Agent skill

Upgrade Notes

by getknit in getknit/knit

Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

GPL-3.0Auto-check passedSecurity

Install Upgrade Notes

skills CLI
$ npx skills add getknit/knit --skill upgrade-notes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getknit/knit upgrade-notes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getknit/knit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/upgrade-notes .claude/skills/upgrade-notes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upgrade-notes
GitHub stars
130
Token cost
~1.2k tokens
SKILL.md length
588 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
GPL-3.0

At a glance

Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

  • Works in 5 steps: List what is moving. For each… → Call upgrade_notes, up to 20… → Check match before you read anything.… → …
  • Any dependency version changes in this repository — a bump
  • SKILL.md covers When the tool is missing and Steps
  • Reaches whatsnew.fyi

What it does

Upgrade Notes is an agent skill from getknit/knit. Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. Use WHENEVER any dependency version changes in this repository — a bump, downgrade, add or swap in gradle/libs.versions.toml, gradle/wrapper/gradle-wrapper.properties, a plugin or buildscript version, a GitHub Actions uses: ref, or a CI image tag — and whenever asked "is it safe to upgrade X", "what changed in X…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Dependency management, Vulnerability scanning and CI/CD. It works with Gradle, Model Context Protocol, GitHub Actions and Kotlin. The repository describes itself as: Offline, serverless, end-to-end-encrypted mesh messenger for Android — runs Wi-Fi Aware and Bluetooth LE simultaneously, with no servers and no Google Play Services. The licence is GPL-3.0.

When your agent uses it

  • Any dependency version changes in this repository — a bump
  • Swap in gradle/libs.versions.toml
  • Gradle/wrapper/gradle-wrapper.properties
  • Buildscript version

Example prompts

  • “is it safe to upgrade X”
  • “what changed in X since Y”
  • “/upgrade-notes”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. List what is moving. For each dependency, take from from what is pinned now (the catalog entry,
  2. Call upgrade_notes, up to 20 dependencies per call. The tool has no Maven registry: the
  3. Check match before you read anything. match.slug must be the library you meant. A note that
  4. Read the result per dependency.
  5. Act on it. Apply migrations the notes call for in the same change as the bump. Report to the user,

What it can do on your machine

Read from SKILL.md and the folder at commit 71c07bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • whatsnew.fyi

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upgrade Notes loads about 1.2k tokens when it runs. Until then it costs about 165 tokens; SKILL.md has 588 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~165
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getknit/knit at commit 71c07bc, republished under its GPL-3.0 licence (© getknit). 588 words, ~1,222 tokens.

Download SKILL.mdSave it as .claude/skills/upgrade-notes/SKILL.md (or your agent's skills folder).
name
upgrade-notes
description
Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the `whatsnew` MCP server's `upgrade_notes` tool. Use WHENEVER any dependency version changes in this repository — a bump, downgrade, add or swap in `gradle/libs.versions.toml`, `gradle/wrapper/gradle-wrapper.properties`, a plugin or `buildscript` version, a GitHub Actions `uses:` ref, or a CI image tag — and whenever asked "is it safe to upgrade X", "what changed in X since Y", or to review a Renovate/Dependabot-style bump. Run it BEFORE editing the version, not after the build breaks.

Upgrade notes

Every version change in this repo gets the vendor's own notes read first. The whatsnew MCP server (https://whatsnew.fyi/mcp, declared in .mcp.json, no auth) returns every tracked release between two versions with the breaking, deprecation, migration and security sections verbatim, including breaking changes that shipped in a minor or a patch.

This skill tells you what to read before a bump. .agents/context/toolchain.md still decides whether the bump is allowed (minCompileSdk, the Kotlin/KSP lockstep, stable-only). Read both.

When the tool is missing

If no whatsnew tools are loaded, the server is not approved in this session. Tell the user once (Claude Code: /mcp, approve whatsnew) and carry on with the upgrade by reading the vendor's release notes directly. The skill is advisory; never block a bump on it.

Steps

  1. List what is moving. For each dependency, take from from what is pinned now (the catalog entry, or app/gradle.lockfile / settings-gradle.lockfile for a transitive one) and to from the target version. Use exact versions, never ranges. A catalog [versions] key that several libraries share (lifecycle, cameraX, room3) is one call, not one per artifact.

  2. Call upgrade_notes, up to 20 dependencies per call. The tool has no Maven registry: the registry field takes only npm, pypi, crates and rubygems, so leave it out and let repository make the match.

    • name: the Maven coordinate group:artifact, the plugin id, or the action's owner/repo.
    • repository: the library's GitHub repo as owner/repo, whenever it has one. Without it a Maven coordinate usually comes back untracked. Measured on this catalog: JetBrains/kotlin, google/ksp, square/okhttp, InsertKoinIO/koin, coil-kt/coil, tink-crypto/tink-java, robolectric/robolectric, pinterest/ktlint, detekt/detekt, gradle/gradle.
  3. Check match before you read anything. match.slug must be the library you meant. A note that says "Matched by name only" is a guess, and it can be wrong:

    • com.android.tools.build:gradle (AGP, and apksig rides the same version) matches Gradle, the build tool, by name. Call it with name: "android-gradle-plugin" instead.
    • For androidx and other Google libraries with no GitHub repo, the coordinate comes back untracked. Call list_products with the library's product name, then retry upgrade_notes with that slug as name. Measured: camerax and room resolve this way; Compose, lifecycle, core, activity, navigation and datastore are not tracked.
    • Discard a result whose slug is some other product. Don't report its notes.
  4. Read the result per dependency.

    • status: ok: start with signals (major bump, breaking mentions, removed and deprecated counts, cves), then read each entry in releases for its sections (breaking, security, deprecated, migration). The dependency's changes is the categorized list across the whole interval. A section's under names the sub-package in a monorepo release; skip sections about artifacts this app doesn't use.
    • untracked, unversioned, unreadable: What's New has no usable history for it. Read the vendor's notes yourself and say so.
    • notes like "is not tracked yet; the newest we track is …": the target version is newer than the tracked history (common with a same-week release), or it is a pre-release. The history holds stable releases only, so the detekt 2.0.0-alpha line and similar return no notes. Fall back to the vendor's notes for that stretch.
    • truncated or a cut change list: open the release's url or sourceUrl for the rest before concluding there is nothing breaking.
  5. Act on it. Apply migrations the notes call for in the same change as the bump. Report to the user, per dependency: breaking items that touch code or config this repo uses, CVEs fixed, and anything unchecked because it was untracked. Don't paste the whole payload. Then follow .agents/rules/build-and-test.md (regenerate every lock, then ./gradlew lint).

© getknit, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/upgrade-notes of getknit/knit.

Open the folder on GitHubat commit 71c07bc

Compare with similar skills

Upgrade Notes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upgrade Notes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upgrade Notes this skillgetknit/knit130—~1.2kAutomated safety check: PassGPL-3.0
Levyra CI WorkflowsLUC4N3X/Levyra-deepsound543—~2kAutomated safety check: PassGPL-3.0
Review Dependenciestobihagemann/turbo406—~1.5kAutomated safety check: PassMIT
Kt Search Releasejillesvangurp/kt-search155—~1.2kAutomated safety check: PassMIT
Validating Compose Stabilityskydoves/android-testing-skills333—~3.5kAutomated safety check: PassApache-2.0
Android Developmentdpconde/claude-android-skill336—~1.7kAutomated safety check: PassMIT

Similar skills

  • Levyra CI Workflows

    LUC4N3X/Levyra-deepsound

    Automatically use for Levyra GitHub Actions, CI, F-Droid, Gradle/AGP/Kotlin/KSP compatibility, build performance, configuration/build cache, artifacts, release automation, workflow security, or…

    543 GitHub stars~2k tokensUpdated today
    MobileAuto-check passed
  • Review Dependencies

    tobihagemann/turbo

    Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

    406 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Kt Search Release

    jillesvangurp/kt-search

    A skill your agent uses when the user wants to cut, publish, tag, or create a GitHub release for kt-search, especially when the task includes version bumping, validating that commits are pushed…

    155 GitHub stars~1.2k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Validating Compose Stability

    skydoves/android-testing-skills

    A skill your agent uses to gate CI on Jetpack Compose stability — catch when a composable becomes unskippable/unrestartable or a parameter goes stable → unstable, before it ships and tanks…

    333 GitHub stars~3.5k tokensUpdated 4 mo ago
    MobileAuto-check passed
  • Android Development

    dpconde/claude-android-skill

    Create production-quality Android applications following Google's official architecture guidance and NowInAndroid best practices.

    336 GitHub stars~1.7k tokensUpdated 10 mo ago
    MobileAuto-check passed
  • Official

    Looks up Kotlin Multiplatform libraries, their latest stable versions, Gradle coordinates and verified target support through klibs.io instead of guessing.

    108 GitHub stars~1.1k tokensUpdated 2 days ago
    MobileAuto-check passed

More from getknit/knit

  • Kotlin Patterns

    getknit/knit

    Idiomatic Kotlin patterns, best practices, and conventions for building robust, efficient, and maintainable Kotlin applications with coroutines, null safety, and DSL builders.

    130 GitHub starsUsed in 5 repos~4.7k tokens
    Auto-check passed
  • Dotagents Standard

    getknit/knit

    Set up, author, and navigate the dotagents standard — a slim AGENTS.md "router" at the repository root plus a hidden .agents/ directory (rules, context, memory, personas, skills, specs, logs, tasks)…

    130 GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Debug Bridge

    getknit/knit

    Drive and verify Knit on a device or emulator through the headless debug bridge (am broadcast to app.getknit.knit.debug.<ACTION, replies as JSON) — send a message on one phone and confirm it landed…

    130 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Upgrade Notes

What does Upgrade Notes do?

Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool. Upgrade Notes is an agent skill from getknit/knit. Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

When should I use Upgrade Notes?

Upgrade Notes fits situations like: any dependency version changes in this repository — a bump; swap in gradle/libs.versions.toml; gradle/wrapper/gradle-wrapper.properties; buildscript version.

How do I install Upgrade Notes in Claude Code?

Run `npx skills add getknit/knit --skill upgrade-notes -a claude-code`. Or copy the skill folder (.agents/skills/upgrade-notes in getknit/knit) into .claude/skills/upgrade-notes in your project. Claude Code loads it when a task matches its description.

How do I install Upgrade Notes in Codex?

Run `npx skills add getknit/knit --skill upgrade-notes -a codex`. Or copy the skill folder (.agents/skills/upgrade-notes in getknit/knit) into .agents/skills/upgrade-notes in your project. Codex loads it when a task matches its description.

Can I use Upgrade Notes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getknit/knit --skill upgrade-notes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-notes, .gemini/skills/upgrade-notes, .github/skills/upgrade-notes and .opencode/skills/upgrade-notes in your project.

What does Upgrade Notes need to run?

SKILL.md names no scripts, command-line tools or credentials: Upgrade Notes is instructions for the agent only.

Does Upgrade Notes access the network?

SKILL.md names 1 domain. In commands or code: whatsnew.fyi; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Upgrade Notes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Upgrade Notes use?

Upgrade Notes is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upgrade Notes use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upgrade Notes?

Skills that share tags, products or a category with Upgrade Notes: Levyra CI Workflows (LUC4N3X/Levyra-deepsound, 543 stars), Review Dependencies (tobihagemann/turbo, 406 stars), Kt Search Release (jillesvangurp/kt-search, 155 stars) and Validating Compose Stability (skydoves/android-testing-skills, 333 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upgrade Notes?

getknit (a GitHub organization) maintains it in getknit/knit, which has 130 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 4, 2026.

Source: getknit/knit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.