Install
$ agentstack add skill-aaronflorey-agent-skills-depsdotdev ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
deps.dev API
Use this skill to map package coordinates (system/name/version) to high-signal dependency intelligence from Open Source Insights.
Start Here
- Prefer stable API base:
https://api.deps.dev/v3 - Use
v3alphaonly when you need purl and batch endpoints - Percent-encode all path/query values before sending requests
- Use canonical values returned in responses (
packageKey,versionKey,projectKey) for follow-up calls
Fast Routing
| If you need to... | Use | Read | |---|---|---| | List versions for a package | GetPackage | references/endpoint-map.md | | Inspect one version (licenses, advisories, links) | GetVersion | references/endpoint-map.md | | Get declared constraints | GetRequirements | references/endpoint-map.md | | Get resolved dependency graph | GetDependencies | references/endpoint-map.md | | Map project repo to package versions | GetProjectPackageVersions | references/endpoint-map.md | | Query by file hash or exact version key | Query | references/endpoint-map.md | | Avoid encoding mistakes | URL/purl rules | references/request-shapes-and-encoding.md | | Handle limits and error cases | batch/query limits | references/limits-errors-and-reliability.md | | Use purl/batch/dependents | v3alpha features | references/v3alpha-extras.md |
Minimal Workflow
- Normalize user input into
{system, name, version?}. - Call
GetPackageif version is missing; preferisDefaultor newest published version. - Call
GetVersionfor license/advisory/provenance metadata. - Add
GetRequirementsandGetDependencieswhen user asks "declared" vs "resolved" dependency questions. - If input is a hash or purl, use
Queryorv3alphapurl endpoints.
Examples
- Curl patterns and jq snippets:
examples/curl-cheatsheet.md
External Docs
- API overview and versions: https://docs.deps.dev/api/
- Stable REST schema: https://docs.deps.dev/api/v3/
- Experimental REST schema: https://docs.deps.dev/api/v3alpha/
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: aaronflorey
- Source: aaronflorey/agent-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.