Agent skill

Update Package Skill

by skilld-dev in skilld-dev/skilld

Updates an existing package Skill for a new release of its npm or local package by testing only what changed since the version the Skill names.

MITAuto-check passedDevelopment

Install Update Package Skill

skills CLI
$ npx skills add skilld-dev/skilld --skill update-package-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install skilld-dev/skilld update-package-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/skilld-dev/skilld.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/update-package-skill .claude/skills/update-package-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-package-skill
GitHub stars
315
Token cost
~992 tokens
SKILL.md length
601 words
Files
2 (incl. assets)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Updates an existing package Skill for a new release of its npm or local package by testing only what changed since the version the Skill names.

  • Works in 5 steps: Copy, then diff → Map changes to the Skill → Test the affected lines → …
  • A maintainer asks to refresh a package Skill after a release
  • SKILL.md covers Inputs, 1. Copy, then diff, 2. Map changes to the Skill and 3. Test the affected lines, plus 2 more sections
  • Calls npm

What it does

Update Package Skill is an agent skill from skilld-dev/skilld. Updates an existing package Skill for a new release of its npm or local package by testing only what changed since the version the Skill names. Use when a maintainer asks to refresh a package Skill after a release, or when a SKILL.md names an older tested version than the package.

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including assets (for example `assets/harness-request.md`).

It sits in Development. It works with npm. The repository describes itself as: Open-source, privacy friendly skills.sh alternative for humans and agents. The licence is MIT.

When your agent uses it

  • A maintainer asks to refresh a package Skill after a release
  • A SKILL.md names an older tested version than the package

Example prompts

  • “Use the update-package-skill skill to update an existing package Skill for a new release of its npm or local package by testing only what changed…”
  • “/update-package-skill”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Copy, then diff
  2. Map changes to the Skill
  3. Test the affected lines
  4. Edit
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 5797f37. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Package Skill loads about 992 tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 601 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~992

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from skilld-dev/skilld at commit 5797f37, republished under its MIT licence (© skilld-dev). 601 words, ~992 tokens.

Download SKILL.mdSave it as .claude/skills/update-package-skill/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
update-package-skill
description
Updates an existing package Skill for a new release of its npm or local package by testing only what changed since the version the Skill names. Use when a maintainer asks to refresh a package Skill after a release, or when a SKILL.md names an older tested version than the package.

Update a package Skill

Bring an existing package Skill to a new package version with the smallest correct edit. The current Skill was tested against an earlier version. Trust what the release did not touch. To write a Skill from nothing, use generate-package-skill.

Inputs

  • The current Skill directory, and the package at the new version: a name and version, a directory, or prepared source.
  • The tested version is the version the Skill's first paragraph names. If it names none, stop and report that the Skill needs a full rewrite.
  • If the tested version equals the new version, change nothing and report that.

1. Copy, then diff

  1. Copy the current Skill to the destination unchanged. Edit only the copy.
  2. Diff the two published versions: npm diff --diff=PACKAGE@OLD --diff=PACKAGE@NEW. For a local package, diff the old tarball against the packed build.
  3. Read the changelog or release notes between the two versions.
  4. List what changed for a consumer: exports, types, options and their defaults, config keys, error messages, CLI flags, peer ranges, engines, and behaviour the notes describe.

2. Map changes to the Skill

For each change, find the Skill lines it affects: a claim, an example, a trap, a version limit. A change is relevant when it affects a Skill line, or when it adds or breaks something an Agent would get wrong: a new trap, a renamed call, a new required setup step. Internals, refactors, and fixes the Skill never mentioned are not relevant.

If no change is relevant, leave the copy byte-identical and stop. Report "no change needed" with a one-line diff summary.

3. Test the affected lines

  1. Create one consumer fixture outside the package source, with its own pnpm-workspace.yaml. Install the new version and the documented peers.
  2. Run each affected example and claim, and each example you add. Compare output with the claim: return values, type errors, build logs, exit codes.
  3. Run each with one failure input as well, such as a bad option or an unreachable URL.
  4. Do not re-run untouched examples. The earlier version's tests cover them.
  5. Wrap every run in timeout 120. Start servers from your own script, record each process ID you start, and stop only those. Never kill by port or with pkill -f.
  6. Spend about 20 tool calls on testing. Report an affected claim you could not test as untested; never claim it passed.
Show full SKILL.md (200 more words)Show less

4. Edit

  • Change only affected lines, and add what the release needs: a new trap, an old call → new call row, a new common task.
  • Delete lines the release made false, and version limits it fixed.
  • Update the tested version in the first paragraph. Other version literals go stale; avoid them.
  • Keep the wording, order, and formatting of untouched lines exactly. The diff must show only what the release changed.
  • Update the description only when a trigger changed, such as a renamed export or a new config key.

Keep the format rules:

  • The frontmatter contains only name and description. The name matches the directory.
  • The description is one plain YAML line without double quotes, backticks, or %.
  • SKILL.md stays under 500 lines. Write at most eight reference files, each linked from SKILL.md.

5. Report

  • The tested version, old → new, and the files you changed.
  • Each changed line with the diff hunk or release note behind it.
  • Each affected claim left untested.
  • Each mismatch between the new docs and observed behaviour: example, documented result, observed result. These are package bugs.

For a direct run, show the Skill diff for review. A direct run has no Harness checks; never claim it passed them.

© skilld-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (assets) in skills/update-package-skill of skilld-dev/skilld.

  • SKILL.md
  • assets/harness-request.md

Open the folder on GitHubat commit 5797f37

Compare with similar skills

Update Package Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Package Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Package Skill this skillskilld-dev/skilld315—~992Automated safety check: PassMIT
Nx Run Tasksnomcopter/react-mosaic4.8k7 repos~613Automated safety check: PassCustom licence
Get API Docs with chubandrewyng/context-hub14k2 repos~775Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost55k—~3.8kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0

Similar skills

  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 7 repos~613 tokens
    DevelopmentAuto-check passed
  • Get API Docs with chub

    andrewyng/context-hub

    Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.

    14k GitHub starsUsed in 2 repos~775 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Looks up current documentation and code examples for any library, framework, SDK or CLI with the Context7 ctx7 command instead of relying on training data.

    1.5k GitHub starsUsed in 3 repos~1.6k tokens
    DevelopmentAuto-check passed

More from skilld-dev/skilld

  • Generate Package Skill

    skilld-dev/skilld

    Generate or update an Agent Skill that teaches consumers one npm or local package the user maintains, including framework modules and wrappers.

    315 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Skilld

    skilld-dev/skilld

    Operate skilld CLI for Skill discovery, use, installation, inspection, updates, authentication, configuration, restoration, and removal, including Repository, curator, and collection refs.

    315 GitHub stars~5.3k tokensUpdated today
    Auto-check passed
  • Review Skill

    skilld-dev/skilld

    Review an Agent Skill for valid structure, clear triggers, usable instructions, current evidence, and risky or unclear actions.

    315 GitHub stars~648 tokensUpdated today
    Auto-check passed
  • Generate Project Skill

    skilld-dev/skilld

    Generate or update an Agent Skill from the observed workflows, boundaries, and conventions of one software project.

    315 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Update Package Skill

What does Update Package Skill do?

Updates an existing package Skill for a new release of its npm or local package by testing only what changed since the version the Skill names. Update Package Skill is an agent skill from skilld-dev/skilld. Updates an existing package Skill for a new release of its npm or local package by testing only what changed since the version the Skill names.

When should I use Update Package Skill?

Update Package Skill fits situations like: A maintainer asks to refresh a package Skill after a release; A SKILL.md names an older tested version than the package.

How do I install Update Package Skill in Claude Code?

Run `npx skills add skilld-dev/skilld --skill update-package-skill -a claude-code`. Or copy the skill folder (skills/update-package-skill in skilld-dev/skilld) into .claude/skills/update-package-skill in your project. Claude Code loads it when a task matches its description.

How do I install Update Package Skill in Codex?

Run `npx skills add skilld-dev/skilld --skill update-package-skill -a codex`. Or copy the skill folder (skills/update-package-skill in skilld-dev/skilld) into .agents/skills/update-package-skill in your project. Codex loads it when a task matches its description.

Can I use Update Package Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add skilld-dev/skilld --skill update-package-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-package-skill, .gemini/skills/update-package-skill, .github/skills/update-package-skill and .opencode/skills/update-package-skill in your project.

What does Update Package Skill need to run?

Going by SKILL.md and its folder, Update Package Skill needs the command-line tools its instructions call (npm).

Does Update Package Skill access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Package Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Package Skill use?

Update Package Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Package Skill use?

About 992 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Package Skill?

Skills that share tags, products or a category with Update Package Skill: Nx Run Tasks (nomcopter/react-mosaic, 4.8k stars), Get API Docs with chub (andrewyng/context-hub, 14k stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 55k stars) and Open Code Review CLI (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Package Skill?

skilld-dev (a GitHub organization) maintains it in skilld-dev/skilld, which has 315 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 7, 2026.

Source: skilld-dev/skilld on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.