Agent skill

Auto Updater

by zhou210712 in zhou210712/claude-for-legal-ZH

检查已安装社区技能的更新。展示差异并要求明确批准后才应用. An agent skill from zhou210712/claude-for-legal-ZH.

Apache-2.0Auto-check passed

Install Auto Updater

skills CLI
$ npx skills add zhou210712/claude-for-legal-ZH --skill auto-updater -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhou210712/claude-for-legal-ZH auto-updater --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/legal-builder-hub/skills/auto-updater .claude/skills/auto-updater && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auto-updater
GitHub stars
225
Token cost
~647 tokens
SKILL.md length
140 words
Files
1
Skills in repo
122
Repo updated
First seen
Licence
Apache-2.0

At a glance

检查已安装社区技能的更新。展示差异并要求明确批准后才应用. An agent skill from zhou210712/claude-for-legal-ZH.

  • Works in 4 steps: 加载… → 使用以下工作流。 → 检查每个已安装技能的源是否有更新版本。 → …
  • SKILL.md covers 目的, 信任姿态, 加载上下文 and 工作流, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Auto Updater is an agent skill from zhou210712/claude-for-legal-ZH. 检查已安装社区技能的更新。展示差异并要求明确批准后才应用。 当用户说"检查更新""更新我的技能""已安装技能有什么更新"或从 registry-sync agent 调用时使用。

Its SKILL.md is about 650 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Model Context Protocol. The licence is Apache-2.0.

Example prompts

  • “更新我的技能”
  • “已安装技能有什么更新”
  • “/auto-updater”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 加载 ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md → 已安装技能 + 自动更新偏好。
  2. 使用以下工作流。
  3. 检查每个已安装技能的源是否有更新版本。
  4. 按偏好:应用 / 通知 / 展示差异。

What it can do on your machine

Read from SKILL.md and the folder at commit 2f01c92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are diff).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auto Updater loads about 647 tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 140 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~26
When it runs · the whole SKILL.md, loaded when a task matches
~647

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhou210712/claude-for-legal-ZH at commit 2f01c92, republished under its Apache-2.0 licence (© zhou210712). 140 words, ~647 tokens.

Download SKILL.mdSave it as .claude/skills/auto-updater/SKILL.md (or your agent's skills folder).
name
auto-updater
description
检查已安装社区技能的更新。展示差异并要求明确批准后才应用。 当用户说"检查更新""更新我的技能""已安装技能有什么更新"或从 registry-sync agent 调用时使用。
argument-hint
[--apply 更新全部,否则仅通知]

/auto-updater

  1. 加载 ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md → 已安装技能 + 自动更新偏好。
  2. 使用以下工作流。
  3. 检查每个已安装技能的源是否有更新版本。
  4. 按偏好:应用 / 通知 / 展示差异。

目的

社区技能会改进。本技能注意到改进时机,展示变更内容,仅在获得明确批准后应用更新。

信任姿态

已安装技能是在你特权法律环境中运行的代码。上游仓库可能被攻破、转让给新所有者、或以你不希望的方式改变行为。本技能的设计确保在没有你阅读差异并批准的情况下,绝无任何更新被应用。 这不是偏好——这是设计。

加载上下文

~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md → 已安装技能(附版本/提交 SHA)、更新偏好(通知 / 手动)。

工作流

第1步:检查每个已安装技能

对已安装列表中的每个技能:

  • 从源注册表获取当前提交 SHA(精确提交,非标签或分支头——标签可变且可被发布者追溯改写;仅提交 SHA 不可变)
  • 与安装时固定的 SHA 比较
  • 如不同:有可用更新
第2步:差异与信任审查

对于每个更新,展示完整差异:

diff
# [技能名称] — [已安装 SHA] → [最新 SHA]

## SKILL.md 变更
[统一差异]

## hooks/hooks.json 变更
[统一差异 — 标记:hooks 可执行任意代码]

## .mcp.json 变更
[统一差异 — 标记:MCP 服务器以你的凭据运行]

## 其他文件
[附差异的新增/删除/修改文件列表]

然后运行信任检查:

  • hooks/hooks.json 是否变更? Hooks 可执行任意 shell 命令。显著展示差异并请用户确认他们理解新 hooks 的功能。
  • .mcp.json 是否变更? 新增或变更的 MCP 服务器可访问你的环境。同样处理。
  • allowed-tools 或 tools frontmatter 是否扩展? 新增工具访问是权限提升。
  • SKILL.md 中是否有新增的网络调用、技能目录外的文件写入或命令执行? 标记它们。
  • 技能的 description 或声明的目的是否变化? 声称"审查保密协议"现在声称"发送合同"的技能已改变其用途。
第2.5步:重新扫描新版本(GlassWorm 门控)

在应用更新前,对新版本重新运行完整的 skills-qa 扫描。一个在 v1.0 干净的技能可能在 v1.1 携带有害内容(GlassWorm 模式:受信任的发布者、已建立的技能、携带有害代码的小版本号升级)。安装时的信任不转移到更新。

规则:

  1. 发现回归时不应更新。 如果新版本产生了旧版本没有的发现——在任何 skills-qa 第1.5步类别中——默认拒绝更新并解释原因。
  2. 安全面差异无论评估结果如何均需人工批准。 任何涉及 hooks/hooks.json、.mcp.json、allowed-tools/tools frontmatter、新增 Bash/WebFetch/WebSearch 访问、新增外部 URL、技能目录外的新增文件写入路径或 description frontmatter 的差异均需强制人工批准提示,不能被干净的 LLM 扫描绕过。
  3. 只读扫描上下文。 扫描读取攻击者控制的文本(新 SKILL.md)。在可用时在只读子代理中运行。安装代理接收子代理的报告;仅在人工批准后才获得写权限。
  4. 拒绝扫描现在失败的更新。 如果新版本命中 REFUSE 层级模式,不提供"仍然应用"选项。
第2.6步:新鲜度触发的重新核实

不仅检查新提交。还检查已安装技能是否已过新鲜度窗口。

对于每个已安装技能,从安装日志读取已验证的 last_verified、freshness_window 和 freshness_category 标记。

如果活跃窗口已过且无更新的提交: 提供选项:(a) 自行检查来源,(b) 标记给注册表维护者,(c) 禁用该技能直至重新核实。

如果活跃窗口已过且有更新的提交: 始终重新核实,不静默应用。

第3步:按偏好处理

通知(默认): 展示完整差异和信任检查。"有可用更新。审查以上差异。应用?[y/n]"

手动: 仅列出哪些有可用更新。用户准备好时运行 /legal-builder-hub:auto-updater --apply [技能名称]。

没有"自动"模式。对在你法律环境中运行的代码的更新始终需要人工阅读差异。

第4步:应用(在明确批准后)

用新版本替换已安装技能文件。更新已安装列表中的提交 SHA。先备份旧版本以便回滚。

回滚

如果更新破坏了某些功能:/legal-builder-hub:auto-updater --rollback [技能名称] 从备份恢复。

本技能不做什么

  • 自动应用更新。绝不。每次更新均有差异和批准。
  • 更新非通过中心安装的技能(手动放置的技能由用户自行管理)。
  • 信任标签、分支或版本号。仅固定提交 SHA,因为仅提交 SHA 不可变。

© zhou210712, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in legal-builder-hub/skills/auto-updater of zhou210712/claude-for-legal-ZH.

Open the folder on GitHubat commit 2f01c92

Compare with similar skills

Auto Updater next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auto Updater compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auto Updater this skillzhou210712/claude-for-legal-ZH225—~647Automated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills8.5k6 repos~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Stitch to Remotion Walkthrough Videos

    google-labs-code/stitch-skills

    Official

    Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.

    8.5k GitHub starsUsed in 6 repos~3.2k tokens
    Media & CreativeAuto-check: notes
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed

More from zhou210712/claude-for-legal-ZH

All 122 skills in this repo
  • Claim Chart

    zhou210712/claude-for-legal-ZH

    构建或审查要件分析表——专利权利要求对照表(侵权、无效或审查)或 民事构成要件分析表(任何诉讼请求或抗辩),每个单元格附精确引用, 缺口检测为优先输出。当用户要求要件分析表、权利要求对照表、 证据对照表、侵权或无效主张、逐要件映射,或问"我们证明[主张]还缺什么"时使用。

    225 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Client Intake

    zhou210712/claude-for-legal-ZH

    结构化接待——实践领域模板、跨领域考点识别、利益冲突标记、分流分类. An agent skill from zhou210712/claude-for-legal-ZH.

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Gap Surfacer

    zhou210712/claude-for-legal-ZH

    参考资料:支持 /regulatory-legal:gaps 和 /regulatory-legal:comments 的共享差距和意见征集跟踪框架。跟踪未关闭的政策差距及其整改状态, 从 policy-diff 中获取差距,呈现开放和即将到期的事项,路由给负责人, 并通过企业通讯工具通知差距负责人,每次发送前需确认。

    225 GitHub stars~757 tokensUpdated 4 mo ago
    Auto-check passed
  • Launch Review

    zhou210712/claude-for-legal-ZH

    对照您的框架和风险校准进行全面产品上线审查。当用户说"审查这个上线" "[功能]法务审查""我们能上线吗""[产品]有什么法律问题"或引用了需要 逐类审查备忘录的产品需求文档或上线追踪工单时使用。

    225 GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Reg Feed Watcher

    zhou210712/claude-for-legal-ZH

    检查法规动态源,报告自上次检查以来的新事项,按重要度阈值过滤。适用于用户说"检查法规动态"、"有什么新规定"、"法规更新"、从定时任务触发执行,或手动粘贴法规动态进行分类和差异分析时。

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Renewal Tracker

    zhou210712/claude-for-legal-ZH

    展示具有即将到来的取消截止日期的合同,在通知窗口关闭前发出预警, 基于维护的续约登记册运行。当用户询问"什么即将续约""哪些续约即将到期" "我们是否错过了取消窗口""将此添加到续约追踪器"时使用,或按计划运行。

    225 GitHub stars~681 tokensUpdated 4 mo ago
    Auto-check passed

Questions about Auto Updater

What does Auto Updater do?

检查已安装社区技能的更新。展示差异并要求明确批准后才应用. An agent skill from zhou210712/claude-for-legal-ZH. Auto Updater is an agent skill from zhou210712/claude-for-legal-ZH.

How do I install Auto Updater in Claude Code?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill auto-updater -a claude-code`. Or copy the skill folder (legal-builder-hub/skills/auto-updater in zhou210712/claude-for-legal-ZH) into .claude/skills/auto-updater in your project. Claude Code loads it when a task matches its description.

How do I install Auto Updater in Codex?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill auto-updater -a codex`. Or copy the skill folder (legal-builder-hub/skills/auto-updater in zhou210712/claude-for-legal-ZH) into .agents/skills/auto-updater in your project. Codex loads it when a task matches its description.

Can I use Auto Updater in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhou210712/claude-for-legal-ZH --skill auto-updater -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auto-updater, .gemini/skills/auto-updater, .github/skills/auto-updater and .opencode/skills/auto-updater in your project.

What does Auto Updater need to run?

SKILL.md names no scripts, command-line tools or credentials: Auto Updater is instructions for the agent only.

Does Auto Updater access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Auto Updater safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auto Updater use?

Auto Updater is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auto Updater use?

About 647 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auto Updater?

Skills that share tags, products or a category with Auto Updater: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auto Updater?

zhou210712 (a GitHub user) maintains it in zhou210712/claude-for-legal-ZH, which has 225 GitHub stars. The repository holds 122 skills in this directory. The repository was last updated on May 15, 2026.

Source: zhou210712/claude-for-legal-ZH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.