skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
levnikolaevich/claude-code-skills221 installs

ln-823-pip-upgrader

Upgrades Python pip/poetry/pipenv dependencies with breaking change handling. Use when updating Python dependencies.

How do I install this agent skill?

npx skills add https://github.com/levnikolaevich/claude-code-skills --skill ln-823-pip-upgrader
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill facilitates Python dependency upgrades using standard package managers. It includes a fallback to fetch reference files from the author's GitHub repository and uses various shell commands for its core functionality. It presents a potential surface for indirect prompt injection as it processes untrusted dependency data and web search results while maintaining command execution capabilities.

  • Socketpass

    No alerts

  • Snykwarn

    Risk: MEDIUM · 2 issues

  • Runlayerpass

    2 files scanned · No issues

What does this agent skill do?

Paths: File paths (references/, ../ln-*) are relative to this skill directory.

ln-823-pip-upgrader

Type: L3 Worker Category: 8XX Optimization

Upgrades Python dependencies with automatic breaking change detection.


Overview

AspectDetails
InputProject path plus package manager type
OutputUpdated dependency manifests and a machine-readable dependency upgrade summary
Supportspip, poetry, pipenv

Workflow

Phases: Pre-flight -> Detect Manager -> Security Audit -> Check Outdated -> Apply Upgrades -> Verify Installation -> Report


Phase 0: Pre-flight Checks

CheckRequiredAction if Missing
requirements.txt, pyproject.toml, or PipfileYesBlock upgrade
Python package manager availableYesBlock upgrade
Virtual environment activeNoWarn user if managed environment is unclear
Workspace baseline safeYesIn managed runs coordinator already prepared it; in standalone runs protect rollback locally

Runtime Coordination

Managed runs receive deterministic runId and exact summaryArtifactPath from ln-820. Standalone runs remain supported; if runtime arguments are omitted, generate a standalone run-scoped artifact before returning.


Phase 1: Detect Manager

ManagerIndicator Files
piprequirements.txt
poetrypyproject.toml + poetry.lock
pipenvPipfile + Pipfile.lock

Phase 2: Security Audit

ManagerCommand
pippip-audit --json
poetrypoetry audit
pipenvpipenv check

Actions:

SeverityAction
CriticalBlock and report
HighWarn and continue
Moderate/LowLog only

Phase 3: Check Outdated

ManagerCommand
pippip list --outdated --format=json
poetrypoetry show --outdated
pipenvpipenv update --outdated

Phase 4: Apply Upgrades

ManagerCommand
pippip install --upgrade <package>
pip (freeze)pip freeze > requirements.txt
poetrypoetry update
pipenvpipenv update

MCP Tools for Migration Search

PriorityToolWhen to Use
1mcp__context7__query-docsFirst choice for library docs
2mcp__Ref__ref_search_documentationOfficial docs and PyPI
3WebSearchLatest info and community fixes

Use MCP tools whenever a package upgrade crosses a major version or introduces import errors.


Phase 5: Verify Installation

CheckCommand
Import smoke testpython -c "import <package>"
Testspytest or python -m pytest

Common breaking examples:

MANDATORY READ: Load breaking_changes_patterns.md for shared patterns.

PackageBreaking VersionKey Changes
pydantic1 -> 2Compatibility layer required
sqlalchemy1 -> 2Query API changes
fastapi0.99 -> 0.100+Pydantic v2 alignment

Phase 6: Report Results

FieldDescription
projectProject path
packageManagerpip, poetry, or pipenv
durationTotal time
upgrades[]Applied upgrades
verificationImport/test verdict
warnings[]Non-blocking issues
artifact_pathDurable worker report path, if written

Configuration

Options:
  upgradeType: major          # major | minor | patch
  auditLevel: high
  minimumReleaseAge: 14
  pythonVersion: "3.12"
  useVirtualenv: true
  runTests: true

Error Handling

ErrorCauseSolution
ImportErrorBreaking API changeSearch current migration docs
Dependency conflictVersion mismatchRegenerate lock file or rollback offending package

References


Runtime Summary Artifact

MANDATORY READ: Load references/coordinator_summary_contract.md

Emit a dependency-worker summary envelope.

Managed mode:

  • ln-820 passes deterministic runId and exact summaryArtifactPath
  • write the summary to the provided summaryArtifactPath

Standalone mode:

  • omit runId and summaryArtifactPath
  • write .hex-skills/runtime-artifacts/runs/{run_id}/dependency-worker/ln-823--{identifier}.json

Monitor (2.1.98+): For install/audit/test commands expected >30s, use Monitor. Fallback: Bash(run_in_background=true).

Definition of Done

  • Package manager detected from project indicators
  • Security audit completed for the selected Python manager
  • Outdated packages identified
  • Breaking changes checked via patterns plus current docs
  • Upgrades applied with manifest and lock updates persisted
  • Import smoke test and required tests succeed
  • dependency-worker summary artifact written to the managed or standalone path

Version: 1.1.0 Last Updated: 2026-01-10

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/levnikolaevich/claude-code-skills/ln-823-pip-upgrader">View ln-823-pip-upgrader on skillZs</a>