Cyberowlai
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
$ npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Varnan-Tech/opendirectory dependency-update-bot --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Varnan-Tech/opendirectory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dependency-update-bot .claude/skills/dependency-update-bot && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-update-bot" agent skill from https://github.com/Varnan-Tech/opendirectory/tree/main/skills/dependency-update-bot into .claude/skills/dependency-update-bot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-update-bot", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Varnan-Tech/opendirectory/tree/main/skills/dependency-update-botType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Varnan-Tech/opendirectory dependency-update-bot --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Varnan-Tech/opendirectory.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dependency-update-bot .agents/skills/dependency-update-bot && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-update-bot" agent skill from https://github.com/Varnan-Tech/opendirectory/tree/main/skills/dependency-update-bot into .agents/skills/dependency-update-bot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-update-bot", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Varnan-Tech/opendirectory dependency-update-bot --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Varnan-Tech/opendirectory.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dependency-update-bot .cursor/skills/dependency-update-bot && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-update-bot" agent skill from https://github.com/Varnan-Tech/opendirectory/tree/main/skills/dependency-update-bot into .cursor/skills/dependency-update-bot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-update-bot", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Varnan-Tech/opendirectory.git --path skills/dependency-update-bot--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Varnan-Tech/opendirectory dependency-update-bot --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Varnan-Tech/opendirectory.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dependency-update-bot .gemini/skills/dependency-update-bot && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-update-bot" agent skill from https://github.com/Varnan-Tech/opendirectory/tree/main/skills/dependency-update-bot into .gemini/skills/dependency-update-bot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-update-bot", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Varnan-Tech/opendirectory dependency-update-botInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Varnan-Tech/opendirectory.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dependency-update-bot .github/skills/dependency-update-bot && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-update-bot" agent skill from https://github.com/Varnan-Tech/opendirectory/tree/main/skills/dependency-update-bot into .github/skills/dependency-update-bot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-update-bot", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Varnan-Tech/opendirectory dependency-update-bot --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Varnan-Tech/opendirectory.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dependency-update-bot .opencode/skills/dependency-update-bot && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-update-bot" agent skill from https://github.com/Varnan-Tech/opendirectory/tree/main/skills/dependency-update-bot into .opencode/skills/dependency-update-bot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-update-bot", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-update-botScans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
Dependency Update Bot is an agent skill from Varnan-Tech/opendirectory. Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. Runs a CVE security audit. Fetches changelogs, summarizes breaking changes with Gemini, and opens one PR per risk group (patch, minor, major). Includes Diagnosis Mode for install conflicts. Use when asked to update dependencies, check for outdated packages, open dependency PRs, scan for package updates, audit for CVEs, or flag breaking changes in upgrades. Trigger when a user says "check for outdated packages", "update my dependencies", "open…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `README.md`, `evals/evals.json` and `references/changelog-patterns.md`). Compatibility notes: ["claude-code","gemini-cli","github-copilot"]
It sits in Development, covering Dependency management, Vulnerability scanning and Changelog and release notes. It works with npm and Ruby. The repository describes itself as: AI Agent Skills built for Founders who hate Marketing. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 62e437a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3npmcurlcargogitgoghbundlepippythonFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
registry.npmjs.orgpypi.orgapi.github.comgenerativelanguage.googleapis.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GEMINI_API_KEYGITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
["claude-code","gemini-cli","github-copilot"]
From compatibility in the SKILL.md frontmatter.
Dependency Update Bot loads about 3k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 155 tokens; SKILL.md has 503 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
t at aistudio.google.com. Add it to your .env file."Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Varnan-Tech/opendirectory at commit 62e437a, republished under its MIT licence (© Varnan-Tech). 503 words, ~3,000 tokens.
.claude/skills/dependency-update-bot/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Scan for outdated packages. Run a security audit. Fetch changelogs. Summarize breaking changes. Open one PR per risk group.
Critical rule: Only update packages that the package manager's outdated command actually reports. Never guess or invent version numbers. If a changelog cannot be fetched, note the gap rather than inventing content.
echo "GEMINI_API_KEY: ${GEMINI_API_KEY:+set}"
echo "GITHUB_TOKEN: ${GITHUB_TOKEN:-not set, changelog fetching rate-limited to 60/hour}"
gh auth status 2>/dev/null | head -1 || echo "gh: not authenticated"If GEMINI_API_KEY is missing: Stop. Tell the user: "GEMINI_API_KEY is required. Get it at aistudio.google.com. Add it to your .env file."
If gh is not authenticated: Stop. Tell the user: "GitHub CLI must be authenticated. Run: gh auth login"
Detect package manager(s):
ls package.json 2>/dev/null && echo "npm"
ls requirements.txt pyproject.toml 2>/dev/null && echo "pip"
ls Cargo.toml 2>/dev/null && echo "cargo"
ls go.mod 2>/dev/null && echo "go"
ls Gemfile 2>/dev/null && echo "ruby"If multiple are found, ask: "Found [list]. Which should I scan? (all / npm / pip / cargo / go / ruby)"
npm:
npm outdated --json --long 2>/dev/null | python3 -c "
import sys, json
data = json.load(sys.stdin)
for name, info in data.items():
print(json.dumps({'name': name, 'current': info.get('current','?'), 'latest': info.get('latest','?'), 'dep_type': info.get('type','dependencies')}))
"pip:
pip list --outdated --format=json 2>/dev/null | python3 -c "
import sys, json
for p in json.load(sys.stdin):
print(json.dumps({'name': p['name'], 'current': p['version'], 'latest': p['latest_version']}))
"Cargo (Rust):
cargo outdated --format json 2>/dev/null || \
cargo outdated 2>/dev/null | grep -v "^---" | tail -n +3 | head -30
# If cargo-outdated not installed: cargo install cargo-outdatedGo modules:
go list -u -m -json all 2>/dev/null | python3 -c "
import sys, json
decoder = json.JSONDecoder()
buf = sys.stdin.read()
pos = 0
while pos < len(buf):
try:
obj, idx = decoder.raw_decode(buf, pos)
if obj.get('Update'):
print(json.dumps({'name': obj['Path'], 'current': obj['Version'], 'latest': obj['Update']['Version']}))
pos += idx
except: break
"Ruby (Bundler):
bundle outdated --parseable 2>/dev/null | python3 -c "
import sys
for line in sys.stdin:
parts = line.strip().split()
if len(parts) >= 4:
print('{\"name\":\"' + parts[0] + '\",\"current\":\"' + parts[3].strip('()') + '\",\"latest\":\"' + parts[1] + '\"}')
"If all return empty: "All packages are up to date." Stop.
State count before proceeding: "Found X outdated packages."
Parse version bump (current → latest):
python3 -c "
def classify(current, latest):
try:
c = [int(x) for x in current.lstrip('v').split('.')[:3]]
l = [int(x) for x in latest.lstrip('v').split('.')[:3]]
if l[0] > c[0]: return 'major'
if len(l) > 1 and len(c) > 1 and l[1] > c[1]: return 'minor'
return 'patch'
except: return 'unknown'
"State the breakdown: "Patch: X packages. Minor: Y packages. Major: Z packages."
Run a CVE scan before creating any PRs. This determines urgency.
npm:
npm audit --json 2>/dev/null | python3 -c "
import sys, json
d = json.load(sys.stdin)
vulns = d.get('vulnerabilities', {})
for pkg, info in vulns.items():
sev = info.get('severity', 'unknown')
via = [v.get('title','') for v in info.get('via',[]) if isinstance(v, dict)]
print(f' [{sev.upper()}] {pkg}: {via[0] if via else \"see npm audit\"}')
" 2>/dev/null || echo "No vulnerabilities found or npm audit not available"pip:
pip-audit --format=json 2>/dev/null | python3 -c "
import sys, json
for vuln in json.load(sys.stdin):
print(f' [{vuln.get(\"aliases\",[\"\"])[0]}] {vuln[\"name\"]} {vuln[\"version\"]}: {vuln[\"description\"][:80]}')
" 2>/dev/null || echo "pip-audit not installed. Run: pip install pip-audit"Cargo:
cargo audit 2>/dev/null | grep -E "^(ID|Package|Severity|URL)" | head -30 \
|| echo "cargo-audit not installed. Run: cargo install cargo-audit"Escalation rule: If a PATCH or MINOR update has a Critical or High CVE, promote it to MAJOR priority: it gets its own PR and the CVE details go in the PR body.
Report security findings before proceeding:
Security audit: [N] vulnerabilities found
[CRITICAL] lodash 4.17.19: Prototype Pollution (CVE-2021-23337)
[HIGH] axios 0.21.1: Server-Side Request Forgery (CVE-2021-3749)If no vulnerabilities: "Security audit: clean."
For each package, try sources in order. Stop at first that returns content.
Source 1: GitHub Releases API
Get repo URL from registry:
# npm
curl -s "https://registry.npmjs.org/{PACKAGE}/latest" \
| python3 -c "import sys,json; d=json.load(sys.stdin); r=d.get('repository',{}); print(r.get('url','') if isinstance(r,dict) else str(r))"
# pip
curl -s "https://pypi.org/pypi/{PACKAGE}/json" \
| python3 -c "import sys,json; d=json.load(sys.stdin); print(d.get('info',{}).get('home_page','') or d.get('info',{}).get('project_urls',{}).get('Source',''))"Fetch last 5 releases:
AUTH_HEADER=""
[ -n "$GITHUB_TOKEN" ] && AUTH_HEADER="-H \"Authorization: Bearer $GITHUB_TOKEN\""
curl -s $AUTH_HEADER \
"https://api.github.com/repos/{OWNER}/{REPO}/releases?per_page=5" \
| python3 -c "import sys,json; [print(json.dumps({'tag':r.get('tag_name',''),'body':r.get('body','')[:1500]})) for r in json.load(sys.stdin)]"Keep releases between current and latest version only.
Source 2: npm registry README (fallback)
curl -s "https://registry.npmjs.org/{PACKAGE}" \
| python3 -c "import sys,json; print(json.load(sys.stdin).get('readme','')[:3000])"Source 3: PyPI description (last resort for pip)
curl -s "https://pypi.org/pypi/{PACKAGE}/json" \
| python3 -c "import sys,json; print(json.load(sys.stdin).get('info',{}).get('description','')[:2000])"If no source returns content: note "No changelog found" and continue.
One request per risk group. Include security findings for any CVE-affected packages:
cat > /tmp/deps-summary-request.json << 'ENDJSON'
{
"system_instruction": {
"parts": [{
"text": "You are a developer writing a GitHub PR description for a dependency update. Given a list of packages being updated and their raw changelog content, write a concise PR body in Markdown. Rules: For each package, list only what changed between the OLD version and the NEW version. Use bullet points. Flag breaking changes with a BREAKING prefix. Flag CVE fixes with a SECURITY prefix and include the CVE ID. Keep each package section to 3-5 bullets maximum. If no changelog was found for a package, write 'No changelog available.' Do not use em dashes. Do not use these words: seamless, robust, leverage, transform, innovative. Output only the Markdown PR body, no commentary."
}]
},
"contents": [{
"parts": [{
"text": "PACKAGES_AND_CHANGELOGS_HERE"
}]
}],
"generationConfig": {
"temperature": 0.2,
"maxOutputTokens": 2048
}
}
ENDJSON
curl -s -X POST \
"https://generativelanguage.googleapis.com/v1beta/models/gemini-2.0-flash:generateContent?key=$GEMINI_API_KEY" \
-H "Content-Type: application/json" \
-d @/tmp/deps-summary-request.json \
| python3 -c "import sys,json; d=json.load(sys.stdin); print(d['candidates'][0]['content']['parts'][0]['text'])"One PR per non-empty risk group. One PR per package for major updates (individual review required).
1. Create branch:
BRANCH="deps/{RISK}-updates-$(date +%Y%m%d)"
git checkout -b "$BRANCH"2. Update package file:
npm:
npm install {package}@{latest_version} --save-exact
# devDependencies:
npm install {package}@{latest_version} --save-dev --save-exactpip:
python3 -c "
import re, sys
pkg, version, filename = sys.argv[1], sys.argv[2], sys.argv[3]
with open(filename) as f: content = f.read()
pattern = rf'^{re.escape(pkg)}[>=<!\s].*$'
new_content = re.sub(pattern, f'{pkg}=={version}', content, flags=re.MULTILINE|re.IGNORECASE)
if new_content == content: new_content = content + f'\n{pkg}=={version}'
open(filename, 'w').write(new_content)
" "{PACKAGE}" "{LATEST}" "requirements.txt"Cargo:
# Edit Cargo.toml version field for the package, then:
cargo update {package}Go:
go get {module}@{latest_version}
go mod tidyRuby:
bundle update {gem_name}3. Commit:
git add -A
git commit -m "chore(deps): update {RISK} dependencies $(date +%Y-%m-%d)"4. Create PR:
cat > /tmp/dep-pr-body-{RISK}.md << 'ENDMD'
PR_BODY_FROM_GEMINI
ENDMD
gh pr create \
--title "chore(deps): update {RISK} dependencies" \
--body-file /tmp/dep-pr-body-{RISK}.md \
--label "dependencies" \
--base mainMajor updates get label dependencies,breaking-change. CVE-fixing updates get label dependencies,security.
After each PR, return to main: git checkout main
Trigger: If any package install command fails mid-run, enter Diagnosis Mode instead of stopping.
Detect the failure type:
| Error pattern | Likely cause | Suggested fix |
|---|---|---|
peer dep conflict | Peer dependency incompatibility | Show conflicting pair, suggest --legacy-peer-deps flag or downgrade |
ERESOLVE | npm resolution conflict | Run npm install --legacy-peer-deps for the affected package only |
version not found | Version does not exist in registry | Check registry with npm view {pkg} versions |
python requires | Python version incompatibility | Note required Python version, skip package |
cargo E0463 | Rust edition incompatibility | Flag for manual review |
Present a diagnosis summary:
Install failed for {package}: {error type}
Likely cause: {explanation}
Suggested fix: {specific command or action}
Remaining packages: proceeding with {N} that succeeded.Do not stop the entire run when one package fails. Continue with packages that succeed.
## Dependency Update Summary: [YYYY-MM-DD]
### Security
[CRITICAL] lodash: CVE-2021-23337 fixed in 4.17.21: PR #42
[HIGH] axios: CVE-2021-3749 fixed in 0.21.4: PR #42
| Risk Level | Packages | PR |
|------------|----------|-----|
| Patch | lodash 4.17.19→4.17.21, axios 0.21.1→0.21.4 | #42 |
| Minor | express 4.17.1→4.18.2 | #43 |
| Major | react 17.0.2→18.2.0 | #44 |
PRs opened: 3
Packages with no changelog: some-obscure-pkg (no GitHub repo in registry)
Install failures: none
Next action: Review major update PRs individually before merging.© Varnan-Tech, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/dependency-update-bot of Varnan-Tech/opendirectory.
Open the folder on GitHubat commit 62e437a
Dependency Update Bot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Update Bot this skillVarnan-Tech/opendirectory | 674 | — | ~3k | Automated safety check: Notes | MIT | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Ghost Scan Depsghostsecurity/skills | 408 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Cve Scansoftspark/ai-toolkit | 179 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Sca AuditOWASP/secure-agent-playbook | 187 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | |
| Gem Dependency Managementruby-git/ruby-git | 1.8k | — | ~806 | Automated safety check: Pass | MIT |
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
ghostsecurity/skills
Ghost Security - Software Composition Analysis (SCA) scanner.
softspark/ai-toolkit
Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).
OWASP/secure-agent-playbook
Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.
ruby-git/ruby-git
Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.
dralgorhythm/claude-agentic-framework
Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.
Varnan-Tech/opendirectory
A skill your agent uses when fetching, searching, or analyzing transcripts from Lenny's Podcast, Dwarkesh Podcast, Cheeky Pint, 20VC, or A16z Podcast.
Varnan-Tech/opendirectory
Creates professionally designed B2B SaaS e-books in HTML + CSS, exported as print-ready PDF.
Varnan-Tech/opendirectory
Given a product utility and ICP, researches the internet to find the specific channels.
Varnan-Tech/opendirectory
Generates and updates README.md and API reference docs by reading your codebase's functions, routes, types, schemas, and architecture.
Varnan-Tech/opendirectory
Generates data visualization charts (bar, line, area, pie, doughnut, scatter, radar, treemap) as PNG using Apache ECharts v6.
Varnan-Tech/opendirectory
Creates animated looping GIFs from CSS animations (default) or AI image-to-video.
Categories
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. Dependency Update Bot is an agent skill from Varnan-Tech/opendirectory. Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.
Dependency Update Bot fits situations like: asked to update dependencies; check for outdated packages; open dependency PRs; scan for package updates.
Run `npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a claude-code`. Or copy the skill folder (skills/dependency-update-bot in Varnan-Tech/opendirectory) into .claude/skills/dependency-update-bot in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a codex`. Or copy the skill folder (skills/dependency-update-bot in Varnan-Tech/opendirectory) into .agents/skills/dependency-update-bot in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Varnan-Tech/opendirectory --skill dependency-update-bot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-update-bot, .gemini/skills/dependency-update-bot, .github/skills/dependency-update-bot and .opencode/skills/dependency-update-bot in your project.
Going by SKILL.md and its folder, Dependency Update Bot needs the command-line tools its instructions call (python3, npm, curl, cargo, git and go) and credentials named GEMINI_API_KEY and GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A credential in GEMINI_API_KEY; A credential in GITHUB_TOKEN. Compatibility (from SKILL.md): ["claude-code","gemini-cli","github-copilot"].
SKILL.md names 4 domains. In commands or code: registry.npmjs.org, pypi.org, api.github.com and generativelanguage.googleapis.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Dependency Update Bot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dependency Update Bot: Cyberowlai (karimhabush/cyberowl, 263 stars), Ghost Scan Deps (ghostsecurity/skills, 408 stars), Cve Scan (softspark/ai-toolkit, 179 stars) and Sca Audit (OWASP/secure-agent-playbook, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Varnan-Tech (a GitHub organization) maintains it in Varnan-Tech/opendirectory, which has 674 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on August 16, 2026.
Source: Varnan-Tech/opendirectory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.