Agent skill

Update Qm

by yc-software in yc-software/qm

Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR.

MITAuto-check passedDevOps & Cloud

Install Update Qm

skills CLI
$ npx skills add yc-software/qm --skill update-qm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yc-software/qm update-qm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/update-qm .claude/skills/update-qm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-qm
GitHub stars
15k
Token cost
~1.8k tokens
SKILL.md length
995 words
Files
2
Skills in repo
29
Repo updated
First seen
Licence
MIT

At a glance

Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR.

  • Asked to update qm
  • SKILL.md covers Identify the checkout, Merge, never rebase, Resolving conflicts and Verify before opening the PR, plus 2 more sections
  • Calls git, gh and npm
  • Sync from upstream

What it does

Update Qm is an agent skill from yc-software/qm. Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR. Use when asked to "update qm", "sync from upstream", "pull in the latest qm".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in DevOps & Cloud, covering Pull requests and Deployment. It works with Git. The repository describes itself as: Multiplayer agent harness for work. The licence is MIT.

When your agent uses it

  • Asked to update qm
  • Sync from upstream
  • Pull in the latest qm

Example prompts

  • “update qm”
  • “sync from upstream”
  • “pull in the latest qm”
  • “/update-qm”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 0492745. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, gh and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Qm loads about 1.8k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 995 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yc-software/qm at commit 0492745, republished under its MIT licence (© yc-software). 995 words, ~1,827 tokens.

Download SKILL.mdSave it as .claude/skills/update-qm/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
update-qm
description
Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR. Use when asked to "update qm", "sync from upstream", "pull in the latest qm".

update-qm

Determine whether this is a source fork or a package deployment before choosing the update procedure. Source forks may intentionally change core; preserve those changes. Contributing them upstream is optional.

Identify the checkout

Run git remote -v and inspect the files and ancestry. If origin is yc-software/qm, this is upstream itself, not a downstream sync target. A different origin alone does not prove a source fork. A source fork has the QM source tree and shared upstream history; a package deployment has a deployment config and a pinned @yc-software/qm dependency. In a source fork with nested deployment directories, update source unless the request specifically targets a nested package pin.

For a package deployment, work on a topic branch and install the requested release with npm install --save-exact @yc-software/qm@<version>. If no version is specified, resolve the current published release first. Review the package and lockfile diff, contract changes, and image overrides that could keep workloads on older images. Package updates do not refresh generated runbooks, skills, or vendored Terraform: compare the release's scaffold in a separate temporary directory and reconcile required changes without reinitializing or overwriting the existing deployment. Run the installed CLI's check, doctor, and plan, then open a PR in the deployment repository. Deploy only within the user's requested scope, following its deployment runbook and live checks. Do not add an upstream source remote or merge source into a package deployment.

For a source fork, check the upstream remote points to yc-software/qm; if absent, add git remote add upstream git@github.com:yc-software/qm. Confirm shared history before merging. Never merge downstream history into upstream. Use --repo on every gh command. Inspect the actual default branch; the examples below assume main and must be adapted if the fork deliberately uses another name. If a mirror-seeded repository has a stale feature branch as its default, identify the intended base before syncing; do not silently merge into the stale branch or delete existing refs.

Merge, never rebase

origin/main is published history that deploys and other clones track. Rebasing it onto upstream rewrites those commits, so always merge.

bash
git switch main
git pull --ff-only origin main
git fetch upstream
git switch -c codex/sync-upstream-<yyyy-mm-dd>
git log --oneline main..upstream/main
git merge upstream/main

Record the commit range before resolving anything so the PR can state it. If the merge reports "Already up to date", delete the branch and report that instead of opening an empty PR.

Resolving conflicts

Read both sides and the local commits that explain the customization. Preserve intentional local behavior while integrating upstream fixes; a core conflict is expected maintenance, not a policy violation. Keep deployment data in the layer or separate private deployment repository where practical. Do not discard a core modification just because it is organization-specific or insist it be contributed upstream.

Document conflicts, resolutions, and remaining divergence in the sync PR. When intent cannot be recovered from code, tests, or history, ask the operator before choosing a behavior. Review inherited CI and publishing changes for the fork's own accounts and registries rather than enabling upstream workflows blindly.

Verify before opening the PR

Determine affected tests from the merged range and conflict resolutions. Run those locally plus typecheck and lint; include CLI tests for CLI or deployment-contract changes. Use the full local suite only when the affected scope cannot be determined; otherwise let CI run it. Install the locked dependencies first:

bash
npm ci
npm run typecheck
npm run lint

A sync can raise the deployment contract major, and the CLI rejects a layer config written for the old one. Check each organization layer with the in-tree CLI (npm exec qm does not work in a source checkout; the workspace symlink points at cli/, which is unbuilt):

bash
node cli/bin/qm.ts check --config deploy/layers/<org>/qm.config.jsonc

For deployments outside the checkout, substitute their config paths. If a config reports an unsupported contract major, adapting it is part of the sync. Verify non-trivial behavior changes in a live dev instance before opening the PR, per AGENTS.md. Production service builds must use --build-from against this checkout (or deliberately published custom images); merging source does not update published runtime images. See the README source deployment procedure.

Show full SKILL.md (345 more words)Show less

Open the PR

bash
git push -u origin codex/sync-upstream-<yyyy-mm-dd>
gh pr create --repo <source-fork> --base main \
  --title "Sync upstream qm through <short-sha>" \
  --body-file .generated/sync-body.md

Pass --repo to every gh command you run in a private fork. Without it, gh picks a base repository from the clone's remotes and may choose upstream: the sync PR gets opened against qm, and gh pr edit 1 overwrites whatever PR is number 1 in the source repository. The same applies to gh pr view, gh pr list, and gh issue.

The description should state the upstream commit range merged, any file outside deploy/layers/ that conflicted and how it was resolved, and the results of the checks above.

When authorized to land a source-sync PR, preserve the upstream ancestry with a merge commit (gh pr merge --repo <source-fork> <pr> --merge) or an ancestry-preserving fast-forward. Never squash or rebase a source-sync PR, even if the repository's usual shipping workflow uses squash: that loses the upstream merge and causes later syncs to revisit already-integrated history. If repository settings prohibit merge commits, resolve that policy before landing; do not fall back to squash. Package dependency PRs can follow the deployment repository's ordinary merge policy.

If the private fork deploys from main, merging this PR ships upstream's changes to production, so merge when someone can watch it.

A source fork runs its enabled CI workflows in its own account. A sync that adds or changes CI changes what runs on the next PR, and workflows that need secrets the fork never received will fail until those are supplied.

Never do these

  • git push --mirror to seed or update a source fork. It copies unrelated branches and tags, leaves initial default-branch selection implicit, and can delete destination-only refs. Seed only main and explicitly set the default branch as the README shows.
  • Pushing a branch whose history contains organization commits to upstream. The upstream-pr skill pushes upstream only from branches cut fresh from upstream/main and scrubbed.
  • Rebasing main onto upstream/main, or force-pushing a private fork's main.
  • Resolving a conflict by deleting the upstream side wholesale to quiet the merge. That silently diverges core from upstream, and the divergence returns as a larger conflict in the next sync.

© yc-software, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/update-qm of yc-software/qm.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 0492745

Compare with similar skills

Update Qm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Qm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Qm this skillyc-software/qm15k—~1.8kAutomated safety check: PassMIT
Vercel Deploy Previewjeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
Reviewwerf/werf4.7k—~2kAutomated safety check: PassApache-2.0
GitHub Workflow AutomationFNOSP/FlyNarwhal4958 repos~5.4kAutomated safety check: PassAGPL-3.0
Agr Releasecomputerlovetech/agr451—~1.6kAutomated safety check: PassMIT
Releasear-io/ar-io-node127—~4.2kAutomated safety check: NotesAGPL-3.0

Similar skills

  • Vercel Deploy Preview

    jeremylongshore/tons-of-skills-marketplace

    Create and manage Vercel preview deployments for branches and pull requests.

    2.8k GitHub stars~1.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Review

    werf/werf

    Code review of a pull request, branch, or diff. An agent skill from werf/werf.

    4.7k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Automate GitHub workflows with AI assistance. An agent skill from FNOSP/FlyNarwhal.

    495 GitHub starsUsed in 8 repos~5.4k tokens
    DevOps & CloudAuto-check passed
  • Agr Release

    computerlovetech/agr

    Release process for the agr package. An agent skill from computerlovetech/agr.

    451 GitHub stars~1.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Release

    ar-io/ar-io-node

    Drive the AR.IO Node release process end-to-end — preflight checks, prepare commit, finalize with image SHAs, test docker compose profiles, tag & publish, and post-release cleanup.

    127 GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Mecatl Release Cutting

    stacklok/mecatl

    Cuts a tagged mecatl release by dispatching the release-PR workflow, merging the bot's pull request and verifying the tag, images, Helm chart, signed archives and Homebrew formula.

    241 GitHub stars~3.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from yc-software/qm

All 29 skills in this repo
  • Admin

    yc-software/qm

    Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…

    15k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Browse

    yc-software/qm

    Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel…

    15k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Composio

    yc-software/qm

    Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.

    15k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Dev Instance

    yc-software/qm

    Run the current worktree as a production-shaped local dev instance with web, Slack, or both, on a real LLM + Postgres.

    15k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes
  • GitHub GitLab

    yc-software/qm

    Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.

    15k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Google Workspace

    yc-software/qm

    Read and act on the user's Gmail, Google Calendar, and Google Tasks through per-user OAuth.

    15k GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Update Qm

What does Update Qm do?

Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR. Update Qm is an agent skill from yc-software/qm. Update a QM source fork by merging upstream, or upgrade a package deployment dependency, and open a PR.

When should I use Update Qm?

Update Qm fits situations like: asked to update qm; sync from upstream; pull in the latest qm.

How do I install Update Qm in Claude Code?

Run `npx skills add yc-software/qm --skill update-qm -a claude-code`. Or copy the skill folder (.codex/skills/update-qm in yc-software/qm) into .claude/skills/update-qm in your project. Claude Code loads it when a task matches its description.

How do I install Update Qm in Codex?

Run `npx skills add yc-software/qm --skill update-qm -a codex`. Or copy the skill folder (.codex/skills/update-qm in yc-software/qm) into .agents/skills/update-qm in your project. Codex loads it when a task matches its description.

Can I use Update Qm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yc-software/qm --skill update-qm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-qm, .gemini/skills/update-qm, .github/skills/update-qm and .opencode/skills/update-qm in your project.

What does Update Qm need to run?

Going by SKILL.md and its folder, Update Qm needs the command-line tools its instructions call (git, gh, npm and node). Our summary lists: Node.js.

Does Update Qm access the network?

SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Qm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Qm use?

Update Qm is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Qm use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Qm?

Skills that share tags, products or a category with Update Qm: Vercel Deploy Preview (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Review (werf/werf, 4.7k stars), GitHub Workflow Automation (FNOSP/FlyNarwhal, 495 stars) and Agr Release (computerlovetech/agr, 451 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Qm?

yc-software (a GitHub organization) maintains it in yc-software/qm, which has 15,362 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 8, 2026.

Source: yc-software/qm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.