Install
$ agentstack add skill-pekral-cursor-rules-composer-update ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Composer Update
Purpose
Analyze dependency updates after composer update, detect conflicts, and summarize relevant changes.
Constraints
- Apply @rules/php/core-standards.mdc
- Apply @rules/php/dependency-selection.mdc — this skill primarily bumps existing packages (rule out of scope per its Scope section), but a bump frequently uncovers an upstream that has been archived or marked abandoned. When that happens, re-run the Activity gate + Compatibility gate against the suggested replacement (or against a fresh search if no replacement is documented) before recommending the migration. Never silently keep an archived / abandoned package in the lockfile just because the bump compiles.
- Output Markdown only
Execution
1. Update Context
- Use output from
composer updateif available - Otherwise compare current
composer.lockwith the previous version
2. Detect Updated Packages
- List all added or changed packages
- Include version changes:
old → new
3. Conflict Detection
- Identify dependency conflicts from:
- composer output
- version constraint mismatches (
composer.jsonvscomposer.lock) - Summarize conflicts clearly (package → reason)
- If none: state "No conflicts detected"
4. Changelog Extraction
For each updated package:
- Prefer:
vendor//CHANGELOG*- Fallback:
- repository releases (GitHub/GitLab)
- package homepage
- Extract:
- breaking changes
- new features
- important fixes
- If unavailable:
- state "No changelog found"
5. Suggested Follow-up
- Recommend relevant checks:
- run tests
composer validatecomposer audit
Output Format
Use the template defined in templates/update-report.md. ---
Principles
- Focus on impactful changes, not noise
- Highlight breaking changes first
- Prefer local sources over remote
- Be concise and actionable
- Highlight security-related changes when present
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: pekral
- Source: pekral/cursor-rules
- License: MIT
- Homepage: https://pekral.cz
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.