ai-assist-npm-update
Bulk-update outdated npm dependencies across one or more package.json files. Finds every package.json in the current working directory (recursively, skipping node_modules), runs npm outdated, bumps each outdated dependency to its 'wanted' version prefixed with ^, then runs npm in
Supply asset profile
Coding and developer agents
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
Maintenance
fresh
2d since push
Risk
Needs review
License is unclear
GitHub quality
88
61/100 Quality · 64/100 Trust
Coverage tags
Review notes
License is unclear · Financial research output is not financial advice; require human review before any live investment decision
Agent adoption scorecard
Trust, audit, and install readiness at a glance
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
PromisingUseful candidate, but compare it with alternatives before adopting.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Human review before install
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
88 GitHub stars
Repo activity
88 stars, 12 forks
Maintenance
2d since push
License
Unknown
Install
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
Install safety
standard package or runtime install path
Permission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Review before production
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
- Financial research output is not financial advice; require human review before any live investment decision.
- License is unclear
- Quality score needs review
Install readiness
Install path available
- Install path is available
- Repository evidence is available
- License is unclear
- No Agent Proven outcome evidence yet
Agent-readable metadata
Machine-readable decision data for this skill.
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
- Browser automation workflows
- Claude Code teams
- builders willing to evaluate younger projects
- Navigate pages
Suited agents
Install decision
- Command
- npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
- Policy
- review
- Human review
- yes
Trust and risk
- Trust
- 56/100
- Audit
- 72/100
- Risk level
- Needs review
Outcome loop
- Endpoint
- /api/agent/outcome
- Event ID
- resolve
- Outcomes
- 5
Install command
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-updateDo not use when
- teams that need a vendor-supported SLA
- production agents without a repository review
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
- High-risk permission hints: Shell or command execution
- License is unclear
Agent safety v2
40/100 · Avoid automatic install
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Shell or command execution
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Browser automation
Skill may drive a browser or interact with web pages.
medium
Network access
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Filesystem access
Skill may read or write project files, documents, generated artifacts, or local workspace state.
- High-risk permission hints: Shell or command execution
- License is unclear
Install targets
Install this skill in your agent workflow
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install jparkerweb-ai-assist-npm-updateAgent resolve plan
Let an agent verify fit before installing.
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20ai-assist-npm-update%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20ai-assist-npm-update%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/jparkerweb-ai-assist-npm-update/install
Agent should check
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Copy prompt
Task: Use ai-assist-npm-update in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ai-assist-npm-update%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/jparkerweb-ai-assist-npm-update/install
Install command: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Give an agent the install path, not another directory page.
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/jparkerweb-ai-assist-npm-update/install
LLM text format
/api/skills/jparkerweb-ai-assist-npm-update/install?format=text
Find alternatives
/api/skills/search?q=ai-assist-npm-update&limit=3
Agent prompt
Use ai-assist-npm-update for this task. Review https://www.openagentskill.com/api/skills/jparkerweb-ai-assist-npm-update/install, then install with: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-updateRegistry metadata
Agent-readable profile for automatic skill selection.
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/jparkerweb-ai-assist-npm-update
LLM text
/api/registry/manifest/jparkerweb-ai-assist-npm-update?format=text
Install alias
/api/registry/install/jparkerweb-ai-assist-npm-update
Recommend
/api/registry/recommend?task=Use%20ai-assist-npm-update%20in%20an%20agent%20workflow&limit=3
Agent fit
Browser automation
Use-case tags
Platforms
Claude Code
Audit report
Needs review · 72/100
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Fallback candidate for Browser automation
Prototype with this skill first; keep a fallback candidate ready.
Role in stack
Fallback candidate
Primary fit
Browser automation
Trust label
Prototype first
Install path
Command ready
Use when
- Browser automation workflows
- Claude Code teams
- builders willing to evaluate younger projects
Evidence
- recent repository activity
- install command or GitHub repo available
- 61/100 quality profile
- 1 OpenAgentSkill engagement events
review first
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
Implementation path
- 1Install it in a sandbox agent and run one Browser automation task end to end.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Trust profile
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
CHECK88 GitHub stars
Stars/forks activity
CHECK88 stars, 12 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
CHECKUnknown
Good signals
- AI review approved
- Install path is available
- Repository evidence is available
- Recently maintained repository
- Install command has no obvious high-risk pattern
- Outcome loop is ready but needs first real agent run
Review before install
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
- Financial research output is not financial advice; require human review before any live investment decision.
- License is unclear
- Quality score needs review
- GitHub adoption: 88 GitHub stars
- Stars/forks activity: 88 stars, 12 forks; issue activity unavailable in current metadata
- License clarity: Unknown
- No real agent outcome reports yet
- Human review required before unattended installation
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Promising candidate for agent workflows
Useful candidate, but compare it with alternatives before adopting.
Workflow fit
Use this skill in these scenarios
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Automate repeated work
Workflow automation
I need my agent to automate a repeated workflow across tools and files.
Workflow fit
Add it to a complete workflow
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Compare before you install
Similar skills that may fit this task.
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
MoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Cua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
Overview
--- name: ai-assist-npm-update description: "Bulk-update outdated npm dependencies across one or more package.json files. Finds every package.json in the current working directory (recursively, skipping node_modules), runs npm outdated, bumps each outdated dependency to its 'wanted' version prefixed with ^, then runs npm install. Use whenever the user wants to update npm dependencies, bump packages to their wanted versions, refresh package.json versions, or run npm outdated and apply the results — including across a monorepo or multiple projects at once. Triggers on: update npm packages, update dependencies, bump npm versions, npm outdated, refresh package.json." argument-hint: "[--dry-run] [--root <path>]" ---
# npm Update
Update outdated npm dependencies across every `package.json` under the current working directory. For each project the skill bumps each outdated dependency's version specifier to `^<wanted>` (the "wanted" version reported by `npm outdated`, i.e. the highest version satisfying the existing semver range), then runs `npm install` to refresh the lockfile and `node_modules`.
This is a deterministic, scripted workflow — run the bundled script rather than performing the steps by hand.
## When to use
Invoke when the user wants to update npm dependencies to their latest in-range versions, refresh `package.json` version numbers, or apply `npm outdated` results in bulk. Works for a single project or a whole monorepo with many `package.json` files.
## What "wanted" means
`npm outdated` reports three versions per package: **current** (installed), **wanted** (the newest version allowed by the existing semver range in `package.json`), and **latest** (the newest published). This skill updates to **wanted** — the safe, in-range upgrade — not `latest`. After the bump, the specifier is rewritten as `^<wanted>` so future installs allow compatible minor/patch updates.
## Workflow
### Step 1 — (Recommended) Preview with a dry run
Run the script with `--dry-run` first to show the user exactly which dependencies would change, without writing any files or installing:
```bash node skills/ai-assist-npm-update/scripts/npm-update.mjs --dry-run ```
Use the path to `scripts/npm-update.mjs` relative to wherever the skill is installed. Present the listed changes to the user and confirm before applying — dependency bumps modify lockfiles and can affect builds.
### Step 2 — Apply the updates
Once confirmed (or if the user asked to just do it), run without `--dry-run`:
```bash node skills/ai-assist-npm-update/scripts/npm-update.mjs ```
The script will, for each `package.json` it finds:
1. Run `npm outdated --json --long` in that project's directory. 2. For every outdated dependency (across `dependencies`, `devDependencies`, `optionalDependencies`, and `peerDependencies`), rewrite its version specifier to `^<wanted>`. 3. Write `package.json` back, preserving the original indentation and trailing newline. 4. Run `npm install` in that directory to update the lockfile and `node_modules`.
Projects that are already up to date are left untouched.
### Step 3 — Report
Summarize for the user: which projects were updated, which dependencies were bumped (and from/to what), and flag any project where `npm install` failed so they can investigate.
## What the script handles
- **Recursive discovery** of `package.json` files, skipping `node_modules`, `.git`, `dist`, `build`, `vendor`, and other vendored/VCS/output folders so it only touches real project manifests. - **Non-semver specs** (git URLs, `file:` links, `MISSING`) are skipped — only normal `x.y.z` version ranges are rewritten. - **`npm outdated` exit code** — npm exits non-zero when packages are outdated; the script captures the JSON output regardless. - **Formatting preservation** — keeps the file's existing indentation and trailing newline so diffs stay minimal.
## Options
- `--dry-run` — list every change without writing files or running `npm install`. - `--root <path>` — search a directory other than the current working directory.
## Notes
- Requires Node.js and npm on the PATH (the script invokes `npm` directly). - Updating to `wanted` stays within existing semver ranges, so it's low-risk — but it still changes lockfiles. After running, suggest the user run their build/tests to confirm nothing broke. - Version specifiers are always rewritten as `^<wanted>` regardless of the original form (`~`, exact, `>=`). If specific packages deliberately use `~` or exact pins, review the diff before committing. - If the project is a publishable library (has `files` or `publishConfig` in `package.json`), review any `peerDependencies` changes before committing — bumping them changes the declared compatibility range for consumers of your package. - This skill does not upgrade to `latest` (major-version) versions. If the user wants major upgrades, that's a different, riskier operation — tell them to use a tool like `npm-check-updates` instead.
Technical details
- Version
- 1.0.0
- License
- Unknown
- Last updated
- Aug 21, 2026
- Published
- Aug 21, 2026
Decision snapshot
Fallback candidate
recent repository activity
Audit
Install review
Install and adoption review
- Security
- 69/100
- Maintenance
- 100/100
- Install
- 92/100
Agent-proven evidence
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
- Success rate
- —
- Recent failure
- —
- Outcomes
- 0
- Output quality
- —
- Failed
- 0
- Not relevant
- 0
- Installs
- 0
- Risk blocked
- 0
- Setup needed
- 0
- Production
- 0
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Add to agent workflow
Free and open source. Review the report before installing into production agents.
Growth loop
Share kit
Scenario-led draft for ai-assist-npm-update, ready for a manual X post.
ai-assist-npm-update: Bulk-update outdated npm dependencies across one or more package.json files. Finds every pack... 88 stars https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update?ref=x
Optional reply with install command
Listing + install path for ai-assist-npm-update: https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update?ref=x Install: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
Listing source
Registry indexed
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
- Creator
- jparkerweb
- Indexed by
- OpenAgentSkill community index
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
Claim this skill listing
This Registry indexed listing is attributed to jparkerweb but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Add the evidence badges to your README
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update/audit)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update)Author
jparkerweb
@jparkerweb
Tags
Platform fit
Health signals
- GitHub stars
- 88
- Quality score
- 37/100
- Last GitHub push
- Aug 20, 2026
- Framework hints
- Unknown
- OpenAgentSkill views
- 1
- Install copies
- 0
- Outbound clicks
- 0
Community signal
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Trust & safety
Do not auto-install
- GitHub adoption88 GitHub starsCHECK
- Stars/forks activity88 stars, 12 forks; issue activity unavailable in current metadataCHECK
- Recent maintenance2d since pushPASS
- License clarityUnknownCHECK
- README/SKILL.md completenessMetadata includes enough usage and workflow contextPASS
- Dependency/runtime riskcommand execution surface, external package install surfaceINFO
Related skills
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsCua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
21.4K Stars