Agent skill

Logseq Dependency Upgrade

by logseq in logseq/logseq

Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…

AGPL-3.0Auto-check passedKnowledge Management

Install Logseq Dependency Upgrade

skills CLI
$ npx skills add logseq/logseq --skill logseq-dependency-upgrade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install logseq/logseq logseq-dependency-upgrade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/logseq-dependency-upgrade .claude/skills/logseq-dependency-upgrade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
logseq-dependency-upgrade
GitHub stars
45k
Token cost
~1.1k tokens
SKILL.md length
471 words
Files
2 (incl. scripts)
Skills in repo
12
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…

  • Works in 2 steps: Read the generated Markdown report — it… → To execute an upgrade batch
  • Tasks that involve Dependency management
  • SKILL.md covers Workflow, Audit scope, Classification and Version prefix preservation, plus 4 more sections
  • Runs JavaScript scripts from its folder; calls node

What it does

Logseq Dependency Upgrade is an agent skill from logseq/logseq. Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions, cross-root consistency, lockfile resolution, deprecation, staleness, and OSV vulnerabilities, then generating a batch-ordered upgrade plan and compact JSON artifact.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.

It sits in Knowledge Management, covering Dependency management. It works with npm. The repository describes itself as: A privacy-first, open-source platform for knowledge management and collaboration. Download link: http://github.com/logseq/logseq/releases. roadmap: https://logseq.io/p/NX4mcggEV. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Dependency management

Example prompts

  • “/logseq-dependency-upgrade”

Requirements

  • Node.js

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Read the generated Markdown report — it is the primary planning document, structured for batch-wise execution.
  2. To execute an upgrade batch

What it can do on your machine

Read from SKILL.md and the folder at commit 22a29b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Logseq Dependency Upgrade loads about 1.1k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 471 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from logseq/logseq at commit 22a29b3, republished under its AGPL-3.0 licence (© logseq). 471 words, ~1,066 tokens.

Download SKILL.mdSave it as .claude/skills/logseq-dependency-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
logseq-dependency-upgrade
description
Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions, cross-root consistency, lockfile resolution, deprecation, staleness, and OSV vulnerabilities, then generating a batch-ordered upgrade plan and compact JSON artifact.

Logseq Dependency Upgrade

Use this skill when the task is to audit dependencies, build an upgrade plan, or refresh dependency-upgrade facts for this repository.

Workflow

  1. Run the audit script:
bash
node .agents/skills/logseq-dependency-upgrade/scripts/audit_logseq_dependencies.mjs \
  --output-json <json-output-path> \
  --output-md <markdown-output-path> \
  [--stale-months <months>] \
  [--max-update-interval <months>] \
  [--include-prerelease]
  • --stale-months — number of months since last publish to flag a package as stale (default: 36).
  • --max-update-interval — maximum number of months between the current version's publish date and the latest version's publish date. If the interval is within this threshold, the package is NOT considered outdated and is excluded from upgrade batches (default: 6).
  • --include-prerelease — boolean flag (no value). When present, the Risk column annotates any newer upstream pre-release version (SNAPSHOT / RC / alpha / beta / nightly / canary etc.). The target version is always the latest stable release regardless of this flag. When absent (default), pre-release versions are neither fetched nor shown.
  1. Read the generated Markdown report — it is the primary planning document, structured for batch-wise execution.

  2. To execute an upgrade batch:

    • Read the target batch section from the Markdown report (one read, one self-contained table).
    • Apply the upgrades (change manifest files, run install/test).
    • Overwrite the batch's Status line and table to record results.
    • Update the Summary counts at the top.

CAUTION: Verify dependency usage before updating; remove unused packages instead of upgrading. For any dependency crossing a major version boundary, perform a rigorous review for breaking changes.

  1. After all batches, or to refresh data, rerun the audit script to regenerate both files.

Audit scope

  • Every non-gitignored package.json (dependencies + devDependencies).
  • Every non-gitignored deps.edn and nbb.edn (:deps + :aliases extra-deps / replace-deps — covers clj-kondo, test deps, etc.).
  • Every non-gitignored bb.edn (:deps + :pods).
  • Project-internal local/root deps (e.g. logseq/db, logseq/common) are excluded.
  • Gitignored / generated manifests are excluded.
Show full SKILL.md (199 more words)Show less

Classification

  1. Toolchain
  2. Root JS Incremental
  3. Root JS Major / High-Risk
  4. Clojure / Babashka Libraries
  5. deps/* & libs/* Package Islands
  6. packages/ui
  7. Mobile / Capacitor
  8. Infra / Build Islands
  9. Manual Review

Version prefix preservation

Target versions preserve the original specifier prefix. If current is ^1.0.0 and latest is 1.5.0, target is ^1.5.0. If current is 1.0.0 (fixed), target is 1.5.0.

Lockfile resolution

For npm packages with a range specifier (e.g. ^), the script checks pnpm-lock.yaml to see if the resolved version already matches latest. These packages are flagged as already resolved — they need only a manifest/range update, not a lockfile refresh/install, and carry zero upgrade risk.

Output contract

The script writes:

  • JSON — compact, no null/false/empty-default fields. Structured by batches[] array for machine consumption.
  • Markdown — batch-centric layout. Each batch is a self-contained section with a Status line and a table. An agent can read one batch section, execute it, and overwrite that section to record results — no scattered edits needed.

Notes

  • deprecated comes from upstream package metadata.
  • vulnerabilities come from OSV batch queries.
  • stale / low-maintenance is based on upstream publish dates.
  • Clojure package latest versions are fetched from Clojars first, then Maven Central as fallback.

Script

© logseq, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .agents/skills/logseq-dependency-upgrade of logseq/logseq.

  • SKILL.md
  • scripts/audit_logseq_dependencies.mjs

Open the folder on GitHubat commit 22a29b3

Compare with similar skills

Logseq Dependency Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Logseq Dependency Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Logseq Dependency Upgrade this skilllogseq/logseq45k—~1.1kAutomated safety check: PassAGPL-3.0
Validator Dependency Upgradeexpress-validator/express-validator6.2k—~1.2kAutomated safety check: PassMIT
Claude Code Version Checkykdojo/claude-code-tips10k—~1.8kAutomated safety check: PassCustom licence
Agent SDK Version Bumppreset-io/agor1.4k—~1.4kAutomated safety check: PassCustom licence
Bun Runtimespinspire/pocketbase-sveltekit-starter5115 repos~653Automated safety check: NotesMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT

Similar skills

  • Validator Dependency Upgrade

    express-validator/express-validator

    Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.

    6.2k GitHub stars~1.2k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Claude Code Version Check

    ykdojo/claude-code-tips

    Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.

    10k GitHub stars~1.8k tokensUpdated 12 days ago
    DevelopmentAuto-check passed
  • Upgrades a pinned agent SDK in the agor project, such as the Claude, Codex or Gemini CLI one, and plans the release that carries it to packaged installs.

    1.4k GitHub stars~1.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Bun Runtime

    spinspire/pocketbase-sveltekit-starter

    Bun as runtime, package manager, bundler, and test runner. An agent skill from spinspire/pocketbase-sveltekit-starter.

    511 GitHub starsUsed in 5 repos~653 tokens
    DevelopmentAuto-check: notes
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.

    2k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check: warnings

More from logseq/logseq

All 12 skills in this repo
  • Compare two revisions of the Logseq logseq-review-workflow skill by running the same review prompt against isolated before and after skill snapshots, collecting both outputs, and producing a…

    45k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Esm Cjs Risk Scan

    logseq/logseq

    Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.

    45k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Logseq Plugin SDK

    logseq/logseq

    Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).

    45k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Logseq CLI

    logseq/logseq

    Operate the current Logseq command-line interface to inspect or modify graphs, pages, blocks, tasks, tags, and properties; run Datascript queries; show page/block trees; manage graphs; and manage…

    45k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Logseq I18n

    logseq/logseq

    Logseq i18n workflow for adding, renaming, reviewing, or editing translation keys and user-facing strings.

    45k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Answer user questions about the Logseq repository by researching source code, docs, tests, runtime behavior, and local tools.

    45k GitHub stars~1.2k tokensUpdated today
    Auto-check: warnings

Works with

Questions about Logseq Dependency Upgrade

What does Logseq Dependency Upgrade do?

Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…. Logseq Dependency Upgrade is an agent skill from logseq/logseq.edn manifest, checking latest upstream versions, cross-root consistency, lockfile resolution, deprecation, staleness, and OSV vulnerabilities, then generating a batch-ordered upgrade plan and compact JSON artifact.

When should I use Logseq Dependency Upgrade?

Logseq Dependency Upgrade fits situations like: tasks that involve Dependency management.

How do I install Logseq Dependency Upgrade in Claude Code?

Run `npx skills add logseq/logseq --skill logseq-dependency-upgrade -a claude-code`. Or copy the skill folder (.agents/skills/logseq-dependency-upgrade in logseq/logseq) into .claude/skills/logseq-dependency-upgrade in your project. Claude Code loads it when a task matches its description.

How do I install Logseq Dependency Upgrade in Codex?

Run `npx skills add logseq/logseq --skill logseq-dependency-upgrade -a codex`. Or copy the skill folder (.agents/skills/logseq-dependency-upgrade in logseq/logseq) into .agents/skills/logseq-dependency-upgrade in your project. Codex loads it when a task matches its description.

Can I use Logseq Dependency Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add logseq/logseq --skill logseq-dependency-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/logseq-dependency-upgrade, .gemini/skills/logseq-dependency-upgrade, .github/skills/logseq-dependency-upgrade and .opencode/skills/logseq-dependency-upgrade in your project.

What does Logseq Dependency Upgrade need to run?

Going by SKILL.md and its folder, Logseq Dependency Upgrade needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.

Does Logseq Dependency Upgrade access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Logseq Dependency Upgrade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Logseq Dependency Upgrade use?

Logseq Dependency Upgrade is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Logseq Dependency Upgrade use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Logseq Dependency Upgrade?

Skills that share tags, products or a category with Logseq Dependency Upgrade: Validator Dependency Upgrade (express-validator/express-validator, 6.2k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars), Agent SDK Version Bump (preset-io/agor, 1.4k stars) and Bun Runtime (spinspire/pocketbase-sveltekit-starter, 511 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Logseq Dependency Upgrade?

logseq (a GitHub organization) maintains it in logseq/logseq, which has 45,158 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.

Source: logseq/logseq on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.