repo-dependency-review

Detect and document repository dependency and supply-chain surfaces for human review.

4|1|Updated Feb 3, 2026
One-click install
npx skills add https://github.com/danielbaustin/agent-design-language --skill repo-dependency-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: repo-dependency-review
Source: https://github.com/danielbaustin/agent-design-language/tree/main/adl/tools/skills/repo-dependency-review
Command: npx skills add https://github.com/danielbaustin/agent-design-language --skill repo-dependency-review

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Review repository dependencies and supply-chain surfaces to detect drift, licensing cues, and configuration anomalies without performing upgrades or edits.

Core Features & Use Cases

  • Surface manifests, lockfiles, CI workflows, Docker and toolchain configurations for review
  • Identify dependency drift, floating versions, and license-attribution cues for human follow-up
  • Integrate with CodeBuddy-style packets to produce a findings-first specialty artifact for synthesis

Quick Start

Provide bounded, findings-first dependency and supply-chain review from a CodeBuddy packet.

Frequently Asked Questions about repo-dependency-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review repository dependencies and supply-chain surfaces without upgrading code?

Review repository dependencies by detecting and documenting manifests, lockfiles, CI, Docker, and toolchain configurations to identify drift and licensing cues without performing upgrades or edits.

What is a dependency surface map for supply-chain review?

A dependency surface map documents repository dependency surfaces including manifests, lockfiles, CI workflows, and Docker configurations to support human review and produce a findings-first artifact for synthesis.

How do I detect dependency drift and floating versions in lockfiles and manifests?

Detect dependency drift by surfacing manifests and lockfiles to identify floating versions, configuration anomalies, and license-attribution cues for human follow-up without modifying code.

Can I integrate dependency review with a CodeBuddy-style review packet?

Yes, integrate with CodeBuddy-style packets to provide bounded, findings-first dependency and supply-chain review using packet evidence and a generated dependency surface map.

Does this dependency review tool modify or upgrade repository dependencies?

No, this dependency review detects and documents repository dependency surfaces and supply-chain cues to support human review without upgrading or editing code.

What supply-chain cues and configurations can I review for repository dependencies?

Review supply-chain cues by surfacing manifests, lockfiles, CI workflows, Docker configurations, and toolchain configs to detect drift, floating versions, and license-attribution anomalies.