🔍
DevOpsJavaScript

Dependency Triage

by cobusgreyling

Dependency Triage is a DevOps skill for Claude Code, published by cobusgreyling in loop-engineering.

10.4K stars1.4K forkson cobusgreyling/loop-engineeringAdded 2026/08/15+1% in starsRepository updated 2026/08/15
agentic-aiai-agentsai-codinganthropicautomationclaudeclaude-codecodexcoding-agentsdevops-automationdevtoolsgithub-actionsgrokllmloop-engineeringmcpprompt-engineering
Install in seconds
Install Dependency Triage
Copy Dependency Triage into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/cobusgreyling/loop-engineering/tree/main/starters/dependency-sweeper/.claude/skills/dependency-triage ~/.claude/skills/dependency-triage

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/cobusgreyling/loop-engineering.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
starters/dependency-sweeper/.claude/skills/dependency-triage/SKILL.md in cobusgreyling/loop-engineering
Installs to
~/.claude/skills/dependency-triage
Collection
One of 23 skills cataloged from this repository
Category
DevOps798 skills

What Dependency Triage does

Dependency Triage scans package manifests and lockfiles for outdated packages and known CVEs, grouping updates by risk (patch, minor, major). Use it in dependency sweeper loops to decide which updates are safe to apply automatically and which need human escalation.

Dependency Triage is cataloged under DevOps on DirSkills. Dependency Triage comes from a repository tagged agentic-ai, ai-agents, ai-coding, anthropic and automation.

Documentation

README

Dependency Triage Skill

Output per package

### package-name (ecosystem: npm|pip|go|etc.)
- Current: x.y.z
- Suggested: x.y.z
- Risk: patch | minor | major
- CVE: none | CVE-XXXX (severity)
- Actionable: yes | no (denylist / human gate)
- Suggested loop action: patch-in-worktree | escalate-human | skip

Classification Rules

  • patch: semver patch or lockfile-only security fix with no API change
  • minor: semver minor — cautious, verifier required
  • major: always escalate-human unless explicitly pre-approved in state
  • denylist: packages in state denylist → escalate-human, no auto-touch
  • high-severity CVE: escalate if fix requires major or breaking change

Rules

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Dependency Triage

  • What else does cobusgreyling publish alongside Dependency Triage?

    Dependency Triage is one of 23 skills that DirSkills catalogs from cobusgreyling/loop-engineering, the repository it ships in. Its siblings there include Budget Negotiator, CI Triage and CI Triage. Each one is a separate skill with its own page in this directory, installs the same way Dependency Triage does, and is maintained by cobusgreyling in that same repository. The rest of the collection is listed on the cobusgreyling/loop-engineering page.

  • How does Dependency Triage compare to other DevOps skills?

    Dependency Triage ranks #116 by stars among the 798 DevOps skills in this catalog. The most-starred ones next to it are Backend Patterns, API Connector Builder and Migration. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Dependency Triage against them. Open each page to compare what they document and how they install.

More from cobusgreyling/loop-engineering

Dependency Triage is one of 23 skills cataloged on DirSkills from cobusgreyling/loop-engineering.

See all 23 skills
💰
2w ago

Budget Negotiator

Budget Negotiator enables an L3 autonomous loop to request a token budget increase when near its cap and high-priority work remains. It calculates ROI from run logs and escalates a tagged request for human approval.
AI Engineering
10.4K1.4K
🩺
2w ago

CI Triage

CI Triage classifies failing CI checks into clear regressions, infra flakes, security-test failures, and non-deterministic failures, then updates ci-sweeper-state.md with suggested next actions and attempt counts. Use it when you need to decide whether to auto-fix, retry, or escalate each CI failure.
DevOps
10.4K1.4K
🔍
2w ago

CI Triage

CI Triage parses CI failures, identifies the failing job and step, and classifies each failure as flake, regression, env, or config to guide next actions. Use it before attempting any fix to decide whether to minimal-fix, watch, or escalate.
DevOps
10.4K1.4K
📝
2w ago

Changelog Scan

Changelog Scan scans merged PRs and commits since a given reference, extracting titles, labels, types, and signals. It produces structured input for release notes drafting.
DevOps
10.4K1.4K
📋
2w ago

Changelog Scan

Changelog Scan reviews recent merges, PRs, and commits to extract release note content, returning structured per-item blocks and a scan summary. It surfaces breaking and security changes explicitly and ignores dependency and bot noise unless security-related.
DevOps
10.4K1.4K
📋
2w ago

Changelog Scan

Changelog Scan analyzes recent merges and commits since the last release to extract user-facing changes, breaking changes, and security signals. Use it to generate structured changelog entries for release notes.
DevOps
10.4K1.4K