Agent skill

Updating npm Package

by spencerpauly in spencerpauly/awesome-cursor-skills

Safely update an npm package by checking npmjs.com for the latest version, reading release notes, and handling minor vs major upgrades differently.

CC0-1.0Auto-check passedDevelopment

Install Updating npm Package

skills CLI
$ npx skills add spencerpauly/awesome-cursor-skills --skill updating-npm-package -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spencerpauly/awesome-cursor-skills updating-npm-package --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spencerpauly/awesome-cursor-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/updating-npm-package .claude/skills/updating-npm-package && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
updating-npm-package
GitHub stars
844
Token cost
~923 tokens
SKILL.md length
304 words
Files
1
Skills in repo
60
Repo updated
First seen
Licence
CC0-1.0

At a glance

Safely update an npm package by checking npmjs.com for the latest version, reading release notes, and handling minor vs major upgrades differently.

  • Works in 5 steps: Check the current version — read… → Find the latest version on npm — fetch… → Determine the update type — compare… → …
  • Tasks that involve Code migrations
  • SKILL.md covers Steps and Notes
  • Calls npm and npx

What it does

Updating npm Package is an agent skill from spencerpauly/awesome-cursor-skills. Safely update an npm package by checking npmjs.com for the latest version, reading release notes, and handling minor vs major upgrades differently. For minor updates, just do it. For major updates, find the upgrade guide, validate breaking changes, and produce a detailed migration report.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code migrations and Changelog and release notes. It works with npm. The repository describes itself as: A curated list of awesome skills for Cursor. The licence is CC0-1.0.

When your agent uses it

  • Tasks that involve Code migrations
  • Tasks that involve Changelog and release notes

Example prompts

  • “/updating-npm-package”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Check the current version — read package.json to find the installed version
  2. Find the latest version on npm — fetch the package info
  3. Determine the update type — compare current version to latest
  4. For patch or minor updates — just do it
  5. For major updates — do a thorough investigation first

What it can do on your machine

Read from SKILL.md and the folder at commit 99cd265. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Updating npm Package loads about 923 tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 304 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~923

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spencerpauly/awesome-cursor-skills at commit 99cd265, republished under its CC0-1.0 licence (© spencerpauly). 304 words, ~923 tokens.

Download SKILL.mdSave it as .claude/skills/updating-npm-package/SKILL.md (or your agent's skills folder).
name
updating-npm-package
description
Safely update an npm package by checking npmjs.com for the latest version, reading release notes, and handling minor vs major upgrades differently. For minor updates, just do it. For major updates, find the upgrade guide, validate breaking changes, and produce a detailed migration report.

Updating an npm Package

Use this skill when the user asks to update, upgrade, or bump a specific npm dependency.

Steps

  1. Check the current version — read package.json to find the installed version:

    bash
    npm ls <package-name>
  2. Find the latest version on npm — fetch the package info:

    bash
    npm view <package-name> versions --json
    npm view <package-name> dist-tags --json

    This gives you the latest tag and all published versions.

  3. Determine the update type — compare current version to latest:

    • Patch (1.2.3 → 1.2.4): bug fixes only
    • Minor (1.2.3 → 1.3.0): new features, backwards compatible
    • Major (1.2.3 → 2.0.0): breaking changes
  4. For patch or minor updates — just do it:

    bash
    npm install <package-name>@latest

    Run the build and tests to make sure nothing broke:

    bash
    npm run build && npm test

    If everything passes, commit and report what changed.

  5. For major updates — do a thorough investigation first:

    a. Fetch the changelog and release notes — check the package's GitHub repo for CHANGELOG.md, MIGRATION.md, or release notes. Use the web to find the official upgrade guide:

    Search: "<package-name> v<major> migration guide" OR "<package-name> v<major> upgrade guide"

    b. Read the breaking changes — identify every breaking change between the current and target version. Common things to check:

    • Removed or renamed APIs
    • Changed function signatures or return types
    • Dropped Node.js version support
    • New peer dependency requirements
    • Changed default behavior
    • Config file format changes

    c. Scan the codebase for impact — search for every usage of the package:

    bash
    # Find all imports
    grep -r "from ['\"]<package-name>" src/
    grep -r "require(['\"]<package-name>" src/

    For each usage, check if it's affected by a breaking change.

    d. Apply the update:

    bash
    npm install <package-name>@latest

    e. Fix breaking changes — update each affected usage based on the migration guide. Apply changes file by file.

    f. Verify — run the full suite:

    bash
    npm run lint && npx tsc --noEmit && npm test && npm run build

    g. Produce a migration report — summarize:

    markdown
    ## Package Update: <package-name> v<old> → v<new> (Major)
    
    ### Breaking Changes Applied
    - `oldFunction()` renamed to `newFunction()` — updated in 3 files
    - Config format changed from `.js` to `.config.ts` — migrated
    - Dropped support for Node 16 — verified we're on Node 20
    
    ### Files Modified
    - src/lib/client.ts — updated import and function call
    - src/config/settings.ts — migrated config format
    - package.json — bumped version
    
    ### Validation
    - ✅ Lint passes
    - ✅ TypeScript compiles
    - ✅ All 47 tests pass
    - ✅ Build succeeds
Show full SKILL.md (57 more words)Show less

Notes

  • Always check peer dependency compatibility before updating — npm install will warn about mismatches.
  • For monorepos, check if the package is used in multiple workspaces and update them all together.
  • If the package has a codemod tool (e.g. npx @next/codemod), use it instead of manual migration.
  • Lock file (package-lock.json) changes are expected — commit them with the update.

© spencerpauly, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in resources/updating-npm-package of spencerpauly/awesome-cursor-skills.

Open the folder on GitHubat commit 99cd265

Compare with similar skills

Updating npm Package next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Updating npm Package compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Updating npm Package this skillspencerpauly/awesome-cursor-skills844—~923Automated safety check: PassCC0-1.0
Hz API Upgrademeta-quest/agentic-tools215—~1.8kAutomated safety check: PassApache-2.0
Migrate Internal Package into GhostTryGhost/Ghost56k—~3.8kAutomated safety check: PassMIT
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Deprecate R Functions and Argumentstidyverse/dplyr5.1k1 repos~1.2kAutomated safety check: PassCustom licence
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Hz API Upgrade

    meta-quest/agentic-tools

    Upgrades Meta VR apps to newer Horizon OS SDK versions — migration guides, deprecated API replacements, changelog.

    215 GitHub stars~1.8k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    56k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Walks through deprecating an R function or argument in a package: lifecycle warning, silenced tests, a new snapshot test, documentation badge and NEWS entry.

    5.1k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.6k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from spencerpauly/awesome-cursor-skills

All 60 skills in this repo
  • Generating Images

    spencerpauly/awesome-cursor-skills

    Generate or edit images using the OpenAI Image API (gpt-image-2).

    844 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check: notes
  • Babysitting PR

    spencerpauly/awesome-cursor-skills

    Monitor a pull request for CI failures, review comments, and merge conflicts — then fix them automatically.

    844 GitHub stars~930 tokensUpdated 2 mo ago
    Auto-check passed
  • Best Of N Solving

    spencerpauly/awesome-cursor-skills

    Solve a hard problem by trying multiple approaches in parallel using isolated git worktrees.

    844 GitHub stars~698 tokensUpdated 2 mo ago
    Auto-check passed
  • Grinding Until Pass

    spencerpauly/awesome-cursor-skills

    Keep iterating on code changes until the tests pass, the build succeeds, or linting is clean.

    844 GitHub stars~796 tokensUpdated 2 mo ago
    Auto-check passed
  • Parallel CI Triage

    spencerpauly/awesome-cursor-skills

    When GitHub Actions fails, fetch failing job logs and assign each failing job to a separate subagent that fixes its slice of the problem in parallel.

    844 GitHub stars~793 tokensUpdated 2 mo ago
    Auto-check passed
  • Parallel Exploring

    spencerpauly/awesome-cursor-skills

    Explore a large codebase in parallel by launching multiple explore subagents that each investigate a different area simultaneously.

    844 GitHub stars~787 tokensUpdated 2 mo ago
    Auto-check: notes

Works with

Categories

Questions about Updating npm Package

What does Updating npm Package do?

Safely update an npm package by checking npmjs.com for the latest version, reading release notes, and handling minor vs major upgrades differently. Updating npm Package is an agent skill from spencerpauly/awesome-cursor-skills.com for the latest version, reading release notes, and handling minor vs major upgrades differently.

When should I use Updating npm Package?

Updating npm Package fits situations like: tasks that involve Code migrations; tasks that involve Changelog and release notes.

How do I install Updating npm Package in Claude Code?

Run `npx skills add spencerpauly/awesome-cursor-skills --skill updating-npm-package -a claude-code`. Or copy the skill folder (resources/updating-npm-package in spencerpauly/awesome-cursor-skills) into .claude/skills/updating-npm-package in your project. Claude Code loads it when a task matches its description.

How do I install Updating npm Package in Codex?

Run `npx skills add spencerpauly/awesome-cursor-skills --skill updating-npm-package -a codex`. Or copy the skill folder (resources/updating-npm-package in spencerpauly/awesome-cursor-skills) into .agents/skills/updating-npm-package in your project. Codex loads it when a task matches its description.

Can I use Updating npm Package in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spencerpauly/awesome-cursor-skills --skill updating-npm-package -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/updating-npm-package, .gemini/skills/updating-npm-package, .github/skills/updating-npm-package and .opencode/skills/updating-npm-package in your project.

What does Updating npm Package need to run?

Going by SKILL.md and its folder, Updating npm Package needs the command-line tools its instructions call (npm and npx). Our summary lists: Node.js.

Does Updating npm Package access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Updating npm Package safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Updating npm Package use?

Updating npm Package is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Updating npm Package use?

About 923 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Updating npm Package?

Skills that share tags, products or a category with Updating npm Package: Hz API Upgrade (meta-quest/agentic-tools, 215 stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 56k stars), Cutting A Release (TriliumNext/Trilium, 38k stars) and Deprecate R Functions and Arguments (tidyverse/dplyr, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Updating npm Package?

spencerpauly (a GitHub user) maintains it in spencerpauly/awesome-cursor-skills, which has 844 GitHub stars. The repository holds 60 skills in this directory. The repository was last updated on August 2, 2026.

Source: spencerpauly/awesome-cursor-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.