Agent skill

Helmor Bump Vendors

by dohooo in dohooo/helmor

Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…

Apache-2.0Auto-check passedAgent Workflows

Install Helmor Bump Vendors

skills CLI
$ npx skills add dohooo/helmor --skill helmor-bump-vendors -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dohooo/helmor helmor-bump-vendors --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dohooo/helmor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/helmor-bump-vendors .claude/skills/helmor-bump-vendors && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
helmor-bump-vendors
GitHub stars
1.3k
Token cost
~2.1k tokens
SKILL.md length
883 words
Files
3 (incl. scripts, references)
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…

  • Works in 8 steps: Scope. Confirm which vendors to bump.… → Find the target version. Check LIVE —… → Edit the pins (package.json and/or the… → …
  • The user wants to upgrade / bump / update / refresh a bundled agent CLI
  • SKILL.md covers The pin sites, Vendor classes (determine the…, Workflow and Critical rules (the…, plus 3 more sections
  • Runs Shell scripts from its folder; calls bun, cargo and codex; reaches registry.npmjs.org and api.github.com

What it does

Helmor Bump Vendors is an agent skill from dohooo/helmor. Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab / cloudflared / llama.cpp / Node. Encodes exactly which files to edit (sidecar/package.json, sidecar/scripts/vendor-platform.ts), how to source each version and compute its SHA256, the Claude SDK↔CLI lockstep rule, npm dist-tags caveats (latest vs next vs stable), the cross-arch (arm64+x64) SHA requirement, and the…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/vendors.md` and `scripts/npm_vendor_sha.sh`).

It sits in Agent Workflows, covering LLM inference and serving. It works with npm, Claude Agent SDK, Kimi and llama.cpp. The repository describes itself as: Open-source local workbench for multi-agent software development. The licence is Apache-2.0.

When your agent uses it

  • The user wants to upgrade / bump / update / refresh a bundled agent CLI
  • Check whether a vendor is behind latest
  • Run a dependency version sweep in the Helmor repo

Example prompts

  • “/helmor-bump-vendors”

Requirements

  • A Bash shell

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Scope. Confirm which vendors to bump. For each, open references/vendors.md for its class,
  2. Find the target version. Check LIVE — never trust memory; dist-tags flip within hours.
  3. Edit the pins (package.json and/or the _VERSION const). Apply the Claude lockstep rule
  4. cd sidecar && bun install — pulls the new versions. Sanity-check: resolved versions are
  5. Compute + fill SHA256 for class B/C. Use scripts/npm_vendor_sha.sh for B; see the reference
  6. Run the verification gates (below) — all must pass.
  7. Create release metadata. Once the gates pass, invoke the /helmor-release skill to draft
  8. Report: current → target per vendor, breaking-change assessment, gate results, exact files

What it can do on your machine

Read from SKILL.md and the folder at commit a76cda1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bun
    • cargo
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org
    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Helmor Bump Vendors loads about 2.1k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 191 tokens; SKILL.md has 883 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~191
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from dohooo/helmor at commit a76cda1, republished under its Apache-2.0 licence (© dohooo). 883 words, ~2,074 tokens.

Download SKILL.mdSave it as .claude/skills/helmor-bump-vendors/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
helmor-bump-vendors
description
Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab / cloudflared / llama.cpp / Node. Encodes exactly which files to edit (`sidecar/package.json`, `sidecar/scripts/vendor-platform.ts`), how to source each version and compute its SHA256, the Claude SDK↔CLI lockstep rule, npm dist-tags caveats (latest vs next vs stable), the cross-arch (arm64+x64) SHA requirement, and the mandatory verification gates. Use whenever the user wants to upgrade / bump / update / refresh a bundled agent CLI or SDK version, check whether a vendor is behind latest, or run a dependency version sweep in the Helmor repo.

Helmor Bump Vendors

Standardized procedure for upgrading the third-party agent CLIs, SDKs, and helper binaries that Helmor pins and bundles. Goal: a correct, verified bump with no guesswork about where versions live, how to source each SHA256, or what to run before declaring it done.

The pin sites

Every bundled version is pinned in one (or both) of these files:

  • sidecar/package.json — npm dependencies. Covers SDKs (imported in TS) and the npm-distributed CLIs whose native binary is staged from node_modules (@anthropic-ai/claude-code, @openai/codex, opencode-ai).
  • sidecar/scripts/vendor-platform.ts — version constants + per-version SHA256 tables for every staged binary. Source of truth for what gets bundled into the release.
  • sidecar/scripts/stage-vendor.ts — staging logic. Only edit it when a vendor's archive layout changes (rare; see codex/cursor notes in references/vendors.md).

Vendor classes (determine the change-set)

ClassVendorsWhat to editSHA256?
A. npm SDK only@anthropic-ai/claude-agent-sdk, @cursor/sdk, @opencode-ai/sdk, @earendil-works/pi-*package.json lineNo — plain npm dep
B. npm-distributed staged binaryclaude-code, codex, opencodepackage.json line + SHA256 table key in vendor-platform.tsYes — from npm tarball
C. GitHub-release staged binarykimi, gh, glab, cloudflared, llama.cpp, node<NAME>_VERSION const + SHA256 table in vendor-platform.ts (NOT in package.json)Yes — source varies

Per-vendor exact pin location, SHA256 source, and gotchas live in references/vendors.md — read the relevant section before editing.

Workflow

  1. Scope. Confirm which vendors to bump. For each, open references/vendors.md for its class, pin location, SHA source, and gotchas.
  2. Find the target version. Check LIVE — never trust memory; dist-tags flip within hours.
    • npm: bun -e 'console.log((await (await fetch("https://registry.npmjs.org/<pkg>")).json())["dist-tags"])' Target latest (the stable channel). next is a prerelease — do not pin it unless the user explicitly asks. claude-code also publishes a conservative stable tag that lags (e.g. 2.1.179); Helmor tracks latest, not stable.
    • GitHub-release vendors: check the repo's Releases (or https://api.github.com/repos/<owner>/<repo>/releases).
  3. Edit the pins (package.json and/or the _VERSION const). Apply the Claude lockstep rule and any per-vendor gotcha from the reference.
  4. cd sidecar && bun install — pulls the new versions. Sanity-check: resolved versions are correct, any removed deps dropped from bun.lock, transitive deps you rely on are still present.
  5. Compute + fill SHA256 for class B/C. Use scripts/npm_vendor_sha.sh for B; see the reference for C. Both arm64 and x64 are mandatory (see Critical rules).
  6. Run the verification gates (below) — all must pass.
  7. Create release metadata. Once the gates pass, invoke the /helmor-release skill to draft the changeset (and an in-app announcement if the bump warrants one). Don't skip this — a vendor bump is a user-visible change and needs a changeset. A routine bundled-agent refresh is typically a patch changeset with no announcement; the body should name the user-visible change (which agents moved to latest), not the internal cleanup (Pi removal, pin tidy-ups, doc fixes).
  8. Report: current → target per vendor, breaking-change assessment, gate results, exact files touched, and the changeset created. Leave commit / PR to the user unless asked.
Show full SKILL.md (417 more words)Show less

Critical rules (the non-obvious parts that cause bad bumps)

  • Claude lockstep. @anthropic-ai/claude-agent-sdk@0.3.X and @anthropic-ai/claude-code@2.1.X share patch X and ship together — always bump both to the same X. Verify: the SDK's node_modules/@anthropic-ai/claude-agent-sdk/package.json carries claudeCodeVersion: "2.1.X". Only claude-code (the staged binary) needs a SHA256 entry; the agent-sdk is a plain npm dep.
  • Cross-arch SHA is mandatory. Every class B/C SHA table needs both arm64 and x64. CI cross-builds the x86_64 bundle on an arm64 runner. On a native-arch host the build uses node_modules directly and does not verify the SHA — so a wrong/missing x64 entry passes locally but breaks CI. Always compute both from the tarballs.
  • dist-tags drift. Re-check latest at bump time even if you "just looked" — a newer patch can be promoted from next to latest within hours.
  • SHA table = rolling history. The tables keep a few recent version keys (cache is version-keyed, so old keys coexist harmlessly). Add the new key; keep the prior one. If you are superseding an uncommitted entry you added this session, replace it (don't stack) for a clean diff.
  • Layout-change watch. Codex ships a self-describing codex-package.json descriptor; after a bump, diff it — a layoutVersion change or new field means stage-vendor.ts needs review. See references/vendors.md for codex, cursor (Node engines floor + phantom dep), and kimi (ACP protocol version) specifics.

Verification gates (run in order; all must pass)

bash
cd sidecar && bun install        # 1. installs targets; confirm versions + dropped deps in bun.lock
cd sidecar && bun run typecheck  # 2. catches SDK API breaks (removed/renamed exports) — main breaking-change detector
cd sidecar && bun test           # 3. sidecar unit tests
# 4. MANDATORY after ANY agent CLI/SDK bump — validates the stdout event-shape contract the Rust pipeline depends on:
cd src-tauri && cargo test --test pipeline_scenarios --test pipeline_fixtures --test pipeline_streams
cd sidecar && bun run build      # 5. full staging + compile; a wrong SHA256 hard-fails here (downloads + verifies kimi / cross-arch)

What each gate proves:

  • typecheck is the real breaking-change detector for SDK bumps (removed/renamed exports, changed types).
  • cargo pipeline tests replay stored fixtures, so they catch pipeline-code regressions — not new event shapes from a newer binary. For the latter, read the upstream changelog (focus on the stdout event JSON: codex item/,turn/,thread/ methods; claude SDKMessage/stream blocks; opencode message.part; kimi ACP session/update) and capture fresh fixtures if the shape moved.
  • build is the only gate that exercises SHA256 verification and the staging layout.

Breaking-change diligence

Before pinning, read the upstream changelog/release notes across the current→target window. Most agent-CLI patch bumps are additive; the risks that matter for Helmor are (a) SDK export/type changes (typecheck catches these) and (b) stdout event-shape changes (the Rust pipeline contract). Tag each notable change affects Helmor or no impact with reasoning, and surface it before bumping.

Tools in this skill

  • scripts/npm_vendor_sha.sh <claude-code|codex|opencode> <version> — downloads the darwin arm64 + x64 npm tarballs and prints their SHA256, ready to paste into the vendor-platform.ts table. (Class B only. Class A SDKs need no SHA; class C sources differ — see the reference.)
  • references/vendors.md — exhaustive per-vendor map: integration mechanism, exact pin location, SHA256 source/recipe, gotchas, and post-bump steps.

© dohooo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in .agents/skills/helmor-bump-vendors of dohooo/helmor.

  • SKILL.md
  • references/vendors.md
  • scripts/npm_vendor_sha.sh

Open the folder on GitHubat commit a76cda1

Compare with similar skills

Helmor Bump Vendors next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Helmor Bump Vendors compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Helmor Bump Vendors this skilldohooo/helmor1.3k—~2.1kAutomated safety check: PassApache-2.0
Prime Agentwcygan/dotfiles194—~1.8kAutomated safety check: PassNone
Agent SDK Version Bumppreset-io/agor1.4k—~1.4kAutomated safety check: PassCustom licence
Compact Memory Implementationsimbajigege/book2skills183—~2.5kAutomated safety check: PassMIT
Pi AgentK-Dense-AI/scientific-agent-skills48k1 repos~2.1kAutomated safety check: PassMIT
Agent BuilderMathews-Tom/armory329—~1.7kAutomated safety check: PassMIT

Similar skills

  • Prime Agent

    wcygan/dotfiles

    A skill your agent uses when learning, configuring, or troubleshooting Prime Agent (PrimeIntellect-ai/prime-agent), including installation, providers, custom OpenAI-compatible models, local…

    194 GitHub stars~1.8k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Upgrades a pinned agent SDK in the agor project, such as the Claude, Codex or Gemini CLI one, and plans the release that carries it to packaged installs.

    1.4k GitHub stars~1.4k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Compact Memory Implementation

    simbajigege/book2skills

    A developer guide to adding compact memory to an agent: when to trigger compaction, how to fork a compactor sub-agent, what the summary holds, and how to restore it.

    183 GitHub stars~2.5k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Pi Agent

    K-Dense-AI/scientific-agent-skills

    Builds with and operates Pi, the minimal terminal coding harness.

    48k GitHub starsUsed in 1 repo~2.1k tokens
    AI & LLM EngineeringAuto-check passed
  • Agent Builder

    Mathews-Tom/armory

    Build AI agents and automate Claude Code programmatically via the Claude Agent SDK and headless CLI mode.

    329 GitHub stars~1.7k tokensUpdated 5 days ago
    AI & LLM EngineeringAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 1 repo~775 tokens
    DevelopmentAuto-check passed

More from dohooo/helmor

  • Helmor CLI

    dohooo/helmor

    Use the Helmor CLI to remote-control Helmor from the terminal.

    1.3k GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Helmor Debug Loop

    dohooo/helmor

    Autonomous local-development debugging loop for Helmor bugs.

    1.3k GitHub stars~917 tokensUpdated 1 mo ago
    Auto-check passed
  • Helmor Release

    dohooo/helmor

    Prepare Helmor releases by inspecting the current branch, drafting a concise user-facing Changesets entry first (bump + body — keep it as short as possible), creating any needed pending in-app…

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check: warnings
  • Operate, reproduce, and debug a running local Helmor desktop development build through the Tauri MCP bridge.

    1.3k GitHub stars~6.6k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Helmor Bump Vendors

What does Helmor Bump Vendors do?

Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…. Helmor Bump Vendors is an agent skill from dohooo/helmor.cpp / Node.

When should I use Helmor Bump Vendors?

Helmor Bump Vendors fits situations like: the user wants to upgrade / bump / update / refresh a bundled agent CLI; check whether a vendor is behind latest; run a dependency version sweep in the Helmor repo.

How do I install Helmor Bump Vendors in Claude Code?

Run `npx skills add dohooo/helmor --skill helmor-bump-vendors -a claude-code`. Or copy the skill folder (.agents/skills/helmor-bump-vendors in dohooo/helmor) into .claude/skills/helmor-bump-vendors in your project. Claude Code loads it when a task matches its description.

How do I install Helmor Bump Vendors in Codex?

Run `npx skills add dohooo/helmor --skill helmor-bump-vendors -a codex`. Or copy the skill folder (.agents/skills/helmor-bump-vendors in dohooo/helmor) into .agents/skills/helmor-bump-vendors in your project. Codex loads it when a task matches its description.

Can I use Helmor Bump Vendors in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dohooo/helmor --skill helmor-bump-vendors -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/helmor-bump-vendors, .gemini/skills/helmor-bump-vendors, .github/skills/helmor-bump-vendors and .opencode/skills/helmor-bump-vendors in your project.

What does Helmor Bump Vendors need to run?

Going by SKILL.md and its folder, Helmor Bump Vendors needs a shell for the scripts in its folder and the command-line tools its instructions call (bun, cargo and codex). Our summary lists: A Bash shell.

Does Helmor Bump Vendors access the network?

SKILL.md names 2 domains. In commands or code: registry.npmjs.org and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Helmor Bump Vendors safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Helmor Bump Vendors use?

Helmor Bump Vendors is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Helmor Bump Vendors use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Helmor Bump Vendors?

Skills that share tags, products or a category with Helmor Bump Vendors: Prime Agent (wcygan/dotfiles, 194 stars), Agent SDK Version Bump (preset-io/agor, 1.4k stars), Compact Memory Implementation (simbajigege/book2skills, 183 stars) and Pi Agent (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Helmor Bump Vendors?

dohooo (a GitHub user) maintains it in dohooo/helmor, which has 1,309 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 22, 2026.

Source: dohooo/helmor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.