Agent skill

Dep Refs

by zai-org in zai-org/ZCode

A skill your agent uses when needs to inspect TypeScript export references in the z-code workspace, list exports from a file, verify whether an export is unused before deletion, investigate who…

Apache-2.0Auto-check passedDevelopment

Install Dep Refs

skills CLI
$ npx skills add zai-org/ZCode --skill dep-refs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zai-org/ZCode dep-refs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zai-org/ZCode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dep-refs .claude/skills/dep-refs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dep-refs
GitHub stars
7.6k
Token cost
~552 tokens
SKILL.md length
215 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when needs to inspect TypeScript export references in the z-code workspace, list exports from a file, verify whether an export is unused before deletion, investigate who…

  • Needs to inspect TypeScript export references in the z-code workspace
  • SKILL.md covers Workflow, JSON Mode and Interpreting Results
  • Calls pnpm and jq
  • List exports from a file

What it does

Dep Refs is an agent skill from zai-org/ZCode. Use when needs to inspect TypeScript export references in the z-code workspace, list exports from a file, verify whether an export is unused before deletion, investigate who imports a symbol during refactors, or combine pnpm knip unused-export results with pnpm dep:refs symbol-level reference tracing.

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Refactoring. It works with pnpm and TypeScript. The repository describes itself as: Z.ai's coding agent harness. Powerful, intelligent, extensible. The licence is Apache-2.0.

When your agent uses it

  • Needs to inspect TypeScript export references in the z-code workspace
  • List exports from a file
  • Verify whether an export is unused before deletion
  • Investigate who imports a symbol during refactors

Example prompts

  • “/dep-refs”

What it can do on your machine

Read from SKILL.md and the folder at commit 29628c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dep Refs loads about 552 tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 215 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~552

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zai-org/ZCode at commit 29628c9, republished under its Apache-2.0 licence (© zai-org). 215 words, ~552 tokens.

Download SKILL.mdSave it as .claude/skills/dep-refs/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
dep-refs
description
Use when needs to inspect TypeScript export references in the z-code workspace, list exports from a file, verify whether an export is unused before deletion, investigate who imports a symbol during refactors, or combine pnpm knip unused-export results with pnpm dep:refs symbol-level reference tracing.
disable-model-invocation
true

Dep Refs

Use the repository's pnpm dep:refs CLI to answer symbol-level questions before changing or deleting TypeScript exports. Run commands from the z-code repository root.

Workflow

Start broad when deleting code:

bash
pnpm knip

Use knip to find likely unused exports, then inspect any risky or unclear export with dep:refs:

bash
pnpm dep:refs packages/shared/src/remoteTarget.ts:stripRemoteTargetSecrets

List all exports in a file when the exact symbol name is unknown:

bash
pnpm dep:refs --list-exports packages/shared/src/remoteTarget.ts

Use scoped scans for fast exploration only when the scope is intentionally limited:

bash
pnpm dep:refs --scope packages/services packages/shared/src/remoteTarget.ts:stripRemoteTargetSecrets

Before claiming an export is safe to delete, prefer an unscoped dep:refs run so cross-package callers are not missed.

JSON Mode

Use silent pnpm mode for machine-readable output, because normal pnpm output includes extra banner lines:

bash
pnpm -s dep:refs packages/shared/src/remoteTarget.ts:stripRemoteTargetSecrets --json | jq .

Use JSON when summarizing many symbols, feeding results to jq, or comparing references and reExports counts programmatically.

Interpreting Results

Treat References (0) and Re-exports (0) as "no static references found", not as proof that no dynamic usage exists. The script does not detect dynamic import() paths or string-based references.

If a symbol only appears under Re-exports, trace the outward barrel path before deleting. A re-export can still be part of the public surface even when there are no direct internal imports.

For refactors, report concrete callers with file and line from the CLI output, then decide whether to update callers, preserve the export, or delete it.

© zai-org, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/dep-refs of zai-org/ZCode.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 29628c9

Compare with similar skills

Dep Refs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dep Refs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dep Refs this skillzai-org/ZCode7.6k—~552Automated safety check: PassApache-2.0
Dead Code Removal with Knipshift-editor/shift348—~1.8kAutomated safety check: PassApache-2.0
Tabler Shared Lib Helperstabler/tabler42k—~1.2kAutomated safety check: PassMIT
Link Workspace Packagesnomcopter/react-mosaic4.8k6 repos~760Automated safety check: PassCustom licence
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence
Testing Changespnpm/pnpm37k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Dead Code Removal with Knip

    shift-editor/shift

    Finds unused files, exports and class members with Knip, then verifies each candidate through reference tracing before removing anything, never using knip --fix.

    348 GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Moves logic out of Astro frontmatter into tested helper modules under shared/lib, with rules for naming, typing, deterministic demo data and sibling test files.

    42k GitHub stars~1.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 6 repos~760 tokens
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Run the tests that cover a change in the pnpm repository, in the Rust workspace (pnpm/, pnpr/) or the TypeScript CLI (pnpm11/), and recognize the cases where a scoped run passes without testing…

    37k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Svelte5 Best Practices

    SikandarJODD/cnblocks

    Svelte 5 runes, snippets, SvelteKit patterns, and modern best practices for TypeScript and component development.

    430 GitHub starsUsed in 1 repo~810 tokens
    DevelopmentAuto-check passed

More from zai-org/ZCode

  • Apply the repository's architecture policy to code changes by generating a bounded context package, checking module and layer boundaries, and reporting baseline-aware violations.

    7.6k GitHub stars~1.2k tokensUpdated 10 days ago
    Auto-check passed
  • Map a ZCode behavior change to current UI surfaces, state owners, protocol commands, persistence, and validation.

    7.6k GitHub stars~1.4k tokensUpdated 10 days ago
    Auto-check passed
  • Control Browser

    zai-org/ZCode

    A skill your agent uses when opening, navigating, inspecting, testing, clicking, typing, filling, screenshotting, or verifying web pages and local HTTP targets (localhost, 127.0.0.1, ::1) inside…

    7.6k GitHub stars~4.6k tokensUpdated 10 days ago
    Auto-check passed
  • Dynamic Workflows

    zai-org/ZCode

    A skill your agent uses when writing, debugging, or resubmitting a dynamic-workflow script for the CreateWorkflow tool: choosing subagent topology, typing subagent results, fanning out over files or…

    7.6k GitHub stars~23k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Dep Refs

What does Dep Refs do?

A skill your agent uses when needs to inspect TypeScript export references in the z-code workspace, list exports from a file, verify whether an export is unused before deletion, investigate who…. Dep Refs is an agent skill from zai-org/ZCode. Use when needs to inspect TypeScript export references in the z-code workspace, list exports from a file, verify whether an export is unused before deletion, investigate who imports a symbol during refactors, or combine pnpm knip unused-export results with pnpm dep:refs symbol-level reference tracing.

When should I use Dep Refs?

Dep Refs fits situations like: needs to inspect TypeScript export references in the z-code workspace; list exports from a file; verify whether an export is unused before deletion; investigate who imports a symbol during refactors.

How do I install Dep Refs in Claude Code?

Run `npx skills add zai-org/ZCode --skill dep-refs -a claude-code`. Or copy the skill folder (.agents/skills/dep-refs in zai-org/ZCode) into .claude/skills/dep-refs in your project. Claude Code loads it when a task matches its description.

How do I install Dep Refs in Codex?

Run `npx skills add zai-org/ZCode --skill dep-refs -a codex`. Or copy the skill folder (.agents/skills/dep-refs in zai-org/ZCode) into .agents/skills/dep-refs in your project. Codex loads it when a task matches its description.

Can I use Dep Refs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zai-org/ZCode --skill dep-refs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-refs, .gemini/skills/dep-refs, .github/skills/dep-refs and .opencode/skills/dep-refs in your project.

What does Dep Refs need to run?

Going by SKILL.md and its folder, Dep Refs needs the command-line tools its instructions call (pnpm and jq).

Does Dep Refs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dep Refs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dep Refs use?

Dep Refs is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dep Refs use?

About 552 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dep Refs?

Skills that share tags, products or a category with Dep Refs: Dead Code Removal with Knip (shift-editor/shift, 348 stars), Tabler Shared Lib Helpers (tabler/tabler, 42k stars), Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars) and Pnpm Engine (teambit/bit, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dep Refs?

zai-org (a GitHub organization) maintains it in zai-org/ZCode, which has 7,572 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 29, 2026.

Source: zai-org/ZCode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.