Safely plan and execute JavaScript/TypeScript dependency maintenance across npm and pnpm repositories, including npm lockfiles, pnpm workspaces, catalogs, overrides, release-age policies, audits, CI validation, Dependabot boundaries, PRs, and GitHub tracking issues. Use whenever the user asks to update, bump, refresh, audit, clean, modernize, or review dependencies, reduce vulnerabilities, clean overrides, or prepare dependency PRs/issues.
92
92%
Does it follow best practices?
Impact
89%
1.00xAverage score across 3 eval scenarios
Advisory
Suggest reviewing before use
npm repo dependency refresh with override cleanup
npm-only tooling
100%
100%
No audit fix --force
100%
100%
Lockfile-only install
33%
22%
Candidate triage documented
100%
100%
Release-age cutoff documented
50%
50%
Peer dependency inspection
62%
37%
Version style preserved
100%
100%
Override justification
100%
100%
Audit before/after
100%
100%
Validation commands listed
100%
100%
Blocked items documented
100%
100%
Single draft PR scope
100%
100%
pnpm monorepo with catalog and release-age policy
pnpm-only tooling
100%
100%
Catalog updated first
100%
100%
catalog: references preserved
100%
100%
minimumReleaseAge as minutes
100%
100%
minimumReleaseAgeExclude honored
100%
100%
Skipped versions with timestamps
100%
100%
Override staleness check
100%
100%
Filtered monorepo validation
100%
100%
Audit before/after
100%
100%
Deferred major tracking
50%
100%
pnpm install for lockfile
100%
100%
Candidate triage present
100%
100%
Major upgrade tracking issues and override cleanup
Major not in PR
100%
100%
chore(deps) title format
0%
0%
Tracking issue has required sections
83%
83%
Audit-only blocked item tracked
100%
100%
No broad transitive override for express
100%
100%
Override staleness assessed
100%
100%
Override removal justified
100%
100%
Kept overrides documented
90%
80%
pr-summary references tracking issues
100%
100%
Audit posture in PR summary
62%
50%
Safe updates applied
100%
100%
8ff65cd
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.