Agent skill

Upgrade JS Deps

by saaspegasus in saaspegasus/django-boilerplate

Upgrade JavaScript dependencies using npm-check-updates, then run post-upgrade checks to ensure nothing is broken.

MITAuto-check passed

Install Upgrade JS Deps

skills CLI
$ npx skills add saaspegasus/django-boilerplate --skill upgrade-js-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install saaspegasus/django-boilerplate upgrade-js-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/saaspegasus/django-boilerplate.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/upgrade-js-deps .claude/skills/upgrade-js-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upgrade-js-deps
GitHub stars
177
Token cost
~402 tokens
SKILL.md length
189 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Upgrade JavaScript dependencies using npm-check-updates, then run post-upgrade checks to ensure nothing is broken.

  • Works in 5 steps: Check for available upgrades → Update package.json → Install updated dependencies → …
  • Calls make and npx

What it does

Upgrade JS Deps is an agent skill from saaspegasus/django-boilerplate. Upgrade JavaScript dependencies using npm-check-updates, then run post-upgrade checks to ensure nothing is broken.

Its SKILL.md is about 400 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm and JavaScript. The repository describes itself as: The original SaaS Boilerplate for Django, trusted by thousands. The licence is MIT.

Example prompts

  • “/upgrade-js-deps”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(npx npm-check-updates *), Bash(make npm-install *), Bash(make npm-build *), Bash(make npm-type-check *), Bash(make test *)

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Check for available upgrades
  2. Update package.json
  3. Install updated dependencies
  4. Run post-upgrade checks
  5. Summarize and commit

What it can do on your machine

Read from SKILL.md and the folder at commit e9d11b0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(npx npm-check-updates *)
    • Bash(make npm-install *)
    • Bash(make npm-build *)
    • Bash(make npm-type-check *)
    • Bash(make test *)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upgrade JS Deps loads about 402 tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~402

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from saaspegasus/django-boilerplate at commit e9d11b0, republished under its MIT licence (© saaspegasus). 189 words, ~402 tokens.

Download SKILL.mdSave it as .claude/skills/upgrade-js-deps/SKILL.md (or your agent's skills folder).
name
upgrade-js-deps
description
Upgrade JavaScript dependencies using npm-check-updates, then run post-upgrade checks to ensure nothing is broken.
allowed-tools
Bash(npx npm-check-updates *), Bash(make npm-install *), Bash(make npm-build *), Bash(make npm-type-check *), Bash(make test *)

Your task

Upgrade all JavaScript dependencies and verify nothing is broken.

Step 1: Check for available upgrades

Run npx npm-check-updates to see what upgrades are available. Review the output and present the list to the user.

Step 2: Update package.json

Run npx npm-check-updates -u to update package.json with the new versions.

Step 3: Install updated dependencies

Run make npm-install to install the upgraded dependencies and update package-lock.json.

Step 4: Run post-upgrade checks

Run these checks sequentially, stopping if any step fails:

  1. TypeScript type checking: Run make npm-type-check and report any new type errors.
  2. Build: Run make npm-build to verify the production build still works.
  3. Tests: Run make test to verify the test suite still passes.
Step 5: Summarize and commit

Summarize what was done:

  • Which packages were upgraded (notable version changes)
  • Whether any type errors were introduced
  • Whether the build succeeded
  • Whether all tests passed
  • Any issues that need manual attention

If there were failures, present the issues and ask how the user wants to proceed.

If everything passed, ask the user if they'd like to commit the changes. If yes, commit using the /commit skill.

© saaspegasus, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/upgrade-js-deps of saaspegasus/django-boilerplate.

Open the folder on GitHubat commit e9d11b0

Compare with similar skills

Upgrade JS Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upgrade JS Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upgrade JS Deps this skillsaaspegasus/django-boilerplate177—~402Automated safety check: PassMIT
Chrome CDP Browser Controlzenstory-ai/oh-story-claudecode7.4k2 repos~1.2kAutomated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.4k—~2.2kAutomated safety check: PassMIT
Logseq Plugin SDKlogseq/logseq45k—~2.3kAutomated safety check: PassAGPL-3.0
Compromise NLP for JavaScriptspencermountain/compromise12k—~1.8kAutomated safety check: PassMIT
Tavily Search API Integrationandrewyng/context-hub14k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Chrome CDP Browser Control

    zenstory-ai/oh-story-claudecode

    Drives a Chrome window over the DevTools Protocol with the agent-browser CLI, so the agent can reuse your logged-in sessions, read pages and pull tokens.

    7.4k GitHub starsUsed in 2 repos~1.2k tokens
    Productivity & AutomationAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.4k GitHub stars~2.2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Logseq Plugin SDK

    logseq/logseq

    Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).

    45k GitHub stars~2.3k tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Compromise NLP for JavaScript

    spencermountain/compromise

    Guide for writing correct code with the compromise rule-based NLP library: tagging, match syntax, in-place transforms and common tasks like tense changes and redaction.

    12k GitHub stars~1.8k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Tavily Search API Integration

    andrewyng/context-hub

    Guides building Tavily integrations for web search, URL extraction, site crawling and AI-assisted research in Python or JavaScript agent and RAG projects.

    14k GitHub stars~1.1k tokensUpdated 4 mo ago
    AI & LLM EngineeringAuto-check passed
  • Release Round

    ethereumjs/ethereumjs-monorepo

    Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.

    2.8k GitHub stars~2k tokensUpdated 22 days ago
    DevelopmentAuto-check passed

More from saaspegasus/django-boilerplate

  • Pegasus Projects

    saaspegasus/django-boilerplate

    A skill your agent uses when the user asks to create, view, or modify a SaaS Pegasus project via the pegasus CLI — e.g.

    177 GitHub stars~5.1k tokensUpdated 2 days ago
    Auto-check passed
  • Resolve Pegasus Conflicts

    saaspegasus/django-boilerplate

    Resolve merge conflicts when upgrading SaaS Pegasus. An agent skill from saaspegasus/django-boilerplate.

    177 GitHub stars~3.2k tokensUpdated 2 days ago
    Auto-check passed
  • Upgrade Pegasus

    saaspegasus/django-boilerplate

    Upgrade to the latest version of SaaS Pegasus. An agent skill from saaspegasus/django-boilerplate.

    177 GitHub stars~621 tokensUpdated 2 days ago
    Auto-check passed
  • Fix Types

    saaspegasus/django-boilerplate

    Interactively fix any type checking issues in Python code. An agent skill from saaspegasus/django-boilerplate.

    177 GitHub stars~806 tokensUpdated 2 days ago
    Auto-check passed
  • Upgrade Python Deps

    saaspegasus/django-boilerplate

    Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken.

    177 GitHub stars~570 tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Upgrade JS Deps

What does Upgrade JS Deps do?

Upgrade JavaScript dependencies using npm-check-updates, then run post-upgrade checks to ensure nothing is broken. Upgrade JS Deps is an agent skill from saaspegasus/django-boilerplate. Upgrade JavaScript dependencies using npm-check-updates, then run post-upgrade checks to ensure nothing is broken.

How do I install Upgrade JS Deps in Claude Code?

Run `npx skills add saaspegasus/django-boilerplate --skill upgrade-js-deps -a claude-code`. Or copy the skill folder (.claude/skills/upgrade-js-deps in saaspegasus/django-boilerplate) into .claude/skills/upgrade-js-deps in your project. Claude Code loads it when a task matches its description.

How do I install Upgrade JS Deps in Codex?

Run `npx skills add saaspegasus/django-boilerplate --skill upgrade-js-deps -a codex`. Or copy the skill folder (.claude/skills/upgrade-js-deps in saaspegasus/django-boilerplate) into .agents/skills/upgrade-js-deps in your project. Codex loads it when a task matches its description.

Can I use Upgrade JS Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add saaspegasus/django-boilerplate --skill upgrade-js-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-js-deps, .gemini/skills/upgrade-js-deps, .github/skills/upgrade-js-deps and .opencode/skills/upgrade-js-deps in your project.

What does Upgrade JS Deps need to run?

Going by SKILL.md and its folder, Upgrade JS Deps needs the command-line tools its instructions call (make and npx). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(npx npm-check-updates *), Bash(make npm-install *), Bash(make npm-build *), Bash(make npm-type-check *), Bash(make test *).

Does Upgrade JS Deps access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Upgrade JS Deps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Upgrade JS Deps use?

Upgrade JS Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upgrade JS Deps use?

About 402 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upgrade JS Deps?

Skills that share tags, products or a category with Upgrade JS Deps: Chrome CDP Browser Control (zenstory-ai/oh-story-claudecode, 7.4k stars), Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.4k stars), Logseq Plugin SDK (logseq/logseq, 45k stars) and Compromise NLP for JavaScript (spencermountain/compromise, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upgrade JS Deps?

saaspegasus (a GitHub organization) maintains it in saaspegasus/django-boilerplate, which has 177 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: saaspegasus/django-boilerplate on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.