AgentStack
SKILL verified MIT Self-run

Update

skill-camjac251-cc-enhanced-update · by camjac251

>-

No reviews yet
0 installs
1 views
0.0% view→install

Install

$ agentstack add skill-camjac251-cc-enhanced-update

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README — it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-camjac251-cc-enhanced-update)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
today

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Update? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

/update [version] [mode flags]

Run the staged upstream-release update lifecycle. $ARGUMENTS is an optional version spec; defaults to latest. Mode flags can include --inspect-only, --repair-only, --promote, --dry-run, or --force.

The process is evidence-first: inspect the live registry and clean bundle before changing source, dry-run patches against the target before promotion, and report patch verification, prompt-surface validity, and prompt drift as separate states.

Mode Selection

  • Use inspect-only when the user asks "what changed", asks for prompt-drift review first, says no verify:patches, says no heavy scripts, or asks to compare the CLI against patches with rg/bat/inspect.
  • Use repair-only when the target clean bundle is known and the user asks to patch or fix broken tags, but has not asked to promote the native binary.
  • Use promote/full update when the user asks to update, upgrade, promote, or run native:update.
  • Use promote-only when source patches are already repaired and verified, and the next request is specifically to upgrade the active binary.
  • Do not edit workflow docs or workflow files unless the user explicitly asks for workflows.

Steps

  1. Resolve the target from live state. Do not rely on memory or an older cached bundle.

``bash npm view @anthropic-ai/claude-code version dist-tags --json ``

Use the explicit newest version if next is ahead of latest, and say so in the update summary.

  1. Pre-flight the local install and worktree. Record current and previous versions before changing anything.

``bash mise run status ``

``bash git status --short ``

  1. Pull the clean target bundle. This writes versions_clean//cli.js.

``bash mise run native:pull -- ``

If the previous current version is missing from versions_clean/, pull it too before diffing.

  1. Review upstream drift before source edits. Prefer matrix diff when the release range has multiple adjacent versions.

``bash mise run diff -- matrix versions_clean//cli.js versions_clean//cli.js --cache ``

Re-run focused diffs for commands, env, prompts, or patches when the matrix output points at those areas.

  1. Run the requested pre-promotion verification lane.

For inspect-only or a user-requested no-heavy-verifier run, do not run mise run verify:patches, mise run verify:patches:matrix, or mise run native:update.

Inspect the clean bundle and local patches directly:

``bash rg -n '' versions_clean//cli.js src/patches README.md ``

``bash bun run inspect search versions_clean//cli.js '' --scope --breadcrumb-depth 4 ``

Use bat -r : versions_clean//cli.js for line context after rg finds candidate anchors. If source changes are needed, run focused tests for the touched patches plus repository hygiene:

``bash bun test src/patches/.test.ts --parallel=1 ``

``bash bun run typecheck ``

``bash bun run lint ``

Then patch the clean bundle into OS temp without promoting:

``bash bun run cli -- --target versions_clean//cli.js --output /patched.js --summary-path /summary.json ``

Read /summary.json and inspect the patched temp bundle for the expected helper calls, literal replacements, and guards with rg or bun run inspect search. State clearly that native verification was skipped by request.

For full update or when heavy verification is allowed, dry-run patch verification against the clean target:

``bash SELECTED_VERSION= mise run verify:patches:matrix ``

If a tag fails, inspect the clean target with bun run inspect search, fix the patch/verifier/tests for the new upstream shape only, run focused tests, and rerun the matrix. Do not add old-version fallbacks.

  1. Optionally dispatch anchor-review subagents. Use this when the drift is broad or the user asks for extra confidence.
  • Spawn the patch-verifier agent at most once per target release unless the user explicitly asks for another independent pass.
  • Skip the subagent when the clean-bundle dry-run already names a narrow failed-tag list and the parent can inspect the relevant files directly.
  • Pass only paths: versions_clean//cli.js and the assigned patch files.
  • Require file:line, exact query strings, OK / DRIFT / BROKEN status, and a test coverage note.
  • Keep subagents read-only; the parent edits and verifies.
  • Do not let subagent evidence replace verify:patches:matrix.
  1. Preflight prompt surfaces from a scratch patched bundle before promotion. Write scratch artifacts under OS temp, not inside versions_clean/.

``bash mktemp -d -t cc-update-XXXXXX ``

``bash bun src/index.ts --target versions_clean//cli.js --output /patched.js --summary-path /summary.json ``

``bash bun scripts/export-prompts.ts /patched.js --label -patched --output-dir /export ``

``bash mise run verify:prompt-surfaces -- /export ``

``bash mise run verify:prompt-drift -- /export --prompt-drift-baseline prompt-surface-baseline.json ``

  1. Correct prompt drift deliberately. If prompt surfaces fail, read the exported Markdown that failed and update the patch, exporter, or src/verification/prompt-surface-rules.ts.

If drift hashes fail, generate a comparison report:

``bash mise run prompts:export -- --label -clean --output-dir /clean-export ``

``bash bun run prompts:compare /clean-export /export /etc/claude-code -- --output /prompt-compare.md ``

Refresh prompt-surface-baseline.json only after the new patched export is reviewed as known-good:

``bash mise run prompts:drift-baseline -- prompt-surface-baseline.json /export --prompt-drift-version ``

Do not call drift corrected until a fresh verify:prompt-drift run passes.

  1. Update release docs and checked baselines. Update the README target badge, README compatibility target, and prompt-surface-baseline.json version when the target changes. Check for stale version anchors:

``bash rg -n '|' README.md prompt-surface-baseline.json ``

When the patch count changes, update the README intro and patch-count badge. When only the target version changes, update the README target badge and Compatibility target but leave the patch count unchanged.

  1. Promote the native binary. Forward --dry-run or --force only if the user supplied it or a local source fix needs a fresh cached build.

``bash mise run native:update -- ``

If a fixed source change still appears absent from the promoted build, rerun with --force to avoid cached-build reuse.

  1. Confirm the promoted runtime.

``bash claude --version ``

``bash mise run status ``

  1. Run final verification and read the output.

``bash mise run verify:patches ``

Run focused tests for any touched patch or verifier files, and run the full suite when source tests changed:

``bash bun run test ``

If native:update promoted successfully but post-update verification fails on formatting or lint, fix the source issue and rerun mise run verify:patches before reporting completion.

  1. Final report. Separate these states:
  • Patch verification: matrix, native update, runtime version, status, and verify:patches.
  • Prompt-surface validity: verify:prompt-surfaces on the patched export.
  • Prompt drift: verify:prompt-drift against the reviewed baseline.
  • Drift summary: command/env/prompt/patch-risk highlights from mise run diff.
  • Changed files and any uncommitted leftovers.

If promotion fails after changing the active binary, surface the exact error, show mise run status, and suggest mise run native:rollback.

Gotchas

  • Clean bundle first. Do not start from the patched promoted bundle when fixing upstream anchor drift.
  • latest may lag next; state which npm tag supplied the chosen target.
  • No-heavy-verifier mode still needs direct evidence: clean-bundle diff, rg/bat/inspect anchors, focused tests for touched patches, a temp patched bundle summary, and patched-bundle inspection.
  • native:update passing does not mean prompt drift was corrected. Drift is corrected only by a source fix or reviewed baseline refresh followed by a passing drift verifier.
  • prompts:compare is review evidence, not a pass/fail gate.
  • verify:patches:matrix is pre-promotion confidence; verify:patches on the real native path is still the completion floor.
  • native:update may reuse a cached build; use --force after source edits when the promoted bundle still shows the old patch behavior.
  • Memoized renderer patches may need cache guards neutralized so added summaries cannot go stale behind upstream memoization.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.