Skip to content
Back to skills

Project Vendor Boundary

ASecurity

Overlay for app-owned versus vendored dependency boundaries. Portable across repos that vendor third-party code. Use when work touches vendored dependencies or their integration seam.

  • 4 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 28, 2026
ai-agents

Security analysis

A100/100

Scanned May 28, 2026

npx -y skills add n-n-code/n-n-code-skills --skill project-vendor-boundary --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Project Vendor Boundary?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Project Vendor Boundary
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/n-n-code-project-vendor-boundary/badge)](https://www.skillsdirectory.com/skills/n-n-code-project-vendor-boundary)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: project-vendor-boundary
description: Overlay for app-owned versus vendored dependency boundaries. Portable across repos that vendor third-party code. Use when work touches vendored dependencies or their integration seam.
---

# Project Vendor Boundary

This is a composable overlay, not a standalone workflow.
Use alongside the repo's implementation skill when work touches vendored
dependencies or their integration boundary.

## When to use

The change involves vendored third-party code, the boundary between app-owned
and vendored code, or dependency integration (subtrees, vendor directories,
copied sources).

## Not for

App-owned code that does not touch vendor boundaries (use the implementation
skill directly), or release/packaging concerns (use **project-release-maintainer**).

## Rules

- prefer app-side integration changes before editing vendored code
- treat vendored code as subtree/vendor content, not normal project code
- keep notices, provenance, upstream version/source, local patch rationale, and
  install rules aligned with vendor changes
- prefer adapter or wrapper changes in app-owned code before patching vendored
  sources; patch vendor code only when the seam cannot reasonably absorb the
  change
- avoid unrelated churn inside vendor trees

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…