Agent skill

Absolute Upgrade

by maddhruv in maddhruv/absolute

Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles regenerated and tests green after…

MITAuto-check passedDevelopment

Install Absolute Upgrade

skills CLI
$ npx skills add maddhruv/absolute --skill absolute-upgrade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maddhruv/absolute absolute-upgrade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maddhruv/absolute.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/absolute-upgrade .claude/skills/absolute-upgrade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
absolute-upgrade
GitHub stars
218
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
518 words
Files
3 (incl. references)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles regenerated and tests green after…

  • Works in 4 steps: Lockfile-only "upgrade". Bumping the… → Batching a major in with patches. One… → Green install ≠ green project. npm… → …
  • Absolute upgrade
  • SKILL.md covers Absolute Upgrade, When to use, What it scans and Risk ranking (TRIAGE), plus 3 more sections
  • Calls npm, pnpm and yarn

What it does

Absolute Upgrade is an agent skill from maddhruv/absolute. Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles regenerated and tests green after each. Runs on green main. Triggers on "absolute upgrade", "upgrade our dependencies", "bump deps", "update packages", "move off the deprecated X", "clear the Dependabot backlog".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/health-engine.md`).

It sits in Development, covering Dependency management and Changelog and release notes. It works with npm and pnpm. The repository describes itself as: Absolute Skills to 10x your Development Lifecycle. The licence is MIT.

When your agent uses it

  • Absolute upgrade
  • Upgrade our dependencies
  • Update packages
  • Move off the deprecated X

Example prompts

  • “absolute upgrade”
  • “upgrade our dependencies”
  • “bump deps”
  • “/absolute-upgrade”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Lockfile-only "upgrade". Bumping the manifest without regenerating + committing the
  2. Batching a major in with patches. One breaking bump fails the whole wave and hides
  3. Green install ≠ green project. npm install succeeding proves nothing — run tests.
  4. Pinning around a failure. If a bump breaks something, fix or defer it; don't pin the

What it can do on your machine

Read from SKILL.md and the folder at commit 2166274. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pnpm
    • yarn
    • pip
    • poetry
    • uv
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pnpm, yarn, pip and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Absolute Upgrade loads about 1.1k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 518 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maddhruv/absolute at commit 2166274, republished under its MIT licence (© maddhruv). 518 words, ~1,126 tokens.

Download SKILL.mdSave it as .claude/skills/absolute-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
absolute-upgrade
description
Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles regenerated and tests green after each. Runs on green main. Triggers on "absolute upgrade", "upgrade our dependencies", "bump deps", "update packages", "move off the deprecated X", "clear the Dependabot backlog".
version
0.5.0
category
workflow
tags
workflow, maintenance, dependencies, upgrade, security
platforms
claude-code, gemini-cli, openai-codex, mcp
user-invocable
true
argument-hint
[target]
license
MIT

Start your first response with the ⬆️ emoji.

Absolute Upgrade

Bring dependencies current — safely, in risk-ranked waves, with tests green after each. Not a blind npm update: outdated and vulnerable deps are grouped by blast radius (patch/minor → safe wave; major/breaking → gated, one at a time, changelog-read), applied incrementally, and verified against the project's own test suite.

Runs the shared engine in references/health-engine.md — read it for the DETECT → SCAN → TRIAGE → FIX → VERIFY → REPORT loop and the safety contract. This file covers only what's specific to dependency upgrades.


When to use

  • Routine "bring deps up to date" / "upgrade our dependencies".
  • A specific bump: "upgrade React to 19", "move off the deprecated X package".
  • Clearing npm outdated / Dependabot backlog without 40 separate PRs.

Not for: adding a new dependency (that's a work/feature decision), or auditing vulnerabilities specifically → use /absolute audit (it triages CVEs; upgrade moves versions).


What it scans

Per ecosystem, list outdated deps with current → wanted → latest and the jump type:

EcosystemDetect outdatedLockfile / manifest
npmnpm outdated --jsonpackage-lock.json
pnpmpnpm outdated --format jsonpnpm-lock.yaml
yarnyarn outdated --jsonyarn.lock
Python (pip)pip list --outdated --format=jsonrequirements*.txt
Python (poetry/uv)poetry show --outdated / uv pip list --outdatedpyproject.toml + lock
Gogo list -u -m -json allgo.mod / go.sum

Also flag: deps with known deprecations, duplicate/multiple versions of the same package, and direct vs transitive (only direct deps are upgrade targets; transitives follow).


Risk ranking (TRIAGE)

Group the upgrade plan into waves by semver jump — safest first:

WaveJumpDefault
1patch (x.y.Z)batch together, fix now
2minor (x.Y.z)batch by package family, fix now
3major (X.y.z) / pre-1.0 minorone at a time, gated — read the changelog/migration guide first, list breaking changes

For every major bump: locate breaking changes (CHANGELOG, release notes, codemod if the package ships one), inventory call sites that touch the changed API, and state the migration before applying. Peer-dependency conflicts get resolved in the same wave as their driver.


Show full SKILL.md (196 more words)Show less

Fix & verify

  • Apply a wave, regenerate the lockfile, run the project's full test + build (a passing install is not a passing upgrade).
  • Majors: apply the version bump and the required code migration in the same wave, or the build breaks. Use the package's codemod where one exists.
  • A wave that can't go green within reason → revert it, report it as blocked with the error, keep the green waves. Never --force / --legacy-peer-deps to mask a real conflict.

Gotchas

  1. Lockfile-only "upgrade". Bumping the manifest without regenerating + committing the lockfile ships untested transitive versions. Always regenerate.
  2. Batching a major in with patches. One breaking bump fails the whole wave and hides which change broke it. Majors are always solo.
  3. Green install ≠ green project. npm install succeeding proves nothing — run tests.
  4. Pinning around a failure. If a bump breaks something, fix or defer it; don't pin the dependency tree to dodge it silently.

Companion commands

  • /absolute audit — if the goal is fixing vulnerabilities, start there; it'll route back here for the version moves.
  • /absolute deflake — flaky tests can mask whether an upgrade truly passed.
  • /absolute work — if an upgrade needs real feature-level migration work, hand off.

© maddhruv, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/absolute-upgrade of maddhruv/absolute.

  • SKILL.md
  • README.md
  • references/health-engine.md

Open the folder on GitHubat commit 2166274

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in maddhruv/absolute, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Absolute Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Absolute Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Absolute Upgrade this skillmaddhruv/absolute2181 repos~1.1kAutomated safety check: PassMIT
Update Depsviclafouch/meme-studio110—~2.6kAutomated safety check: PassNone
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Claude Code Version Checkykdojo/claude-code-tips10k—~1.8kAutomated safety check: PassCustom licence
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT

Similar skills

  • Update Deps

    viclafouch/meme-studio

    Audit all outdated dependencies with detailed research on changelogs, breaking changes, bug fixes, and deprecations.

    110 GitHub stars~2.6k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Claude Code Version Check

    ykdojo/claude-code-tips

    Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.

    10k GitHub stars~1.8k tokensUpdated 12 days ago
    DevelopmentAuto-check passed
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Release Clawpatch

    openclaw/clawpatch

    clawpatch release: version/changelog, CI, npm publish, GitHub release, verify.

    813 GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from maddhruv/absolute

All 10 skills in this repo
  • Absolute Init

    maddhruv/absolute

    One-time setup for absolute: interview how you want it to behave (output style, autonomy, TDD strictness, spec dir, families) + detect the stack once, then write .absolute.config.json (project…

    218 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Absolute Spec

    maddhruv/absolute

    Lightweight standalone design spec for AI coding agents: codebase scan → bounded clarify pass (3–5 questions, not a grill) → reviewed design doc written to docs/plans/ → independent scored review →…

    218 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Absolute Audit

    maddhruv/absolute

    Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…

    218 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Absolute Simplify

    maddhruv/absolute

    A skill your agent uses when the user wants to simplify, clean up, refactor, tidy, or refine code — their staged/unstaged git changes or a target file/path.

    218 GitHub stars~6.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Absolute Debt

    maddhruv/absolute

    Lint and typecheck debt paydown: clear pre-existing repo-wide lint/type violations and suppressions (@ts-ignore, type: ignore) one rule per wave, fixing causes not symptoms.

    218 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Absolute Work

    maddhruv/absolute

    End-to-end, phase-gated SDLC for AI coding agents: relentless design interview → reviewed spec → dependency-graphed task board → safe-wave TDD execution → verification → converge.

    218 GitHub stars~5.3k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Absolute Upgrade

What does Absolute Upgrade do?

Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles regenerated and tests green after…. Absolute Upgrade is an agent skill from maddhruv/absolute. Dependency upgrades: outdated/vulnerable deps planned into semver waves (patch/minor batched, majors gated and changelog-read), applied incrementally with lockfiles regenerated and tests green after each.

When should I use Absolute Upgrade?

Absolute Upgrade fits situations like: absolute upgrade; upgrade our dependencies; update packages; move off the deprecated X.

How do I install Absolute Upgrade in Claude Code?

Run `npx skills add maddhruv/absolute --skill absolute-upgrade -a claude-code`. Or copy the skill folder (skills/absolute-upgrade in maddhruv/absolute) into .claude/skills/absolute-upgrade in your project. Claude Code loads it when a task matches its description.

How do I install Absolute Upgrade in Codex?

Run `npx skills add maddhruv/absolute --skill absolute-upgrade -a codex`. Or copy the skill folder (skills/absolute-upgrade in maddhruv/absolute) into .agents/skills/absolute-upgrade in your project. Codex loads it when a task matches its description.

Can I use Absolute Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maddhruv/absolute --skill absolute-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/absolute-upgrade, .gemini/skills/absolute-upgrade, .github/skills/absolute-upgrade and .opencode/skills/absolute-upgrade in your project.

What does Absolute Upgrade need to run?

Going by SKILL.md and its folder, Absolute Upgrade needs the command-line tools its instructions call (npm, pnpm, yarn, pip, poetry and uv). Our summary lists: Python 3; Node.js.

Does Absolute Upgrade access the network?

SKILL.md contains no URLs. Its commands use npm, pip and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Absolute Upgrade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Absolute Upgrade use?

Absolute Upgrade is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Absolute Upgrade use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Absolute Upgrade?

Skills that share tags, products or a category with Absolute Upgrade: Update Deps (viclafouch/meme-studio, 110 stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars) and ZCF Release Automation (UfoMiao/zcf, 6.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Absolute Upgrade?

maddhruv (a GitHub user) maintains it in maddhruv/absolute, which has 218 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on July 6, 2026.

Source: maddhruv/absolute on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.