Agent skill

Upgrade Packages

by maotoumao in maotoumao/Cebian

调研 package.json 所有依赖的最新版本,交叉验证版本差异,给出可升级到最新版的结论. An agent skill from maotoumao/Cebian.

AGPL-3.0Auto-check passedDevelopment

Install Upgrade Packages

skills CLI
$ npx skills add maotoumao/Cebian --skill upgrade-packages -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maotoumao/Cebian upgrade-packages --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maotoumao/Cebian.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/upgrade-packages .claude/skills/upgrade-packages && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upgrade-packages
GitHub stars
164
Token cost
~505 tokens
SKILL.md length
115 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
AGPL-3.0

At a glance

调研 package.json 所有依赖的最新版本,交叉验证版本差异,给出可升级到最新版的结论. An agent skill from maotoumao/Cebian.

  • Works in 4 steps: 盘点依赖 → 逐库深入调研 → 交叉验证(必做) → …
  • Development work in your project
  • SKILL.md covers 工作流 and 输出格式
  • Calls pnpm

What it does

Upgrade Packages is an agent skill from maotoumao/Cebian. 调研 package.json 所有依赖的最新版本,交叉验证版本差异,给出可升级到最新版的结论

Its SKILL.md is about 510 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development. It works with npm, Chrome Extensions, pnpm and GitHub. The repository describes itself as: An AI assistant that lives in your browser side panel. The licence is AGPL-3.0.

When your agent uses it

  • Development work in your project

Example prompts

  • “/upgrade-packages”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 盘点依赖
  2. 逐库深入调研
  3. 交叉验证(必做)
  4. 分类结论

What it can do on your machine

Read from SKILL.md and the folder at commit 68c3d16. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upgrade Packages loads about 505 tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 115 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~16
When it runs · the whole SKILL.md, loaded when a task matches
~505

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maotoumao/Cebian at commit 68c3d16, republished under its AGPL-3.0 licence (© maotoumao). 115 words, ~505 tokens.

Download SKILL.mdSave it as .claude/skills/upgrade-packages/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
upgrade-packages
description
调研 package.json 所有依赖的最新版本,交叉验证版本差异,给出可升级到最新版的结论

帮我调研当前项目所有依赖的最新版本,深入对比每个库「已安装版本」和「最新版本」之间的内容差异,交叉验证后给出结论:哪些库可以安全升级到最新版。

这是一次调研 + 报告任务,默认不要修改 package.json 或执行安装命令。除非我明确要求,否则只产出结论,不动代码。

工作流

1. 盘点依赖
  • 读取 package.json,列出全部 dependencies 和 devDependencies。
  • 在终端运行 pnpm outdated(项目用 pnpm,不要用 npm/yarn)拿到「Current / Wanted / Latest」三列。
  • 如果我在参数里指定了具体库名,只处理这些库;否则处理全部有可升级版本的库。
  • 已经是最新版的库直接跳过,不必逐个写说明。
  • 不要更新typescript版本。
2. 逐库深入调研

对每个「有更新」的库,调研已安装版本 → 最新版本之间发生了什么:

  • 优先官方渠道:GitHub Releases / CHANGELOG.md / 官方迁移指南 / npm 页面。
  • 判断版本跳变性质:patch / minor / major(遵循 semver),跨越多个大版本时要把中间每个 major 的破坏性变更都覆盖到,不能只看最新一版。
  • 重点提取:breaking changes、废弃 API、需要手动迁移的步骤、对等依赖(peerDependencies)要求。
  • 特例 @earendil-works/pi-agent-core / pi-ai:变更日志在 pi monorepo 仓库内,不在 npm release notes——看 packages/ai/CHANGELOG.md 和 packages/agent/CHANGELOG.md(github.com/earendil-works/pi)。二者须锁步升到同一版本;深入调研这两个包时优先使用项目的 upgrade-pi workflow。
3. 交叉验证(必做)

每个结论至少要有两类独立来源相互印证,避免只信单一页面:

  • 来源交叉:GitHub Releases 与 CHANGELOG/官方文档说法是否一致。
  • 代码交叉:用代码搜索确认本项目实际怎么用这个库(用到的 API、入口、是否只是间接依赖),据此评估破坏性变更对本项目的真实影响——别人眼里的 breaking 在我们这儿可能根本没用到。
  • 生态交叉:注意 React 19、WXT、Tailwind v4 等关键依赖的 peer 兼容要求,别让单个升级破坏整体。特别地,typebox 与 pi(pi-ai / pi-agent-core)内部捆绑的 typebox 必须同版本——本项目精确 pin typebox(无 ^)就是为此,不要单独升 typebox,它只能跟随 pi 一起动;升级前后都去 pnpm-lock.yaml 核对 pi 解析的 typebox 版本。
  • 遇到来源互相矛盾或信息不足,如实标注「未确认」,不要猜。
4. 分类结论

把每个库归入下面四类之一,并给出一句话理由:

  • ✅ 可安全升级——patch/minor,无破坏性变更,本项目用法不受影响。
  • ⚠️ 可升级但需注意——有废弃项或行为变化,需小改或回归验证。
  • ⛔ 破坏性升级——major 跨越且本项目用到了受影响 API,需要改代码/迁移。
  • ❓ 暂不建议 / 待确认——信息不足、peer 冲突,或收益不明。

输出格式

先给一张总览表:

库已安装最新跳变结论一句话理由

再按「需要注意」「破坏性」「待确认」分组展开细节(✅ 可安全升级的库列在表里即可,不必逐个展开)。每个展开项写明:关键变更、对本项目的真实影响、升级要做的事、来源链接。

最后用一段话给出整体建议:这一轮优先升哪些、哪些先放着、有没有需要分批进行的。

调研中如果发现某个库的判断把握不大,直接告诉我「这个我没法确认」,并说明卡在哪里——不要给出没有依据的结论。

© maotoumao, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/upgrade-packages of maotoumao/Cebian.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 68c3d16

Compare with similar skills

Upgrade Packages next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upgrade Packages compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upgrade Packages this skillmaotoumao/Cebian164—~505Automated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Repomix Browser Extension Developeryamadashy/repomix29k1 repos~288Automated safety check: PassMIT
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Releaseseasonedcc/remix-forms514—~1.3kAutomated safety check: PassMIT

Similar skills

  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content…

    29k GitHub starsUsed in 1 repo~288 tokens
    DevelopmentAuto-check passed
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Release

    seasonedcc/remix-forms

    Release a new version of the remix-forms npm package. An agent skill from seasonedcc/remix-forms.

    514 GitHub stars~1.3k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Release Clawpatch

    openclaw/clawpatch

    clawpatch release: version/changelog, CI, npm publish, GitHub release, verify.

    813 GitHub stars~1.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from maotoumao/Cebian

  • Code Review

    maotoumao/Cebian

    A skill your agent uses when completing a coding task to perform senior-level code review.

    164 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • I18n Naming

    maotoumao/Cebian

    Cebian project i18n key naming, placeholder, pluralization, file layout, and glossary conventions.

    164 GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Skill Creator

    maotoumao/Cebian

    Create new Cebian skills, edit or improve existing ones, scaffold multi-file skill packages, and validate them against the agentskills.io specification.

    164 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Cl

    maotoumao/Cebian

    审计自上次发版以来的提交,把遗漏的「用户可见变更」补进 CHANGELOG.md 的 [Unreleased];可选地把 [Unreleased] 收口成正式版本节

    164 GitHub stars~428 tokensUpdated today
    Auto-check passed
  • Start Task

    maotoumao/Cebian

    Resume execution of an approved plan from the next unchecked subtask, following the gated Task Execution Workflow in AGENTS.md.

    164 GitHub stars~580 tokensUpdated today
    Auto-check passed
  • Upgrade Pi

    maotoumao/Cebian

    升级pi-agent-core和pi-ai到最新版本

    164 GitHub stars~894 tokensUpdated today
    Auto-check passed

Categories

Questions about Upgrade Packages

What does Upgrade Packages do?

调研 package.json 所有依赖的最新版本,交叉验证版本差异,给出可升级到最新版的结论. An agent skill from maotoumao/Cebian. Upgrade Packages is an agent skill from maotoumao/Cebian.

When should I use Upgrade Packages?

Upgrade Packages fits situations like: development work in your project.

How do I install Upgrade Packages in Claude Code?

Run `npx skills add maotoumao/Cebian --skill upgrade-packages -a claude-code`. Or copy the skill folder (.agents/skills/upgrade-packages in maotoumao/Cebian) into .claude/skills/upgrade-packages in your project. Claude Code loads it when a task matches its description.

How do I install Upgrade Packages in Codex?

Run `npx skills add maotoumao/Cebian --skill upgrade-packages -a codex`. Or copy the skill folder (.agents/skills/upgrade-packages in maotoumao/Cebian) into .agents/skills/upgrade-packages in your project. Codex loads it when a task matches its description.

Can I use Upgrade Packages in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maotoumao/Cebian --skill upgrade-packages -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-packages, .gemini/skills/upgrade-packages, .github/skills/upgrade-packages and .opencode/skills/upgrade-packages in your project.

What does Upgrade Packages need to run?

Going by SKILL.md and its folder, Upgrade Packages needs the command-line tools its instructions call (pnpm).

Does Upgrade Packages access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Upgrade Packages safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Upgrade Packages use?

Upgrade Packages is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upgrade Packages use?

About 505 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upgrade Packages?

Skills that share tags, products or a category with Upgrade Packages: Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Repomix Browser Extension Developer (yamadashy/repomix, 29k stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars) and Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upgrade Packages?

maotoumao (a GitHub user) maintains it in maotoumao/Cebian, which has 164 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 10, 2026.

Source: maotoumao/Cebian on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.