Agent skill

Upgrade Python Deps

by saaspegasus in saaspegasus/django-boilerplate

Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken.

MITAuto-check passed

Install Upgrade Python Deps

skills CLI
$ npx skills add saaspegasus/django-boilerplate --skill upgrade-python-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install saaspegasus/django-boilerplate upgrade-python-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/saaspegasus/django-boilerplate.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/upgrade-python-deps .claude/skills/upgrade-python-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upgrade-python-deps
GitHub stars
177
Token cost
~570 tokens
SKILL.md length
286 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken.

  • Works in 5 steps: Upgrade the lock file → Remove the cooldown marker from the lock… → Sync the environment → …
  • Calls uv and make

What it does

Upgrade Python Deps is an agent skill from saaspegasus/django-boilerplate. Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken.

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Python. The repository describes itself as: The original SaaS Boilerplate for Django, trusted by thousands. The licence is MIT.

Example prompts

  • “/upgrade-python-deps”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): [, Bash(uv lock *), Bash(uv sync *), Bash(make test *), Bash(uv run mypy *), Bash(sed -i '/^\[options\]$/,/^$/d' uv.lock), Bash(grep * uv.lock), ]

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Upgrade the lock file
  2. Remove the cooldown marker from the lock file
  3. Sync the environment
  4. Run post-upgrade checks
  5. Summarize and commit

What it can do on your machine

Read from SKILL.md and the folder at commit 0174a41. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • [
    • Bash(uv lock *)
    • Bash(uv sync *)
    • Bash(make test *)
    • Bash(uv run mypy *)
    • Bash(sed -i '/^\[options\]$/
    • /^$/d' uv.lock)
    • Bash(grep * uv.lock)
    • ]

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upgrade Python Deps loads about 570 tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 286 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~570

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from saaspegasus/django-boilerplate at commit 0174a41, republished under its MIT licence (© saaspegasus). 286 words, ~570 tokens.

Download SKILL.mdSave it as .claude/skills/upgrade-python-deps/SKILL.md (or your agent's skills folder).
name
upgrade-python-deps
description
Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken.
allowed-tools
[, Bash(uv lock *), Bash(uv sync *), Bash(make test *), Bash(uv run mypy *), Bash(sed -i '/^\[options\]$/,/^$/d' uv.lock), Bash(grep * uv.lock), ]

Your task

Upgrade all Python dependencies and verify nothing is broken.

Step 1: Upgrade the lock file

Run uv lock --upgrade --exclude-newer "7 days" to upgrade all dependencies to their latest compatible versions (with a 7-day cooldown to mitigate supply-chain attacks).

Review the output for any resolution errors. If there are conflicts, report them to the user and ask how to proceed before continuing.

Step 2: Remove the cooldown marker from the lock file

uv records the --exclude-newer cutoff inside uv.lock as project configuration. Since it isn't declared in pyproject.toml, any later uv sync or uv run sees a config mismatch, discards the lockfile, and silently re-resolves everything to the newest versions — undoing the cooldown. Prevent this by deleting the [options] block at the top of uv.lock (the exclude-newer / exclude-newer-span lines) before syncing:

bash
sed -i '/^\[options\]$/,/^$/d' uv.lock

The cooldown-resolved versions stay in place; only the marker is removed. Verify with grep exclude-newer uv.lock (should print nothing).

Step 3: Sync the environment

Run uv sync to install the upgraded dependencies into the virtual environment.

Step 4: Run post-upgrade checks

Run these checks sequentially, stopping if any step fails:

  • Type checking: Run uv run mypy . and report any new type errors. These may be caused by updated type stubs or changes in library APIs.
  • Tests: Run make test to verify the test suite still passes.
Step 5: Summarize and commit

Summarize what was done:

  • Which packages were upgraded (notable version changes)
  • Whether any type errors were introduced
  • Whether all tests passed
  • Any issues that need manual attention

If there were failures, present the issues and ask how the user wants to proceed.

If everything passed, ask the user if they'd like to commit the changes. If yes, commit using the /commit skill.

© saaspegasus, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/upgrade-python-deps of saaspegasus/django-boilerplate.

Open the folder on GitHubat commit 0174a41

Compare with similar skills

Upgrade Python Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upgrade Python Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upgrade Python Deps this skillsaaspegasus/django-boilerplate177—~570Automated safety check: PassMIT
MCP Server Builderanthropics/skills180k64 repos~2.3kAutomated safety check: PassApache-2.0
PDF Processinganthropics/skills180k48 repos~2kAutomated safety check: PassProprietary
NotebookLM Research AssistantPleasePrompto/notebooklm-skill7.8k14 repos~2.4kAutomated safety check: NotesMIT
Manim Video Productionbrowser-use/video-use28k6 repos~3kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 64 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • PDF Processing

    anthropics/skills

    Official

    Handles everyday PDF jobs in Python and on the command line: extract text and tables, merge, split, rotate, watermark, fill forms, encrypt and OCR.

    180k GitHub starsUsed in 48 repos~2k tokens
    Documents & OfficeAuto-check passed
  • NotebookLM Research Assistant

    PleasePrompto/notebooklm-skill

    Lets Claude Code ask questions of your Google NotebookLM notebooks through browser automation and return answers grounded in your uploaded sources.

    7.8k GitHub starsUsed in 14 repos~2.4k tokens
    Knowledge ManagementAuto-check: notes
  • Manim Video Production

    browser-use/video-use

    Produces math and technical explainer videos with Manim Community Edition: concept animations, equation derivations, algorithm walkthroughs and data stories.

    28k GitHub starsUsed in 6 repos~3k tokens
    Media & CreativeAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • PPT Master

    hugohe3/ppt-master

    Generates editable PowerPoint decks, rebuilds slides from images, fills .pptx templates and polishes existing presentations through routed workflows.

    58k GitHub starsUsed in 1 repo~2.5k tokens
    Documents & OfficeAuto-check passed

More from saaspegasus/django-boilerplate

  • Pegasus Projects

    saaspegasus/django-boilerplate

    A skill your agent uses when the user asks to create, view, or modify a SaaS Pegasus project via the pegasus CLI — e.g.

    177 GitHub stars~5.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Resolve Pegasus Conflicts

    saaspegasus/django-boilerplate

    Resolve merge conflicts when upgrading SaaS Pegasus. An agent skill from saaspegasus/django-boilerplate.

    177 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Upgrade Pegasus

    saaspegasus/django-boilerplate

    Upgrade to the latest version of SaaS Pegasus. An agent skill from saaspegasus/django-boilerplate.

    177 GitHub stars~621 tokensUpdated 1 mo ago
    Auto-check passed
  • Fix Types

    saaspegasus/django-boilerplate

    Interactively fix any type checking issues in Python code. An agent skill from saaspegasus/django-boilerplate.

    177 GitHub stars~806 tokensUpdated 1 mo ago
    Auto-check passed
  • Upgrade JS Deps

    saaspegasus/django-boilerplate

    Upgrade JavaScript dependencies using npm-check-updates, then run post-upgrade checks to ensure nothing is broken.

    177 GitHub stars~402 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Upgrade Python Deps

What does Upgrade Python Deps do?

Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken. Upgrade Python Deps is an agent skill from saaspegasus/django-boilerplate. Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken.

How do I install Upgrade Python Deps in Claude Code?

Run `npx skills add saaspegasus/django-boilerplate --skill upgrade-python-deps -a claude-code`. Or copy the skill folder (.claude/skills/upgrade-python-deps in saaspegasus/django-boilerplate) into .claude/skills/upgrade-python-deps in your project. Claude Code loads it when a task matches its description.

How do I install Upgrade Python Deps in Codex?

Run `npx skills add saaspegasus/django-boilerplate --skill upgrade-python-deps -a codex`. Or copy the skill folder (.claude/skills/upgrade-python-deps in saaspegasus/django-boilerplate) into .agents/skills/upgrade-python-deps in your project. Codex loads it when a task matches its description.

Can I use Upgrade Python Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add saaspegasus/django-boilerplate --skill upgrade-python-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-python-deps, .gemini/skills/upgrade-python-deps, .github/skills/upgrade-python-deps and .opencode/skills/upgrade-python-deps in your project.

What does Upgrade Python Deps need to run?

Going by SKILL.md and its folder, Upgrade Python Deps needs the command-line tools its instructions call (uv and make). Our summary lists: Python 3. Its frontmatter pre-approves these tools: [, Bash(uv lock *), Bash(uv sync *), Bash(make test *), Bash(uv run mypy *), Bash(sed -i '/^\[options\]$/,/^$/d' uv.lock), Bash(grep * uv.lock), ].

Does Upgrade Python Deps access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Upgrade Python Deps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Upgrade Python Deps use?

Upgrade Python Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upgrade Python Deps use?

About 570 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upgrade Python Deps?

Skills that share tags, products or a category with Upgrade Python Deps: MCP Server Builder (anthropics/skills, 180k stars), PDF Processing (anthropics/skills, 180k stars), NotebookLM Research Assistant (PleasePrompto/notebooklm-skill, 7.8k stars) and Manim Video Production (browser-use/video-use, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upgrade Python Deps?

saaspegasus (a GitHub organization) maintains it in saaspegasus/django-boilerplate, which has 177 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 7, 2026.

Source: saaspegasus/django-boilerplate on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.