Agent skill

Upgrade Packages

by Nimblesite in Nimblesite/SharpLsp

Upgrades all project dependencies to latest compatible versions.

MITAuto-check passed

Install Upgrade Packages

skills CLI
$ npx skills add Nimblesite/SharpLsp --skill upgrade-packages -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Nimblesite/SharpLsp upgrade-packages --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Nimblesite/SharpLsp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/upgrade-packages .claude/skills/upgrade-packages && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upgrade-packages
GitHub stars
138
Token cost
~1.3k tokens
SKILL.md length
545 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Upgrades all project dependencies to latest compatible versions.

  • Works in 6 steps: Detect Package Managers → List Outdated Packages → Read the official upgrade docs → …
  • The user says upgrade packages
  • SKILL.md covers Arguments, Step 1 — Detect Package Managers, Step 2 — List Outdated Packages and Step 3 — Read the official…, plus 4 more sections
  • Calls cargo, dotnet and npm

What it does

Upgrade Packages is an agent skill from Nimblesite/SharpLsp. Upgrades all project dependencies to latest compatible versions. Use when the user says "upgrade packages", "update deps", "bump dependencies", or "upgrade dependencies".

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with .NET, npm, Rust and C#. The licence is MIT.

When your agent uses it

  • The user says upgrade packages
  • Bump dependencies
  • Upgrade dependencies

Example prompts

  • “upgrade packages”
  • “update deps”
  • “bump dependencies”
  • “/upgrade-packages”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect Package Managers
  2. List Outdated Packages
  3. Read the official upgrade docs
  4. Run Upgrades
  5. Verify the upgrade
  6. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 34f38bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • dotnet
    • npm
    • make
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • doc.rust-lang.org
    • docs.npmjs.com
    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upgrade Packages loads about 1.3k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 545 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Nimblesite/SharpLsp at commit 34f38bf, republished under its MIT licence (© Nimblesite). 545 words, ~1,314 tokens.

Download SKILL.mdSave it as .claude/skills/upgrade-packages/SKILL.md (or your agent's skills folder).
name
upgrade-packages
description
Upgrades all project dependencies to latest compatible versions. Use when the user says "upgrade packages", "update deps", "bump dependencies", or "upgrade dependencies".
argument-hint
[--check-only] [--major] [specific-package-name]
<!-- agent-pmo:2efd847 -->

Upgrade Packages

Upgrade all project dependencies to their latest compatible versions across all languages in the repo.

Arguments

  • --check-only — List outdated packages without upgrading. Stop after Step 2.
  • --major — Include major version bumps (breaking changes). Without this flag, stay within semver-compatible ranges.
  • Any other argument is treated as a specific package name to upgrade (instead of all packages).

Step 1 — Detect Package Managers

Scan the repo for these package ecosystems:

Marker FileEcosystemLocation
Cargo.toml (workspace)Rust (cargo)Repo root
package.json / package-lock.jsonNode.js (npm)src/editors/vscode/
*.csproj / *.fsproj / .config/dotnet/common.propsC#/F# (.NET / NuGet)src/sidecars/SharpLsp.Sidecars.sln

Step 2 — List Outdated Packages

Run the appropriate command to list what's outdated BEFORE upgrading anything. Show the user what will change.

Rust (cargo)
bash
cargo outdated --root-deps-only --workspace
cargo update --dry-run

If cargo-outdated is not installed: cargo install cargo-outdated

Read the docs: https://doc.rust-lang.org/cargo/commands/cargo-update.html

Node.js (npm)
bash
npm outdated --prefix src/editors/vscode

Read the docs: https://docs.npmjs.com/cli/v10/commands/npm-update

C#/.NET (NuGet)
bash
dotnet list src/sidecars/SharpLsp.Sidecars.sln package --outdated

For transitive dependencies too: dotnet list src/sidecars/SharpLsp.Sidecars.sln package --outdated --include-transitive

Read the docs: https://learn.microsoft.com/en-us/dotnet/core/tools/dotnet-list-package

If --check-only was passed, stop here and report the outdated list.

Step 3 — Read the official upgrade docs

Before running any upgrade command, you MUST fetch and read the official documentation URL listed above for the detected package manager. Use WebFetch to retrieve the page. This ensures you use the correct flags and understand the behavior. Do not guess at flags or options from memory.

For any package with a major version bump (when --major is passed), also check the package's changelog or release notes for breaking changes before upgrading.

Step 4 — Run Upgrades

If a specific package name was given as an argument, upgrade only that package.

Rust
bash
cargo update                          # semver-compatible updates
# --major flag:
cargo update --breaking               # major version bumps (cargo 1.84+)

For workspace members, run from workspace root.

Node.js (npm)
bash
npm update --prefix src/editors/vscode                        # semver-compatible
# --major flag:
npx npm-check-updates -u --packageFile src/editors/vscode/package.json && npm install --prefix src/editors/vscode
C#/.NET (NuGet)
bash
dotnet outdated --upgrade src/sidecars/SharpLsp.Sidecars.sln

If dotnet-outdated tool is not installed: dotnet tool install -g dotnet-outdated-tool

Read the docs: https://github.com/dotnet-outdated/dotnet-outdated

Shared NuGet package versions live in .config/dotnet/common.props — check there first and update centrally when possible, rather than editing individual .csproj/.fsproj files.

Show full SKILL.md (239 more words)Show less

Step 5 — Verify the upgrade

After upgrading, run the full CI pipeline:

bash
make ci

If tests fail:

  1. Read the failure output carefully
  2. Check the changelog / migration guide for the upgraded packages (fetch the release notes URL if available)
  3. Fix breaking changes in the code
  4. Re-run make ci
  5. If stuck after 3 attempts on the same failure, report it to the user with the error details and the package that caused it

Step 6 — Report

Provide a summary:

  • Packages upgraded (old version -> new version)
  • Packages skipped (and why, e.g., major version bump without --major flag)
  • Build/test result after upgrade
  • Any breaking changes that were fixed
  • Any packages that could not be upgraded (with error details)

Rules

  • Always list outdated packages first before upgrading anything
  • Always read the official docs for the package manager before running upgrade commands
  • Always run make ci after upgrading to catch breakage immediately
  • Never remove packages unless they were explicitly deprecated and replaced
  • Never downgrade packages unless rolling back a broken upgrade
  • Never modify lockfiles manually (Cargo.lock, package-lock.json) — let the package manager regenerate them
  • Keep Cargo.lock changes in the same commit as Cargo.toml changes
  • Keep package-lock.json changes in the same commit as package.json changes
  • .config/dotnet/common.props is the source of truth for shared .NET package versions — update there first
  • If stuck after 3 attempts, revert and report — do not loop forever
  • Commit nothing — leave changes in the working tree for the user to review

© Nimblesite, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/upgrade-packages of Nimblesite/SharpLsp.

Open the folder on GitHubat commit 34f38bf

Compare with similar skills

Upgrade Packages next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upgrade Packages compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upgrade Packages this skillNimblesite/SharpLsp138—~1.3kAutomated safety check: PassMIT
Find Untested Sourcesdotnet/skills5.6k1 repos~3.3kAutomated safety check: PassMIT
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh878—~895Automated safety check: PassMIT
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
Release Coherencemacalbert/envilder138—~1.3kAutomated safety check: PassMIT

Similar skills

  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Testing & QAAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    878 GitHub stars~895 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Release Coherence

    macalbert/envilder

    Unified release coherence workflow for any component (CLI, GHA, or SDK).

    138 GitHub stars~1.3k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Precheck

    ayutaz/piper-plus

    PR 作成前の lint + format + test 一括実行。引数で scope (python/rust/cs/go/js/cpp/all) を指定可能。未指定なら git diff から自動判定。

    220 GitHub stars~647 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from Nimblesite/SharpLsp

  • CI Prep

    Nimblesite/SharpLsp

    Prepares the current branch for CI by running the exact same steps locally and fixing issues.

    138 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Code Dedup

    Nimblesite/SharpLsp

    Searches for duplicate code, duplicate tests, and dead code across the SharpLsp repo, then safely merges or removes them.

    138 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed

Questions about Upgrade Packages

What does Upgrade Packages do?

Upgrades all project dependencies to latest compatible versions. Upgrade Packages is an agent skill from Nimblesite/SharpLsp. Upgrades all project dependencies to latest compatible versions.

When should I use Upgrade Packages?

Upgrade Packages fits situations like: the user says upgrade packages; bump dependencies; upgrade dependencies.

How do I install Upgrade Packages in Claude Code?

Run `npx skills add Nimblesite/SharpLsp --skill upgrade-packages -a claude-code`. Or copy the skill folder (.agents/skills/upgrade-packages in Nimblesite/SharpLsp) into .claude/skills/upgrade-packages in your project. Claude Code loads it when a task matches its description.

How do I install Upgrade Packages in Codex?

Run `npx skills add Nimblesite/SharpLsp --skill upgrade-packages -a codex`. Or copy the skill folder (.agents/skills/upgrade-packages in Nimblesite/SharpLsp) into .agents/skills/upgrade-packages in your project. Codex loads it when a task matches its description.

Can I use Upgrade Packages in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Nimblesite/SharpLsp --skill upgrade-packages -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-packages, .gemini/skills/upgrade-packages, .github/skills/upgrade-packages and .opencode/skills/upgrade-packages in your project.

What does Upgrade Packages need to run?

Going by SKILL.md and its folder, Upgrade Packages needs the command-line tools its instructions call (cargo, dotnet, npm, make and npx). Our summary lists: Node.js.

Does Upgrade Packages access the network?

SKILL.md names 4 domains. As links in the text: doc.rust-lang.org, docs.npmjs.com, learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Upgrade Packages safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Upgrade Packages use?

Upgrade Packages is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upgrade Packages use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upgrade Packages?

Skills that share tags, products or a category with Upgrade Packages: Find Untested Sources (dotnet/skills, 5.6k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Dep Auditor (laolaoshiren/claude-code-skills-zh, 878 stars) and Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upgrade Packages?

Nimblesite (a GitHub organization) maintains it in Nimblesite/SharpLsp, which has 138 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.

Source: Nimblesite/SharpLsp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.