Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Package Updater Update Package

ASecurity

Use when updating one named dependency to a target version everywhere it is pinned across one repository or a fleet.

3 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentsgobashnodeterraformgit

Works with

claude code

Security Analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned 9/19/2026

$npx -y skills add tony/skills --skill package-updater-update-package --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Package Updater Update Package?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Package Updater Update Package
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tony-package-updater-update-package/badge)](https://www.skillsdirectory.com/skills/tony-package-updater-update-package)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: package-updater-update-package
description: >-
  Use when updating one named dependency to a target version everywhere it
  is pinned across one repository or a fleet.
disable-model-invocation: true
allowed-tools: ["Bash", "Read", "Grep", "Glob", "Edit", "Write", "WebSearch", "WebFetch", "Task", "AskUserQuestion"]
metadata:
  argument-hint: "<package> [version] [--root <dir>] [--repo <path|slug>...] [--owner <name>...] [--audit-only] [--branch <name>] [--pr] [--no-push]"
  source: "plugins/package-updater/skills/update-package/SKILL.md"
---

# Update one package

Move one named package to a target version wherever it is pinned, with a
body that says what the release means for each repository it lands in.

Use the `package-updater-updating-packages` skill for the
phase structure, and its references:
`references/repo-scope.md`,
`references/ecosystems.md`,
`references/commit-conventions.md`,
`references/upstream-links.md`, and
`references/follow-ups.md`.

For a full sweep, use the `package-updater-update` skill. For a runtime or
toolchain pin, use the `package-updater-update-toolchain` skill.

User arguments: $ARGUMENTS

## Context

Repository — run this command and read the output:

```bash
git remote get-url origin 2>/dev/null || echo "(not a git repository)"
```

Default branch — run this command and read the output:

```bash
git symbolic-ref --short refs/remotes/origin/HEAD 2>/dev/null || echo "(unknown)"
```

Manifests that could pin it — run this command and read the output:

```bash
out=$(git ls-files -- 'pyproject.toml' '**/pyproject.toml' 'requirements*.txt' 'package.json' '**/package.json' 'Cargo.toml' 'go.mod' 2>/dev/null | grep -v node_modules | head -30); if [ -n "$out" ]; then echo "$out"; else echo "(none found)"; fi
```

Cooldown configuration — run this command and read the output:

```bash
out=$({ grep -hi 'minimumReleaseAge\|min-release-age' pnpm-workspace.yaml .npmrc; grep -hi 'exclude-newer' uv.toml pyproject.toml "${UV_CONFIG_FILE:-$HOME/.config/uv/uv.toml}"; } 2>/dev/null); if [ -n "$out" ]; then echo "$out"; else echo "(no cooldown configured)"; fi
```

## Procedure

### 1. Resolve the target and confirm it exists

If the user named a version, use it. Otherwise take the latest stable
release. Either way confirm it is published and record its publication
timestamp — you need it to reason about the cooldown, and a version
written before it is confirmed to exist is the expensive failure this
ordering prevents.

If the cooldown currently hides it, say when it becomes visible and stop
rather than exempting it. Exempt only when the release is needed now,
and then per the exemption protocol in the ecosystems reference: narrow,
annotated, its own commit, reverted when the block lapses.

### 2. Find every pin site

The package can be pinned in more than one place in one repository —
several workspace members, a dependency group, a lockfile, a
pre-commit configuration, a CI workflow. Enumerate them all. Every pin
site in a repository moves in the same commit, or none does.

Note where the pin shapes disagree — an exact pin in one package and a
caret range in another is drift worth reporting even when both resolve
to the same version.

### 3. Establish scope

Default scope is the current repository. `--root`, `--repo` and
`--owner` widen it as in the `package-updater-update` skill. Drop repositories
that do not pin the package and those already at the target.

A widened scope goes through
`references/repo-scope.md` first: worktrees and
forks are out, and a repository whose ownership is unclear is a question
for the user, not a guess.

### 4. Research the span once

Read the release notes for every version between the current pin and the
target, not just the endpoint. Collect links per the upstream-links
reference and verify each resolves.

Then, separately per repository, work out what the release actually
reaches. A release note describes the package; only the repository can
say whether the change applies. Where the general claim does not hold,
the body says something different in that repository.

Predict the follow-up now — a formatter, compiler or framework bump
usually needs one, per the follow-ups reference.

### 5. Present the plan and wait

Show the pin sites per repository, the target, the verified links, the
follow-up expected, and whether any repository will be red between the
bump and its follow-up. With `--audit-only`, stop here.

### 6. Land

One commit per repository, subject and body per the commit-conventions
reference — `why:` then `what:`, written through a heredoc or a file.
The follow-up lands immediately after as its own commit.

Commits land on the default branch by default. `--branch` works on a
branch; `--pr` opens a pull request; `--no-push` stops after committing.

### 7. Verify

Run the project's own quality checks. Attribute failures against the
default branch before blaming the bump. A knowingly-red bump is only
acceptable when its body said so and its follow-up lands in the same
run.

## Rules

- No version is written before it is confirmed published; no URL before
  it is confirmed to resolve.
- Every pin site in a repository moves in one commit, or none does.
- The body says what the release means for *this* repository, never a
  generalization that does not hold here.
- A follow-up is its own commit, never folded into the bump.
- Waiting out a cooldown is the default; an exemption is narrow,
  annotated, separately committed and reverted.
- Report unrelated breakage; fix it only when the bump caused it.
- ruff belongs to the `ruff-bump` skill; action pins to
  the `github-actions-update-action` skill; Terraform providers to
  the `terraform-bump-provider` skill.

## Output

Open with a one-line hero (`✓ <package> <old> -> <new> across N repos`
or `⚠ Gated: <package> <version> visible <date>`), then exactly these
sections:

1. `## Release` — what the span changes, with verified links to every
   version in it.
2. `## Pin sites` — per repository, every place the package is pinned
   and its current shape, plus what was excluded as not pinning it or
   already current.
3. `## Impact` — per repository, what the release actually reaches
   there, and where the general claim does not apply.
4. `## Commits` — the commits made, their follow-ups, and whether they
   were pushed.
5. `## Verification` — the quality checks run and their real results,
   with any pre-existing failure named as pre-existing.
6. `## Drift` — pin shapes disagreeing across a workspace or a fleet.

End with an `ask-user-choice` panel offering next steps — for example:
run the sweep for the rest of the tree, take a gated release once it
ages out, land the follow-up separately, or stop here. Skip the panel
only in plan mode.


## Portability notes

- `ask-user-choice` — present the listed options and wait for the user to pick one. Hosts with a structured multiple-choice tool (Claude Code's `AskUserQuestion`) should use it; otherwise print a numbered list and wait for a numbered reply. Never proceed on an assumed answer.
- `$ARGUMENTS` — the text the user passed when invoking this skill. If your host does not substitute it, read it as the user's request in the current turn, and ask when there is none.
- Bundled files — every relative path in this skill points at a file shipped inside this skill directory. Read them from here, not from the host's plugin tree.

Attribution

tonytony
View sourceSee grades on GitHubMore from tony →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →