Official agent skill

Pnpm Upgrade

by openai in openai/openai-agents-js

Keep pnpm current: preflight the published package and pnpm/action-setup self-installer, update pnpm locally, align packageManager in package.json, and refresh CI pins.

OfficialMITAuto-check passed

Install Pnpm Upgrade

skills CLI
$ npx skills add openai/openai-agents-js --skill pnpm-upgrade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openai/openai-agents-js pnpm-upgrade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openai/openai-agents-js.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pnpm-upgrade .claude/skills/pnpm-upgrade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pnpm-upgrade
GitHub stars
3.9k
Token cost
~1.1k tokens
SKILL.md length
503 words
Files
3 (incl. scripts)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Keep pnpm current: preflight the published package and pnpm/action-setup self-installer, update pnpm locally, align packageManager in package.json, and refresh CI pins.

  • Works in 9 steps: Resolve the target pnpm release → Find the target pnpm/action-setup release → Resolve the action tag to an immutable… → …
  • SKILL.md covers Steps (run from repo root) and Notes
  • Runs JavaScript scripts from its folder; calls curl, jq and git; reaches registry.npmjs.org and github.com; needs GITHUB_TOKEN and GH_TOKEN

What it does

Pnpm Upgrade is an agent skill from openai/openai-agents-js, published by the product's own GitHub organization. Keep pnpm current: preflight the published package and pnpm/action-setup self-installer, update pnpm locally, align packageManager in package.json, and refresh CI pins. Use this when refreshing the pnpm toolchain manually or in automation.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml`).

It works with pnpm, OpenAI and npm. The repository describes itself as: A lightweight, powerful framework for multi-agent workflows and voice agents. The licence is MIT.

Example prompts

  • “/pnpm-upgrade”

Requirements

  • Node.js
  • A credential in GITHUB_TOKEN

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the target pnpm release
  2. Find the target pnpm/action-setup release
  3. Resolve the action tag to an immutable commit SHA
  4. Preflight the release and CI installation path
  5. Update pnpm locally
  6. Align package.json
  7. Update workflows carefully (no broad regex)
  8. Verify
  9. Follow-up

What it can do on your machine

Read from SKILL.md and the folder at commit 33e2741. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • jq
    • git
    • pnpm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org
    • github.com
    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pnpm Upgrade loads about 1.1k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 503 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from openai/openai-agents-js at commit 33e2741, republished under its MIT licence (© openai). 503 words, ~1,104 tokens.

Download SKILL.mdSave it as .claude/skills/pnpm-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
pnpm-upgrade
description
Keep pnpm current: preflight the published package and pnpm/action-setup self-installer, update pnpm locally, align packageManager in package.json, and refresh CI pins. Use this when refreshing the pnpm toolchain manually or in automation.

pnpm Upgrade

Use these steps to update pnpm and CI pins without blunt search/replace.

Steps (run from repo root)

  1. Resolve the target pnpm release

    • Query the npm registry before changing the local toolchain: PNPM_VERSION=$(curl -fsSL https://registry.npmjs.org/pnpm/latest | jq -r .version).
    • Abort if the version is missing.
    • Resolve the exact package integrity: curl -fsSL "https://registry.npmjs.org/pnpm/${PNPM_VERSION}" | jq -r .dist.integrity.
    • Store the result as PNPM_INTEGRITY.
    • Abort if the integrity is missing or does not start with sha512-.
    • Convert the base64 digest after sha512- to lowercase hex, for example:
      bash
      printf '%s' "${PNPM_INTEGRITY#sha512-}" | base64 -d | xxd -p -c 256
    • Store the result as PNPM_SHA512_HEX.
  2. Find the target pnpm/action-setup release

    • Query GitHub API: curl -fsSL https://api.github.com/repos/pnpm/action-setup/releases/latest | jq -r .tag_name.
    • Use GITHUB_TOKEN/GH_TOKEN if available for higher rate limits.
    • Store as ACTION_TAG (e.g., v4.2.0). Abort if missing.
  3. Resolve the action tag to an immutable commit SHA

    • Run git ls-remote https://github.com/pnpm/action-setup "refs/tags/${ACTION_TAG}^{}" and capture the SHA as ACTION_SHA.
    • If the dereferenced tag is missing, fall back to git ls-remote https://github.com/pnpm/action-setup "refs/tags/${ACTION_TAG}".
    • Abort if ACTION_SHA is empty.
  4. Preflight the release and CI installation path

    • Run node .agents/skills/pnpm-upgrade/scripts/preflight.mjs --version "${PNPM_VERSION}" --action-ref "${ACTION_SHA}".
    • The script first rejects published pnpm manifests with non-empty dependencies or devDependencies. pnpm bundles its runtime dependencies, so these fields indicate a broken publication such as pnpm@11.12.0.
    • It then reproduces both pnpm/action-setup installation paths in separate temporary directories: install the regular pnpm bootstrap from pnpm-lock.json and the standalone @pnpm/exe bootstrap from exe-lock.json, set isolated PNPM_HOME directories, and self-update each bootstrap to PNPM_VERSION.
    • Abort the upgrade on any failure. Do not bypass this check with a direct local install; the preflight exists to exercise the CI-only bootstrap path.
  5. Update pnpm locally

    • Run pnpm self-update "${PNPM_VERSION}".
    • If pnpm is missing or self-update fails only because the current installation cannot update itself, run corepack prepare "pnpm@${PNPM_VERSION}" --activate. Do not use this fallback to bypass a failed preflight.
    • Confirm pnpm -v exactly matches PNPM_VERSION.
  6. Align package.json

    • Open package.json and set packageManager to pnpm@${PNPM_VERSION}+sha512.${PNPM_SHA512_HEX} (preserve trailing newline and formatting).
  7. Update workflows carefully (no broad regex)

    • Files: everything under .github/workflows/ that uses pnpm/action-setup.
    • For each file, edit by hand:
      • Set uses: pnpm/action-setup@${ACTION_SHA}.
      • If a with: version: field exists, set it to ${PNPM_VERSION} (keep quoting style/indent).
    • Do not touch unrelated steps. Avoid multiline sed/perl one-liners.
  8. Verify

    • Run pnpm -v and confirm it matches the version portion of packageManager.
    • Confirm packageManager keeps the exact +sha512.${PNPM_SHA512_HEX} suffix.
    • git diff to ensure only intended workflow/package.json changes.
  9. Follow-up

    • If runtime code/build/test config was changed (not typical here), run $code-change-verification; otherwise, a light check is enough.
    • Commit with chore: upgrade pnpm toolchain and open a PR (automation may do this).
Show full SKILL.md (65 more words)Show less

Notes

  • Tools needed: curl, jq, base64, xxd, node, npm, and pnpm/corepack. Install if missing.
  • Keep edits minimal and readable—prefer explicit file edits over global replacements.
  • GitHub Actions must stay pinned to commit SHAs, not tags. Use the latest release tag only to discover the commit SHA to pin.
  • If GitHub API is rate-limited, retry with a token or bail out rather than guessing the tag.

© openai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .agents/skills/pnpm-upgrade of openai/openai-agents-js.

  • SKILL.md
  • agents/openai.yaml
  • scripts/preflight.mjs

Open the folder on GitHubat commit 33e2741

Compare with similar skills

Pnpm Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pnpm Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pnpm Upgrade this skillopenai/openai-agents-js3.9k—~1.1kAutomated safety check: PassMIT
Check Deps SyncHyk260/PureChat546—~594Automated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review45k—~3.1kAutomated safety check: PassApache-2.0
Get API Docs with chubandrewyng/context-hub14k1 repos~775Automated safety check: PassMIT
Link Workspace Packagesnomcopter/react-mosaic4.8k6 repos~760Automated safety check: PassCustom licence
KrillinAI CLI Operatorkrillinai/OpenCreator13k—~869Automated safety check: PassApache-2.0

Similar skills

  • Check Deps Sync

    Hyk260/PureChat

    Check if package.json files are in sync with pnpm-lock.yaml.

    546 GitHub stars~594 tokensUpdated 23 days ago
    DevOps & CloudAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    45k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 1 repo~775 tokens
    DevelopmentAuto-check passed
  • Link Workspace Packages

    nomcopter/react-mosaic

    Link workspace packages in monorepos (npm, yarn, pnpm, bun).

    4.8k GitHub starsUsed in 6 repos~760 tokens
    DevelopmentAuto-check passed
  • KrillinAI CLI Operator

    krillinai/OpenCreator

    Routes agents to the right KrillinAI command for subtitles, dubbing, video rendering, covers and speech, and explains how to read its JSON and manifest output.

    13k GitHub stars~869 tokensUpdated 5 days ago
    Media & CreativeAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from openai/openai-agents-js

All 10 skills in this repo
  • Changeset Validation

    openai/openai-agents-js

    Official

    Validate changesets in openai-agents-js using LLM judgment against git diffs (including uncommitted local changes).

    3.9k GitHub stars~607 tokensUpdated yesterday
    Auto-check passed
  • Final Release Review

    openai/openai-agents-js

    Official

    Assess a JS SDK release candidate or release plan against the previous release and recommend ship or block.

    3.9k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • Sensitive Logging Audit

    openai/openai-agents-js

    Official

    Audit or fix sensitive-data exposure in JS SDK diagnostics, exceptions, logging, and telemetry.

    3.9k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Runtime Behavior Probe

    openai/openai-agents-js

    Official

    Plan and, after explicit approval, execute runtime-behavior probes for local or live integrations.

    3.9k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Code Change Verification

    openai/openai-agents-js

    Official

    Run the required final install, build, type, lint, test, and format checks after eligible SDK changes pass review.

    3.9k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Examples Run Analysis

    openai/openai-agents-js

    Official

    Analyze logs and source from a completed repository example run.

    3.9k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Pnpm Upgrade

What does Pnpm Upgrade do?

Keep pnpm current: preflight the published package and pnpm/action-setup self-installer, update pnpm locally, align packageManager in package.json, and refresh CI pins. Pnpm Upgrade is an agent skill from openai/openai-agents-js, published by the product's own GitHub organization.json, and refresh CI pins.

How do I install Pnpm Upgrade in Claude Code?

Run `npx skills add openai/openai-agents-js --skill pnpm-upgrade -a claude-code`. Or copy the skill folder (.agents/skills/pnpm-upgrade in openai/openai-agents-js) into .claude/skills/pnpm-upgrade in your project. Claude Code loads it when a task matches its description.

How do I install Pnpm Upgrade in Codex?

Run `npx skills add openai/openai-agents-js --skill pnpm-upgrade -a codex`. Or copy the skill folder (.agents/skills/pnpm-upgrade in openai/openai-agents-js) into .agents/skills/pnpm-upgrade in your project. Codex loads it when a task matches its description.

Can I use Pnpm Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openai/openai-agents-js --skill pnpm-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pnpm-upgrade, .gemini/skills/pnpm-upgrade, .github/skills/pnpm-upgrade and .opencode/skills/pnpm-upgrade in your project.

What does Pnpm Upgrade need to run?

Going by SKILL.md and its folder, Pnpm Upgrade needs JavaScript for the scripts in its folder, the command-line tools its instructions call (curl, jq, git, pnpm and node) and credentials named GITHUB_TOKEN and GH_TOKEN. Our summary lists: Node.js; A credential in GITHUB_TOKEN.

Does Pnpm Upgrade access the network?

SKILL.md names 3 domains. In commands or code: registry.npmjs.org, github.com and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Pnpm Upgrade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Pnpm Upgrade use?

Pnpm Upgrade is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pnpm Upgrade use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pnpm Upgrade?

Skills that share tags, products or a category with Pnpm Upgrade: Check Deps Sync (Hyk260/PureChat, 546 stars), Open Code Review CLI (alibaba/open-code-review, 45k stars), Get API Docs with chub (andrewyng/context-hub, 14k stars) and Link Workspace Packages (nomcopter/react-mosaic, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pnpm Upgrade?

openai (a GitHub organization, an official publisher) maintains it in openai/openai-agents-js, which has 3,902 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 8, 2026.

Source: openai/openai-agents-js on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.