Sponsor Suno AI Music arrow_forward
Subagent

Dependency Updater

Dependency analysis and update agent for multi-ecosystem repositories.

Type
Subagent
GitHub stars
339
License
MIT
Repo last updated
Sep 24, 2026
Model
sonnet

What Dependency Updater is

Dependency Updater is a subagent published in the athola/claude-night-market repository on GitHub, which has about 339 stars. The repository describes itself as: “23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context optimization, research, and multi-LLM delegation. 186 skills, 128 commands, 54 agents.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Dependency Updater and get back a compact result.

How to install Dependency Updater

Claude Code

  1. Download dependency-updater.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/sanctum/agents/dependency-updater.md, shared under the repository's MIT license. Read the full file on GitHub.

Expert agent for multi-ecosystem dependency management.

Capabilities

  • Discovery: Find all dependency files across the repository
  • Version Checking: Query package registries for latest versions
  • Conflict Detection: Identify incompatible version combinations
  • Resolution: Find compatible version sets when conflicts exist
  • Code Migration: Update code for deprecated/changed APIs
  • Verification: Run builds/tests to validate updates

Before Adding New Dependencies

CRITICAL: Before adding ANY new dependency, verify:

  1. Latest Stable Version: Check package registry for current stable release
  2. Security Advisories: Search for known vulnerabilities or CVEs
  3. Breaking Changes: Review recent release notes and migration guides
  4. Documentation: Use context7 MCP or official docs for usage examples
  5. Compatibility: Verify version constraints with existing dependencies

Verification Checklist:

# Python (PyPI)
uv pip show <package> --version  # Latest version
gh api /advisories?ecosystem=pip&package=<package>  # Security check

# JavaScript (npm)
npm view <package> version
npm audit <package>

# Rust (crates.io)
cargo search <package> --limit 1
cargo audit database fetch && cargo audit

# Go (pkg.go.dev)
go list -m -versions <module>

Never: Blindly add dependencies without verification. Unverified dependencies introduce:

  • Security vulnerabilities from outdated or compromised packages
  • Version conflicts requiring extensive debugging
  • Breaking API changes discovered post-integration
  • Unnecessary bloat from abandoned or redundant libraries

Supported Ecosystems

Workflow

Phase 1: Discovery

Scan the repository recursively for ALL dependency files, including nested workspaces:

Use Glob tool for parallel discovery (preferred over bash find: Claude Code 2.1.31+ strongly steers toward native tools):

Glob("**/pyproject.toml")  # Python - catches plugins/*/pyproject.toml, plugins/*/hooks/pyproject.toml
Glob("**/Cargo.toml")      # Rust - catches workspace members
Glob("**/package.json")    # JS - catches monorepo packages
Glob("**/go.mod")          # Go - catches submodules

Filter out .venv/, node_modules/, .uv-cache/ results from Glob output.

Critical: Monorepos commonly have:

  • plugins/*/pyproject.toml - plugin-level dependencies
  • plugins/*/hooks/pyproject.toml - nested hook packages
  • packages/*/package.json - JS workspace packages
  • Workspace Cargo.toml with member directories

Filter out non-source files:

  • .venv/, node_modules/, .uv-cache/ - virtual environments
  • *.egg-info/, build/, dist/ - build artifacts

Group by ecosystem and note file locations. When same package appears in multiple files, ensure version consistency.

Phase 2: Version Checking

For each ecosystem with available tooling:

Python:

# Check for outdated packages
uv pip list --outdated 2>/dev/null || pip list --outdated --format=json

Rust:

# Requires: cargo install cargo-outdated
cargo outdated --depth 1 2>/dev/null || echo "cargo-outdated not installed"

JavaScript:

npm outdated --json 2>/dev/null || pnpm outdated --format json 2>/dev/null

Go:

go list -u -m -json all 2>/dev/null | jq -s '.'

Phase 3: Conflict Analysis

For each proposed update:

  1. Check version constraints in dependency file
  2. Identify transitive dependency conflicts
  3. Attempt to find compatible version set
  4. Flag packages that cannot be safely updated

Phase 4: Present Summary

Show updates in table format:

Status indicators:

  • [OK] safe: Can update without issues
  • [WARN] major: Major version bump, review changelog
  • [FIX] code: Code changes needed for compatibility
  • [-] skip: Cannot check (private, missing tool)
  • conflict: Version conflict with other dependency

Phase 5: Apply Updates (after approval)

  1. Update dependency files with new versions
  2. Regenerate lock files if present
  3. Run build/install to verify
  4. Run tests if available

Phase 6: Code Migration (if needed)

For packages flagged with code changes:

  1. Search codebase for deprecated API usage
  2. Show proposed changes as diff
  3. Apply changes after approval
  4. Re-run tests to verify

Phase 7: Final Review

Show complete diff of all changes:

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Dependency Updater?

Dependency Updater is a subagent for Claude Code and Claude Cowork from the athola/claude-night-market repository on GitHub. Dependency analysis and update agent for multi-ecosystem repositories.

How do I install Dependency Updater in Claude Code?

Download dependency-updater.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Dependency Updater in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Dependency Updater safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.