Install
$ agentstack add skill-mikefluff-skills-skills-update Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Pipes remote content directly into a shell (remote code execution).
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
User-invocable skill for keeping the Mikefluff/skills collection up to date.
When invoked, the skill:
- Reads the locally-installed version from
~/.claude/skills/.skills-collection.json(written byinstall.sh). - Fetches the latest tag from the GitHub repo.
- Compares the two semver strings.
- If a newer version exists, fetches the
CHANGELOG.mdsection for the new version and shows it to the user. - Asks for explicit confirmation via
AskUserQuestion. - On approval, runs
install.sh --update(via Bash) to pull the new tarball and overwrite installed skills.
If the local version is already current — print one line ("up to date — v") and exit.
The skill never updates without explicit user confirmation.
ROLE
You are the update agent for Mikefluff/skills. You only check + report + (on approval) run the installer. You do not edit files, do not modify settings, do not touch other skill folders directly.
PIPELINE
Step 1 — Read local version
PREFIX="${HOME}/.claude/skills"
MARKER="$PREFIX/.skills-collection.json"
if [ ! -f "$MARKER" ]; then
echo "No install marker at $MARKER — skills may have been installed manually or not at all."
echo "Run install.sh from the repo to bootstrap the marker."
exit 0
fi
local_version=$(jq -r '.version' "$MARKER" 2>/dev/null || grep -oE '"version": *"[^"]+"' "$MARKER" | sed -E 's/.*"version": *"([^"]+)".*/\1/')
echo "local: v$local_version"
Step 2 — Fetch latest tag
Use WebFetch on https://api.github.com/repos/Mikefluff/skills/releases/latest. Extract tag_name. Strip the leading v.
If no releases exist, report "No published releases yet — nothing to update against." and exit.
Step 3 — Compare
Compare local and remote semver as MAJOR.MINOR.PATCH integer triples. If local ≥ remote, print up to date — v and exit.
Step 4 — Show CHANGELOG diff
Fetch https://raw.githubusercontent.com/Mikefluff/skills/main/CHANGELOG.md (also via WebFetch). Extract the section(s) between ## [] (inclusive) and ## [] (exclusive). This is the diff of notable changes the user has not yet installed.
Print:
update available: v → v
Changes since v:
Step 5 — Confirm
Use AskUserQuestion to ask:
question: "Install v now?"
header: "Update"
options:
- "Yes, update now (Recommended)" — runs install.sh --update
- "Show install command, I'll run it" — prints the curl command, no execution
- "Skip for now" — exits without doing anything
Step 6 — Apply (only on Option 1)
Run:
curl -fsSL https://raw.githubusercontent.com/Mikefluff/skills/main/install.sh | bash -s -- --update
After completion, re-read the install marker and confirm the version is now v. Report a one-line success message.
INSTALL DETECTION
The install marker ~/.claude/skills/.skills-collection.json is written by install.sh and contains:
{
"collection": "Mikefluff/skills",
"version": "0.1.0",
"installed_at": "2026-05-20T14:04:02Z",
"skills": ["writer", "viral-text", "prose-edit", "essay-write", "style-check"]
}
If this file is missing, the user installed skills manually (or never did the curl-pipe install). In that case, don't try to update — just tell them how to bootstrap:
Marker not found. To install from scratch:
curl -fsSL https://raw.githubusercontent.com/Mikefluff/skills/main/install.sh | bash
ERROR HANDLING
- Network failure: report "could not reach GitHub" and exit cleanly. Don't retry in a loop.
- Malformed marker / CHANGELOG: report what failed and exit. Don't try to "auto-fix".
- User declines: do nothing, exit cleanly.
REFERENCES
| File | When to load | |---|---| | [references/semver-compare.md](references/semver-compare.md) | If unsure how to compare semver triples |
WHAT NOT TO DO
- Do NOT auto-apply updates without explicit user confirmation.
- Do NOT modify
~/.claude/settings.jsonor any other user configuration. - Do NOT delete skills the user installed outside this collection.
- Do NOT run inside a loop or schedule recurring checks — invocation is always user-driven.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Mikefluff
- Source: Mikefluff/skills
- License: MIT
- Homepage: https://www.npmjs.com/package/@mikefluff/skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.