Our review
This skill automates dependency management, version conflict resolution, and security audits across npm, pip, Maven, Cargo, and Go modules.
Strengths
- Multi-ecosystem support with automatic package manager detection.
- Structured security audits with a table of vulnerabilities and recommended fixes.
- Batch updates by severity or ecosystem to minimize risk.
Limitations
- Does not handle application code fixes resulting from breaking changes.
- May require manual adjustments for complex setups (monorepos, private registries).
- Audit tools may produce false positives or negatives.
Use this skill to update dependencies, resolve version conflicts, or audit for security vulnerabilities.
Avoid this skill if the primary task involves writing or refactoring application code unrelated to dependencies.
Security analysis
SafeThe skill uses standard package manager audit tools (npm audit, pip-audit, cargo audit, govulncheck) via Bash, which are read-only and non-destructive. No dangerous patterns like curl-pipe-shell, arbitrary file deletion, or exfiltration are present. The allowed tools (Read, Write, Bash, Grep, Glob) are appropriate for dependency management and do not introduce unusual risk.
No concerns found
Examples
Update all npm dependencies to their latest version, checking for breaking changes.Audit my Python project for security vulnerabilities using pip-audit and generate a report.Check for version conflicts in my Go module and resolve them.name: dependency-specialist description: Dependency management, version conflict resolution, security patch updates, and supply chain hygiene across npm, pip, Maven, Cargo, and Go modules. Use when asked to update dependencies, resolve a version conflict, audit for vulnerabilities, set up Dependabot or Renovate, fix a broken lock file, or evaluate whether to add or remove a package. allowed-tools:
- Read
- Write
- Bash
- Grep
- Glob
metadata:
author: Daryl Lundy
version: 2.0.0
category: operations
tags:
- dependencies
- npm
- pip
- maven
- cargo
- go-modules
- renovate
- dependabot
- security
Dependency Specialist
Activation criteria
- User language explicitly matches trigger phrases such as
update dependencies,version conflict,npm audit. - The requested work fits this skill's lane: Updating dependencies, resolving conflicts, security audits, Renovate/Dependabot setup.
- The task stays inside this skill's boundary and avoids adjacent areas called out as out of scope: Application code changes caused by breaking dependency updates.
First actions
Glob('**/package.json', '**/requirements.txt', '**/Pipfile', '**/go.mod', '**/Cargo.toml', '**/pom.xml', '**/build.gradle')— identify package manager(s) in useReadthe manifest file and lock file (package-lock.json, Pipfile.lock, go.sum, etc.)- For security audits: run
npm audit,pip-audit,cargo audit, orgovulncheckdepending on ecosystem
Decision rules
- For security vulnerabilities: fix CRITICAL and HIGH first; document MEDIUM/LOW for backlog
- For major version updates: check changelog for breaking changes before upgrading; update one major dependency at a time
- If a lock file is missing: generate it before making any other changes
- For supply chain: prefer packages with active maintenance (recent commits, responsive maintainers)
Output contract
- For security audits: structured table — Package | Version | CVE | Severity | Fix Version | Status
- For updates: exact commands to run; note any breaking changes that require code changes
Constraints
- NEVER update all dependencies in one commit — update in batches by severity or ecosystem
- Scope boundary: fixing breaking changes in application code after a dependency update belongs to the relevant language/framework skill
Reference
references/legacy-agent.md: package manager reference, CVE tracking, automated update tools, monorepo dependency management
Docker Compose Architect
DevOps
Designs optimized Docker Compose configurations.
Incident Postmortem Writer
DevOps
Writes structured and blameless incident postmortem reports.
Runbook Creator
DevOps
Creates clear operational runbooks for common DevOps procedures.