gemini-cli-extensions/security · Archived

dependency-manager

Safely resolve and install isolated dependencies for isolated sandboxes (PoC execution).

First seen Apr 7, 2026

Installation

$ npx skills add gemini-cli-extensions/security --skill dependency-manager

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from gemini-cli-extensions/security.

npx skills add gemini-cli-extensions/security

Browse all from gemini-cli-extensions/security

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 791
License LICENSE
Default branch main
Open issues 44
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

Declared agents gemini

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,528 B
  • docs SUMMARY.md 114 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 10 installs

SKILL.md

Proceed with these steps to ensure isolated execution while bypassing full installer locks.

Instructions:

  1. Locate and Read Dependency Files:

Use an MCP read_file tool to locate and read the closest dependency manifest files walking up from the targetFile coordinate. TypeScript/Node.js: Grab package.json and package-lock.json. Python: Grab requirements.txt or Pipfile.lock. C++: Check for conanfile.txt or CMakeLists.txt. Go: Grab go.mod and go.sum. Java: Grab pom.xml (Maven) or build.gradle/build.gradle.kts (Gradle).

  1. Extract Version Constraints:

* Read the manifest files to find the exact version constraints for packages used in the PoC/verification code.

  1. Bypass Full Installs (Node.js):

* Instruct commands to utilize prefixes like npmconfigcache=.npx_cache so downloads bypass global proxy auth locks.

  1. Write Deterministic Running Script:

* Generate a standalone dependency runner file on disk named deterministically e.g., installdeps<targetfilebase>.sh (or .js/.py).

  1. Trigger Isolated Execute:

* Call the install_dependencies Tool passing the absolute path to the generated script in the scriptPath argument AND providing targetFile as an argument to let the tool calculate isolated execution contexts.