Vendor a tiny dependency into the repo to drop the package and its install/supply-chain cost
Scanned 9/3/2026
Install to Claude Code
npx -y skills add black141312/ada --skill vendor --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Vendor?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/black141312-vendor)More formats (shields.io, HTML) on the badges page.
---
name: vendor
description: Vendor a tiny dependency into the repo to drop the package and its install/supply-chain cost
category: dependencies
---
# Vendor
Reach for this when a dependency is small enough that copying its source in beats carrying the package and its tree.
1. Confirm it's worth vendoring: the package is tiny, stable, and has few/no transitive deps — otherwise keep the dependency.
2. Check the license permits copying and note the requirement (attribution, header retention) for the vendored file.
3. Copy the minimal source you actually use into a clearly named `vendor/` (or `internal/`) path, preserving the license header.
4. Record provenance: a comment or NOTICE with the package name, version, source URL, and license.
5. Replace imports of the package with the local path, then remove the dependency from the manifest and lockfile.
6. Run tests and a build; reinstall clean to confirm the package is fully gone.
## Rules
- Only vendor small, slow-moving code — vendoring something that gets security patches means you now own those patches.
- Preserve the original license header and attribution; stripping it is a license violation.
- Pin the exact version you copied and write down where it came from for future updates.
- Trim to what you use, but don't refactor the vendored code — keep it diffable against upstream.
- After removing the dep, confirm nothing else (peer deps, types) still references it.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.
Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.
**Complete production-ready guide for Google Gemini embeddings API** This skill provides comprehensive coverage of the `gemini-embedding-001` model for generating text embeddings, including SDK usage, REST API patterns, batch processing, RAG integration with Cloudflare Vectorize, and advanced use cases like semantic search and document clustering. ---
Recovers prior coding-agent session context by running `catchup <agent> --since-compact`, which extracts a clean summary of a previous Codex, Claude Code, Antigravity, OpenCode, or Pi Agent session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", or asks to recover/summarize a previous session before continuing. Do NOT use for the current conversation, git history, or any non-agent log.