache-2.0
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0
Sca AuditOWASP/secure-agent-playbook187—~494Automated safety check: PassCC-BY-4.0
Gem Dependency Managementruby-git/ruby-git1.8k—~806Automated safety check: PassMIT

Similar skills

  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Ghost Scan Deps

    ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner.

    408 GitHub stars~1.3k tokensUpdated 9 days ago
    SecurityAuto-check: notes
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    187 GitHub stars~494 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Gem Dependency Management

    ruby-git/ruby-git

    Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

    1.8k GitHub stars~806 tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Dependency Upgrade Protocol

    dralgorhythm/claude-agentic-framework

    Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

    125 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from Varnan-Tech/opendirectory

All 61 skills in this repo
  • Podcast Transcript Fetcher

    Varnan-Tech/opendirectory

    A skill your agent uses when fetching, searching, or analyzing transcripts from Lenny's Podcast, Dwarkesh Podcast, Cheeky Pint, 20VC, or A16z Podcast.

    674 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check: notes
  • Graphic Ebook

    Varnan-Tech/opendirectory

    Creates professionally designed B2B SaaS e-books in HTML + CSS, exported as print-ready PDF.

    674 GitHub stars~5k tokensUpdated 1 mo ago
    Auto-check passed
  • Where Your Customer Lives

    Varnan-Tech/opendirectory

    Given a product utility and ICP, researches the internet to find the specific channels.

    674 GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Docs From Code

    Varnan-Tech/opendirectory

    Generates and updates README.md and API reference docs by reading your codebase's functions, routes, types, schemas, and architecture.

    674 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Graphic Chart

    Varnan-Tech/opendirectory

    Generates data visualization charts (bar, line, area, pie, doughnut, scatter, radar, treemap) as PNG using Apache ECharts v6.

    674 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Graphic Gif

    Varnan-Tech/opendirectory

    Creates animated looping GIFs from CSS animations (default) or AI image-to-video.

    674 GitHub stars~3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Dependency Update Bot

What does Dependency Update Bot do?

Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. Dependency Update Bot is an agent skill from Varnan-Tech/opendirectory. Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

When should I use Dependency Update Bot?

Dependency Update Bot fits situations like: asked to update dependencies; check for outdated packages; open dependency PRs; scan for package updates.

How do I install Dependency Update Bot in Claude Code?

Run `npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a claude-code`. Or copy the skill folder (skills/dependency-update-bot in Varnan-Tech/opendirectory) into .claude/skills/dependency-update-bot in your project. Claude Code loads it when a task matches its description.

How do I install Dependency Update Bot in Codex?

Run `npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a codex`. Or copy the skill folder (skills/dependency-update-bot in Varnan-Tech/opendirectory) into .agents/skills/dependency-update-bot in your project. Codex loads it when a task matches its description.

Can I use Dependency Update Bot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-update-bot, .gemini/skills/dependency-update-bot, .github/skills/dependency-update-bot and .opencode/skills/dependency-update-bot in your project.

What does Dependency Update Bot need to run?

Going by SKILL.md and its folder, Dependency Update Bot needs the command-line tools its instructions call (python3, npm, curl, cargo, git and go) and credentials named GEMINI_API_KEY and GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A credential in GEMINI_API_KEY; A credential in GITHUB_TOKEN. Compatibility (from SKILL.md): ["claude-code","gemini-cli","github-copilot"].

Does Dependency Update Bot access the network?

SKILL.md names 4 domains. In commands or code: registry.npmjs.org, pypi.org, api.github.com and generativelanguage.googleapis.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Dependency Update Bot safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dependency Update Bot use?

Dependency Update Bot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependency Update Bot use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Dependency Update Bot?

Skills that share tags, products or a category with Dependency Update Bot: Cyberowlai (karimhabush/cyberowl, 263 stars), Ghost Scan Deps (ghostsecurity/skills, 408 stars), Cve Scan (softspark/ai-toolkit, 179 stars) and Sca Audit (OWASP/secure-agent-playbook, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependency Update Bot?

Varnan-Tech (a GitHub organization) maintains it in Varnan-Tech/opendirectory, which has 674 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on August 16, 2026.

Source: Varnan-Tech/opendirectory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.