Agent skill

Pastoralist

by yowainwright in yowainwright/pastoralist

Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects.

MITAuto-check passedDevelopment

Install Pastoralist

skills CLI
$ npx skills add yowainwright/pastoralist --skill pastoralist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yowainwright/pastoralist pastoralist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yowainwright/pastoralist.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pastoralist .claude/skills/pastoralist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pastoralist
GitHub stars
109
Token cost
~1.5k tokens
SKILL.md length
537 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects.

  • Pastoralist onboarding
  • SKILL.md covers Understand it in 30 seconds, Set up a project, Choose the task and Fix, install, verify, plus 1 more section
  • Calls pnpm, npx and npm
  • Override maintenance

What it does

Pastoralist is an agent skill from yowainwright/pastoralist. Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects. Use for Pastoralist onboarding, override maintenance, install hooks, agent skills, or CI checks involving overrides, resolutions, pnpm-workspace.yaml, or the appendix.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Monorepo tooling. It works with pnpm and npm. The repository describes itself as: A CLI for automatically shepherding package.json overrides 👩🏽🌾. The licence is MIT.

When your agent uses it

  • Pastoralist onboarding
  • Override maintenance
  • CI checks involving overrides
  • Pnpm-workspace.yaml

Example prompts

  • “/pastoralist”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 1d7ff5f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npx
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, npx and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pastoralist loads about 1.5k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 537 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yowainwright/pastoralist at commit 1d7ff5f, republished under its MIT licence (© yowainwright). 537 words, ~1,488 tokens.

Download SKILL.mdSave it as .claude/skills/pastoralist/SKILL.md (or your agent's skills folder).
name
pastoralist
description
Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects. Use for Pastoralist onboarding, override maintenance, install hooks, agent skills, or CI checks involving overrides, resolutions, pnpm-workspace.yaml, or the appendix.

Pastoralist

Understand it in 30 seconds

Pastoralist manages the reasons for dependency overrides. The package manager still installs the dependencies.

  • Overrides choose versions: npm/Bun overrides, Yarn resolutions, or pnpm overrides in pnpm-workspace.yaml (legacy package.json#pnpm.overrides is supported).
  • Appendix records dependents and a ledger of dates, reasons, and security evidence under pastoralist.appendix.
  • Lockfile records resolved versions. After changing overrides, run the project's package manager to update it. Pastoralist does not run that install.

Set up a project

Read package.json, its scripts, lockfile, workspace settings, and any existing Pastoralist config first. Use the project's package manager; do not replace its lockfile or overwrite existing hooks. Pastoralist requires Node >=20.19.0.

For pnpm, run from the project root:

sh
pnpm add -D pastoralist
pnpm exec pastoralist doctor
pnpm exec pastoralist --dry-run
pnpm exec pastoralist

Use pnpm add -Dw pastoralist when installing at a pnpm workspace root. For npm, use npm install -D pastoralist and npx pastoralist. Use the equivalent local CLI runner for Yarn or Bun. For a one-off preview before installing, use npx pastoralist doctor.

Basic tracking needs no config wizard. Run pastoralist init interactively when workspace paths, an external config, or security defaults need configuring. Config belongs under package.json#pastoralist, or as top-level settings in .pastoralistrc, .pastoralistrc.json, pastoralist.json, or pastoralist.config.*.

Optional setup, using the installed CLI:

sh
pnpm exec pastoralist --setup-hook --dry-run
pnpm exec pastoralist --setup-hook
pnpm exec pastoralist init agent-skill --dry-run
pnpm exec pastoralist init agent-skill

The hook appends pastoralist to postinstall, preserving an existing script. The skill installs at .agents/skills/pastoralist/SKILL.md; an existing unmanaged skill is left alone. setup:local-dev is for developing Pastoralist itself, not a prerequisite in consumer projects.

Choose the task

Commands below use pastoralist as shorthand for the installed CLI runner above.

TaskCommandEffect
Inspect setup and overridespastoralist doctorDry-run with summary
Preview tracking changespastoralist --dry-runNo project writes
Refresh the appendixpastoralistWrites tracking data
Preview stale override removalpastoralist --remove-unused --dry-runReview before removing
Remove reviewed unused overridespastoralist --remove-unusedWrites overrides and appendix
Inspect security findingspastoralist --checkSecurity --dry-run --securityProvider osv --strictScan without applying fixes
Gate CI on security findingspastoralist --checkSecurity --dry-run --securityProvider osv --strict --quiet --no-cacheExit 1 on findings or provider errors

--checkSecurity alone can update tracking data: include --dry-run for a preview. OSV needs no token. Keep other provider credentials in environment variables. Use --outputFormat json for machine-readable output; check the process exit status and reported findings, not just whether the scan completed.

Show full SKILL.md (170 more words)Show less

Fix, install, verify

When automatic security fixes are requested:

sh
pnpm exec pastoralist --checkSecurity --forceSecurityRefactor --securityProvider osv --strict
pnpm install --no-frozen-lockfile
pnpm exec pastoralist --checkSecurity --dry-run --securityProvider osv --strict --quiet --no-cache

Review the override, appendix, and lockfile diff, then run the project's checks. A successful fix command does not prove the installed dependency tree is clean: the final scan must run after installation. Fixes may be unavailable or require a direct dependency update. Report remaining findings rather than bypassing CI.

Use --root <project-directory> to target another project. For independently locked packages such as a docs app, repeat the cycle in that package. Add --hasWorkspaceSecurityChecks when workspace packages must be included.

For GitHub Actions, the existing yowainwright/pastoralist@v1 action supports mode: check. Follow the repository's install and security policy.

Preserve deliberate overrides

When best-case selection conflicts with an override the user controls, show its active version and appendix ledger addedDate. Ask whether it should be user-owned; the date alone does not establish ownership. Persist approved names in pastoralist.bestCase.userOwnedOverrides. The active override supplies the required version. Re-run security checks with those versions as hard constraints.

Finish with changed files, verification results, and any remaining findings.

© yowainwright, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/pastoralist of yowainwright/pastoralist.

Open the folder on GitHubat commit 1d7ff5f

Compare with similar skills

Pastoralist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pastoralist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pastoralist this skillyowainwright/pastoralist109—~1.5kAutomated safety check: PassMIT
Link Workspace Packagesnomcopter/react-mosaic4.8k6 repos~760Automated safety check: PassCustom licence
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
TS SDK Authormindfold-ai/Trellis15k—~6.1kAutomated safety check: PassMIT
Monorepo Tooling and Dependenciespierrecomputer/pierre6.3k—~1.1kAutomated safety check: PassApache-2.0
ReleaseWebMCP-org/npm-packages104—~1.6kAutomated safety check: NotesMIT

Similar skills

  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 6 repos~760 tokens
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • TS SDK Author

    mindfold-ai/Trellis

    Design, build, verify, and publish production-grade TypeScript SDKs as npm packages inside a pnpm monorepo.

    15k GitHub stars~6.1k tokensUpdated 11 days ago
    DevelopmentAuto-check passed
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.3k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release

    WebMCP-org/npm-packages

    Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

    104 GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Turborepo Workflow

    ChatbotXIO/ChatbotX

    Manage turborepo monorepo development workflow including dev servers, builds, linting, and package management.

    885 GitHub stars~880 tokensUpdated yesterday
    DevelopmentAuto-check: notes

Works with

Categories

Questions about Pastoralist

What does Pastoralist do?

Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects. Pastoralist is an agent skill from yowainwright/pastoralist. Set up and use Pastoralist to explain dependency overrides, find stale overrides, scan vulnerabilities, and apply security fixes in npm, pnpm, Yarn, or Bun projects.

When should I use Pastoralist?

Pastoralist fits situations like: pastoralist onboarding; override maintenance; CI checks involving overrides; pnpm-workspace.yaml.

How do I install Pastoralist in Claude Code?

Run `npx skills add yowainwright/pastoralist --skill pastoralist -a claude-code`. Or copy the skill folder (skills/pastoralist in yowainwright/pastoralist) into .claude/skills/pastoralist in your project. Claude Code loads it when a task matches its description.

How do I install Pastoralist in Codex?

Run `npx skills add yowainwright/pastoralist --skill pastoralist -a codex`. Or copy the skill folder (skills/pastoralist in yowainwright/pastoralist) into .agents/skills/pastoralist in your project. Codex loads it when a task matches its description.

Can I use Pastoralist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yowainwright/pastoralist --skill pastoralist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pastoralist, .gemini/skills/pastoralist, .github/skills/pastoralist and .opencode/skills/pastoralist in your project.

What does Pastoralist need to run?

Going by SKILL.md and its folder, Pastoralist needs the command-line tools its instructions call (pnpm, npx and npm). Our summary lists: Node.js.

Does Pastoralist access the network?

SKILL.md contains no URLs. Its commands use npx and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pastoralist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pastoralist use?

Pastoralist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pastoralist use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pastoralist?

Skills that share tags, products or a category with Pastoralist: Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), TS SDK Author (mindfold-ai/Trellis, 15k stars) and Monorepo Tooling and Dependencies (pierrecomputer/pierre, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pastoralist?

yowainwright (a GitHub user) maintains it in yowainwright/pastoralist, which has 109 GitHub stars. The repository was last updated on October 6, 2026.

Source: yowainwright/pastoralist on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.