ai-assist-npm-update
Bulk-update outdated npm dependencies across one or more package.json files. Finds every package.json in the current working directory (recursively, skipping node_modules), runs npm outdated, bumps each outdated dependency to its 'wanted' version prefixed with ^, then runs npm in
供给资产档案
编程与开发 Agent
代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。
场景
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
适配 Agent
Claude Code + CLI + Codex
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
维护状态
新鲜
距上次推送 2 天
风险
需审查
许可证不清晰
GitHub 质量
88
61/100 质量 · 64/100 信任
覆盖标签
审查说明
许可证不清晰 · Financial research output is not financial advice; require human review before any live investment decision
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
有潜力有用的候选项,但采用前应与替代方案比较。
信任
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
安装前需人工审查
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
88 个 GitHub Stars
仓库活跃度
88 个 Star,12 个 Fork
维护状态
距上次推送 2 天
许可证
未知
安装
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
安装安全性
标准软件包或运行时安装路径
权限范围
shell or command execution, filesystem or document access
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
- Financial research output is not financial advice; require human review before any live investment decision.
- 许可证不清晰
- Quality score needs review
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 许可证不清晰
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- Browser automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
- Navigate pages
适用 Agent
安装决策
- 命令
- npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
- 策略
- 审查
- 人工审查
- 是
信任与风险
- 信任
- 56/100
- 审计
- 72/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
不适用场景
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
- 暂未有 OpenAgentSkill 使用反馈数据
- 高风险权限提示:Shell 或命令执行
Agent 安全 v2
40/100 · 避免自动安装
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
Browser automation
Skill may drive a browser or interact with web pages.
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
- 高风险权限提示:Shell 或命令执行
- 许可证不清晰
安装目标
在你的 Agent 工作流中安装此 Skill
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install jparkerweb-ai-assist-npm-updateAgent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20ai-assist-npm-update%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20ai-assist-npm-update%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/jparkerweb-ai-assist-npm-update/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use ai-assist-npm-update in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ai-assist-npm-update%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/jparkerweb-ai-assist-npm-update/install
Install command: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/jparkerweb-ai-assist-npm-update/install
LLM 文本格式
/api/skills/jparkerweb-ai-assist-npm-update/install?format=text
寻找替代方案
/api/skills/search?q=ai-assist-npm-update&limit=3
Agent 提示词
Use ai-assist-npm-update for this task. Review https://www.openagentskill.com/api/skills/jparkerweb-ai-assist-npm-update/install, then install with: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-updateRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Agent 决策面板
Fallback candidate for Browser automation
先用此 Skill 做原型验证,并保留备选方案。
栈中角色
备选候选
主要匹配
Browser automation
信任标签
先做原型验证
安装路径
命令已就绪
适用场景
- Browser automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
证据
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 61/100 质量档案
先审查
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
- 暂未有 OpenAgentSkill 使用反馈数据
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次Browser automation任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub 采用度
检查88 个 GitHub Stars
Star/Fork 活跃度
检查88 个 Star,12 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过距上次推送 2 天
许可证清晰度
检查未知
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- The repository license is listed as Unknown, and the skill itself does not include an explicit license or attribution statement, which creates legal uncertainty for reuse.
- Financial research output is not financial advice; require human review before any live investment decision.
- 许可证不清晰
- Quality score needs review
- GitHub adoption: 88 GitHub stars
- Stars/forks activity: 88 stars, 12 forks; issue activity unavailable in current metadata
- License clarity: Unknown
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
Choose a stronger alternative or inspect the source manually before any install attempt.
质量档案
有潜力 适用于 Agent 工作流的候选
有用的候选项,但采用前应与替代方案比较。
工作流匹配
在这些场景使用此 Skill
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Automate repeated work
Workflow automation
I need my agent to automate a repeated workflow across tools and files.
工作流匹配
加入完整工作流
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
概览
--- name: ai-assist-npm-update description: "Bulk-update outdated npm dependencies across one or more package.json files. Finds every package.json in the current working directory (recursively, skipping node_modules), runs npm outdated, bumps each outdated dependency to its 'wanted' version prefixed with ^, then runs npm install. Use whenever the user wants to update npm dependencies, bump packages to their wanted versions, refresh package.json versions, or run npm outdated and apply the results — including across a monorepo or multiple projects at once. Triggers on: update npm packages, update dependencies, bump npm versions, npm outdated, refresh package.json." argument-hint: "[--dry-run] [--root <path>]" ---
# npm Update
Update outdated npm dependencies across every `package.json` under the current working directory. For each project the skill bumps each outdated dependency's version specifier to `^<wanted>` (the "wanted" version reported by `npm outdated`, i.e. the highest version satisfying the existing semver range), then runs `npm install` to refresh the lockfile and `node_modules`.
This is a deterministic, scripted workflow — run the bundled script rather than performing the steps by hand.
## When to use
Invoke when the user wants to update npm dependencies to their latest in-range versions, refresh `package.json` version numbers, or apply `npm outdated` results in bulk. Works for a single project or a whole monorepo with many `package.json` files.
## What "wanted" means
`npm outdated` reports three versions per package: **current** (installed), **wanted** (the newest version allowed by the existing semver range in `package.json`), and **latest** (the newest published). This skill updates to **wanted** — the safe, in-range upgrade — not `latest`. After the bump, the specifier is rewritten as `^<wanted>` so future installs allow compatible minor/patch updates.
## Workflow
### Step 1 — (Recommended) Preview with a dry run
Run the script with `--dry-run` first to show the user exactly which dependencies would change, without writing any files or installing:
```bash node skills/ai-assist-npm-update/scripts/npm-update.mjs --dry-run ```
Use the path to `scripts/npm-update.mjs` relative to wherever the skill is installed. Present the listed changes to the user and confirm before applying — dependency bumps modify lockfiles and can affect builds.
### Step 2 — Apply the updates
Once confirmed (or if the user asked to just do it), run without `--dry-run`:
```bash node skills/ai-assist-npm-update/scripts/npm-update.mjs ```
The script will, for each `package.json` it finds:
1. Run `npm outdated --json --long` in that project's directory. 2. For every outdated dependency (across `dependencies`, `devDependencies`, `optionalDependencies`, and `peerDependencies`), rewrite its version specifier to `^<wanted>`. 3. Write `package.json` back, preserving the original indentation and trailing newline. 4. Run `npm install` in that directory to update the lockfile and `node_modules`.
Projects that are already up to date are left untouched.
### Step 3 — Report
Summarize for the user: which projects were updated, which dependencies were bumped (and from/to what), and flag any project where `npm install` failed so they can investigate.
## What the script handles
- **Recursive discovery** of `package.json` files, skipping `node_modules`, `.git`, `dist`, `build`, `vendor`, and other vendored/VCS/output folders so it only touches real project manifests. - **Non-semver specs** (git URLs, `file:` links, `MISSING`) are skipped — only normal `x.y.z` version ranges are rewritten. - **`npm outdated` exit code** — npm exits non-zero when packages are outdated; the script captures the JSON output regardless. - **Formatting preservation** — keeps the file's existing indentation and trailing newline so diffs stay minimal.
## Options
- `--dry-run` — list every change without writing files or running `npm install`. - `--root <path>` — search a directory other than the current working directory.
## Notes
- Requires Node.js and npm on the PATH (the script invokes `npm` directly). - Updating to `wanted` stays within existing semver ranges, so it's low-risk — but it still changes lockfiles. After running, suggest the user run their build/tests to confirm nothing broke. - Version specifiers are always rewritten as `^<wanted>` regardless of the original form (`~`, exact, `>=`). If specific packages deliberately use `~` or exact pins, review the diff before committing. - If the project is a publishable library (has `files` or `publishConfig` in `package.json`), review any `peerDependencies` changes before committing — bumping them changes the declared compatibility range for consumers of your package. - This skill does not upgrade to `latest` (major-version) versions. If the user wants major upgrades, that's a different, riskier operation — tell them to use a tool like `npm-check-updates` instead.
技术详情
- 版本
- 1.0.0
- 许可证
- Unknown
- 最近更新
- 2026年8月21日
- 发布时间
- 2026年8月21日
决策摘要
备选候选
仓库近期活跃
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 ai-assist-npm-update 准备的场景化草稿,可手动发布到 X。
ai-assist-npm-update: Bulk-update outdated npm dependencies across one or more package.json files. Finds every pack... 88 stars https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update?ref=x
可选:带安装命令的回复
Listing + install path for ai-assist-npm-update: https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update?ref=x Install: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-npm-update
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- jparkerweb
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 jparkerweb,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update/audit)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-npm-update)作者
jparkerweb
@jparkerweb
平台适配
健康信号
- GitHub Stars
- 88
- 质量评分
- 37/100
- 最近 GitHub 推送
- 2026年8月20日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 0
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
Do not auto-install
- GitHub 采用度88 个 GitHub Stars检查
- Star/Fork 活跃度88 个 Star,12 个 Fork; 当前元数据中没有议题活跃度信息检查
- 近期维护距上次推送 2 天通过
- 许可证清晰度未知检查
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险command execution surface, external package install surface信息