Agent skill

Review Dep Upgrade

by react-cosmos in react-cosmos/react-cosmos

Review npm dependency upgrade diffs. An agent skill from react-cosmos/react-cosmos.

MITAuto-check passedDevelopment

Install Review Dep Upgrade

skills CLI
$ npx skills add react-cosmos/react-cosmos --skill review-dep-upgrade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install react-cosmos/react-cosmos review-dep-upgrade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/react-cosmos/react-cosmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-dep-upgrade .claude/skills/review-dep-upgrade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-dep-upgrade
GitHub stars
8.7k
Token cost
~1.1k tokens
SKILL.md length
481 words
Files
2 (incl. scripts)
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Review npm dependency upgrade diffs. An agent skill from react-cosmos/react-cosmos.

  • Works in 5 steps: Identify the comparison range. → Collect direct dependency upgrades. → Sanity-check the dates. → …
  • Comparing upgraded direct dependency versions between refs
  • SKILL.md covers Workflow, Output and Helper Script
  • Runs JavaScript scripts from its folder; calls git, npm and node

What it does

Review Dep Upgrade is an agent skill from react-cosmos/react-cosmos. Review npm dependency upgrade diffs. Use when comparing upgraded direct dependency versions between refs or package.json changes, fetching npm release dates, sorting by release gap, and summarizing upstream changes plus repo-specific impact.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.

It sits in Development. It works with npm and React. The repository describes itself as: Sandbox for developing and testing UI components in isolation. The licence is MIT.

When your agent uses it

  • Comparing upgraded direct dependency versions between refs
  • Package.json changes
  • Fetching npm release dates
  • Sorting by release gap

Example prompts

  • “/review-dep-upgrade”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify the comparison range.
  2. Collect direct dependency upgrades.
  3. Sanity-check the dates.
  4. Add analysis.
  5. Verify claims.

What it can do on your machine

Read from SKILL.md and the folder at commit aae77c6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Dep Upgrade loads about 1.1k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 481 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from react-cosmos/react-cosmos at commit aae77c6, republished under its MIT licence (© react-cosmos). 481 words, ~1,057 tokens.

Download SKILL.mdSave it as .claude/skills/review-dep-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-dep-upgrade
description
Review npm dependency upgrade diffs. Use when comparing upgraded direct dependency versions between refs or package.json changes, fetching npm release dates, sorting by release gap, and summarizing upstream changes plus repo-specific impact.

Review Dependency Upgrades

Workflow

  1. Identify the comparison range.

    • If the user gives refs, use them.
    • If not, inspect git status --short and git diff -- package.json '**/package.json'.
    • For clean worktrees, ask for the base/head refs unless the conversation already provides enough version pairs.
  2. Collect direct dependency upgrades.

    • Run the helper script (see Helper Script below); it emits JSON sorted by largest release gap.
    • The script covers dependencies, devDependencies, peerDependencies, and optionalDependencies, skips workspace-internal packages, and dedupes by name/version pair.
    • Do not include transitive-only package-lock.json churn unless the user explicitly asks for it.
    • Mention added or removed direct dependencies separately only when they explain a repo-impact change.
  3. Sanity-check the dates.

    • If any entry has "lookupError": true, the npm view call failed for that package (the script also exits non-zero and prints the failure to stderr). Treat this as a tooling problem: request escalation for npm registry access and re-run before presenting the report — do not ship a report with lookupError entries.
    • If a date is null without lookupError, that specific version is missing from npm's time data — it may have been unpublished or renamed. Call it out in the report.
    • Keep negative or same-day release gaps in the report, but call them out briefly.
  4. Add analysis.

    • Notable changes: only upstream changes likely to matter for this repo or the upgrade risk. Prefer official changelogs, migration guides, release notes, or docs. Avoid irrelevant metadata trivia.
    • Repo impact: concrete local files, config changes, test fixes, build/lint failures, or None observed.
    • Mark uncertainty explicitly instead of overstating causes.
  5. Verify claims.

    • Run relevant repo commands when practical, especially tests/build/lint/type-check if discussing required changes.
    • Use verification results to inform Repo impact.
Show full SKILL.md (202 more words)Show less

Output

Produce a Markdown section for each dependency, sorted by largest positive release gap first:

markdown
### `dependency` — `previous` (YYYY-MM-DD) → `current` (YYYY-MM-DD)

- **Release gap:** 3y 5mo
- **Notable changes:** TODO
- **Repo impact:** TODO

Guidelines:

  • Use backticks around package names and versions.
  • Use YYYY-MM-DD for release dates (slice the script's ISO timestamps).
  • Use the script's releaseGap string verbatim (compact forms like 3y 5mo, 54d 1h).
  • If a date is null, omit the parens for that version.
  • Fill in Notable changes and Repo impact for every entry before presenting the report.
  • Notable changes and Repo impact may be multiple sentences when needed for important context.
  • Use None observed. for repo impact when there is nothing concrete.
  • End with a ### Sources section when upstream summaries depend on browsed pages.

Helper Script

Run from the repo root:

bash
node .agents/skills/review-dep-upgrade/scripts/collect-dep-upgrades.mjs --base HEAD~1 --head HEAD

Defaults: --base HEAD~1, --head worktree. Options:

  • --base <ref>: git ref for previous versions.
  • --head <ref>: git ref for current versions. Use worktree for current files on disk.

Emits a JSON array of direct dependency upgrades, sorted by largest release gap, with workspace-internal packages filtered out. Example entry:

json
{
  "dependency": "ts-loader",
  "previousVersion": "9.5.4",
  "previousDate": "2025-08-24T08:06:29.241Z",
  "currentVersion": "9.5.7",
  "currentDate": "2026-04-02T07:49:53.845Z",
  "releaseGap": "7mo 10d",
  "releaseGapMs": 19093404604
}

If npm view fails for a package, its entries gain "lookupError": true, the failure is logged to stderr, and the script exits non-zero. Render the Markdown report (see Output) from this data and fill in Notable changes and Repo impact.

© react-cosmos, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .agents/skills/review-dep-upgrade of react-cosmos/react-cosmos.

  • SKILL.md
  • scripts/collect-dep-upgrades.mjs

Open the folder on GitHubat commit aae77c6

Compare with similar skills

Review Dep Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Dep Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Dep Upgrade this skillreact-cosmos/react-cosmos8.7k—~1.1kAutomated safety check: PassMIT
Release WorkflowCaldis/react-zmage945—~3.6kAutomated safety check: NotesMIT
Release Managerukorvl/lightweight-charts-react-components137—~1.7kAutomated safety check: PassCustom licence
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Release New Versionkcsujeet/ilamy-calendar351—~5.8kAutomated safety check: PassMIT
Pixijs Createpixijs/pixijs-skills351—~3.1kAutomated safety check: PassMIT

Similar skills

  • Release Workflow

    Caldis/react-zmage

    A skill your agent uses when the user wants to ship a new version of react-zmage to npm.

    945 GitHub stars~3.6k tokensUpdated 4 mo ago
    DevelopmentAuto-check: notes
  • Release Manager

    ukorvl/lightweight-charts-react-components

    Prepare or finalize semver releases for this repository. An agent skill from ukorvl/lightweight-charts-react-components.

    137 GitHub stars~1.7k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release New Version

    kcsujeet/ilamy-calendar

    Cut a new release of @ilamy/calendar — analyze commits since the last tag, suggest a semver bump, draft a CHANGELOG entry in the project's existing style, run the CI gate, commit, tag, push to…

    351 GitHub stars~5.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Pixijs Create

    pixijs/pixijs-skills

    A skill your agent uses when scaffolding a new PixiJS v8 project with the create-pixi CLI or adding PixiJS to an existing project.

    351 GitHub stars~3.1k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Dev Server

    lablup/backend.ai-webui

    Start the project's development server (pnpm dev for backend.ai-webui; discovered from README/package.json elsewhere), deriving the header color, app name, default backend endpoint and login…

    133 GitHub stars~7.5k tokensUpdated today
    DevelopmentAuto-check: notes

More from react-cosmos/react-cosmos

  • Gh Release Notes

    react-cosmos/react-cosmos

    Generate a clean list of commits between two git tags for GitHub release notes.

    8.7k GitHub stars~335 tokensUpdated 17 days ago
    Auto-check passed

Works with

Categories

Questions about Review Dep Upgrade

What does Review Dep Upgrade do?

Review npm dependency upgrade diffs. An agent skill from react-cosmos/react-cosmos. Review Dep Upgrade is an agent skill from react-cosmos/react-cosmos. Review npm dependency upgrade diffs.

When should I use Review Dep Upgrade?

Review Dep Upgrade fits situations like: comparing upgraded direct dependency versions between refs; package.json changes; fetching npm release dates; sorting by release gap.

How do I install Review Dep Upgrade in Claude Code?

Run `npx skills add react-cosmos/react-cosmos --skill review-dep-upgrade -a claude-code`. Or copy the skill folder (.agents/skills/review-dep-upgrade in react-cosmos/react-cosmos) into .claude/skills/review-dep-upgrade in your project. Claude Code loads it when a task matches its description.

How do I install Review Dep Upgrade in Codex?

Run `npx skills add react-cosmos/react-cosmos --skill review-dep-upgrade -a codex`. Or copy the skill folder (.agents/skills/review-dep-upgrade in react-cosmos/react-cosmos) into .agents/skills/review-dep-upgrade in your project. Codex loads it when a task matches its description.

Can I use Review Dep Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add react-cosmos/react-cosmos --skill review-dep-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-dep-upgrade, .gemini/skills/review-dep-upgrade, .github/skills/review-dep-upgrade and .opencode/skills/review-dep-upgrade in your project.

What does Review Dep Upgrade need to run?

Going by SKILL.md and its folder, Review Dep Upgrade needs JavaScript for the scripts in its folder and the command-line tools its instructions call (git, npm and node). Our summary lists: Node.js.

Does Review Dep Upgrade access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Dep Upgrade safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Review Dep Upgrade use?

Review Dep Upgrade is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Dep Upgrade use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Dep Upgrade?

Skills that share tags, products or a category with Review Dep Upgrade: Release Workflow (Caldis/react-zmage, 945 stars), Release Manager (ukorvl/lightweight-charts-react-components, 137 stars), Dependabot Alerts Update (livesession/xyd, 114 stars) and Release New Version (kcsujeet/ilamy-calendar, 351 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Dep Upgrade?

react-cosmos (a GitHub organization) maintains it in react-cosmos/react-cosmos, which has 8,686 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 22, 2026.

Source: react-cosmos/react-cosmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.