Agent skill

Distilled SDK Update

by alchemy-run in alchemy-run/distilled

Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg/patches/ with pnpm patches:audit and delete or slim the patches the new spec has absorbed, then open…

Apache-2.0Auto-check passed

Install Distilled SDK Update

skills CLI
$ npx skills add alchemy-run/distilled --skill distilled-sdk-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alchemy-run/distilled distilled-sdk-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alchemy-run/distilled.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/distilled-sdk-update .claude/skills/distilled-sdk-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
distilled-sdk-update
GitHub stars
432
Token cost
~2.8k tokens
SKILL.md length
1,410 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg/patches/ with pnpm patches:audit and delete or slim the patches the new spec has absorbed, then open…

  • Works in 6 steps: move the mirror → regenerate → audit the patches → …
  • Update <pkg to the latest spec
  • SKILL.md covers Step 1 — move the mirror, Step 2 — regenerate, Step 3 — audit the patches and Step 4 — check the delta, plus 2 more sections
  • Calls pnpm, git and gh; reaches github.com

What it does

Distilled SDK Update is an agent skill from alchemy-run/distilled. Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg/patches/ with pnpm patches:audit and delete or slim the patches the new spec has absorbed, then open the PR. Use for "update <pkg to the latest spec", "regenerate <pkg", "audit / remove unused patches", "which patches does the new spec no longer need", or when a provider says they fixed their spec. Adding, changing, merging or rebasing a single patch, including "do we still need this patch PR?", is distilled-sdk-patch…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with pnpm, Amazon Web Services and Cloudflare. The repository describes itself as: Effect-native SDKs for cloud providers. The licence is Apache-2.0.

When your agent uses it

  • Update <pkg to the latest spec
  • Regenerate <pkg
  • Audit / remove unused patches
  • Which patches does the new spec no longer need

Example prompts

  • “update <pkg to the latest spec”
  • “regenerate <pkg”
  • “audit / remove unused patches”
  • “/distilled-sdk-update”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. move the mirror
  2. regenerate
  3. audit the patches
  4. check the delta
  5. commit and PR
  6. reconcile open PRs for the provider (when asked)

What it can do on your machine

Read from SKILL.md and the folder at commit 46d2d3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Distilled SDK Update loads about 2.8k tokens when it runs. Until then it costs about 191 tokens; SKILL.md has 1,410 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~191
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alchemy-run/distilled at commit 46d2d3b, republished under its Apache-2.0 licence (© alchemy-run). 1,410 words, ~2,837 tokens.

Download SKILL.mdSave it as .claude/skills/distilled-sdk-update/SKILL.md (or your agent's skills folder).
name
distilled-sdk-update
description
Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg>/patches/ with `pnpm patches:audit` and delete or slim the patches the new spec has absorbed, then open the PR. Use for "update <pkg> to the latest spec", "regenerate <pkg>", "audit / remove unused patches", "which patches does the new spec no longer need", or when a provider says they fixed their spec. Adding, changing, merging or rebasing a single patch, including "do we still need this patch PR?", is distilled-sdk-patch, which reads the generated diff and runs no audit. When also asked to "look at / go through the open PRs" for that provider, it reconciles them against the new spec (Step 6). Building a new SDK is the distilled-sdk skill.

Updating a distilled SDK to its latest spec

Every patch under packages/<pkg>/patches/ is a claim that the upstream description is wrong. Upstreams fix things, so every regeneration is also the moment to drop the patches that no longer change anything. The two halves are one job: a spec update that keeps stale patches hides the fix, and a patch audit against an old spec finds nothing.

Work in a worktree cut from origin/main and run pnpm install there. Nothing here needs a full pnpm specs:sync; one mirror is enough.

Step 1 — move the mirror

sh
pnpm --filter @distilled.cloud/<pkg> run specs:fetch    # initialise at the committed commit
pnpm --filter @distilled.cloud/<pkg> run specs:update   # move to the mirror's tip
git -C packages/<pkg>/specs/spec-mirror-<pkg> log -1 --format='%h %ci'

specs:update alone skips a submodule that was never initialised, which is why specs:fetch comes first. git status now shows the gitlink (M packages/<pkg>/specs/spec-mirror-<pkg>) — that line is part of the commit; it is how anyone else reproduces the generation.

The mirror refetches daily, so its tip is at most a day behind upstream. When you need today's upstream (a provider just published a fix), preview with pnpm specs:local <pkg> and DISTILLED_SPECS_LOCAL=1 pnpm generate <pkg>, but commit only a generation from the mirror gitlink — a .local generation is one nobody can reproduce.

Step 2 — regenerate

sh
pnpm generate <pkg>

A patch whose pointer no longer resolves fails convert with ❌ bad patch: <file> [<op> <path>]: stale target. That is the new spec telling you something moved: either upstream now has what the op added (delete the op) or the path changed (re-point it). Fix the patch and rerun; onStalePatch: "warn" is how a whole chain once vanished silently.

Step 3 — audit the patches

sh
pnpm patches:audit <pkg>          # one verdict per file
pnpm patches:audit <pkg> --ops    # also one per op inside every needed file
pnpm patches:audit <pkg> --only <substring>
pnpm patches:audit <pkg> --jobs <n>   # parallel converts; default from cores and free memory

Run the audit only after the mirror has moved (step 1): it answers which patches the new spec has absorbed, and nothing else. Always name the package. To check what one patch you just wrote or edited does, read the generated diff instead (distilled-sdk-patch, step 5).

The audit (@distilled.cloud/core/codegen/patch-audit) builds the model once with every patch, then once per patch with that patch left out, and diffs the result. It runs convert on scratch copies of the package (packages/.audit-<pkg>-<n>, removed on exit; the package itself is never written), so the spec mirror must be fetched (step 1); without it the package is reported as skipped. Patches are Smithy ops applied in finalizeConvert, so each file is judged in memory: one convert, then only the finalize steps re-run per file. All of cloudflare (about 2,850 files) takes under two minutes, posthog and azure well under a minute, most packages seconds. Railway's GraphQL patches apply outside finalizeConvert and cost one convert each (DISTILLED_SKIP_PATCHES), spread over --jobs copies.

VerdictMeaningDo
🗑 no effectthe model is byte-identical without itdelete the file
✔ neededthe model differs; the pointers are listedkeep, and read the diff — it is the patch's description, mechanically
🔗 the build fails without ita later patch targets what this one addskeep both, or delete both
op N: no effect (--ops)one op in a needed file is deadremove that op

Verdicts are one-at-a-time. Two patches that add the same thing each look unused alone; only the second deletion changes the model. So: delete what it lists, pnpm generate <pkg>, audit again, until the list is empty.

Two things the audit cannot judge:

  • Typed patch configs. packages/aws/patches/<sdkId>.json is applyAwsSpecPatches config, not RFC-6902; the audit reports those files as not audited. Judge them by reading the model.
  • Whether a needed patch is right. A patch that still changes the model may still be wrong about the wire. Patches that encode observed behaviour — error statuses the spec omits, required fields the API actually omits, x-sensitive marks — are only confirmable against the live API. With credentials, probe: create throwaway resources, hit the mutating routes with invalid bodies, record the statuses, tear down promptly. Add only what you observed; a probe that never reached validation (401/404 on a dummy slug) proves nothing. Writing the patch that records it is the distilled-sdk-patch skill.

While slimming, keep each file's description true to what is left, and fold files of the same kind together when they shrink to a few ops (two files that both only add omitted 422s are one file). The description is the bug report you will send upstream.

Step 4 — check the delta

sh
git diff --stat -- packages/<pkg>
pnpm exec tsc -b packages/<pkg> --noCheck false   # the root typecheck:ci is heavy
pnpm lint

Read git diff -- packages/<pkg>/src/services for what upstream changed underneath you, beyond the patches:

  • Renamed or removed operations. An upstream operationId change renames an export; a removed path removes one. Both are breaking and belong in the PR body by name, old → new.
  • Nullability and required flips on shapes callers already use — T → T | null in an output is a type break too.
  • Operation count before and after, as one line.

Step 5 — commit and PR

Stage explicit paths — the gitlink, .generated-specs/, patches/, src/services/, and README.md if an example changed:

sh
git add -- packages/<pkg>/specs/spec-mirror-<pkg> packages/<pkg>/.generated-specs \
  packages/<pkg>/patches packages/<pkg>/src/services
git commit -m "feat(<pkg>): regenerate from the <YYYY-MM-DD> spec"

The PR body records what the next person needs to reproduce and review:

  • mirror commit before → after, and the date of the spec
  • operations before → after
  • patches deleted, one line each with why (already in the spec, never read by convert, overwrote what upstream now publishes)
  • patches kept, one line each with what the spec still gets wrong
  • renamed / removed operations

That "patches kept" list, with each file's description and a link to it on the branch, is also the message to send the provider. Group it by kind — missing x-nullable, shared models with too many required fields, undocumented error statuses, a wrong response schema, secrets with no sensitive mark — because that is how they will fix it.

Show full SKILL.md (512 more words)Show less

Step 6 — reconcile open PRs for the provider (when asked)

Open PRs that patch packages/<pkg> were written against the old spec, so they are reviewed after the update has merged, never before. The new spec decides each one. The authors' commits should land with their names on them: update their branches and merge, and close only what the spec or another PR already covers.

Find them.

sh
gh pr list --state open --limit 300 --json number,title,author,files \
  --jq '.[] | select(any(.files[]; .path | startswith("packages/<pkg>/")))
        | "#\(.number) \(.author.login): \(.title)"'

Filter on changed files: titles miss PRs scoped to core or to a sibling package that also patch this one.

Read each body and its patches/ diff. If the user excludes a PR or an API, leave it untouched: no push, no comment, no close.

Judge each against the regenerated model (.generated-specs/, not the TypeScript):

FindingDo
The spec now has it: same operations, members or shapesclose with a comment naming the spec commit and the generated symbols
Another open PR does the same, or it already mergedmerge the most complete one; close the rest with a link to it
Part is in the spec nowtrim the PR to what the spec still lacks
None of it is in the specupdate and merge as is
The spec has it, but the converter generates it wrongfix the converter in its own PR, merge it, then close

Usually reading the regenerated model answers it: search .generated-specs/ for the operations, members or shapes the PR adds. When it does not, merge main into the PR's branch and run pnpm generate <pkg>: a stale target means the spec moved underneath the patch, and the generated diff against main shows what the patch still adds. Reach for pnpm patches:audit <pkg> --only <file> --ops only when that diff cannot tell you which ops are dead.

Update a branch in place. Maintainers can push to forks when maintainerCanModify is true; for a fork, fetch refs/pull/<n>/head, since origin/<branch> does not exist:

sh
git fetch origin main "refs/pull/<n>/head:refs/remotes/pr/<n>"
git checkout -B pr-<n> pr/<n>
git merge --no-edit origin/main            # merge, never rebase: keep their commits
pnpm generate <pkg>                        # resolve generated-file conflicts by regenerating
pnpm exec tsc -b packages/<pkg> --noCheck false
pnpm vitest run packages/<pkg>/src/<their>.test.ts
git push https://github.com/<owner>/<repo>.git pr-<n>:<headRefName>
  • Conflicts in .generated-specs/ or src/services/ are not edits to resolve by hand: take either side and regenerate. Conflicts in patches/ are real; read both sides. Two PRs adding the same shape merge into duplicate ops or duplicate JSON keys without a textual conflict, so check the patch parses with no repeated keys.
  • Delete a test the PR added that only checks the patch's generated shape; patches carry no per-package tests (distilled-sdk-patch, step 4). Other tests that predate repo changes (bun:test → vitest, Redacted credentials) get fixed in a separate commit on their branch.
  • When a PR was trimmed, say so in a comment on it: what was dropped and why.

Merge in dependency order. PRs that regenerate the same service conflict with each other once one lands. Merge the independent ones first, then re-merge main into each remaining branch and regenerate before queueing it. main uses a merge queue; enqueue with the GraphQL enqueuePullRequest mutation (with expectedHeadOid) after the checks pass.

Ask before closing anyone's PR, or before a change beyond patches, such as a converter or runtime fix. Every close carries a comment that thanks the author and names what superseded it, by PR number or spec commit.

© alchemy-run, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/distilled-sdk-update of alchemy-run/distilled.

Open the folder on GitHubat commit 46d2d3b

Compare with similar skills

Distilled SDK Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Distilled SDK Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Distilled SDK Update this skillalchemy-run/distilled432—~2.8kAutomated safety check: PassApache-2.0
Crabboxopenclaw/gogcli8.5k—~8kAutomated safety check: NotesMIT
Update Provider Depsmondoohq/mql412—~4.5kAutomated safety check: PassCustom licence
Use Cdkdgo-to-k/cdkd144—~669Automated safety check: PassApache-2.0
Nx Plugin For AWSawslabs/nx-plugin-for-aws152—~3.6kAutomated safety check: PassApache-2.0
Deploy AstermemAsterove/AsterMem161—~3.2kAutomated safety check: WarnAGPL-3.0

Similar skills

  • Crabbox

    openclaw/gogcli

    Use the Crabbox wrapper for OpenClaw remote validation across Linux, macOS, Windows, and WSL2, including delegated Blacksmith Testbox proof.

    8.5k GitHub stars~8k tokensUpdated 2 days ago
    Auto-check: notes
  • Upgrade an mql provider's vendored SDKs (all providers or a named subset), audit the new versions for breaking changes and fix call sites while keeping shipped MQL fields backwards-compatible, check…

    412 GitHub stars~4.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Use Cdkd

    go-to-k/cdkd

    Build the current cdkd checkout and use it from another CDK project.

    144 GitHub stars~669 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Nx Plugin For AWS

    awslabs/nx-plugin-for-aws

    Official

    Scaffold and build cloud-native applications on AWS using @aws/nx-plugin generators.

    152 GitHub stars~3.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Deploy Astermem

    Asterove/AsterMem

    Guide the user through taking AsterMem live — on a cloud server, or on a machine they already own (home NAS, Raspberry Pi, this computer) exposed through Cloudflare Tunnel with no public IP.

    161 GitHub stars~3.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: warnings
  • Svelte Deployment

    spences10/svelte-claude-skills

    Svelte deployment guidance. An agent skill from spences10/svelte-claude-skills.

    218 GitHub stars~380 tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from alchemy-run/distilled

  • Distilled SDK Patch

    alchemy-run/distilled

    Add or change a patch in packages/<pkg/patches/ to correct a distilled SDK's upstream spec — a missing error response or typed error (status, code, message, body or header matchers), a field that…

    432 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Distilled SDK

    alchemy-run/distilled

    Build or update a distilled SDK for an API provider — sourcing its OpenAPI/Smithy/GraphQL/discovery description, adding the spec mirror that feeds it, generating packages/<provider, listing it on…

    432 GitHub stars~6k tokensUpdated today
    Auto-check passed

Questions about Distilled SDK Update

What does Distilled SDK Update do?

Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg/patches/ with pnpm patches:audit and delete or slim the patches the new spec has absorbed, then open…. Distilled SDK Update is an agent skill from alchemy-run/distilled. Move an existing distilled SDK to its mirror's latest spec, regenerate it, audit packages/<pkg/patches/ with pnpm patches:audit and delete or slim the patches the new spec has absorbed, then open the PR.

When should I use Distilled SDK Update?

Distilled SDK Update fits situations like: update <pkg to the latest spec; regenerate <pkg; audit / remove unused patches; which patches does the new spec no longer need.

How do I install Distilled SDK Update in Claude Code?

Run `npx skills add alchemy-run/distilled --skill distilled-sdk-update -a claude-code`. Or copy the skill folder (.agents/skills/distilled-sdk-update in alchemy-run/distilled) into .claude/skills/distilled-sdk-update in your project. Claude Code loads it when a task matches its description.

How do I install Distilled SDK Update in Codex?

Run `npx skills add alchemy-run/distilled --skill distilled-sdk-update -a codex`. Or copy the skill folder (.agents/skills/distilled-sdk-update in alchemy-run/distilled) into .agents/skills/distilled-sdk-update in your project. Codex loads it when a task matches its description.

Can I use Distilled SDK Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alchemy-run/distilled --skill distilled-sdk-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/distilled-sdk-update, .gemini/skills/distilled-sdk-update, .github/skills/distilled-sdk-update and .opencode/skills/distilled-sdk-update in your project.

What does Distilled SDK Update need to run?

Going by SKILL.md and its folder, Distilled SDK Update needs the command-line tools its instructions call (pnpm, git and gh).

Does Distilled SDK Update access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Distilled SDK Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Distilled SDK Update use?

Distilled SDK Update is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Distilled SDK Update use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Distilled SDK Update?

Skills that share tags, products or a category with Distilled SDK Update: Crabbox (openclaw/gogcli, 8.5k stars), Update Provider Deps (mondoohq/mql, 412 stars), Use Cdkd (go-to-k/cdkd, 144 stars) and Nx Plugin For AWS (awslabs/nx-plugin-for-aws, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Distilled SDK Update?

alchemy-run (a GitHub organization) maintains it in alchemy-run/distilled, which has 432 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 9, 2026.

Source: alchemy-run/distilled on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.