Agent skill

Framework Upstream Auto Update

by grandamenium in grandamenium/cortextos

Daily upstream framework auto-update workflow. An agent skill from grandamenium/cortextos.

MITAuto-check: notesDevelopment

Install Framework Upstream Auto Update

skills CLI
$ npx skills add grandamenium/cortextos --skill framework-upstream-auto-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grandamenium/cortextos framework-upstream-auto-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grandamenium/cortextos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/community/skills/framework-upstream-auto-update .claude/skills/framework-upstream-auto-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
framework-upstream-auto-update
GitHub stars
101
Token cost
~1.9k tokens
SKILL.md length
847 words
Files
1
Skills in repo
55
Repo updated
First seen
Licence
MIT

At a glance

Daily upstream framework auto-update workflow. An agent skill from grandamenium/cortextos.

  • Works in 8 steps: Fetch and inspect → Classify each commit → Check touched paths (HARD GUARDRAIL) → …
  • Tasks that involve Debugging
  • SKILL.md covers Trigger, Owner, Inputs and Procedure, plus 3 more sections
  • Calls npm and git

What it does

Framework Upstream Auto Update is an agent skill from grandamenium/cortextos. Daily upstream framework auto-update workflow. Fetches new cortextos commits, classifies by type and touched paths, auto-applies safe bug fixes, routes features/mixed to [ORCHESTRATOR] for approval, and verifies the apply with build + test before reporting.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging. The licence is MIT.

When your agent uses it

  • Tasks that involve Debugging

Example prompts

  • “/framework-upstream-auto-update”

Requirements

  • Node.js

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Fetch and inspect
  2. Classify each commit
  3. Check touched paths (HARD GUARDRAIL)
  4. Apply safe bugfix / docs / chore commits
  5. Handle feature or mixed batches (no apply)
  6. Report to [ORCHESTRATOR] on success
  7. Log and record (run this step ALWAYS, even for noop)
  8. Morning briefing hook

What it can do on your machine

Read from SKILL.md and the folder at commit 6f93838. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Framework Upstream Auto Update loads about 1.9k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 847 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:57
    - `**/.env*` — credentials and secrets

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grandamenium/cortextos at commit 6f93838, republished under its MIT licence (© grandamenium). 847 words, ~1,868 tokens.

Download SKILL.mdSave it as .claude/skills/framework-upstream-auto-update/SKILL.md (or your agent's skills folder).
name
framework-upstream-auto-update
description
Daily upstream framework auto-update workflow. Fetches new cortextos commits, classifies by type and touched paths, auto-applies safe bug fixes, routes features/mixed to [ORCHESTRATOR] for approval, and verifies the apply with build + test before reporting.
effort
low
triggers
upstream check, framework update, check upstream, upstream auto-update, framework upstream, apply upstream, sync upstream

Framework Upstream Auto-Update

Trigger

  • Daily cron (see config.json crons entry daily-framework-upstream-auto-update).
  • Ad hoc if [ORCHESTRATOR] or a user asks for an upstream check.

Owner

[AGENT_NAME] owns upstream framework health for the cortextos workspace. Bug fix application authority should be documented in your MEMORY.md or deployment config. Feature-level changes always route to [ORCHESTRATOR], who routes to the user for approval.

Inputs

  • Framework repo: the cortextos workspace root (the CTX_ROOT parent — the git repo, not the state dir)
  • Upstream: upstream/main (verify with git remote -v if unsure)
  • Current local state: local main can run ahead of upstream (your local fixes may flow upstream). Do NOT try to "sync" ahead-commits downward.

Procedure

Step 1 — Fetch and inspect
bash
cd /path/to/cortextos
cortextos bus check-upstream

Read the output. If it reports no new commits, skip to Step 7 (log noop and stop).

If there are new commits, list them:

bash
git fetch upstream main
git log --oneline HEAD..upstream/main
Step 2 — Classify each commit

For each new commit, read the subject and the diff:

bash
git show --stat <sha>
git show <sha>

Classification buckets:

BucketSubject patternsAction
bugfixfix(...), hotfix(...), fix:, BUG-###, closes BUG-###Auto-apply if safe paths
docs/choredocs:, chore:, test:, refactor:, ci:, build:Auto-apply if safe paths
featurefeat(...), feat:, new:Do NOT apply. Route to [ORCHESTRATOR] for approval.
mixedAny commit that contains multiple fix/feat changes or that is ambiguousRoute to [ORCHESTRATOR].
Step 3 — Check touched paths (HARD GUARDRAIL)

For EVERY new commit, scan the diff for touched paths. If ANY of the new commits touch any of these paths, do NOT auto-apply anything, flag the whole batch to [ORCHESTRATOR], and stop:

  • orgs/ — multi-tenant configuration, never auto-merge
  • **/.env* — credentials and secrets
  • **/memory/ (agent memory subfolders)
  • **/MEMORY.md (agent-level long-term memory)
  • community/skills/ — community skill catalog changes that affect running agents
  • community/agents/ — community agent templates that affect running agents

When flagging: collect the commit SHAs, commit messages, and touched paths, and send them to [ORCHESTRATOR] via cortextos bus send-message [ORCHESTRATOR] normal '<summary>'. Do not apply.

Step 4 — Apply safe bugfix / docs / chore commits

If all new commits are pure bugfix or docs/chore AND none touch the guardrail paths:

bash
cd /path/to/cortextos
CORTEXTOS_CONFIRM_UPSTREAM_MERGE=yes cortextos bus check-upstream --apply

The CORTEXTOS_CONFIRM_UPSTREAM_MERGE=yes env var is required. Without it, check-upstream --apply returns {"status": "error", "error": "Refusing to auto-merge upstream..."} as a safety gate. The env var is the "I have reviewed the diff and I trust the changes" signal. Set it inline, not exported, so it does not leak into subsequent unrelated commands.

After applying:

bash
cd /path/to/cortextos
npm install
npm audit --audit-level=moderate
npm run build
npm test

Security gate (v2): npm audit --audit-level=moderate runs AFTER npm install and BEFORE the build/test gate. If it reports any moderate+ vulnerability:

  • BLOCK the merge — do NOT proceed to build/test
  • Record the audit output (advisory IDs, affected packages, severity)
  • Report to [ORCHESTRATOR]: "Upstream merge blocked by npm audit: [advisory IDs]. Packages: [list]. Severity: [level]. Manual resolution required."
  • The merge stays unapplied until the vulnerability is resolved (upstream fix, manual override, or dep pin)

This gate catches security regressions where upstream merges silently downgrade a dependency that was previously patched (e.g. carrying a pinned old version that reintroduces a known CVE).

Build and test must also succeed. If either fails, DO NOT revert silently — report the failure to [ORCHESTRATOR] with the full error output and wait for instructions. The framework remains in its applied state; [ORCHESTRATOR] will decide whether to revert or patch.

Show full SKILL.md (321 more words)Show less
Step 5 — Handle feature or mixed batches (no apply)

If any new commit is feature or mixed but all paths are safe:

  • Do NOT run --apply
  • Send [ORCHESTRATOR] a summary message containing:
    • Commit list (SHA + subject)
    • Touched paths (de-duped)
    • Your recommendation: apply as-is, hold for user review, or request clarification
  • Wait for [ORCHESTRATOR] to route to the user. The cron exits after sending the message.
Step 6 — Report to [ORCHESTRATOR] on success

When a bugfix batch is successfully applied and the build + tests are green:

bash
cortextos bus send-message [ORCHESTRATOR] normal 'Framework upstream auto-update YYYY-MM-DD: applied N commits. Build + test green. Details: ...'

Include the commit list and any interesting touched paths (e.g. dist/cli.js rebuilt, specific src/ modules touched).

Step 7 — Log and record (run this step ALWAYS, even for noop)
bash
cortextos bus create-task "framework-upstream-check $(date +%Y-%m-%d)" --desc "Daily upstream check. Result: <applied N / flagged M / skipped K / noop>"
cortextos bus log-event action framework_updated info --meta '{"applied":N,"flagged":M,"skipped":K,"noop":BOOL}'

Write a single-line entry to today's daily memory file describing the result.

Step 8 — Morning briefing hook

Include whatever was applied or flagged overnight from Step 7's memory entry in the next morning brief. Users should see the result in their morning summary, not have to ask.

Failure Modes

  • Network failure fetching upstream → log a warning event, do not retry in-loop, wait for next day's run.
  • Merge conflict during apply → do NOT force. Report to [ORCHESTRATOR] with the conflict details and stop. [ORCHESTRATOR] + user will resolve by hand.
  • Build or test failure after apply → do NOT auto-revert. Report to [ORCHESTRATOR] with full error output. [ORCHESTRATOR] decides whether to revert, patch, or tolerate.
  • Unexpected touched path (new guardrail category) → flag to [ORCHESTRATOR], propose the new path for the guardrail list, wait for confirmation before adding it to this SKILL.

Deployment Config

Add to config.json crons:

json
{
  "name": "daily-framework-upstream-auto-update",
  "interval": "24h",
  "prompt": "Read and follow .claude/skills/framework-upstream-auto-update/SKILL.md"
}

Replace [AGENT_NAME] and [ORCHESTRATOR] with your agent's name and the orchestrator agent name in your deployment.

Notes

  • Local main is allowed to run ahead of upstream. check-upstream handles this correctly.
  • Never push to upstream as part of this flow. Push is a separate manual operation.
  • Bug fix application authority belongs to the user and should be granted explicitly in your deployment config or MEMORY.md.

© grandamenium, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in community/skills/framework-upstream-auto-update of grandamenium/cortextos.

Open the folder on GitHubat commit 6f93838

Compare with similar skills

Framework Upstream Auto Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Framework Upstream Auto Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Framework Upstream Auto Update this skillgrandamenium/cortextos101—~1.9kAutomated safety check: NotesMIT
Trellis Session Insightmindfold-ai/Trellis15k4 repos~1.7kAutomated safety check: PassAGPL-3.0
Native Data FetchingCherryHQ/cherry-studio-app4k6 repos~2.9kAutomated safety check: NotesMIT
Debugging Executionsn8n-io/n8n207k—~2.6kAutomated safety check: PassCustom licence
Aoti Debugpytorch/pytorch104k1 repos~1.7kAutomated safety check: PassCustom licence
Herdr Throwaway Reproductionherdrdev/herdr43k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Trellis Session Insight

    mindfold-ai/Trellis

    Reach into past AI conversation history through the trellis mem CLI.

    15k GitHub starsUsed in 4 repos~1.7k tokens
    DevelopmentAuto-check passed
  • Native Data Fetching

    CherryHQ/cherry-studio-app

    A skill your agent uses when implementing or debugging ANY network request, API call, or data fetching.

    4k GitHub starsUsed in 6 repos~2.9k tokens
    DevelopmentAuto-check: notes
  • Official

    Debug failed or wrong-output workflow executions using executions tools.

    207k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Aoti Debug

    pytorch/pytorch

    Debug AOTInductor (AOTI) errors and crashes. An agent skill from pytorch/pytorch.

    104k GitHub starsUsed in 1 repo~1.7k tokens
    DevelopmentAuto-check passed
  • Runs a disposable, uniquely named Herdr session inside an existing one so runtime, pane, terminal or API bugs can be reproduced without touching the main session.

    43k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Systematic Debugging

    ultralisp/ultralisp

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes

    258 GitHub starsUsed in 51 repos~2.4k tokens
    DevelopmentAuto-check passed

More from grandamenium/cortextos

All 55 skills in this repo
  • Cortext Self Diagnosis

    grandamenium/cortextos

    Diagnose cortextOS itself when the framework misbehaves — an agent has gone silent or wedged, agents are crash-looping, Telegram or agent-to-agent messages are not arriving, crons did not fire, an…

    101 GitHub stars~3.7k tokensUpdated 16 days ago
    Auto-check passed
  • Activity Channel

    grandamenium/cortextos

    You have completed something significant and want the whole org — all agents and the user — to know about it.

    101 GitHub stars~624 tokensUpdated 16 days ago
    Auto-check passed
  • Agentcard Purchase

    grandamenium/cortextos

    You need to make a purchase on behalf of the user — buy a SaaS subscription, pay for an API, purchase a domain, or any transaction requiring a credit card.

    101 GitHub stars~1.1k tokensUpdated 16 days ago
    Auto-check passed
  • Claude To Codex Migration

    grandamenium/cortextos

    Migrate ANY cortextOS agent from the claude-code runtime to the live codex-app-server runtime.

    101 GitHub stars~12k tokensUpdated 16 days ago
    Auto-check: warnings
  • Bus Reference

    grandamenium/cortextos

    Complete cortextos bus CLI reference - all available commands with examples.

    101 GitHub stars~3.8k tokensUpdated 16 days ago
    Auto-check passed
  • Business News Monitor

    grandamenium/cortextos

    Daily cron-driven scan of news/forums/social in a domain to surface market shifts, new competitors, regulatory changes, and net-new opportunities.

    101 GitHub stars~1.3k tokensUpdated 16 days ago
    Auto-check passed

Categories

Questions about Framework Upstream Auto Update

What does Framework Upstream Auto Update do?

Daily upstream framework auto-update workflow. An agent skill from grandamenium/cortextos. Framework Upstream Auto Update is an agent skill from grandamenium/cortextos. Daily upstream framework auto-update workflow.

When should I use Framework Upstream Auto Update?

Framework Upstream Auto Update fits situations like: tasks that involve Debugging.

How do I install Framework Upstream Auto Update in Claude Code?

Run `npx skills add grandamenium/cortextos --skill framework-upstream-auto-update -a claude-code`. Or copy the skill folder (community/skills/framework-upstream-auto-update in grandamenium/cortextos) into .claude/skills/framework-upstream-auto-update in your project. Claude Code loads it when a task matches its description.

How do I install Framework Upstream Auto Update in Codex?

Run `npx skills add grandamenium/cortextos --skill framework-upstream-auto-update -a codex`. Or copy the skill folder (community/skills/framework-upstream-auto-update in grandamenium/cortextos) into .agents/skills/framework-upstream-auto-update in your project. Codex loads it when a task matches its description.

Can I use Framework Upstream Auto Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grandamenium/cortextos --skill framework-upstream-auto-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/framework-upstream-auto-update, .gemini/skills/framework-upstream-auto-update, .github/skills/framework-upstream-auto-update and .opencode/skills/framework-upstream-auto-update in your project.

What does Framework Upstream Auto Update need to run?

Going by SKILL.md and its folder, Framework Upstream Auto Update needs the command-line tools its instructions call (npm and git). Our summary lists: Node.js.

Does Framework Upstream Auto Update access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Framework Upstream Auto Update safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Framework Upstream Auto Update use?

Framework Upstream Auto Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Framework Upstream Auto Update use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Framework Upstream Auto Update?

Skills that share tags, products or a category with Framework Upstream Auto Update: Trellis Session Insight (mindfold-ai/Trellis, 15k stars), Native Data Fetching (CherryHQ/cherry-studio-app, 4k stars), Debugging Executions (n8n-io/n8n, 207k stars) and Aoti Debug (pytorch/pytorch, 104k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Framework Upstream Auto Update?

grandamenium (a GitHub user) maintains it in grandamenium/cortextos, which has 101 GitHub stars. The repository holds 55 skills in this directory. The repository was last updated on September 23, 2026.

Source: grandamenium/cortextos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.