Discipline for adding, upgrading, and removing dependencies. Use this skill whenever the user mentions installing, adding, upgrading, updating, removing, or auditing a package, library, or dependency; asks which package or library to use for something, or whether a dependency is needed; mentions a security advisory, CVE, or vulnerable dependency; asks to fix or update a lockfile; or is working in a project with package.json, package-lock.json, requirements.txt, pyproject.toml, Cargo.toml, go.mod, or similar. Trigger even when the user just says "install X" or "can we do X with a library?" — the default answer is "no new dependency" until the existing stdlib and dependenci…