Skill registry
Developer workflowsPublic skills

Package & Dependency Management

Dependency health for AI agents — lookup packages, check versions, review changelogs, assess compatibility, analyze lockfiles, and generate safe upgrade plans via mcp-package-registry.

What this skill teaches

A reusable playbook for a specific kind of work.

An MCP server tells an agent which actions are available. A skill adds the judgment around those actions: how to recognize the job, which sequence to follow, what to avoid, and how to decide that the result is complete.

Manage package dependencies — lookup packages, check versions, review changelogs, assess compatibility, analyze lockfiles, and propose upgrades. Use when updating dependencies, checking for outdated packages, planning major upgrades, reviewing changelogs, or auditing dependency health.

Architecture

How Package & Dependency Management guides an ADK-Rust agent.

The skill stays readable and portable because it contains instructions rather than service credentials or business data. ADK-Rust supplies it to the agent, the agent chooses from its reviewed tool boundary, and the connected MCP server performs the authenticated operation.

01

User request

The agent receives a goal expressed in ordinary language.

02

Package & Dependency Management skill

Matches intent, supplies the decision guide, and narrows the tool boundary.

03

ADK-Rust agent

Plans the workflow and streams each meaningful step through the runtime.

04

mcp-package-registry

Executes authenticated operations against the system that owns the capability.

05

Verified result

The skill's completion rules shape the evidence returned to the user.

Portable instructions: SKILL.md · Capability boundary: mcp-package-registry · Allowed tools: 7

Decision guide

How the agent turns a request into the right action.

These routes come directly from the skill instructions. They help the model recognize intent and select a focused tool or workflow instead of improvising across the entire capability surface.

01

"outdated", "update", "upgrade"?

analyze_lockfile + propose_upgrades

02

"changelog", "what changed"?

get_changelog

03

"compatible", "will it break"?

check_compatibility

04

"vulnerable", "advisory"?

check_advisories

05

"info", "about package"?

lookup_package / list_versions

Proven workflows

Repeatable sequences for useful outcomes.

A workflow joins several tool calls into a task the user actually recognizes. The skill explains the sequence and the intended result while ADK-Rust streams the agent's progress through the shared runtime.

013 calls

Safe Upgrade Plan

Lockfile → prioritize → compatibility check

022 calls

Changelog Review

Versions → what changed

031 calls

Advisory Check

Vulnerable dependencies

Tool boundary

The skill may use 7 documented tools.

This allowlist is declared by the skill. It keeps the agent focused on the actions needed for this job while mcp-package-registry retains responsibility for authentication, validation, and the connected system.

lookup_package
list_versions
get_changelog
check_advisories
check_compatibility
analyze_lockfile
propose_upgrades

Working rules

What the agent should do.

  • Review changelogs for breaking changes before major upgrades
  • Prioritize security advisories over feature upgrades
  • Pin exact versions in production
  • Check transitive dependency impact

Operating boundaries

What the agent should avoid.

  • Never upgrade production deps without testing
  • Don't use floating version ranges in production
  • Don't ignore breaking change warnings

Install and connect

Add the skill beside the capability it expects.

Install the repository where your ADK-Rust skill loader can discover it, connect mcp-package-registry, and confirm the declared tools are available before asking the agent to use the workflow.

Install the skill
git clone https://github.com/zavora-ai/skill-package-dependency-management.git \
  ~/.skills/skills/package-dependency-management
ADK-Rust loading shape
let skills = SkillLoader::from_dir("~/.skills/skills").await?;
let skill = skills.load("package-dependency-management").await?;

let agent = LlmAgentBuilder::new("agent")
    .instruction(skill.instructions())
    .tools(skill.allowed_tools(toolset)?)
    .build()?;

The repository's compatibility statement: Requires mcp-package-registry server connected.

Official documentation

Read the complete skill package.

The repository remains authoritative for its exact instructions, examples, helper scripts, assets, MCP requirements, license, and later updates.

Source record

Repository metadata for this skill entry.

View public repository ↗
License
Apache-2.0
Allowed tools
7
References
3
Revision
bfc74c617952
Updated
May 31, 2026