devs:deps-core
Installation
SKILL.md
Dependency Management
Comprehensive guidance for managing dependencies across TypeScript, Rust, and Python ecosystems.
Core Principle
Commands over inference. Always run the actual package manager command to get information rather than reading manifest or lock files and inferring state. The package manager is the authority on what is installed, what is outdated, and what is vulnerable.
npm lstells you what is installed —package.jsontells you what should be installed. These can differ.cargo treeshows the resolved dependency graph —Cargo.tomlshows declared dependencies.pip listshows what is in the environment —requirements.txtshows what was requested.
Reading manifest files is useful for understanding project structure and intent, but command output is the source of truth for current state.
Ecosystem Detection
If you are dispatched with a specific ecosystem (e.g., "typescript"), skip detection and load the relevant reference directly.
If you need to detect the ecosystem, scan the project root for these files: