claude-update-wizard

REVIEW · 51
Registry indexed

Smart update for SDLC wizard — shows changelog, compares files, lets you selectively adopt changes while preserving customizations.

Verified installs0
Stars44
Version1.0.0
Quality58/100 · Promising
Trust51/100 · Do not auto-install
Audit68/100 · Risky

Supply asset profile

Coding and developer agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Browse track

Scenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent fit

Claude Code + OpenAI Agents + CLI

Codex, Claude Code, Cursor, CLI, or custom agents.

Install

Ready

npx skills add BaseInfinity/claude-sdlc-harness --skill claude-update-wizard

Maintenance

fresh

Pushed today

Risk

Risky

License is unclear

GitHub quality

44

58/100 Quality · 59/100 Trust

Coverage tags

CodingGitHub automationautomationagent-skill

Review notes

License is unclear · Dependency or permission surface needs review

Agent adoption scorecard

Trust, audit, and install readiness at a glance

These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.

Quality

Promising
58

Useful candidate, but compare it with alternatives before adopting.

Trust

Do not auto-install
51

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

Audit

Risky
68

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

OpenAgentSkill Trust Score v5

Sandbox only

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

44 GitHub stars

Repo activity

44 stars, 6 forks

Maintenance

Pushed today

License

Unknown

Install

npx skills add BaseInfinity/claude-sdlc-harness --skill claude-update-wizard

Install safety

standard package or runtime install path

Permission surface

secrets or environment access, shell or command execution

Agent outcomes

No agent outcome data yet

Docs

Strong README/SKILL.md context

Risk summary

Review before production

  • Repository license is unknown; verify licensing before broad distribution.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • License is unclear

Install readiness

Install path available

  • Install path is available
  • Repository evidence is available
  • License is unclear
  • No Agent Proven outcome evidence yet

Agent-readable metadata

Machine-readable decision data for this skill.

Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.

Open JSON

Suited tasks

  • GitHub automation workflows
  • Claude Code teams
  • builders willing to evaluate younger projects
  • Inspect repository metadata

Suited agents

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

Install decision

Command
npx skills add BaseInfinity/claude-sdlc-harness --skill claude-update-wizard
Policy
block
Human review
yes

Trust and risk

Trust
51/100
Audit
68/100
Risk level
Risky

Outcome loop

Endpoint
/api/agent/outcome
Event ID
resolve
Outcomes
5

Install command

npx skills add BaseInfinity/claude-sdlc-harness --skill claude-update-wizard

Do not use when

  • teams that need a vendor-supported SLA
  • production agents without a repository review
  • Low GitHub adoption signal
  • Repository license is unknown; verify licensing before broad distribution.
  • Audit risk risky exceeds max_risk=medium

Agent safety v2

24/100 · Avoid automatic install

Blocked for auto-installblock

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

Resolve via API

high

Shell or command execution

Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.

medium

Network access

Skill likely fetches remote pages, APIs, repositories, or external services.

medium

Filesystem access

Skill may read or write project files, documents, generated artifacts, or local workspace state.

high

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • Audit risk risky exceeds max_risk=medium
  • High-risk permission hints: Shell or command execution, Secrets or environment access
  • License is unclear

Install targets

Install this skill in your agent workflow

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install baseinfinity-claude-update-wizard

Agent resolve plan

Let an agent verify fit before installing.

The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.

Open text plan

Agent should check

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copy prompt

Task: Use claude-update-wizard in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20claude-update-wizard%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/baseinfinity-claude-update-wizard/install
Install command: npx skills add BaseInfinity/claude-sdlc-harness --skill claude-update-wizard
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent handoff

Give an agent the install path, not another directory page.

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

Open install API

Agent prompt

Use claude-update-wizard for this task. Review https://www.openagentskill.com/api/skills/baseinfinity-claude-update-wizard/install, then install with: npx skills add BaseInfinity/claude-sdlc-harness --skill claude-update-wizard

Registry metadata

Agent-readable profile for automatic skill selection.

This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.

Open manifest

Agent fit

58/100

GitHub automation

Platforms

Claude Code, OpenAI Agents

Audit report

Risky · 68/100

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

View audit reportView eval report

Agent decision cockpit

Fallback candidate for GitHub automation

Prototype with this skill first; keep a fallback candidate ready.

58
Readiness
Prototype
Stage

Role in stack

Fallback candidate

Primary fit

GitHub automation

Trust label

Prototype first

Install path

Command ready

Use when

  • GitHub automation workflows
  • Claude Code teams
  • builders willing to evaluate younger projects

Evidence

  • recent repository activity
  • install command or GitHub repo available
  • 58/100 quality profile
  • 2 OpenAgentSkill engagement events

review first

  • Low GitHub adoption signal
  • Repository license is unknown; verify licensing before broad distribution.

Implementation path

  1. 1Install it in a sandbox agent and run one GitHub automation task end to end.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Trust profile

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

51
OpenAgentSkill Trust Score

GitHub adoption

CHECK

44 GitHub stars

Stars/forks activity

CHECK

44 stars, 6 forks; issue activity unavailable in current metadata

Recent maintenance

PASS

Pushed today

License clarity

CHECK

Unknown

Good signals

  • AI review approved
  • Install path is available
  • Repository evidence is available
  • Recently maintained repository
  • Install command has no obvious high-risk pattern
  • Outcome loop is ready but needs first real agent run

Review before install

  • Repository license is unknown; verify licensing before broad distribution.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • License is unclear
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 44 GitHub stars
  • Stars/forks activity: 44 stars, 6 forks; issue activity unavailable in current metadata
  • License clarity: Unknown
  • No real agent outcome reports yet
  • Human review required before unattended installation

Recommended action

Choose a stronger alternative or inspect the source manually before any install attempt.

Quality profile

Promising candidate for agent workflows

Useful candidate, but compare it with alternatives before adopting.

58
GitHub stars
44
Freshness
Today
Install ready
Yes
License
Unknown
Review before install: Low GitHub adoption signal · Repository license is unknown; verify licensing before broad distribution.

Workflow fit

Use this skill in these scenarios

Workflow fit

Add it to a complete workflow

Alternative shortlist

Compare before you install

Similar skills that may fit this task.

Compare all

Overview

--- name: claude-update-wizard description: Smart update for SDLC wizard — shows changelog, compares files, lets you selectively adopt changes while preserving customizations. argument-hint: "[optional: check-only | force-all]" effort: high --- # Update Wizard - Smart SDLC Update

## Task $ARGUMENTS

## Purpose

Guided update assistant. Check what version the user has, show what changed, walk them through selectively adopting updates while preserving their customizations. **DO NOT blindly overwrite files.** Show diffs and let the user decide.

## MANDATORY FIRST ACTION: Read the Wizard Doc

**Before doing ANYTHING else**, use Read on `CLAUDE_CODE_SDLC_WIZARD.md` — specifically the "Staying Updated (Idempotent Wizard)" section near the end. This contains update URLs, version tracking format, and step registry. Do NOT proceed without reading it first.

## Execution Checklist

Follow steps IN ORDER. Do not skip or combine.

### Step 1: Read Installed Version

Read `SDLC.md` and extract from the metadata comment: ``` <!-- SDLC Harness Version: X.X.X --> <!-- Completed Steps: ... --> ``` No version comment → treat as `0.0.0` (suggest `/claude-setup-wizard` instead).

### Step 1.5: Check CLI Version (ROADMAP #232)

The wizard files in the user's project are one half of the install. The other half is the **npm CLI** (`agentic-sdlc-wizard`) — the binary powering `npx agentic-sdlc-wizard init`/`check`/`complexity`. If `init` ran months ago, npx cache (or global install) can be stuck on an old version even after `/claude-update-wizard` patches project files in-session. This step closes that gap.

**Detection — try both paths:**

1. **Global install** (rare): `npm ls -g agentic-sdlc-wizard --json --depth=0 2>/dev/null | jq -r '.dependencies["agentic-sdlc-wizard"].version // empty'`

2. **npx cache** (common): find every `package.json` under `~/.npm/_npx` matching `*agentic-sdlc-wizard*`, extract `.version`, pick the largest **by semver** (do NOT use `sort -u | tail -1` — lexicographic treats `1.9.0 > 1.10.0`). Use a Node `cmp()` helper: split on `-` for prerelease tag, compare `major.minor.patch` numerically, then prerelease order. Track max across stdin lines; empty input → empty output.

If both paths return empty, the user may be running from a custom install or never used `npx`. Treat as **undetectable** — note in the report but do not block. Skip the CLI bump prompt; continue to Step 2.

**Registry comparison:** ```bash curl -fsS "https://registry.npmjs.org/agentic-sdlc-wizard/latest" | jq -r '.version' ``` Cache the result (also used in Step 3).

**Compare with semver-aware logic** — `sort -V` does NOT correctly order prereleases. Reuse the Node `cmp()` helper to produce exit `0` (installed < latest), `1` (installed > latest), `2` (equal).

**Surface the result:** - `installed == latest` → silent, continue. - `installed < latest` → show the gap with the upgrade options below. - `installed > latest` (rare — pre-release/local dev) → silent, continue.

**Upgrade options when behind:**

> Your `agentic-sdlc-wizard` CLI is at **{installed}**, npm has **{latest}**. Step 6 refreshes project files, but `npx` cache keeps the old CLI on disk for `npx agentic-sdlc-wizard check`/`init`/`complexity`. > > **A. Refresh just the CLI cache (recommended).** No project changes; Step 6 handles the rest with diffs: > ```bash > npx -y agentic-sdlc-wizard@latest --version > ``` > > **B. One-shot CLI + project re-init.** Refreshes CLI AND overwrites *non-settings* managed files (skills, hooks, templates) with latest. `settings.json` is smart-merged (custom hooks + permissions preserved); other managed files are NOT smart-merged — local edits are lost unless committed. Use only if no local skill/hook customizations: > ```bash > npx -y agentic-sdlc-wizard@latest init --force > ``` > > **C. Skip the CLI bump.** Keep stale CLI; this session's file updates apply but `npx ... check` keeps using old drift logic. > > Pick A, B, or C: `[A/B/C]` (default A)

If A: prompt the user to run the one-liner, then re-invoke `/claude-update-wizard`. If B: same with the warning. If C: log the choice and continue.

**`check-only` precedence:** if passed, Step 1.5 runs report-only — print the gap if found, but do NOT prompt or run `init --force`. Fallback when CLI undetectable: skip the bump prompt, surface unknown-state in the report, continue to Step 2.

**Why Step 1.5, not later:** subsequent steps shell out to `npx agentic-sdlc-wizard check` (Step 4). If the CLI is stale, Step 4 reports based on the OLD definition of managed files and may miss new templates entirely.

### Step 2: Fetch Latest CHANGELOG

WebFetch: ``` https://raw.githubusercontent.com/BaseInfinity/claude-sdlc-harness/main/CHANGELOG.md ``` Extract latest version from the first `## [X.X.X]` line.

### Step 3: Compare Versions and Show What Changed

**Resolve "latest installable" from npm registry (#405):** Compare the npm registry version (Step 1.5 cache) to the CHANGELOG heading version (Step 2). Use the **lower** of the two as "latest installable" — avoids showing a version not yet published to npm during the publish window. If CHANGELOG is ahead, note it's on GitHub but not yet published.

Parse CHANGELOG entries between the user's installed version and the resolved latest installable. Present a clear summary:

``` Installed: 1.42.0 Latest: 1.99.2

What changed: - [1.92.0] Cowork `Stop` hook REMOVED — it fired 12 times in one session and was wrong 11; Cowork now has no completion enforcement (documented in cowork/README.md). - [1.91.0] TDD hook fixed for monorepos — it had been silently dead since Claude Code 2.1.214 for any repo whose source is not at root `src/`; driver effort default is now `high` (complex) / `medium` (routine web/CRUD). - [1.90.0] Stop hook no longer blocks on in-flight background work; the documented Cowork install URL is corrected (it could not have worked); review-loop, convergence and TDD RED-per-assertion guidance added - [1.89.0] Stop hook can no longer block a turn forever — it honours stop_hook_active, judges the current turn only, and blocks solely on code changed with no verification attempted; a suite with known explained failures no longer blocks. Merge approval no longer means merge bypass: the all-or-nothing escape is deleted, the denylist is tiered, and cross-model clearance satisfies the denylist finding only. Parallel blind dual review documented. - [1.88.0] Opus 5 becomes the Setup A default driver (requires CC v2.1.219+); autocompact fix — Setup A no longer writes a stale CLAUDE_AUTOCOMPACT_PCT_OVERRIDE into consumer settings; escalation ladder codified (Fable → Codex → human last, confidence is not authorization). - [1.87.0] First external contribution (@thejesh23, #444): argument-hint frontmatter quoted so Copilot CLI ≥1.0.65 loads skills, plus regression test; GPT-5.6 Sol reviewer sweep; Sonnet 5 default effort → medium (unbacked 5x quota claim removed, hook floor matched). - [1.86.0] Fix #437: codex-gate-check.sh now blocks stale certifications — a CERTIFIED handoff.json no longer sails through forever; it records commit_sha at cert time and blocks once HEAD moves past it without a re-cert. - [1.85.0] Post-ship retrospective: CI Feedback Loop synced to SKILL.md's stronger version, CERTIFIED≠CI lesson, Policy Migration Inventory checklist, stale round-count correction. - [1.84.0] Hook enforcement fix: cross-model review gate + TDD RED gate now actually block (#436); model-aware effort docs replace blanket max recommendation. - [1.83.0] Model config batch: multi-model hook recommendation (#403), global [1m] pin detection (#391), version race fix (#405), effort config check (#384). - [1.82.0] Usage diagnostics: fix /usage row, Reading Usage Signals guide, advisor fallback procedure, Fable effort guidance, autocompact cross-reference. ... (older entries omitted — read the full CHANGELOG.md for anything pre-1.59.0) ```

Read the actual entries from the fetched CHANGELOG; don't paraphrase. The user wants to see exactly what shipped.

**If versions match:** Step 7.7 (global plugin-registration cleanup) is independent of wizard file versions — it must run even when the user is up-to-date. The `check-only` flag still gates whether cleanup is *applied*:

- **Without `check-only`**: Run Step 7.7 and Step 7.9 in normal mode (detect, prompt, apply) before stopping. Then say "You're up to date! (version X.X.X)" and stop. Do not run Steps 4–10; only Steps 7.7 and 7.9 fire on match. - **With `check-only`**: Run Step 7.7 and Step 7.9 in detection-only mode — report findings but do NOT prompt and do NOT mutate settings. Then say "You're up to date! (version X.X.X)" and stop.

**If user passed `check-only` and versions don't match:** Stop after showing what changed. Do not apply anything.

### Step 4: Run Drift Detection

```bash npx agentic-sdlc-wizard check ``` Reports each managed file as MATCH, CUSTOMIZED, MISSING, or DRIFT.

### Step 5: Fetch Latest Wizard Doc

WebFetch: ``` https://raw.githubusercontent.com/BaseInfinity/claude-sdlc-harness/main/CLAUDE_CODE_SDLC_WIZARD.md ``` Source of truth for all templates, hooks, skills, step registry.

### Step 6: Per-File Update Plan

| Status | Action | |--------|--------| | MATCH | Skip — already current | | MISSING | Recommend install — explain what the file does | | CUSTOMIZED | Show what changed in latest vs user's version. Ask: adopt, skip, or merge? | | DRIFT | Flag the issue (e.g., missing executable permission). Offer to fix |

Read both the installed file and the latest template. Present a human-readable summary of differences — what was added/changed/removed and why, NOT a raw diff.

**If user passed `force-all`:** skip per-file approval, apply all updates.

### Step 7: settings.json (Smart Merge Only)

NEVER overwrite. Read user's current settings.json, compare to latest template's hook definitions, describe what changed (added/updated/removed), offer to merge: update wizard hooks while preserving all custom hooks, permissions, and other settings.

CLI's `init --force` already has smart-merge logic. If manual merge gets complicated, suggest: `npx agentic-sdlc-wizard init --force` (preserves custom hooks).

### Step 7.5: Model Pin Migration (Issue #198)

Wizard 1.31.0–1.33.x unconditionally wrote `"model": "opus[1m]"` and `"env": { "CLAUDE_AUTOCOMPACT_PCT_OVERRIDE": "30" }` to `.claude/settings.json`. Issue #198 flipped that to opt-in because a top-level `model` disables Claude Code's auto-mode.

Check user's `.claude/settings.json`:

1. **`model: "opus[1m]"` AND `env.CLAUDE_AUTOCOMPACT_PCT_OVERRIDE: "30"`** — likely the old wizard-installed pair, not an intentional choice. Ask: > Your `.claude/settings.json` pins `model: "opus[1m]"` with `CLAUDE_AUTOCOMPACT_PCT_OVERRIDE=30`. This pair was the wizard default in 1.31.0–1.33.x, but it disables Claude Code's auto-mode (issue #198). > - **Remove the pin** (recommended) — keeps auto-mode enabled > - **Keep the pin** — guaranteed 1M on whichever Opus `opus[1m]` currently resolves to (now Opus 5, as of 2026-07-24 — swap to `claude-opus-4-6` or `claude-opus-4-8` if you want an earlier version specifically), OK with no auto-selection. Note: the paired `30%` override is **not** documented to take effect on a current-Opus local session (no Opus-5 proactive threshold is published) — see the wizard doc's Autocompact Tuning → "Opus 5 specifics". If you also set `CLAUDE_CODE_AUTO_COMPACT_WINDOW`, the override *does* apply and the two compound (#207). > Remove, keep, or decide later? `[r/k/l]`

2. **Only one of the two fields matches** — treat as intentional customization. Do not prompt. 3. **`model: "sonnet[1m]"`** — ⚠️ warn: "sonnet[1m] draws from usage credits, not Max subscription (#390). Consider switching to `opusplan` (Opus plans, Sonnet executes, both Max-bundled) or plain `sonnet` (200K, Max-bundled)." 4. **`model: "opusplan"`** or other value (`sonnet`, `opus`) — explicit user choice. Do not touch. 5. **Neither

Technical details

Version
1.0.0
License
Unknown
Last updated
Aug 23, 2026
Published
Aug 23, 2026

Decision snapshot

Fallback candidate

58
Ready
Prototype
Stage

recent repository activity

Audit

Install review

Install and adoption review

68
Risky
Security
61/100
Maintenance
100/100
Install
92/100
Open full auditView eval report

Agent-proven evidence

Agent-proven evidence

Outcome reports after resolve, review, install, and one narrow run.

0
Proven
Needs first agent runAuto-install: review firstLast: Unknown
Success rate
Recent failure
Outcomes
0
Output quality
Failed
0
Not relevant
0
Installs
0
Risk blocked
0
Setup needed
0
Production
0

No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.

Install

Add to agent workflow

Free and open source. Review the report before installing into production agents.

Growth loop

Share kit

X

Scenario-led draft for claude-update-wizard, ready for a manual X post.

Curator note
claude-update-wizard: Smart update for SDLC wizard — shows changelog, compares files, lets you selectively adopt ch...

44 stars

https://www.openagentskill.com/skills/baseinfinity-claude-update-wizard?ref=x
Open X draft
Optional reply with install command
Listing + install path for claude-update-wizard:
https://www.openagentskill.com/skills/baseinfinity-claude-update-wizard?ref=x

Install: npx skills add BaseInfinity/claude-sdlc-harness --skill claude-update-wizard

Listing source

Registry indexed

Claimable

This listing was indexed from public sources and is not marked official until a maintainer claim is approved.

Indexed by
OpenAgentSkill community index

Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.

Claim this skill

Owner claim

Claim this skill listing

This Registry indexed listing is attributed to BaseInfinity but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.

Creator backlink kit

Add the evidence badges to your README

Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/baseinfinity-claude-update-wizard?metric=listed&label=Listed)](https://www.openagentskill.com/skills/baseinfinity-claude-update-wizard)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/baseinfinity-claude-update-wizard?metric=trust&label=Trust)](https://www.openagentskill.com/skills/baseinfinity-claude-update-wizard)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/baseinfinity-claude-update-wizard?metric=audit&label=Audit)](https://www.openagentskill.com/skills/baseinfinity-claude-update-wizard/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/baseinfinity-claude-update-wizard?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/baseinfinity-claude-update-wizard)

Author

B

BaseInfinity

@baseinfinity

Health signals

GitHub stars
44
Quality score
35/100
Last GitHub push
Aug 23, 2026
Framework hints
Unknown
OpenAgentSkill views
2
Install copies
0
Outbound clicks
0

Community signal

Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.

Trust & safety

Do not auto-install

51
  • GitHub adoption44 GitHub starsCHECK
  • Stars/forks activity44 stars, 6 forks; issue activity unavailable in current metadataCHECK
  • Recent maintenancePushed todayPASS
  • License clarityUnknownCHECK
  • README/SKILL.md completenessMetadata includes enough usage and workflow contextPASS
  • Dependency/runtime riskcommand execution surface, credential or environment accessFIX