Agent skill

Dsh Upgrade Audit

by NanmiCoder in NanmiCoder/dsh-auto-mode

Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…

MITAuto-check passedDevelopment

Install Dsh Upgrade Audit

skills CLI
$ npx skills add NanmiCoder/dsh-auto-mode --skill dsh-upgrade-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NanmiCoder/dsh-auto-mode dsh-upgrade-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NanmiCoder/dsh-auto-mode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dsh-upgrade-audit .claude/skills/dsh-upgrade-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dsh-upgrade-audit
GitHub stars
165
Used in
1 other repo
Token cost
~2.5k tokens
SKILL.md length
1,192 words
Files
10 (incl. scripts, references)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…

  • Works in 6 steps: Parse input and choose a mode → Materialize the two trees → Establish shared facts first → …
  • The user asks to check/compare/audit two DSH versions
  • SKILL.md covers Phase 0 — Parse input and…, Output contract, Phase 1 — Materialize the two… and Phase 2 — Establish shared…, plus 5 more sections
  • Runs JavaScript scripts from its folder; calls git and node

What it does

Dsh Upgrade Audit is an agent skill from NanmiCoder/dsh-auto-mode. Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm packages without one. Use whenever the user asks to check/compare/audit two DSH versions or whether upgrading is safe — e.g. "more changes or reverts in dsh-vX - dsh-vY", "compare the breaking changes" — even with only two version numbers and no source location. Read-only outside the report directory; npm mode installs in…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts and reference files (for example `SKILL.zh-CN.md`, `evals/evals.json` and `examples/0.1.2alpha1-to-0.1.2alpha2/CHANGELOG.md`).

It sits in Development. It works with npm, DeepSeek and Git. The repository describes itself as: Safe automatic permissions for DeepSeek Harness. The licence is MIT.

When your agent uses it

  • The user asks to check/compare/audit two DSH versions
  • Whether upgrading is safe — e.g

Example prompts

  • “more changes or reverts in dsh-vX - dsh-vY”
  • “compare the breaking changes”
  • “/dsh-upgrade-audit”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse input and choose a mode
  2. Materialize the two trees
  3. Establish shared facts first
  4. Parallel facade scans
  5. Verify before publishing
  6. Write UPGRADE-ADAPTATION.md

What it can do on your machine

Read from SKILL.md and the folder at commit 907d663. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dsh Upgrade Audit loads about 2.5k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 1,192 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from NanmiCoder/dsh-auto-mode at commit 907d663, republished under its MIT licence (© NanmiCoder). 1,192 words, ~2,488 tokens.

Download SKILL.mdSave it as .claude/skills/dsh-upgrade-audit/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
dsh-upgrade-audit
description
Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm packages without one. Use whenever the user asks to check/compare/audit two DSH versions or whether upgrading is safe — e.g. "more changes or reverts in dsh-vX -> dsh-vY", "compare the breaking changes" — even with only two version numbers and no source location. Read-only outside the report directory; npm mode installs in isolation with --ignore-scripts.

English | 简体中文

dsh-upgrade-audit

Audit every change observable by consumers outside the repository between two DSH versions, and produce the set of reports the user expects. The fixed form of this problem: relative to from, does to contain more changes or reverts? — "more changes" means externally visible breakage (removed exports, renamed wire error codes, data formats refused on read); "revert" means behavior present in from deliberately withdrawn by a revert within the interval. Both need evidence: commit messages and subagent summaries are claims — only conclusions drawn after reading both trees (source files or published packages) count as evidence.

External compatibility = everything observable by consumers outside the repository: the npm package public API (exports, types, signatures, dependency surface), the dsh CLI (commands, flags, profiles, config keys), the wire protocol (SDK JSON-RPC, remote gateway/BFF, ACP, hooks), session data on disk (JSONL logs, SQLite stores and their version guards), the model-visible surface (tool names/schemas, system-prompt output), and the Python SDK's expectations. Internal refactors are background, not findings — aggregate and count them.

Note: report language follows the user's language (see "Output contract" below); the existing sample report under examples/ is in English by historical convention.

Phase 0 — Parse input and choose a mode

Input: two version identifiers (accepts 0.1.2-alpha.2, dsh-v0.1.2-alpha.2, dist-tags alpha/latest/next). Choose the analysis mode by specificity, high to low:

  1. Context path — the user named a deepseek-harness checkout directory in the message. Verify: root package.json + packages/ + AGENTS.md all present.
  2. DSH_SOURCE_PATH environment variable — verify the same way. (Optional DSH_NPM_REGISTRY overrides the npm registry.)
  3. CWD heuristic — the current directory is itself a deepseek-harness checkout (marked the same way).
  4. npm mode — none of the above (the default path for third-party repos): download the published packages of the two versions for analysis.

Source mode audits git tags; npm mode audits published artifacts. The audit core (recon surface, classification, verification, reporting) is shared; only the materialization and some evidence sources differ. Know npm mode's boundaries before choosing it: the npm version set ≠ the git tag set (e.g. 0.1.2-alpha.1 is tagged but was never published — the materialization script exits with the published list, so present the gap to the user instead of silently substituting a version pair); the CLI closure does not include every publishable package (the SQLite persistence backend is not a CLI dependency; the script installs it as a supplement package).

Output contract

Everything lands in one directory: tmp/<fromNorm>-to-<toNorm>/ (normalization: strip dsh-v, strip dots in the prerelease segment — dsh-v0.1.2-alpha.1 → 0.1.2alpha1). Source mode creates it inside the checkout (gitignored); npm mode creates it inside the current project. If the target directory already exists it is most likely a previously hand-made report — stop and ask first; do not overwrite.

ArtifactSource modenpm mode
commits.txt, reverts.txtfrom git; reverts folded into CHANGELOGfrom GitHub compare enrichment (none if private repo)
files.txt, diffstat.txt, full .diffgit tree diffmanifest-diff.txt (per-package manifest diff) + a/, b/ published package trees
CHANGELOG.mdcategorized by type, must have a Reverts sectiongenerated when enrichment exists; otherwise omitted with an explicit note
UPGRADE-ADAPTATION.mdaudit report (same skeleton in both modes)same; header records mode and version provenance

Report language follows the user's language (examples/ existing report is in English, a historical convention — not mandatory).

Phase 1 — Materialize the two trees

Source mode — verify purity first; a merge base that is not from itself means base drift: stop and report, never diff against a moving baseline:

sh
git merge-base <from> <to>   # must equal <from>'s commit
node <skill-dir>/scripts/gen-artifacts.mjs <from> <to> tmp/<pair>

npm mode:

sh
node <skill-dir>/scripts/materialize-npm.mjs <from> <to> tmp/<pair>

The script resolves both versions against the registry (missing → exit 1 with the published list — present the gap to the user), installs the @deepseek-ai/dsh dependency closure plus the SQLite supplement package into a/ and b/ with --ignore-scripts, produces manifest-diff.txt from per-package manifest diffs for every @deepseek-ai/* package, and enriches from the public GitHub repository (commits.txt, reverts.txt) — so revert detection works even without a source checkout.

Size the recon from the stats output: ≤40 non-merge commits → run the recon-surface checklist inline; 40–250 → merge 3–4 facades; more → all six facades. For density comparison, open the previous pair's commits.txt — the immediately preceding pair in chronological order, never just the newest directory in tmp/.

Show full SKILL.md (518 more words)Show less

Phase 2 — Establish shared facts first

Run once and feed to every subagent, so they do not each re-derive them:

  • Format guards — source mode reads SESSION_FORMAT_VERSION on both tags (packages/core/session/src/types.ts) and the SQLite SCHEMA_VERSION (packages/session/session-persistence-sqlite/src/schema.ts); npm mode greps the same-named constants from the published lib/*.js of dsh-session and the supplement package. A guard that jumps with no migration path = hard data breakage; put it at the front of the report.
  • Revert list — source mode: git log --grep='[Rr]evert' <from>..<to>; npm mode: the enriched reverts.txt (absent → revert intent is undetectable; say so explicitly and do only the from→to delta audit).
  • Python SDK — source mode: diff python/; npm mode: outside the npm artifact scope, one sentence suffices.

Phase 3 — Parallel facade scans

Dispatch one read-only recon agent per facade in a parallel batch, each carrying the Phase 2 shared facts and the output contract from references/audit-playbook.md: sections REMOVED (first — candidate breakage/reverts), CHANGED (before → after), ADDED, RENAMED; every entry carries package/path, symbol or field, and an impact-surface class (SDK consumers / CLI users / config authors / session data / model-visible / protocol peers / web UI / npm installers); end with a one-line verdict. The per-facade target path lists (per mode) are in the playbook.

Phase 4 — Verify before publishing

Recon output is leads, not findings. Personally re-verify every REMOVED, revert, and wire claim: source mode with git show <tag>:<path> / git ls-tree against both tags; npm mode by reading both published trees (a/node_modules/... vs b/node_modules/...). This step has a real lesson: a recon agent once reported a package that already existed in alpha.1 as "added in alpha.2". Whatever cannot be verified is either marked [INFERENCE] or deleted.

Phase 5 — Write UPGRADE-ADAPTATION.md

Per the references/audit-playbook.md skeleton: header (range, stats, mode & provenance, source-mode purity note), Verdict (answer the comparative question directly), §1 reverts, breaking sections sorted by consumer impact (removals first, each annotating who breaks, with an Adapt: line), Confirmed unchanged (the parts where compatibility holds matter as much as the breaks), the boundary signature table [API surface | from | to | changed?], and a numbered migration checklist. Full worked example at examples/0.1.2alpha1-to-0.1.2alpha2/ (a real source-mode audit). Chat replies follow the user's language.

Guards

  • Read-only: source mode touches nothing outside tmp/<pair>/; npm mode writes only its own tmp/<pair>/ and installs with --ignore-scripts into that directory — never install the dsh package into the host project's node_modules.
  • Prefer tree-level facts (published files, two-tag reads); do not trust narratives inferred from logs.
  • Aggregate internal irrelevant churn (tests, notes, i18n, styles) into a single count; do not itemize it.
  • npm mode records its limitations honestly: no enrichment → no git history; the CLI tarball ships only lib/ (config composition audited via each bundle package's cordis.patch.yml + manifest); Python SDK out of scope.
  • Do not fully fan out a 20-commit range; do not inline a 500-commit range. Misjudging the scale is the main reason audits go stale or shallow.

Relationship to plugin-upgrade

This skill produces evidence of host-version compatibility (report + boundary signature table); plugin-upgrade consumes that evidence (version-change cards) to execute a single plugin's migration. Audit findings can feed a card's "field notes" directly; when adding cards to plugin-upgrade, cite this skill's report directory rather than restating from memory.

© NanmiCoder, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in skills/dsh-upgrade-audit of NanmiCoder/dsh-auto-mode.

  • SKILL.md
  • SKILL.zh-CN.md
  • evals/evals.json
  • examples/0.1.2alpha1-to-0.1.2alpha2/CHANGELOG.md
  • examples/0.1.2alpha1-to-0.1.2alpha2/README.md
  • examples/0.1.2alpha1-to-0.1.2alpha2/UPGRADE-ADAPTATION.md
  • references/audit-playbook.md
  • scripts/gen-artifacts.check.mjs
  • scripts/gen-artifacts.mjs
  • scripts/materialize-npm.mjs

Open the folder on GitHubat commit 907d663

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in NanmiCoder/dsh-auto-mode, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Dsh Upgrade Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dsh Upgrade Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dsh Upgrade Audit this skillNanmiCoder/dsh-auto-mode1651 repos~2.5kAutomated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Open Code Review Delegatealibaba/open-code-review44k—~2kAutomated safety check: PassApache-2.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Code Reviewyaklang/yakit7.8k—~1.4kAutomated safety check: NotesAGPL-3.0

Similar skills

  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    44k GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    yaklang/yakit

    对 Yakit 仓库的代码改动做规范化 code review:按代码逻辑、TS 定义、UI 引用与 Props、CSS 样式、依赖版本、配置项六个维度审查,检查测试用例缺失,强制执行 tsc 类型检查与 vitest 测试验证,输出「结果汇总 / 明细解释 / 合并结论」三块报告,经用户确认后写入文件。当用户要求 review、审查、评审代码改动,或在提交、合并、提 PR…

    7.8k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check: notes
  • AionUi Version Bump

    iOfficeAI/AionUi

    Automates an AionUi release: checks the latest AionCore release and its artifacts, updates package.json, writes the changelog, opens a PR and tags the release.

    33k GitHub stars~2.1k tokensUpdated 28 days ago
    DevelopmentAuto-check passed

More from NanmiCoder/dsh-auto-mode

All 10 skills in this repo
  • Plugin Workflow

    NanmiCoder/dsh-auto-mode

    Coordinate multiple DeepSeek Harness plugin Skills across inspection, migration, runtime debugging, heavy dependencies, testing, naming, and release.

    165 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Plugin Write

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when creating a DeepSeek Harness plugin, choosing public names for a new external DSH plugin, validating a dsh-plugin.naming.json manifest, checking reviewed central…

    165 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Plugin Test

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when writing or reviewing tests for DeepSeek Harness plugins, external DSH plugin packages, or package changes in the deepseek-harness repository.

    165 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Dsh Benchmark Case

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when the user hands over a dsh plugin repository (or a real migration commit / version corridor) and wants its upgrade experience extracted into one auto-graded Harbor…

    165 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: warnings
  • Plugin Release

    NanmiCoder/dsh-auto-mode

    Package, publish, and distribute DeepSeek Harness (DSH) plugins — npm pack artifact validation, GitHub/npm/hub release-track selection, tarball overrides installs for the unpublished cohort…

    165 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check: warnings
  • Plugin Heavy Dep

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when adding a heavyweight browser dependency (diagram/chart renderers like mermaid, code editors, big wasm-adjacent libs) to a lightweight DSH Web plugin that must stay…

    165 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Works with

Categories

Questions about Dsh Upgrade Audit

What does Dsh Upgrade Audit do?

Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…. Dsh Upgrade Audit is an agent skill from NanmiCoder/dsh-auto-mode. Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm packages without one.

When should I use Dsh Upgrade Audit?

Dsh Upgrade Audit fits situations like: the user asks to check/compare/audit two DSH versions; whether upgrading is safe — e.g.

How do I install Dsh Upgrade Audit in Claude Code?

Run `npx skills add NanmiCoder/dsh-auto-mode --skill dsh-upgrade-audit -a claude-code`. Or copy the skill folder (skills/dsh-upgrade-audit in NanmiCoder/dsh-auto-mode) into .claude/skills/dsh-upgrade-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dsh Upgrade Audit in Codex?

Run `npx skills add NanmiCoder/dsh-auto-mode --skill dsh-upgrade-audit -a codex`. Or copy the skill folder (skills/dsh-upgrade-audit in NanmiCoder/dsh-auto-mode) into .agents/skills/dsh-upgrade-audit in your project. Codex loads it when a task matches its description.

Can I use Dsh Upgrade Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NanmiCoder/dsh-auto-mode --skill dsh-upgrade-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dsh-upgrade-audit, .gemini/skills/dsh-upgrade-audit, .github/skills/dsh-upgrade-audit and .opencode/skills/dsh-upgrade-audit in your project.

What does Dsh Upgrade Audit need to run?

Going by SKILL.md and its folder, Dsh Upgrade Audit needs JavaScript for the scripts in its folder and the command-line tools its instructions call (git and node). Our summary lists: Python 3; Node.js.

Does Dsh Upgrade Audit access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Dsh Upgrade Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dsh Upgrade Audit use?

Dsh Upgrade Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dsh Upgrade Audit use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Dsh Upgrade Audit?

Skills that share tags, products or a category with Dsh Upgrade Audit: Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars), Open Code Review CLI (alibaba/open-code-review, 44k stars), Open Code Review Delegate (alibaba/open-code-review, 44k stars) and Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dsh Upgrade Audit?

NanmiCoder (a GitHub user) maintains it in NanmiCoder/dsh-auto-mode, which has 165 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 29, 2026.

Source: NanmiCoder/dsh-auto-mode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.