Link Workspace Packages
nomcopter/react-mosaic
Link workspace packages in monorepos (npm, yarn, pnpm, bun).
Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects.
$ npx skills add yowainwright/pastoralist --skill pastoralist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yowainwright/pastoralist pastoralist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yowainwright/pastoralist.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pastoralist .claude/skills/pastoralist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pastoralist" agent skill from https://github.com/yowainwright/pastoralist/tree/main/skills/pastoralist into .claude/skills/pastoralist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pastoralist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yowainwright/pastoralist/tree/main/skills/pastoralistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yowainwright/pastoralist --skill pastoralist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yowainwright/pastoralist pastoralist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yowainwright/pastoralist.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/pastoralist .agents/skills/pastoralist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pastoralist" agent skill from https://github.com/yowainwright/pastoralist/tree/main/skills/pastoralist into .agents/skills/pastoralist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pastoralist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yowainwright/pastoralist --skill pastoralist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yowainwright/pastoralist pastoralist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yowainwright/pastoralist.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/pastoralist .cursor/skills/pastoralist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pastoralist" agent skill from https://github.com/yowainwright/pastoralist/tree/main/skills/pastoralist into .cursor/skills/pastoralist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pastoralist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yowainwright/pastoralist.git --path skills/pastoralist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yowainwright/pastoralist --skill pastoralist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yowainwright/pastoralist pastoralist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yowainwright/pastoralist.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/pastoralist .gemini/skills/pastoralist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pastoralist" agent skill from https://github.com/yowainwright/pastoralist/tree/main/skills/pastoralist into .gemini/skills/pastoralist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pastoralist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yowainwright/pastoralist pastoralistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yowainwright/pastoralist --skill pastoralist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yowainwright/pastoralist.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/pastoralist .github/skills/pastoralist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pastoralist" agent skill from https://github.com/yowainwright/pastoralist/tree/main/skills/pastoralist into .github/skills/pastoralist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pastoralist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yowainwright/pastoralist --skill pastoralist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yowainwright/pastoralist pastoralist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yowainwright/pastoralist.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/pastoralist .opencode/skills/pastoralist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pastoralist" agent skill from https://github.com/yowainwright/pastoralist/tree/main/skills/pastoralist into .opencode/skills/pastoralist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pastoralist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pastoralistSet up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects.
Pastoralist is an agent skill from yowainwright/pastoralist. Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects. Use for Pastoralist onboarding, override maintenance, install hooks, agent skills, or CI checks involving overrides, resolutions, pnpm-workspace.yaml, or the appendix.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Monorepo tooling. It works with pnpm and npm. The repository describes itself as: A CLI for automatically shepherding package.json overrides 👩🏽🌾. The licence is MIT.
Read from SKILL.md and the folder at commit 1d7ff5f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmnpxnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, npx and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pastoralist loads about 1.5k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 537 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yowainwright/pastoralist at commit 1d7ff5f, republished under its MIT licence (© yowainwright). 537 words, ~1,488 tokens.
.claude/skills/pastoralist/SKILL.md (or your agent's skills folder).Pastoralist manages the reasons for dependency overrides. The package manager still installs the dependencies.
overrides, Yarn resolutions, or pnpm
overrides in pnpm-workspace.yaml (legacy package.json#pnpm.overrides is supported).pastoralist.appendix.Read package.json, its scripts, lockfile, workspace settings, and any existing
Pastoralist config first. Use the project's package manager; do not replace its
lockfile or overwrite existing hooks. Pastoralist requires Node >=20.19.0.
For pnpm, run from the project root:
pnpm add -D pastoralist
pnpm exec pastoralist doctor
pnpm exec pastoralist --dry-run
pnpm exec pastoralistUse pnpm add -Dw pastoralist when installing at a pnpm workspace root. For npm,
use npm install -D pastoralist and npx pastoralist. Use the equivalent local
CLI runner for Yarn or Bun. For a one-off preview before installing, use
npx pastoralist doctor.
Basic tracking needs no config wizard. Run pastoralist init interactively
when workspace paths, an external config, or security defaults need configuring.
Config belongs under package.json#pastoralist, or as top-level settings in
.pastoralistrc, .pastoralistrc.json, pastoralist.json, or pastoralist.config.*.
Optional setup, using the installed CLI:
pnpm exec pastoralist --setup-hook --dry-run
pnpm exec pastoralist --setup-hook
pnpm exec pastoralist init agent-skill --dry-run
pnpm exec pastoralist init agent-skillThe hook appends pastoralist to postinstall, preserving an existing script.
The skill installs at .agents/skills/pastoralist/SKILL.md; an existing unmanaged
skill is left alone. setup:local-dev is for developing Pastoralist itself,
not a prerequisite in consumer projects.
Commands below use pastoralist as shorthand for the installed CLI runner above.
| Task | Command | Effect |
|---|---|---|
| Inspect setup and overrides | pastoralist doctor | Dry-run with summary |
| Preview tracking changes | pastoralist --dry-run | No project writes |
| Refresh the appendix | pastoralist | Writes tracking data |
| Preview stale override removal | pastoralist --remove-unused --dry-run | Review before removing |
| Remove reviewed unused overrides | pastoralist --remove-unused | Writes overrides and appendix |
| Inspect security findings | pastoralist --checkSecurity --dry-run --securityProvider osv --strict | Scan without applying fixes |
| Gate CI on security findings | pastoralist --checkSecurity --dry-run --securityProvider osv --strict --quiet --no-cache | Exit 1 on findings or provider errors |
--checkSecurity alone can update tracking data: include --dry-run for a preview.
OSV needs no token. Keep other provider credentials in environment variables.
Use --outputFormat json for machine-readable output; check the process exit
status and reported findings, not just whether the scan completed.
When automatic security fixes are requested:
pnpm exec pastoralist --checkSecurity --forceSecurityRefactor --securityProvider osv --strict
pnpm install --no-frozen-lockfile
pnpm exec pastoralist --checkSecurity --dry-run --securityProvider osv --strict --quiet --no-cacheReview the override, appendix, and lockfile diff, then run the project's checks. A successful fix command does not prove the installed dependency tree is clean: the final scan must run after installation. Fixes may be unavailable or require a direct dependency update. Report remaining findings rather than bypassing CI.
Use --root <project-directory> to target another project. For independently
locked packages such as a docs app, repeat the cycle in that package. Add
--hasWorkspaceSecurityChecks when workspace packages must be included.
For GitHub Actions, the existing yowainwright/pastoralist@v1 action supports
mode: check. Follow the repository's install and security policy.
When best-case selection conflicts with an override the user controls, show its
active version and appendix ledger addedDate. Ask whether it should be
user-owned; the date alone does not establish ownership. Persist approved names
in pastoralist.bestCase.userOwnedOverrides. The active override supplies the
required version. Re-run security checks with those versions as hard constraints.
Finish with changed files, verification results, and any remaining findings.
© yowainwright, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/pastoralist of yowainwright/pastoralist.
Open the folder on GitHubat commit 1d7ff5f
Pastoralist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pastoralist this skillyowainwright/pastoralist | 109 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Link Workspace Packagesnomcopter/react-mosaic | 4.8k | 6 repos | ~760 | Automated safety check: Pass | Custom licence | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| TS SDK Authormindfold-ai/Trellis | 15k | — | ~6.1k | Automated safety check: Pass | MIT | |
| Monorepo Tooling and Dependenciespierrecomputer/pierre | 6.3k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| ReleaseWebMCP-org/npm-packages | 104 | — | ~1.6k | Automated safety check: Notes | MIT |
nomcopter/react-mosaic
Link workspace packages in monorepos (npm, yarn, pnpm, bun).
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
mindfold-ai/Trellis
Design, build, verify, and publish production-grade TypeScript SDKs as npm packages inside a pnpm monorepo.
pierrecomputer/pierre
Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.
WebMCP-org/npm-packages
Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.
ChatbotXIO/ChatbotX
Manage turborepo monorepo development workflow including dev servers, builds, linting, and package management.
Categories
Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects. Pastoralist is an agent skill from yowainwright/pastoralist. Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects.
Pastoralist fits situations like: pastoralist onboarding; override maintenance; CI checks involving overrides; pnpm-workspace.yaml.
Run `npx skills add yowainwright/pastoralist --skill pastoralist -a claude-code`. Or copy the skill folder (skills/pastoralist in yowainwright/pastoralist) into .claude/skills/pastoralist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yowainwright/pastoralist --skill pastoralist -a codex`. Or copy the skill folder (skills/pastoralist in yowainwright/pastoralist) into .agents/skills/pastoralist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yowainwright/pastoralist --skill pastoralist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pastoralist, .gemini/skills/pastoralist, .github/skills/pastoralist and .opencode/skills/pastoralist in your project.
Going by SKILL.md and its folder, Pastoralist needs the command-line tools its instructions call (pnpm, npx and npm). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pastoralist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pastoralist: Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), TS SDK Author (mindfold-ai/Trellis, 15k stars) and Monorepo Tooling and Dependencies (pierrecomputer/pierre, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yowainwright (a GitHub user) maintains it in yowainwright/pastoralist, which has 109 GitHub stars. The repository was last updated on October 6, 2026.
Source: yowainwright/pastoralist on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.