Upgrade an existing skill, plugin, agent, MCP integration, or agent-system package to a security-first production standard using pain research, architecture decisions, migration planning…

MITAuto-check passedAgent Workflows

Install Production Upgrade

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill production-upgrade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace production-upgrade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/production-upgrade .claude/skills/production-upgrade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
production-upgrade
GitHub stars
2.8k
Token cost
~2.4k tokens
SKILL.md length
999 words
Files
13 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Upgrade an existing skill, plugin, agent, MCP integration, or agent-system package to a security-first production standard using pain research, architecture decisions, migration planning…

  • Works in 6 steps: Recover context and establish authority → Research before designing → Decide scope and safety → …
  • Modernizing a legacy capability
  • SKILL.md covers Overview, When to use, Prerequisites and Orchestration, plus 5 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Production Upgrade is an agent skill from jeremylongshore/tons-of-skills-marketplace. Upgrade an existing skill, plugin, agent, MCP integration, or agent-system package to a security-first production standard using pain research, architecture decisions, migration planning, deterministic implementation, adversarial tests, independent review, and revision-bound evidence. Use when modernizing a legacy capability or asking for Databricks-level diligence. Trigger with "production upgrade", "modernize this skill", "bring this pack to production quality", or "audit and rebuild this plugin".

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including scripts and reference files (for example `eval-spec.yaml`, `references/beads-workflow.md` and `references/evidence-contract.md`). Compatibility notes: Agent Skills-compatible hosts; subagents and Beads are capability-detected with fail-closed fallback

It sits in Agent Workflows, covering MCP servers. It works with Databricks. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Modernizing a legacy capability
  • Asking for Databricks-level diligence
  • With production upgrade
  • Modernize this skill

Example prompts

  • “production upgrade”
  • “modernize this skill”
  • “bring this pack to production quality”
  • “/production-upgrade”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Agent Skills-compatible hosts; subagents and Beads are capability-detected with fail-closed fallback
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Recover context and establish authority
  2. Research before designing
  3. Decide scope and safety
  4. Plan and implement
  5. Validate proportionately
  6. Stop at the approval boundary

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Agent Skills-compatible hosts; subagents and Beads are capability-detected with fail-closed fallback

    From compatibility in the SKILL.md frontmatter.

Context cost

Production Upgrade loads about 2.4k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 999 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 999 words, ~2,350 tokens.

Download SKILL.mdSave it as .claude/skills/production-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
production-upgrade
description
Upgrade an existing skill, plugin, agent, MCP integration, or agent-system package to a security-first production standard using pain research, architecture decisions, migration planning, deterministic implementation, adversarial tests, independent review, and revision-bound evidence. Use when modernizing a legacy capability or asking for Databricks-level diligence. Trigger with "production upgrade", "modernize this skill", "bring this pack to production quality", or "audit and rebuild this plugin".
allowed-tools
Read, Write, Edit
compatibility
Agent Skills-compatible hosts; subagents and Beads are capability-detected with fail-closed fallback
version
1.0.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
production-upgrade, modernization, security, research, validation, beads

Production Upgrade

Run a risk-adjusted, evidence-bound modernization from discovery through a pre-release maintainer checkpoint. The workflow is complete without a specific model, subagent implementation, or task tracker, but it must honor stronger project requirements when they exist.

Overview

The quality bar comes from the Databricks rebuild: understand real operator pain, decide architecture before implementation, move load-bearing logic into deterministic code, preserve compatibility intentionally, and prove safety with negative and adversarial evidence. Match the depth to risk rather than matching another project's document count.

When to use

Use for a legacy artifact, broad rewrite, breaking migration, unsafe integration, or production-readiness claim. Do not trigger for a small typo, isolated bug fix, routine dependency bump, or read-only status question unless the user explicitly requests the full upgrade workflow.

Prerequisites

  • Target repository or artifact and its project instructions.
  • Authority to research and prepare local changes. Publication, deployment, merge, destructive cleanup, and external messaging remain separate approvals.
  • Current primary sources for externally defined contracts.

The pre-authorized Read, Write, and Edit capabilities apply only to local, scoped implementation files. Network, shell, task-tracker, subagent, install, and publication capabilities remain behind host and project approval.

Orchestration

Use five focused roles. When the host supports isolated subagents, dispatch the role packets under references/roles and have the coordinator reconcile their evidence. Otherwise execute the same packets sequentially in the main context. A same-identity or inline review is self-review, never independent.

RoleMutation authorityOutput
ResearcherNoneSource ledger, pain catalog, explicit gaps
ArchitectNoneScope synthesis, decision record, migration plan
Implementation engineerLocal scoped writes onlyMinimal implementation and focused tests
Verification engineerNoneReproduced commands, results, and hashes
Security adversaryNoneThreat-driven findings and exploit attempts

Instructions

1. Recover context and establish authority
  1. Read repository instructions, architecture owners, generated-file rules, current status, worktrees, active reviews, and existing task state.
  2. If the repository uses Beads, follow references/beads-workflow.md: prime, search, create or reuse, claim before mutation, and attach receipts. Project policy can make Beads mandatory.
  3. Preserve dirty work and contributor authorship. Isolate broad changes in a branch or worktree when available.
  4. Record the exact initial revision and the actions currently authorized.
2. Research before designing
  1. Audit the existing artifact, every active and retired capability, consumers, package identities, installation paths, and known defects.
  2. Research current primary sources for product, API, protocol, security, and runtime contracts. Add community or issue evidence for real operator pain when accessible and appropriate.
  3. Build a pain catalog: symptom, trigger, root cause, blast radius, current workaround, evidence, and the right agent primitive. Record source gaps rather than filling them with assumptions.
  4. Compare at least one relevant production benchmark for methodology, then explain where narrower or deeper treatment is justified by risk.
3. Decide scope and safety
  1. Consolidate capabilities around distinct operator outcomes, not quotas.
  2. Write an architecture decision covering adopted, modified, and rejected alternatives; authority boundaries; compatibility; migration; rollback; and explicit non-goals.
  3. Threat-model inputs, outputs, credentials, network destinations, file paths, dependencies, retries, mutations, reviewers, evidence, and publication.
  4. Make offline or read-only behavior the default. Unknown contracts, statuses, fields, destinations, or permissions fail closed.
  5. Put deterministic classification, arithmetic, validation, transformation, and policy decisions in reviewed scripts. Use model reasoning for synthesis and ambiguity, not for load-bearing calculations.
4. Plan and implement
  1. Define measurable acceptance gates before editing. Include structure, behavior, security, migration, provenance, and release evidence.
  2. Implement the smallest complete design. Keep the portable core independent of host adapters and avoid infrastructure that does not add verified capability.
  3. Preserve IDs or provide a machine-readable migration map. Breaking behavior requires an explicit major-version decision and user-facing migration path.
  4. Never generate plaintext secrets, remote-pipe installers, unbounded retries, silent destructive actions, fabricated provider responses, or blanket scanner waivers.
Show full SKILL.md (381 more words)Show less
5. Validate proportionately
  1. Run the narrowest focused tests first, then repository-required gates.

  2. Cover positive, negative, edge, adversarial, failure, and rollback paths. Deliberately broken variants must fail the same gate when certification is claimed.

  3. Validate generated projections, packaging file lists, installation from a disposable path, and removal or rollback where those surfaces changed.

  4. Reproduce every material automated-review finding independently. Reviewer silence or billing failure is unavailable evidence, not approval.

  5. Record evidence using references/evidence-contract.md and audit it without executing recorded commands:

    bash
    python3 scripts/audit_evidence.py upgrade-evidence.json --root <repository>
6. Stop at the approval boundary

Report the exact candidate revision, changed surfaces, test results, unresolved risks, reviewer status, migration impact, rollback, and publication state. Do not commit, push, open or update a PR, merge, tag, publish, deploy, delete, or message externally unless that action is authorized by the user and project policy. High-risk release approval is bound to the exact revision; a changed revision requires renewed approval.

Output

Return a concise executive status plus links to the research, decision, threat model, migration map, tests, and evidence manifest. Use these claim levels:

  • BLOCKED: a required safety or authority boundary failed.
  • CANDIDATE: implementation and local evidence exist; independent review or approval remains.
  • REVIEWED: independent review is bound to the exact revision; release is not yet authorized.
  • RELEASE-READY: all required gates and exact-revision authorization exist.

Error handling

  • Missing Beads when project policy requires it: stop before mutation.
  • Missing subagents: execute role packets inline and label review self-review.
  • Missing current primary source: constrain or remove the affected capability.
  • Conflicting authorities: stop and resolve the conflict at the named owner.
  • Failed test or unknown reviewer finding: remain BLOCKED or CANDIDATE; never average it into a score.
  • Dirty unrelated work: preserve and isolate; do not reset or overwrite it.

Examples

  • A narrow API pack may need fewer documents than Databricks but still requires an official contract audit, threat model, migration map, adversarial tests, exact-revision evidence, and explicit research gaps.
  • An MCP server with destructive methods requires stronger input, authorization, rollback, and live-boundary evidence than an offline read-only skill.
  • A model-neutral skill can be manually used by any capable model, while named native support remains limited to harnesses with registry-backed receipts.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts, references) in skills/.curated/production-upgrade of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • eval-spec.yaml
  • references/beads-workflow.md
  • references/evidence-contract.md
  • references/roles/architect.md
  • references/roles/implementation-engineer.md
  • references/roles/researcher.md
  • references/roles/security-adversary.md
  • references/roles/verification-engineer.md
  • references/runtime-portability.md
  • scripts/audit_evidence.py
  • templates/decision-record.md
  • templates/pain-catalog.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Production Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Production Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Production Upgrade this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.4kAutomated safety check: PassMIT
Tool Selectiondatabricks-solutions/ai-dev-kit1.9k—~519Automated safety check: PassCustom licence
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
PicoClaw Agentsipeed/picoclaw30k—~7.2kAutomated safety check: NotesMIT
Chatgpt AppsHaohao-end/openagent7911 repos~4.9kAutomated safety check: PassApache-2.0
Chatgpt App Builderalpic-ai/skybridge2.2k—~1kAutomated safety check: PassMIT

Similar skills

  • Tool Selection

    databricks-solutions/ai-dev-kit

    Evaluates whether the agent selected appropriate MCP tools instead of shell workarounds.

    1.9k GitHub stars~519 tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • PicoClaw Agent

    sipeed/picoclaw

    Answers questions about running and changing PicoClaw, from onboarding and model selection to MCP server setup, skill loading and scheduled jobs.

    30k GitHub stars~7.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Chatgpt Apps

    Haohao-end/openagent

    Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI.

    791 GitHub starsUsed in 1 repo~4.9k tokens
    Agent WorkflowsAuto-check passed
  • Chatgpt App Builder

    alpic-ai/skybridge

    Guide developers through creating and updating ChatGPT plugins.

    2.2k GitHub stars~1k tokensUpdated 3 days ago
    Agent WorkflowsAuto-check passed
  • Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

    7.2k GitHub stars~5.2k tokensUpdated today
    Agent WorkflowsAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Production Upgrade

What does Production Upgrade do?

Upgrade an existing skill, plugin, agent, MCP integration, or agent-system package to a security-first production standard using pain research, architecture decisions, migration planning…. Production Upgrade is an agent skill from jeremylongshore/tons-of-skills-marketplace. Upgrade an existing skill, plugin, agent, MCP integration, or agent-system package to a security-first production standard using pain research, architecture decisions, migration planning, deterministic implementation, adversarial tests, independent review, and revision-bound evidence.

When should I use Production Upgrade?

Production Upgrade fits situations like: modernizing a legacy capability; asking for Databricks-level diligence; with production upgrade; modernize this skill.

How do I install Production Upgrade in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill production-upgrade -a claude-code`. Or copy the skill folder (skills/.curated/production-upgrade in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/production-upgrade in your project. Claude Code loads it when a task matches its description.

How do I install Production Upgrade in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill production-upgrade -a codex`. Or copy the skill folder (skills/.curated/production-upgrade in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/production-upgrade in your project. Codex loads it when a task matches its description.

Can I use Production Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill production-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/production-upgrade, .gemini/skills/production-upgrade, .github/skills/production-upgrade and .opencode/skills/production-upgrade in your project.

What does Production Upgrade need to run?

Going by SKILL.md and its folder, Production Upgrade needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Agent Skills-compatible hosts; subagents and Beads are capability-detected with fail-closed fallback.

Does Production Upgrade access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Production Upgrade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Production Upgrade use?

Production Upgrade is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Production Upgrade use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Production Upgrade?

Skills that share tags, products or a category with Production Upgrade: Tool Selection (databricks-solutions/ai-dev-kit, 1.9k stars), Crush Configuration (charmbracelet/crush, 29k stars), PicoClaw Agent (sipeed/picoclaw, 30k stars) and Chatgpt Apps (Haohao-end/openagent, 791 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Production Upgrade?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.