Agent skill

Update Deps

by VinkyDev in VinkyDev/vibestart

Move the pinned dependencies to their latest targets, verify, and open a pull request.

MITAuto-check passedDevelopment

Install Update Deps

skills CLI
$ npx skills add VinkyDev/vibestart --skill update-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VinkyDev/vibestart update-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VinkyDev/vibestart.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/update-deps .claude/skills/update-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-deps
GitHub stars
103
Token cost
~445 tokens
SKILL.md length
275 words
Files
2
Repo updated
First seen
Licence
MIT

At a glance

Move the pinned dependencies to their latest targets, verify, and open a pull request.

  • Works in 6 steps: Branch. Start from an up-to-date, clean… → Survey. Run vp run deps. Exit 0 means… → Update. Run vp run deps update. It moves… → …
  • Tasks that involve Pull requests
  • Calls git and gh

What it does

Update Deps is an agent skill from VinkyDev/vibestart. Move the pinned dependencies to their latest targets, verify, and open a pull request.

Its SKILL.md is about 450 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Pull requests. It works with Vite, React, TypeScript and shadcn/ui. The repository describes itself as: Compose a full-stack TypeScript stack and get a cutting-edge, verified project made for AI coding agents, with type safety, lint, and tests built in. | 自由组合全栈 TypeScript… The licence is MIT.

When your agent uses it

  • Tasks that involve Pull requests

Example prompts

  • “/update-deps”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Branch. Start from an up-to-date, clean main, then create deps/update-. Done when git status is clean on the new branch.
  2. Survey. Run vp run deps. Exit 0 means every pin is at its target: report that and stop. Otherwise read the table; a major bump or a…
  3. Update. Run vp run deps update. It moves the pins, refreshes lockfiles, goldens, and snapshots, then runs vp run ready. When a step fails…
  4. Check. Run vp check and vp run ready. Done when both pass on the final tree.
  5. Commit. One commit, chore(deps): update pinned dependencies, authored as the configured git user with no Co-authored-by trailer. A tool…
  6. Pull request. Push the branch and run gh pr create against main. The body lists each moved pin as name: old → new with its bump, and names…

What it can do on your machine

Read from SKILL.md and the folder at commit b7f5031. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Deps loads about 445 tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 275 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~445

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from VinkyDev/vibestart at commit b7f5031, republished under its MIT licence (© VinkyDev). 275 words, ~445 tokens.

Download SKILL.mdSave it as .claude/skills/update-deps/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
update-deps
description
Move the pinned dependencies to their latest targets, verify, and open a pull request.
disable-model-invocation
true

Land a dependency update as one reviewed pull request. Read "Keeping dependencies current" in CONTRIBUTING.md for what a pin is and how the three pin files stay in step.

  1. Branch. Start from an up-to-date, clean main, then create deps/update-<YYYY-MM-DD>. Done when git status is clean on the new branch.
  2. Survey. Run vp run deps. Exit 0 means every pin is at its target: report that and stop. Otherwise read the table; a major bump or a deprecated pin is where a breaking change hides.
  3. Update. Run vp run deps update. It moves the pins, refreshes lockfiles, goldens, and snapshots, then runs vp run ready. When a step fails, the moved pins stay in the working tree: fix the cause at the abstraction that owns it (a template, an integration, a pin rule in packages/integrations/src/deps), then run vp run deps update again. Done when it prints Repository checks passed. CI verifies every stack the pins reach on the pull request.
  4. Check. Run vp check and vp run ready. Done when both pass on the final tree.
  5. Commit. One commit, chore(deps): update pinned dependencies, authored as the configured git user with no Co-authored-by trailer. A tool that appends one gets bypassed with git commit-tree.
  6. Pull request. Push the branch and run gh pr create against main. The body lists each moved pin as name: old → new with its bump, and names every breaking change you handled and where. Done when the pull request's ci check passes; hand its URL to the user. A failing verify job names the stack and ends with its log; fix the cause as in step 3.

© VinkyDev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/update-deps of VinkyDev/vibestart.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit b7f5031

Compare with similar skills

Update Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Deps this skillVinkyDev/vibestart103—~445Automated safety check: PassMIT
Cleanup Specialistahaodev/shadmin174—~1.3kAutomated safety check: PassMIT
Shadmin CLIahaodev/shadmin174—~1.1kAutomated safety check: NotesMIT
Shadmin Devahaodev/shadmin174—~2.8kAutomated safety check: PassMIT
Web Artifacts Builderanthropics/skills180k40 repos~769Automated safety check: PassApache-2.0
Code Refactor Reviewkcsujeet/ilamy-calendar3512 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • Cleanup Specialist

    ahaodev/shadmin

    Safe cleanup of Shadmin's Go backend, React frontend, Go CLI, and docs — remove dead code, consolidate duplication, and improve maintainability without changing behavior or adding features.

    174 GitHub stars~1.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Shadmin CLI

    ahaodev/shadmin

    A skill your agent uses when the user asks to query Shadmin admin platform resources (users, roles, menus, registered API resources) from a terminal — for example "list shadmin users", "show shadmin…

    174 GitHub stars~1.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes
  • Shadmin Dev

    ahaodev/shadmin

    Apply Shadmin feature-development standards (backend Go/Gin/Ent + frontend React/TS).

    174 GitHub stars~2.8k tokensUpdated 2 days ago
    Frontend & DesignAuto-check passed
  • Web Artifacts Builder

    anthropics/skills

    Official

    Builds multi-component claude.ai HTML artifacts as a small React, TypeScript and Tailwind project, then bundles it into one shareable HTML file.

    180k GitHub starsUsed in 40 repos~769 tokens
    Frontend & DesignAuto-check passed
  • Code Refactor Review

    kcsujeet/ilamy-calendar

    Reviews code changes for reuse, composition, codebase consistency, and slop.

    351 GitHub starsUsed in 2 repos~1.6k tokens
    DevelopmentAuto-check passed
  • Morphous Catalog

    Ameyanagi/morphos

    Create or refresh Morphous website design-system/theme bundles from animal, insect, plant, landscape, mineral, weather, or other nature motifs.

    102 GitHub stars~2.1k tokensUpdated 1 mo ago
    Frontend & DesignAuto-check passed

More from VinkyDev/vibestart

  • Vibestart

    VinkyDev/vibestart

    Use the vibestart CLI to create a TypeScript project, choose a stack or recipe, add capabilities such as Knip, Ultracite or Docker, diagnose project state, or upgrade templates while preserving…

    103 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Categories

Questions about Update Deps

What does Update Deps do?

Move the pinned dependencies to their latest targets, verify, and open a pull request. Update Deps is an agent skill from VinkyDev/vibestart. Move the pinned dependencies to their latest targets, verify, and open a pull request.

When should I use Update Deps?

Update Deps fits situations like: tasks that involve Pull requests.

How do I install Update Deps in Claude Code?

Run `npx skills add VinkyDev/vibestart --skill update-deps -a claude-code`. Or copy the skill folder (.agents/skills/update-deps in VinkyDev/vibestart) into .claude/skills/update-deps in your project. Claude Code loads it when a task matches its description.

How do I install Update Deps in Codex?

Run `npx skills add VinkyDev/vibestart --skill update-deps -a codex`. Or copy the skill folder (.agents/skills/update-deps in VinkyDev/vibestart) into .agents/skills/update-deps in your project. Codex loads it when a task matches its description.

Can I use Update Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VinkyDev/vibestart --skill update-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-deps, .gemini/skills/update-deps, .github/skills/update-deps and .opencode/skills/update-deps in your project.

What does Update Deps need to run?

Going by SKILL.md and its folder, Update Deps needs the command-line tools its instructions call (git and gh).

Does Update Deps access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Deps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Deps use?

Update Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Deps use?

About 445 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Deps?

Skills that share tags, products or a category with Update Deps: Cleanup Specialist (ahaodev/shadmin, 174 stars), Shadmin CLI (ahaodev/shadmin, 174 stars), Shadmin Dev (ahaodev/shadmin, 174 stars) and Web Artifacts Builder (anthropics/skills, 180k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Deps?

VinkyDev (a GitHub user) maintains it in VinkyDev/vibestart, which has 103 GitHub stars. The repository was last updated on October 10, 2026.

Source: VinkyDev/vibestart on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.