AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Update

skill-sskarz-nanoclawbster-update · by sskarz

Update NanoClawbster from upstream. Fetches latest changes, merges with your customizations and skills, runs migrations. Triggers on \"update\", \"pull upstream\", \"sync with upstream\", \"get latest changes\".

No reviews yet
0 installs
40 views
0.0% view→install

Install

$ agentstack add skill-sskarz-nanoclawbster-update

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-sskarz-nanoclawbster-update)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Update? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Update NanoClawbster

Pull upstream changes and merge them with the user's installation, preserving skills and customizations. Scripts live in .claude/skills/update/scripts/.

Principle: Handle everything automatically. Only pause for user confirmation before applying changes, or when merge conflicts need human judgment.

UX Note: Use AskUserQuestion for all user-facing questions.

1. Pre-flight

Check that the skills system is initialized:

test -d .nanoclawbster && echo "INITIALIZED" || echo "NOT_INITIALIZED"

If NOT_INITIALIZED: Run initSkillsSystem() first:

npx tsx -e "import { initNanoclawDir } from './skills-engine/init.js'; initNanoclawDir();"

Check for uncommitted git changes:

git status --porcelain

If there are uncommitted changes: Warn the user: "You have uncommitted changes. It's recommended to commit or stash them before updating. Continue anyway?" Use AskUserQuestion with options: "Continue anyway", "Abort (I'll commit first)". If they abort, stop here.

2. Fetch upstream

Run the fetch script:

./.claude/skills/update/scripts/fetch-upstream.sh

Parse the structured status block between >> markers. Extract:

  • TEMP_DIR — path to extracted upstream files
  • REMOTE — which git remote was used
  • CURRENT_VERSION — version from local package.json
  • NEW_VERSION — version from upstream package.json
  • STATUS — "success" or "error"

If STATUS=error: Show the error output and stop.

If CURRENTVERSION equals NEWVERSION: Tell the user they're already up to date. Ask if they want to force the update anyway (there may be non-version-bumped changes). If no, clean up the temp dir and stop.

3. Preview

Run the preview to show what will change:

npx tsx scripts/update-core.ts --json --preview-only 

This outputs JSON with: currentVersion, newVersion, filesChanged, filesDeleted, conflictRisk, customPatchesAtRisk.

Present to the user:

  • "Updating from {currentVersion} to {newVersion}"
  • "{N} files will be changed" — list them if `) and stop.

5. Apply

Run the update:

npx tsx scripts/update-core.ts --json 

Parse the JSON output. The result has: success, previousVersion, newVersion, mergeConflicts, backupPending, customPatchFailures, skillReapplyResults, error.

If success=true with no issues: Continue to step 7.

If customPatchFailures exist: Warn the user which custom patches failed to re-apply. These may need manual attention after the update.

If skillReapplyResults has false entries: Warn the user which skill tests failed after re-application.

6. Handle conflicts

If backupPending=true: There are unresolved merge conflicts.

For each file in mergeConflicts:

  1. Read the file — it contains conflict markers (>>>>>>)
  2. Check if there's an intent file for this path in any applied skill (e.g., .claude/skills//modify/.intent.md)
  3. Use the intent file and your understanding of the codebase to resolve the conflict
  4. Write the resolved file

After resolving all conflicts:

npx tsx scripts/post-update.ts

This clears the backup, confirming the resolution.

If you cannot confidently resolve a conflict: Show the user the conflicting sections and ask them to choose or provide guidance.

7. Run migrations

Run migrations between the old and new versions:

npx tsx scripts/run-migrations.ts   

Parse the JSON output. It contains: migrationsRun (count), results (array of {version, success, error?}).

If any migration fails: Show the error to the user. The update itself is already applied — the migration failure needs manual attention.

If no migrations found: This is normal (most updates won't have migrations). Continue silently.

8. Verify

Run build and tests:

npm run build && npm test

If build fails: Show the error. Common causes:

  • Type errors from merged files — read the error, fix the file, retry
  • Missing dependencies — run npm install first, retry

If tests fail: Show which tests failed. Try to diagnose and fix. If you can't fix automatically, report to the user.

If both pass: Report success.

9. Cleanup

Remove the temp directory:

rm -rf 

Report final status:

  • "Updated from {previousVersion} to {newVersion}"
  • Number of files changed
  • Any warnings (failed custom patches, failed skill tests, migration issues)
  • Build and test status

Troubleshooting

No upstream remote: The fetch script auto-adds upstream pointing to https://github.com/qwibitai/nanoclawbster.git. If the user forked from a different URL, they should set the remote manually: git remote add upstream .

Merge conflicts in many files: Consider whether the user has heavily customized core files. Suggest using the skills system for modifications instead of direct edits, as skills survive updates better.

Build fails after update: Check if package.json dependencies changed. Run npm install to pick up new dependencies.

Rollback: If something goes wrong after applying but before cleanup, the backup is still in .nanoclawbster/backup/. Run:

npx tsx -e "import { restoreBackup, clearBackup } from './skills-engine/backup.js'; restoreBackup(); clearBackup();"

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.