Validator Dependency Upgrade
express-validator/express-validator
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
A skill your agent uses when validating package versions, checking for outdated dependencies, or evaluating third-party libraries in any ecosystem.
$ npx skills add WrongStack/WrongStack --skill tech-stack -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install WrongStack/WrongStack tech-stack --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/tech-stack .claude/skills/tech-stack && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tech-stack" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/tech-stack into .claude/skills/tech-stack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tech-stack", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/tech-stackType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add WrongStack/WrongStack --skill tech-stack -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install WrongStack/WrongStack tech-stack --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/core/skills/tech-stack .agents/skills/tech-stack && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tech-stack" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/tech-stack into .agents/skills/tech-stack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tech-stack", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill tech-stack -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install WrongStack/WrongStack tech-stack --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/core/skills/tech-stack .cursor/skills/tech-stack && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tech-stack" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/tech-stack into .cursor/skills/tech-stack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tech-stack", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/WrongStack/WrongStack.git --path packages/core/skills/tech-stack--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add WrongStack/WrongStack --skill tech-stack -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install WrongStack/WrongStack tech-stack --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/core/skills/tech-stack .gemini/skills/tech-stack && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tech-stack" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/tech-stack into .gemini/skills/tech-stack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tech-stack", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install WrongStack/WrongStack tech-stackInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add WrongStack/WrongStack --skill tech-stack -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/core/skills/tech-stack .github/skills/tech-stack && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tech-stack" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/tech-stack into .github/skills/tech-stack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tech-stack", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill tech-stack -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install WrongStack/WrongStack tech-stack --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/core/skills/tech-stack .opencode/skills/tech-stack && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tech-stack" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/tech-stack into .opencode/skills/tech-stack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tech-stack", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tech-stackA skill your agent uses when validating package versions, checking for outdated dependencies, or evaluating third-party libraries in any ecosystem.
Tech Stack is an agent skill from WrongStack/WrongStack. Use this skill when validating package versions, checking for outdated dependencies, or evaluating third-party libraries in any ecosystem. Triggers: user says "dependency", "package version", "outdated", "npm audit", "deprecated package", "tech stack".
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SKILL.save.md`).
It sits in Development, covering Dependency management. It works with npm. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmpipcargogogemdotnetcomposerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tech Stack loads about 2k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 783 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 783 words, ~2,016 tokens.
.claude/skills/tech-stack/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Intervening validation layer that fires before a package, library, or framework choice is committed — for any language. Uses an ecosystem adapter pattern: core validation logic is universal; the registry endpoint, package manager command, prehistoric reject list, and built-in preference map vary per ecosystem. Runs as a single-shot delegate — fast, read-only, fire-and-forget.
Detect the ecosystem first. Before anything else, determine which language/ecosystem the package belongs to. Two strategies, tried in order:
requests to our Python project")package.json (js), tsconfig.json (ts) → JavaScript/TypeScriptpyproject.toml, setup.py, setup.cfg, requirements.txt → PythonCargo.toml → Rustgo.mod → GoGemfile → Ruby*.csproj, *.fsproj, packages.config → .NETcomposer.json → PHPmix.exs → Elixirpom.xml, build.gradle → Java/JVMpackage.json is present, otherwise ask.Verify existence. Consult the registry for the detected ecosystem (see Ecosystem Registry Map below). Fetch the package endpoint. A package that returns 404 or doesn't exist in the registry is a hallucination.
Check latest version. Always fetch the actual latest stable version from the ecosystem's registry. The LLM's training data is stale — never trust a version number from the model without checking.
Reject dead packages. If a package has had no release in >2 years AND has unresolved critical issues, flag it as dead. Suggest a maintained replacement. Registry-specific dead signals:
"deprecated" field, archived GitHub repoDevelopment Status :: 7 - Inactive classifier"version": null for yanked, archived repolisted: falseReject prehistoric technology. Any package/library/pattern that was superseded ≥5 years ago is automatically rejected. Use the per-ecosystem built-in preference map below before greenlighting any third-party dependency.
Prefer built-in over third-party. Every modern language runtime ships standard library that obsoletes packages. Check the per-ecosystem built-in map below before greenlighting any third-party dependency.
Single-shot budget. This agent is not for deep analysis — it should complete in 1–2 iterations. Detect → search registry → verify → report. Do not recursively analyze transitive dependencies.
The central dispatch table. When verifying a package, use the adapter for the detected ecosystem:
| ID | Language | Registry Host | Path Template | Version Field | Package Manager | Install Command |
|---|---|---|---|---|---|---|
js | JavaScript/TS | registry.npmjs.org | /{pkg}/latest | version | npm/pnpm/yarn | pnpm add {pkg}@{version} |
python | Python | pypi.org | /pypi/{pkg}/json | info.version | pip/poetry/uv | pip install {pkg}=={version} |
rust | Rust | crates.io | /api/v1/crates/{pkg} | crate.max_stable_version | cargo | cargo add {pkg}@{major} |
go | Go | proxy.golang.org | /{pkg}/@latest | (plain text) | go | go get {pkg}@{version} |
ruby | Ruby | rubygems.org | /api/v1/gems/{pkg}.json | version | bundler | gem "{pkg}", "~> {major}.{minor}" |
dotnet | .NET | api.nuget.org | /v3/registration5-gz-semver2/{pkg_lower}/index.json | items[0].upper | dotnet | dotnet add package {pkg} --version {version} |
php | PHP | repo.packagist.org | /p2/{vendor}/{pkg}.json | packages[..].0.version | composer | composer require {vendor}/{pkg}:^{major}.{minor} |
elixir | Elixir | hex.pm | /api/packages/{pkg} | releases[0].version | mix | {:pkg, "~> {major}.{minor}"} (add to mix.exs) |
jvm | Java/JVM | search.maven.org | /solrsearch/select?q=g:{group}+AND+a:{artifact}&rows=1&wt=json | response.docs[0].latestVersion | maven/gradle | implementation '{group}:{artifact}:{version}' |
### Tech Stack Validation — <package>
**Ecosystem**: <detected ecosystem>
**Status**: APPROVED | REJECTED | NEEDS_INVESTIGATION
**Package**: <name>@<version>
**Registry**: <host + URL fetched>
**Age**: <first release year> — <last release date>
**Verdict**: 1–2 sentence explanation.
When REJECTED:
**"This isn't code, this is X-year-old technology."**
**Replaced by**: <modern alternative>
**Migration**: <one concrete step>
When APPROVED:
**Install**: `<ecosystem install command>`
**Note**: <any caveats about the version, semver range, or compatibility>
<nextsteps>
1. Add <package>@<version> to the project auto="true"
</nextsteps>package.json is present and nothing else is.security-scanner's lane. This skill validates existence, version, and deprecation — not vulnerability surface.deprecated, yanked, archived)node-modern — for Node.js built-in vs. third-party decisionsreact-modern — for React version checkstypescript-strict — for TypeScript version alignmentsecurity-scanner — for packages with known CVEsdocker-deploy — for base image version pinningoutput-standards — for standardized <nextsteps> formatting© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in packages/core/skills/tech-stack of WrongStack/WrongStack.
Open the folder on GitHubat commit 57f6018
Tech Stack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tech Stack this skillWrongStack/WrongStack | 370 | — | ~2k | Automated safety check: Pass | MIT | |
| Validator Dependency Upgradeexpress-validator/express-validator | 6.2k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Claude Code Version Checkykdojo/claude-code-tips | 10k | — | ~1.8k | Automated safety check: Pass | Custom licence | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| RStudio Electron Version Updaterstudio/rstudio | 5.1k | — | ~964 | Automated safety check: Pass | Custom licence | |
| Aube Package Manager Helperaubepkg/aube | 2k | — | ~1.1k | Automated safety check: Warn | MIT |
express-validator/express-validator
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
ykdojo/claude-code-tips
Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
rstudio/rstudio
Bumps the pinned Electron version across the RStudio repository, updating NEWS.md, package.json, the lockfile and the allowScripts entry.
aubepkg/aube
Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.
livesession/xyd
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
WrongStack/WrongStack
Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.
WrongStack/WrongStack
A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…
WrongStack/WrongStack
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
WrongStack/WrongStack
A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.
WrongStack/WrongStack
Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…
WrongStack/WrongStack
A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…
Works with
Categories
A skill your agent uses when validating package versions, checking for outdated dependencies, or evaluating third-party libraries in any ecosystem. Tech Stack is an agent skill from WrongStack/WrongStack. Use this skill when validating package versions, checking for outdated dependencies, or evaluating third-party libraries in any ecosystem.
Tech Stack fits situations like: validating package versions; checking for outdated dependencies; evaluating third-party libraries in any ecosystem.
Run `npx skills add WrongStack/WrongStack --skill tech-stack -a claude-code`. Or copy the skill folder (packages/core/skills/tech-stack in WrongStack/WrongStack) into .claude/skills/tech-stack in your project. Claude Code loads it when a task matches its description.
Run `npx skills add WrongStack/WrongStack --skill tech-stack -a codex`. Or copy the skill folder (packages/core/skills/tech-stack in WrongStack/WrongStack) into .agents/skills/tech-stack in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill tech-stack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tech-stack, .gemini/skills/tech-stack, .github/skills/tech-stack and .opencode/skills/tech-stack in your project.
Going by SKILL.md and its folder, Tech Stack needs the command-line tools its instructions call (pnpm, pip, cargo, go, gem and dotnet). Our summary lists: Python 3; Node.js; Docker.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Tech Stack is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Tech Stack: Validator Dependency Upgrade (express-validator/express-validator, 6.2k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and RStudio Electron Version Update (rstudio/rstudio, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.
Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.