Repo Hygiene Scan and Fix
QwenLM/qwen-code
Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.
Upgrade all backend (.NET/NuGet), frontend (npm), and GitHub Actions dependencies to their latest versions, in that fixed order.
$ npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install platformplatform/PlatformPlatform upgrade-packages --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/platformplatform/PlatformPlatform.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/upgrade-packages .claude/skills/upgrade-packages && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "upgrade-packages" agent skill from https://github.com/platformplatform/PlatformPlatform/tree/main/.claude/skills/upgrade-packages into .claude/skills/upgrade-packages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-packages", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/platformplatform/PlatformPlatform/tree/main/.claude/skills/upgrade-packagesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install platformplatform/PlatformPlatform upgrade-packages --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/platformplatform/PlatformPlatform.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/upgrade-packages .agents/skills/upgrade-packages && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "upgrade-packages" agent skill from https://github.com/platformplatform/PlatformPlatform/tree/main/.claude/skills/upgrade-packages into .agents/skills/upgrade-packages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-packages", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install platformplatform/PlatformPlatform upgrade-packages --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/platformplatform/PlatformPlatform.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/upgrade-packages .cursor/skills/upgrade-packages && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "upgrade-packages" agent skill from https://github.com/platformplatform/PlatformPlatform/tree/main/.claude/skills/upgrade-packages into .cursor/skills/upgrade-packages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-packages", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/platformplatform/PlatformPlatform.git --path .claude/skills/upgrade-packages--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install platformplatform/PlatformPlatform upgrade-packages --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/platformplatform/PlatformPlatform.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/upgrade-packages .gemini/skills/upgrade-packages && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "upgrade-packages" agent skill from https://github.com/platformplatform/PlatformPlatform/tree/main/.claude/skills/upgrade-packages into .gemini/skills/upgrade-packages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-packages", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install platformplatform/PlatformPlatform upgrade-packagesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/platformplatform/PlatformPlatform.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/upgrade-packages .github/skills/upgrade-packages && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "upgrade-packages" agent skill from https://github.com/platformplatform/PlatformPlatform/tree/main/.claude/skills/upgrade-packages into .github/skills/upgrade-packages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-packages", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install platformplatform/PlatformPlatform upgrade-packages --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/platformplatform/PlatformPlatform.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/upgrade-packages .opencode/skills/upgrade-packages && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "upgrade-packages" agent skill from https://github.com/platformplatform/PlatformPlatform/tree/main/.claude/skills/upgrade-packages into .opencode/skills/upgrade-packages/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-packages", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
upgrade-packagesUpgrade all backend (.NET/NuGet), frontend (npm), and GitHub Actions dependencies to their latest versions, in that fixed order.
Upgrade Packages is an agent skill from platformplatform/PlatformPlatform. Upgrade all backend (.NET/NuGet), frontend (npm), and GitHub Actions dependencies to their latest versions, in that fixed order. Drives the developer CLI's update-packages command, parses its quiet dry-run output to separate trivial bumps from majors, ships trivial bumps as one bulk commit per side, and gives every major (and any code/config change) its own clean commit. Detects required toolchain installs (e.g. a new .NET SDK that needs sudo) and asks the user to run them up front so the backend upgrades first…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering CI/CD. It works with .NET, npm and GitHub Actions. The repository describes itself as: A platform designed for building enterprise-grade, multi-tenant products using Azure, .NET, React, TypeScript, Infrastructure as Code, etc. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 269de1c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dotnetgitnpmbrewwingetFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Upgrade Packages loads about 2.7k tokens when it runs. Until then it costs about 147 tokens; SKILL.md has 1,408 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from platformplatform/PlatformPlatform at commit 269de1c, republished under its MIT licence (© platformplatform). 1,408 words, ~2,721 tokens.
.claude/skills/upgrade-packages/SKILL.md (or your agent's skills folder).Bring all backend, frontend, and GitHub Actions dependencies to their latest versions. The project always runs the latest version of every package. Don't quit, give up, or recommend reverting just because something is non-trivial — research, debug, push through. The only acceptable reasons to skip an upgrade are the permanent exceptions below.
Every NuGet and npm bump goes through the developer CLI. Run it directly (the Bash hook allows dotnet run --project developer-cli, and the CLI runs its own dotnet/npm subprocesses without tripping the hook):
dotnet run --project developer-cli -- update-packages [--backend|--frontend] [--dry-run] [--exclude <csv>] [--include-major-framework-updates] --quietAlways pass --quiet. In quiet mode the command prints no tables or banners — only parseable plain-text lines:
<side> <patch|minor|major> <package> <current> -> <new> [<extra>]
<side> restricted <package> <current> (latest <X> is a new major, pinned)
<side> excluded <package> <current>
summary <side> patch=<n> minor=<n> major=<n> excluded=<n> uptodate=<n><side> is backend or frontend. restricted lines are the permanent exceptions (pinned to their current major by the CLI). Use a --dry-run --quiet run to plan; parse the major lines to get the package names that need their own commit.
Run the build, format, lint, test, and e2e skills for all verification (never raw dotnet/npm).
These never move to a new major. The CLI enforces them itself (RestrictedNuGetPackages in developer-cli/Commands/UpdatePackagesCommand.cs), so you do not pass --exclude for them — they show up as restricted lines in the dry-run and are pinned to the latest version within their current major:
MediatR, FluentAssertions — later majors changed licensing/APIs.Microsoft.ApplicationInsights, Microsoft.ApplicationInsights.AspNetCore — the next major drops PageView tracking as part of moving to OpenTelemetry; the codebase uses PageView heavily and that migration is a separate effort.Note: frontend @microsoft/applicationinsights-* packages are not restricted and upgrade normally. .NET, Node.js, and @types/node stay within their current major unless you pass --include-major-framework-updates; don't cross a framework major as part of a routine package upgrade.
update-packages for every bump. Never hand-edit package.json / Directory.Packages.props or run raw npm / dotnet to move a version.developer-cli/Commands/UpdatePackagesCommand.cs, and commit that fix on its own. Working around a CLI bug by hand is unacceptable — the next person deserves the fix.build + lint per trivial commit; add e2e after majors that touch runtime, build tooling, or i18n; run format whenever code changes or after upgrading formatter/linter tooling. Run a full backend regression with e2e at the end of the backend phase, before the frontend, and a full regression for both sides at the very end. Fold any fix into the commit that caused it (see Fixing A Regression).When a regression run fails, the bad change belongs in an earlier commit — fold the fix there, don't tack a loose fix on the end. The branch isn't pushed yet, so rewriting local history is safe. Two patterns by cause:
git commit --fixup=<offending-commit> followed by git rebase --autosquash --interactive <base>.--exclude, or drop its version bump from the bulk commit via a fixup), then give it its own commit on top with the code change it needs — exactly like a major.Either way, keep every commit independently green and bisectable, and never move to the next phase with a red suite — the fix-up happens in the phase that caused it.
Verify clean baseline — git status clean; build, lint, test green (run e2e if anything looks risky). Fix or stop if the baseline is broken before you start.
Dry-run — update-packages --dry-run --quiet (no side flag covers both). Read the output and split each side into:
patch and minor line.major line. Collect the package names; each becomes its own commit.(sdk) line (e.g. dotnet-sdk) and any ⚠️ … is NOT installed warning — these gate the backend and are handled first (step 3).restricted lines are the permanent exceptions — ignore them.Toolchain prerequisites (sudo) — resolve before any upgrade — if the dry-run reports a dotnet-sdk (or other framework) bump whose target version is not installed locally, the backend update will abort: update-packages --backend exits when the required SDK is missing. You cannot install it yourself — it needs sudo/admin. Stop and ask the user to run the exact install command the dry-run printed (e.g. brew upgrade dotnet-sdk on macOS, winget upgrade Microsoft.DotNet.SDK.<major> on Windows), then wait for them to confirm. Re-run update-packages --dry-run --quiet and check that nothing is still flagged as not-installed before continuing. This keeps the backend first and unblocked — do not start the frontend while a backend toolchain install is pending.
Backend bulk (trivial) — apply all backend patch/minor at once, excluding the majors so only safe bumps land:
dotnet run --project developer-cli -- update-packages --backend --exclude <comma-separated backend majors> --quietThen build --backend + lint --backend. When green, commit, e.g. Upgrade backend NuGet packages, dotnet tools, and SDK to latest minor and patch versions.
Backend majors, one at a time — for each backend major package P (the only outstanding backend updates after the bulk are the majors, so exclude the other majors to move just P):
dotnet run --project developer-cli -- update-packages --backend --exclude <every other backend major> --quietResearch P's changelog, make the required code changes, adopt cheap new features, run build/format/lint/test (+ e2e if it touches runtime), and commit P and its changes together, e.g. Upgrade <Package> to <version> and <what changed>.
Backend regression gate — full suite with e2e, before the frontend — with every backend commit in place, run the full backend suite: build --backend, format --backend, lint --backend, test, and e2e. The backend must be fully green here, before any frontend work begins — that way a failure is unambiguously a backend regression and its fix lands in a backend commit. If it fails, fix it up now (see Fixing A Regression); never carry a red backend suite into the frontend phase.
Frontend bulk (trivial) — same as step 4 with --frontend. The CLI runs npm install and npm audit fix for you. Then build --frontend + lint --frontend (+ format --frontend since the install may reformat). Commit, e.g. Upgrade frontend npm dependencies to latest minor and patch versions.
Frontend majors, one at a time — same as step 5 with --frontend. Formatter/linter majors (oxfmt, oxlint) and i18n/build-tool majors warrant a format + e2e pass. One commit per major.
GitHub Actions — the last upgrade — only after backend and frontend are fully done, bump the workflow dependencies in .github/workflows/*.yml (not covered by update-packages):
uses: <action>@vN to its latest major (e.g. actions/checkout, actions/setup-node, actions/setup-dotnet, actions/setup-java, actions/upload-artifact, actions/download-artifact, actions/github-script, azure/login, docker/setup-buildx-action).runs-on: runners to the current Ubuntu LTS image (e.g. ubuntu-24.04).with: (node-version, and any others) to match the project's runtime.
Verify nothing else references an old version; commit, e.g. Upgrade GitHub Actions and runner images to latest versions.Final regression — close by running the full set for both sides: build, format, lint, test, e2e. If anything fails, fix it up in the commit that caused it (see Fixing A Regression) rather than tacking a fix on the end. Then summarise to the user: what moved, what was skipped (with reason), what was adopted, what's deferred.
Every non-exception package on its latest version. Trivial bumps in one bulk commit per side; each major and each code/config change in its own clear commit; GitHub Actions current. The CLI is better than when you started — every bug you tripped over is fixed at the source and committed separately. build, format, lint, test, and e2e all green at HEAD.
© platformplatform, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/upgrade-packages of platformplatform/PlatformPlatform.
Open the folder on GitHubat commit 269de1c
Upgrade Packages next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Upgrade Packages this skillplatformplatform/PlatformPlatform | 441 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Repo Hygiene Scan and FixQwenLM/qwen-code | 28k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| CI Pipeline Synthesizerkajisho5/ffmpeg-skill | 1.9k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| GitHub Actions Supply Chain Pinningasyncapi/generator | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Releasechampionswimmer/pi-context-prune | 246 | — | ~907 | Automated safety check: Pass | None | |
| npm Release Via GitHub Actionsjmfederico/pi-web | 866 | — | ~2.9k | Automated safety check: Pass | MIT |
QwenLM/qwen-code
Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
asyncapi/generator
A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).
championswimmer/pi-context-prune
Creates a repository release for this Pi package. An agent skill from championswimmer/pi-context-prune.
jmfederico/pi-web
A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…
molefrog/moi
Release moi-computer to npm — verify locally, hand off to the gated GitHub Actions workflow, then verify the published package.
platformplatform/PlatformPlatform
Create a product requirement document (PRD) for a new feature.
platformplatform/PlatformPlatform
Rebuild a stale branch by cherry-picking each commit onto a fresh branch off main, using a ralph-loop to validate each commit (build, test, format, lint, optional e2e) before moving on.
platformplatform/PlatformPlatform
Diagnose and fix Lingui SWC plugin compatibility errors with Next.js, Rspack, or other SWC runtimes.
platformplatform/PlatformPlatform
Start or restart the .NET Aspire AppHost via the developer CLI.
platformplatform/PlatformPlatform
Commit session changes to git. An agent skill from platformplatform/PlatformPlatform.
platformplatform/PlatformPlatform
Run end-to-end Playwright tests via the developer CLI. An agent skill from platformplatform/PlatformPlatform.
Works with
Categories
Upgrade all backend (.NET/NuGet), frontend (npm), and GitHub Actions dependencies to their latest versions, in that fixed order. Upgrade Packages is an agent skill from platformplatform/PlatformPlatform.NET/NuGet), frontend (npm), and GitHub Actions dependencies to their latest versions, in that fixed order.
Upgrade Packages fits situations like: tasks that involve CI/CD.
Run `npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a claude-code`. Or copy the skill folder (.claude/skills/upgrade-packages in platformplatform/PlatformPlatform) into .claude/skills/upgrade-packages in your project. Claude Code loads it when a task matches its description.
Run `npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a codex`. Or copy the skill folder (.claude/skills/upgrade-packages in platformplatform/PlatformPlatform) into .agents/skills/upgrade-packages in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add platformplatform/PlatformPlatform --skill upgrade-packages -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-packages, .gemini/skills/upgrade-packages, .github/skills/upgrade-packages and .opencode/skills/upgrade-packages in your project.
Going by SKILL.md and its folder, Upgrade Packages needs the command-line tools its instructions call (dotnet, git, npm, brew and winget). Our summary lists: Node.js; Docker.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Upgrade Packages is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Upgrade Packages: Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars) and Release (championswimmer/pi-context-prune, 246 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
platformplatform (a GitHub organization) maintains it in platformplatform/PlatformPlatform, which has 441 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 24, 2026.
Source: platformplatform/PlatformPlatform on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.