deps-install

v2026.09.24

Deps install: auto-detect package manager (uv, bun, npm, yarn, pnpm, cargo, go) and run the right install. Use when installing deps or syncing lockfiles.

GitHub
Install command
npx skhub add laurigates/deps-install
Markdown
SKILL.md

When to Use This Skill

Use this skill when...Use justfile-expert instead when...
Installing packages without picking a manager up frontDefining a project-local just install recipe
One-off --global or --dev installs across mixed projectsStandardising just deps / just sync for a team
Auto-detecting between uv, bun, npm, cargo, and goThe repo already exposes installation as a recipe
Use this skill when...Use shell-expert instead when...
The user just wants the install command runWriting a custom installer script with retries or branching
Syncing the lockfile via the right native subcommandComposing multi-package-manager bootstrap logic in shell

Context

  • Package files: !find . -maxdepth 1 \( -name "package.json" -o -name "pyproject.toml" -o -name "requirements.txt" -o -name "Cargo.toml" -o -name "go.mod" -o -name "Gemfile" \) -type f
  • Lock files: !find . -maxdepth 1 \( -name "uv.lock" -o -name "package-lock.json" -o -name "yarn.lock" -o -name "pnpm-lock.yaml" -o -name "Cargo.lock" -o -name "go.sum" \) -type f

Parameters

Parse $ARGUMENTS and bind these before running anything. They are supplied by the caller; nothing substitutes them for you.

Token in $ARGUMENTSBindsDefault when absent
Non-flag tokensPACKAGES — space-separated package namesempty → install everything from the manifest
--devDEV — add to development dependenciesoff
--globalGLOBAL — install globally rather than into the projectoff

Every command below is written with a literal PACKAGES placeholder — substitute the bound value when you run it.

Execution

Run this install:

Step 1: Detect the package manager

Read the Lock files and Package files lines from Context above. Lock files win — they name the manager that actually produced the current install; a manifest alone only narrows the ecosystem.

Signal (repo root)PACKAGE_MANAGER
uv.lock, or pyproject.toml with a [tool.uv] sectionuv
bun.lock / bun.lockbbun
pnpm-lock.yamlpnpm
yarn.lockyarn
package-lock.jsonnpm
Cargo.lock / Cargo.tomlcargo
go.sum / go.modgo
pyproject.toml / requirements.txt with no lock fileuv
package.json with no lock filebun (this portfolio's default — see bun-package-manager)
  • Several matches in one repo (a polyglot monorepo) → run the matching row for each ecosystem, then report them together.
  • No match → report that no manifest was found and stop; do not guess.

Step 2: Run the row for the detected manager

PACKAGE_MANAGERInstall all (no PACKAGES)Add PACKAGESWith --devWith --global
uvuv syncuv add PACKAGESuv add --dev PACKAGESuv tool install PACKAGES
bunbun installbun add PACKAGESbun add -d PACKAGESbun add -g PACKAGES
npmnpm ci (lock present) else npm installnpm install PACKAGESnpm install -D PACKAGESnpm install -g PACKAGES
yarnyarn install --frozen-lockfileyarn add PACKAGESyarn add -D PACKAGESyarn global add PACKAGES
pnpmpnpm install --frozen-lockfilepnpm add PACKAGESpnpm add -D PACKAGESpnpm add -g PACKAGES
cargocargo buildcargo add PACKAGEScargo add --dev PACKAGEScargo install PACKAGES
gogo mod downloadgo get PACKAGES(Go has no dev-dependency tier)go install PACKAGES@latest

For Python without uv, uv pip install -r requirements.txt installs a legacy requirements file without migrating the project.

System Dependencies

Check for system-level dependencies:

  • macOS: Use Homebrew if Brewfile exists
  • Linux: Detect package manager (apt, yum, dnf, pacman)

Lock File Management

After installation:

  1. Verify lock file is updated
  2. If new lock file created, remind to commit it
  3. Check for security vulnerabilities

Post-install Actions

  1. Display installed packages and versions
  2. Run /lint:check to ensure code quality
  3. Run /test:run to verify nothing broke
  4. Suggest /git:smartcommit if lock files changed
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

tools-plugin/skills/deps-install

Default branch

main

Latest commit

1668324

Tree SHA

b2d4cc3