Skip to content
Back to skills

Dependency Tooling

ASecurity

Manage application dependencies, build tooling, upgrades, and package configuration using ecosystem-agnostic principles.

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentsapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 2, 2026

npx -y skills add soden46/engineer-flow --skill dependency-tooling --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Dependency Tooling?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Dependency Tooling
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/soden46-dependency-tooling/badge)](https://www.skillsdirectory.com/skills/soden46-dependency-tooling)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: dependency-tooling
description: Manage application dependencies, build tooling, upgrades, and package configuration using ecosystem-agnostic principles.
metadata:
  internal: true
---

# dependency-tooling

Use this skill for dependency installation, removal, upgrades, build tooling, package configuration, and runtime compatibility.

## Principles

Use the project's existing package manager and lockfile conventions.

Before changing a dependency consider:

- compatibility
- supported runtime versions
- transitive dependencies
- security
- maintenance status
- migration requirements

Avoid unnecessary dependencies when existing stack capabilities are sufficient.

Keep lockfiles consistent with declared dependencies.

For major upgrades:

1. identify breaking changes
2. identify deprecated APIs
3. update incrementally when practical
4. run relevant tests
5. verify build/runtime behavior

Do not assume the newest package version is compatible with the project.

## Adaptation

Use project evidence to determine the actual language, framework, runtime, and existing conventions.

When stack-specific implementation guidance is needed, prefer project evidence, native framework or language mechanisms, and relevant user-installed specialist skills. Technology-specific guidance must not redefine or weaken the core engineering requirement.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…