Agent skill

Upstream Audit

by kdeldycke in kdeldycke/dotfiles

Create or update the upstream contributions page (docs/upstream.md), which records what this project sends back to its dependencies.

BSD-2-ClauseAuto-check: notesDevelopment

Install Upstream Audit

skills CLI
$ npx skills add kdeldycke/dotfiles --skill upstream-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdeldycke/dotfiles upstream-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dotfiles/.agents/skills/upstream-audit .claude/skills/upstream-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upstream-audit
GitHub stars
173
Token cost
~2.6k tokens
SKILL.md length
1,033 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
BSD-2-Clause

At a glance

Create or update the upstream contributions page (docs/upstream.md), which records what this project sends back to its dependencies.

  • Works in 9 steps: Identify the maintainer → Identify upstream dependencies → Discover contributions → …
  • Development work in your project
  • SKILL.md covers Context and Instructions
  • Calls gh, git and pip; reaches pypi.org

What it does

Upstream Audit is an agent skill from kdeldycke/dotfiles. Create or update the upstream contributions page (docs/upstream.md), which records what this project sends back to its dependencies. Find merged PRs, reported issues, workarounds and declined features.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Recommended model: Opus.

It sits in Development. It works with Git. The repository describes itself as: 🍎 macOS dotfiles for Python developers. The licence is BSD-2-Clause.

When your agent uses it

  • Development work in your project

Example prompts

  • “/upstream-audit”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code. Recommended model: Opus.
  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, Agent

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Identify the maintainer
  2. Identify upstream dependencies
  3. Discover contributions
  4. Check status of each item
  5. Scan git history
  6. Categorize each item
  7. Build the page
  8. Status check
  9. Consistency checks

What it can do on your machine

Read from SKILL.md and the folder at commit 7947d0f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • pypi.org

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code. Recommended model: Opus.

    From compatibility in the SKILL.md frontmatter.

Context cost

Upstream Audit loads about 2.6k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 1,033 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdeldycke/dotfiles at commit 7947d0f, republished under its BSD-2-Clause licence (© kdeldycke). 1,033 words, ~2,579 tokens.

Download SKILL.mdSave it as .claude/skills/upstream-audit/SKILL.md (or your agent's skills folder).
name
upstream-audit
description
Create or update the upstream contributions page (docs/upstream.md), which records what this project sends back to its dependencies. Find merged PRs, reported issues, workarounds and declined features.
allowed-tools
Bash, Read, Grep, Glob, Agent
compatibility
Designed for Claude Code. Recommended model: Opus.
argument-hint
[audit|init|refresh|sync-git]

Context

![ -f pyproject.toml ] && grep '^name' pyproject.toml | head -1 || echo "No pyproject.toml" !git config user.name 2>/dev/null || echo "No git user" !gh api /user --jq '.login' 2>/dev/null || echo "No gh auth" ![ -f docs/upstream.md ] && grep '^## ' docs/upstream.md || echo "No docs/upstream.md yet" ![ -f docs/upstream.md ] && grep -c 'github.com/' docs/upstream.md || echo 0

Instructions

You create and maintain docs/upstream.md, which tracks the project's relationship with its upstream dependencies: code contributed back, workarounds provided, issues reported, and features declined.

Reference example

Fetch this file as reference when building or auditing an upstream page:

  • kdeldycke/click-extra/docs/upstream.md: tracks merged PRs across Click, python-tabulate, Pygments, Furo, Cloup, and click-contrib projects, plus upstreamed workarounds, feature-area-grouped workarounds still in place, declined PRs, and open upstream issues.
Document structure

The page uses five sections:

  1. Code contributed upstream - PRs authored by the maintainer and merged into upstream projects. Organized by project, optionally grouped by theme within large projects.
  2. Upstreamed from this project - Issues the project solved with local workarounds first, then the fix was contributed upstream and the workaround removed locally.
  3. Addressed by this project - Issues that remain open or unfixed upstream; this project provides the solution. Grouped by feature area.
  4. Declined by upstream - PRs or issues rejected by upstream maintainers; this project provides the functionality regardless.
  5. Open upstream - PRs and issues still pending upstream.

Items are listed as markdown links: - [`#N` - Title](url)

Scope selection
  • audit (default): Check status of all linked issues/PRs in an existing page and report items that need to move between sections.
  • init: Create docs/upstream.md from scratch by discovering all upstream contributions.
  • refresh: Same as audit, but also apply the changes.
  • sync-git: Scan the git log for upstream references not yet in the document.
Creating from scratch (init)
1. Identify the maintainer

Determine the GitHub username from gh api /user --jq '.login' or git config user.name. Confirm with the user.

2. Identify upstream dependencies

Extract dependencies from pyproject.toml (both [project.dependencies] and [project.optional-dependencies]/[dependency-groups]). For each dependency, find its GitHub repository:

  • Check PyPI metadata: pip show <pkg> or https://pypi.org/pypi/<pkg>/json
  • Check uv.lock for source URLs

Also include significant build/test/docs dependencies (Sphinx themes, pytest plugins, linters) that the project interacts with.

3. Discover contributions

For each upstream repo, search for the maintainer's participation:

gh api "repos/{owner}/{repo}/issues?creator={username}&state=all&per_page=100" \
  --jq '.[] | "#\(.number) \(.title) [\(.state)] \(.pull_request // empty | "PR") \(.html_url)"'

For repos with many results, also check PRs specifically:

gh search prs --author {username} --repo {owner}/{repo} --limit 50

For a maintainer active across many projects, sweep globally first and filter by repo afterwards: one search over everything they authored beats guessing the repo list, and surfaces upstreams nobody remembered.

gh search prs --author {username} --limit 1000 --json repository,number,title,state,url -- -user:{username}
gh search issues --author {username} --limit 1000 --json repository,number,title,state,url -- -user:{username}

Three traps in that sweep:

  • The raw qualifier excluding their own repos (-user:{username}) must come after the -- separator, and every flag before it: anything after -- is read as a search term.
  • Results are best-match, so a --limit below the true total drops the oldest items silently. Treat a result count equal to the limit as truncated.
  • A URL cited in the codebase is not a contribution: authorship from these sweeps separates "we filed it" from "we cite someone else's issue as evidence". Both matter, but they land in different sections.

When the maintainer runs several projects with upstream pages, dedupe against the sibling pages and give each item one canonical home: the project whose code consumes the dependency. Distribution packaging of the project itself belongs to its packaging docs, not this page.

4. Check status of each item

For PRs: gh pr view <url> --json state,mergedAt,title For issues: gh issue view <url> --json state,stateReason,title

To resolve many items at once, batch them into a single GraphQL call with aliased issueOrPullRequest nodes:

gh api graphql -F query=@states.graphql
graphql
query {
  a1: repository(owner: "{owner}", name: "{repo}") { issueOrPullRequest(number: 123) { ...S } }
  a2: repository(owner: "{owner}", name: "{repo}") { issueOrPullRequest(number: 456) { ...S } }
}
fragment S on IssueOrPullRequest {
  ... on Issue { state stateReason title }
  ... on PullRequest { state merged title }
}

stateReason separates a completed issue from one closed as not planned, which decides its section.

5. Scan git history

Search the git log for upstream references not yet found:

git log --all --oneline --grep="github.com/" | head -100

Search the codebase for inline issue references:

grep -rn 'github\.com/.*/\(issues\|pull\)/' src/ lib/ --include="*.py" | grep -v __pycache__

Also check docs/ and any changelog for upstream references.

Show full SKILL.md (416 more words)Show less
6. Categorize each item
Item typeStatusSection
PRmergedCode contributed upstream
PRclosed, not mergedDeclined by upstream
PRopenOpen upstream
Issueclosed, this project had workaround, workaround removedUpstreamed from this project
Issueopen or closed, this project provides workaroundAddressed by this project
Issueclosed as not plannedDeclined by upstream
Issueopen, no local workaroundOpen upstream

To determine whether the project has a workaround for an issue, search the codebase for references to that issue URL or number.

7. Build the page

Write the document following the five-section structure. Within "Code contributed upstream", group PRs by upstream project and optionally by theme (for projects with many PRs). Within "Addressed by this project", group by feature area rather than by upstream project.

Use the {octicon} title format if sphinx-design is available (check docs/conf.py for the extension):

markdown
# {octicon}`git-pull-request` Upstream
Auditing an existing page (audit)
1. Status check

For every GitHub URL in the document, check its current state via gh:

  • For PRs: gh pr view <url> --json state,mergedAt
  • For issues: gh issue view <url> --json state,stateReason

Flag items that need to move:

Current sectionNew stateAction
Open upstreamPR mergedMove to "Code contributed upstream"
Open upstreamIssue closed as completedMove to "Upstreamed" or "Addressed" depending on whether a local workaround existed
Open upstreamClosed as not plannedMove to "Declined by upstream"
Addressed by this projectFixed upstreamMove to "Upstreamed from this project"
2. Consistency checks
  • All items in "Code contributed upstream" are actually merged (not just closed).
  • All items in "Open upstream" are actually still open.
  • No item appears in multiple sections.
  • Items within each project subsection are sorted by issue number (newest first).
Git log scan (sync-git)

Search for upstream references not yet tracked:

git log --all --oneline --grep="github.com/" | head -100
git log --all --oneline --grep="upstream" | head -50
git log --all --oneline --grep="workaround" | head -50
git log --all --oneline --grep="backport" | head -50

For each new reference, determine which section it belongs to and report it.

Output format

For audit, produce a summary:

ActionCount
Items to moveN
New items to addN
Stale items to removeN

Then list each change with: URL, current section, recommended section, reason.

Do not edit the file until the user confirms (except with refresh).

Cross-referencing with docs/benchmark.md

The upstream page and the benchmark page both track upstream issues and PRs. When items change status in docs/upstream.md (a gap gets fixed, a workaround gets upstreamed, a PR gets merged), check whether docs/benchmark.md has a corresponding entry in its "Gaps and opportunities" or feature tables that needs updating. Suggest running /benchmark-update audit afterward if upstream changes affect the competitive comparison.

© kdeldycke, BSD-2-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in dotfiles/.agents/skills/upstream-audit of kdeldycke/dotfiles.

Open the folder on GitHubat commit 7947d0f

Compare with similar skills

Upstream Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upstream Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upstream Audit this skillkdeldycke/dotfiles173—~2.6kAutomated safety check: NotesBSD-2-Clause
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Finishing A Development Branchfarm-fe/farm5.6k34 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • A skill your agent uses when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for…

    5.6k GitHub starsUsed in 34 repos~1.8k tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    56k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed

More from kdeldycke/dotfiles

All 25 skills in this repo
  • Agent Config Self Tune

    kdeldycke/dotfiles

    Audit and tune the configuration of coding agents across Claude Code and pi - settings files (settings.json, settings.local.json), permission rules, instruction files (CLAUDE.md, AGENTS.md), skill…

    173 GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check: notes
  • Audit Repo Issues

    kdeldycke/dotfiles

    Analyze a GitHub repository's issues and PRs to find unaddressed feature requests, dismissed ideas, maintenance signals, and opportunities relevant to the current project.

    173 GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check passed
  • Brand Assets

    kdeldycke/dotfiles

    Create project logo and banner SVGs, then export them to light and dark PNG variants.

    173 GitHub stars~4.7k tokensUpdated 5 days ago
    Auto-check passed
  • Fill Web Form

    kdeldycke/dotfiles

    Fill a web form using data extracted from local documents (PDFs, images, spreadsheets).

    173 GitHub stars~2.3k tokensUpdated 5 days ago
    Auto-check passed
  • Rename With Dates

    kdeldycke/dotfiles

    Rename documents and files (PDFs, images, screenshots, etc.) by reading their content to extract the effective/publication date, then renaming them with a "YYYY-MM-DD - Clear descriptive title.ext"…

    173 GitHub stars~3.5k tokensUpdated 5 days ago
    Auto-check passed
  • Repomatic Test Matrix

    kdeldycke/dotfiles

    Choose what a repository's CI test matrix covers. An agent skill from kdeldycke/dotfiles.

    173 GitHub stars~2.2k tokensUpdated 5 days ago
    Auto-check: notes

Works with

Categories

Questions about Upstream Audit

What does Upstream Audit do?

Create or update the upstream contributions page (docs/upstream.md), which records what this project sends back to its dependencies. Upstream Audit is an agent skill from kdeldycke/dotfiles.md), which records what this project sends back to its dependencies.

When should I use Upstream Audit?

Upstream Audit fits situations like: development work in your project.

How do I install Upstream Audit in Claude Code?

Run `npx skills add kdeldycke/dotfiles --skill upstream-audit -a claude-code`. Or copy the skill folder (dotfiles/.agents/skills/upstream-audit in kdeldycke/dotfiles) into .claude/skills/upstream-audit in your project. Claude Code loads it when a task matches its description.

How do I install Upstream Audit in Codex?

Run `npx skills add kdeldycke/dotfiles --skill upstream-audit -a codex`. Or copy the skill folder (dotfiles/.agents/skills/upstream-audit in kdeldycke/dotfiles) into .agents/skills/upstream-audit in your project. Codex loads it when a task matches its description.

Can I use Upstream Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdeldycke/dotfiles --skill upstream-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upstream-audit, .gemini/skills/upstream-audit, .github/skills/upstream-audit and .opencode/skills/upstream-audit in your project.

What does Upstream Audit need to run?

Going by SKILL.md and its folder, Upstream Audit needs the command-line tools its instructions call (gh, git and pip). Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Agent. Compatibility (from SKILL.md): Designed for Claude Code. Recommended model: Opus..

Does Upstream Audit access the network?

SKILL.md names 2 domains. In commands or code: pypi.org; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Upstream Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Upstream Audit use?

Upstream Audit is published under the BSD-2-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upstream Audit use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upstream Audit?

Skills that share tags, products or a category with Upstream Audit: Finishing a Development Branch (obra/superpowers, 297k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Code Design Rationale Investigator (cursor/plugins, 10k stars) and Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upstream Audit?

kdeldycke (a GitHub user) maintains it in kdeldycke/dotfiles, which has 173 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 4, 2026.

Source: kdeldycke/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.