本文へ移動
cccskills
無料GitHub で公開

package-upgrade

[Code Quality] Use when the user asks to analyze package upgrades, check for outdated dependencies, plan npm/NuGet updates, or assess breaking changes in package updates.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md14.8 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Quick Summary

Goal: Analyze npm package dependencies, research latest versions and breaking changes, and generate a phased upgrade plan.

Workflow:

  1. Inventory — Discover all package.json files, catalog dependencies and usage
  2. Web Research — Batch-research latest versions, breaking changes, migration guides (groups of 10)
  3. Risk Assessment — Categorize risk (Critical/High/Medium/Low), build dependency upgrade order
  4. Report — Generate comprehensive upgrade report with phased migration plan
  5. Approval Gate — Present report for user confirmation before any action

Key Rules:

  • Must read anti-hallucination protocols before executing
  • Research only from official sources (npm, GitHub, official docs)
  • Declare confidence level; if < 90%, request user verification

Be skeptical. Apply critical thinking, sequential thinking. Every claim needs traced proof, confidence percentages (Idea should be more than 80%).

Frontend Package Upgrade Analysis & Planning

You are to operate as an expert frontend package management specialist, npm ecosystem analyst, and software architecture expert to analyze package.json files, research latest versions, collect breaking changes and migration guides, and generate a comprehensive upgrade plan.

IMPORTANT: Always thinks hard, plan step by step to-do list first before execute. Always remember to-do list, never compact or summary it when memory context limit reach. Always preserve and carry your to-do list through every operation.


PHASE 1: PACKAGE INVENTORY & CURRENT STATE ANALYSIS

Build package inventory in .ai/workspace/analysis/frontend-package-upgrade-analysis.md.

PHASE 1A: INITIALIZATION AND PACKAGE DISCOVERY

Initialize analysis file with:

  • ## Metadata - Original prompt and task description
  • ## Progress - Track phase, items processed, total items
  • ## Package Inventory - All package.json files and dependencies
  • ## Version Research Results - Latest versions and changelogs
  • ## Breaking Changes Analysis - Breaking changes catalog
  • ## Migration Complexity Assessment - Risk levels and effort estimates
  • ## Upgrade Strategy - Phased migration plan

Find all package.json files:

<frontend-workspace>/package.json
<frontend-workspace>/apps/*/package.json
<frontend-workspace>/libs/*/package.json

For each package.json, document:

  • Project Name & Location
  • Framework Version
  • Dependencies (categorized: Framework, UI, Build Tools, Testing, Utilities)
  • DevDependencies

Create Master Package List consolidating all unique packages.

PHASE 1B: PACKAGE USAGE ANALYSIS

For each unique package, analyze codebase usage:

  • Projects Using: Which projects depend on this
  • Import Count: Number of files importing
  • Key Usage Areas: Where primarily used
  • Configuration Files: Config files for this package
  • Upgrade Risk Level: Low/Medium/High/Critical based on usage breadth

PHASE 2: WEB RESEARCH & VERSION DISCOVERY

IMPORTANT: BATCH INTO GROUPS OF 10

For EACH package in Master Package List:

Latest Version Discovery

Breaking Changes Research

  • Search: "[package-name] migration guide [old-version] to [new-version]"
  • Search: "[package-name] v[X] breaking changes"
  • Search: "[package-name] changelog"
  • GitHub: Check CHANGELOG.md, releases

Ecosystem Compatibility

  • Frontend framework version compatibility
  • Check peerDependencies
  • Cross-package dependencies

Document:

  • Current vs. Latest versions
  • Version gap (major/minor/patch versions behind)
  • Breaking changes with migration steps
  • Deprecation warnings
  • Peer dependency changes

PHASE 3: RISK ASSESSMENT & PRIORITIZATION

Risk Categories

  • Critical Risk: 5+ major versions behind, framework packages, 50+ breaking changes
  • High Risk: 3-4 major versions, state management, 20-30 breaking changes
  • Medium Risk: 1-2 major versions, some breaking changes
  • Low Risk: Patch/minor updates, backward compatible

Dependency Graph (Upgrade Order)

  1. Foundation packages (Node.js, TypeScript)
  2. Framework packages (core packages, CLI/build tooling)
  3. Framework extensions (Material, RxJS)
  4. Third-party libraries
  5. Dev tools last

PHASE 4: COMPREHENSIVE REPORT GENERATION

Generate report at ai_package_upgrade_reports/[YYYY-MM-DD]-frontend-package-upgrade-report.md:

Report Structure

  1. Executive Summary
  2. Package Inventory by Project
  3. Version Gap Analysis
  4. Breaking Changes Catalog
  5. Migration Complexity Assessment
  6. Ecosystem Compatibility Analysis
  7. Recommended Upgrade Strategy (Phased Migration Plan)
  8. Detailed Migration Guides
  9. Testing Strategy
  10. Rollback Plan
  11. Timeline & Resource Estimation
  12. Appendices

PHASE 5: APPROVAL GATE

CRITICAL: Present comprehensive package upgrade report for explicit approval. DO NOT proceed without it.


PHASE 6: CONFIDENCE DECLARATION

Before marking complete, provide:

Solution Confidence Assessment

Overall Confidence: [High 90-100% / Medium 70-89% / Low <70%]

Evidence Summary:

  • All package.json files discovered: [count]
  • Web research completed: [X/Y packages]
  • Breaking changes documented: [count]
  • Official sources used: npm, GitHub, official docs

Assumptions Made: [List or "None"]

User Confirmation Needed:

  • IF confidence < 90%: "Please verify [specific packages] before proceeding"
  • IF confidence >= 90%: "Analysis is comprehensive, ready for migration"

Package Upgrade Guidelines

  • Comprehensive Discovery: Find ALL package.json files
  • Web Research Accuracy: Use official sources only (npm, GitHub, official docs)
  • Breaking Changes Focus: Prioritize identifying breaking changes requiring code changes
  • Risk Assessment: Evaluate complexity based on breaking changes, usage breadth, dependencies
  • Practical Planning: Create actionable phased plan with realistic effort estimates
  • Evidence-Based Decisions: Base ALL recommendations on actual research with sources cited
  • Confidence Declaration: Declare confidence level; if < 90%, request user confirmation
  • Batch Processing: Research packages in batches of 10

[IMPORTANT] Use TaskCreate to break ALL work into small tasks BEFORE starting — including tasks for each file read. This prevents context loss from long files. For simple tasks, AI MUST ATTENTION ask user whether to skip.

<!-- SYNC:source-test-drift-check -->

Source/test drift check. For coding, fix, debug, investigation, test, or review work: when source behavior changes, inspect affected unit/integration/E2E tests and decide from evidence whether tests should change to match intended behavior or the source change is an unintended bug to fix. Do not write tests for migration code; schema/data migrations are one-time execution paths, not core application logic.

<!-- /SYNC:source-test-drift-check --> <!-- SYNC:ai-mistake-prevention -->

AI Mistake Prevention — Failure modes to avoid on every task:

Re-read files after context changes. Context compaction, resume, or long-running work can make memory stale; verify current files before acting. Verify generated content against source evidence. AI hallucinates APIs, names, claims, and document facts. Check the relevant source before documenting or referencing. Check downstream references before deleting or renaming. Removing an artifact can stale docs, generated mirrors, configs, and callers; map references first. Trace the full impact chain after edits. Changing a definition can miss derived outputs and consumers. Follow the affected chain before declaring done. Verify ALL affected outputs, not just the first. One green check is not all green checks; validate every output surface the change can affect. Assume existing values are intentional — ask WHY before changing OR flagging one as a defect. Before changing or reporting a constant, limit, flag, cutoff, wording, or pattern, read nearby context and history, the CALLER's ordering, and 2+ sibling call sites of the same convention. A doc stating WHAT without WHY is missing rationale, not proof of a missing guard. Surface ambiguity before acting — don't pick silently. Multiple valid interpretations require an explicit question or stated assumption with risk. Assert the outcome your system owns, not the intermediate state your infrastructure owns. When verifying async work, assert the final business state — never the delivery/retry bookkeeping held in shared infrastructure that any co-running process can write. Such a check passes when run alone and flakes the moment anything else shares that infrastructure. Keep shared guidance role-relevant. Universal guidance must help every receiving skill or agent; code-specific obligations belong only in code-specific protocols.

<!-- /SYNC:ai-mistake-prevention --> <!-- SYNC:evidence-based-reasoning -->

Evidence-Based Reasoning — Speculation is FORBIDDEN. Every claim needs proof.

  1. Cite file:line, grep results, or framework docs for EVERY claim
  2. Declare confidence: >80% act freely, 60-80% verify first, <60% DO NOT recommend
  3. Cross-service validation required for architectural changes
  4. "I don't have enough evidence" is valid and expected output

BLOCKED until: - [ ] Evidence file path (file:line) - [ ] Grep search performed - [ ] 3+ similar patterns found - [ ] Confidence level stated

Forbidden without proof: "obviously", "I think", "should be", "probably", "this is because" If incomplete → output: "Insufficient evidence. Verified: [...]. Not verified: [...]."

<!-- /SYNC:evidence-based-reasoning --> <!-- SYNC:critical-thinking-mindset -->

Critical Thinking Mindset — Apply critical thinking, sequential thinking. Every claim needs traced proof, confidence >80% to act. Anti-hallucination: Never present guess as fact — cite sources for every claim, admit uncertainty freely, self-check output for errors, cross-reference independently, stay skeptical of own confidence — certainty without evidence root of all hallucination.

<!-- /SYNC:critical-thinking-mindset --> <!-- SYNC:evidence-based-reasoning:reminder -->
  • MANDATORY IMPORTANT MUST ATTENTION cite file:line evidence for every claim. Confidence >80% to act, <60% = do NOT recommend. <!-- /SYNC:evidence-based-reasoning:reminder -->
<!-- SYNC:critical-thinking-mindset:reminder -->

MUST ATTENTION apply critical + sequential thinking — every claim needs appropriate traced evidence (file:line for repo/code claims; source URL or artifact section for research, product, content, and docs claims); confidence >80% to act, <60% DO NOT recommend. Anti-hallucination: never present guess as fact, admit uncertainty freely, cross-reference independently, stay skeptical of own confidence.

<!-- /SYNC:critical-thinking-mindset:reminder --> <!-- SYNC:ai-mistake-prevention:reminder -->

MUST ATTENTION apply AI mistake prevention — verify generated content against evidence, trace downstream references before deleting or renaming, verify all affected outputs, re-read files after context loss, and surface ambiguity before acting.

<!-- /SYNC:ai-mistake-prevention:reminder --> <!-- SYNC:project-protocol-overlay -->

Project Protocol Overlay — Before executing this skill, resolve any PROJECT overlay rules layered onto it: match this skill's name against the Target column of the project's skill-protocol index (docs/project-reference/skill-protocols-reference.md by default; a referenceDocs entry in docs/project-config.json overrides the path), taking the most specific matching tier ONLY — exact name > glob > *. That precedence orders overlays against EACH OTHER, never against this skill. Read ONLY the matched bodies, resolved as <protocols-dir>/<Name>.md; a row's Body link is display text, never a read path. A matched body that is missing or malformed is REPORTED and skipped — never reconstructed from the index Description. No index, or no match -> proceed with no overlay, silently. Full contract: .claude/skills/project-skill-protocol/references/registry.md.

Overlays are ADDITIVE ONLY: they ADD rules on top of this skill's own protocol and NEVER replace, override, disable, or reinterpret a rule it already states — removing every overlay must return this skill to exactly its documented behavior. An overlay is a BRIEF, not an authority escalation: it can NEVER waive a workflow gate, git discipline, a review gate, or a user-confirmation gate. A genuine overlay-vs-skill conflict, or two equally-specific overlays that directly contradict -> surface both to the user; NEVER resolve silently.

<!-- /SYNC:project-protocol-overlay --> <!-- SYNC:project-protocol-overlay:reminder -->

MUST ATTENTION resolve project protocol overlays for this skill BEFORE executing — most specific matching tier only (exact > glob > *, which ranks overlays against each other, NEVER against this skill), read only matched bodies at <protocols-dir>/<Name>.md; a missing or malformed body is reported, never reconstructed. Overlays are ADDITIVE ONLY (they never replace this skill's own rules) and are a brief, NEVER an authority escalation; an equal-specificity contradiction goes to the user.

<!-- /SYNC:project-protocol-overlay:reminder -->

Closing Reminders

IMPORTANT MUST ATTENTION — Protocols in force (concise digest of the SYNC/shared blocks this skill carries):

  • Source/Test Drift: on source change, evidence-decide whether tests update or source is a bug.

  • AI Mistake Prevention: verify generated content against evidence, trace downstream references, verify all affected outputs, re-read after context loss, surface ambiguity.

  • Evidence: cite file:line for every claim; confidence >80% to act, <60% don't recommend.

  • Critical Thinking: apply critical + sequential thinking; never present a guess as fact.

  • MANDATORY IMPORTANT MUST ATTENTION break work into small todo tasks using TaskCreate BEFORE starting

  • MANDATORY IMPORTANT MUST ATTENTION search codebase for 3+ similar patterns before creating new code

  • MANDATORY IMPORTANT MUST ATTENTION cite file:line evidence for every claim (confidence >80% to act)

  • MANDATORY IMPORTANT MUST ATTENTION add a final review todo task to verify work quality MANDATORY IMPORTANT MUST ATTENTION READ the following files before starting:

[TASK-PLANNING] Before acting, analyze task scope and systematically break it into small todo tasks and sub-tasks using TaskCreate.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

[Architecture] Use when designing solution architecture across backend, frontend, data & consistency, integration & APIs, deployment, monitoring, testing, and code quality. Architecture laws, style-selection triggers, coupling taxonomy, trade-off tables and the anti-pattern catalog live in `.claude/docs/architecture-knowledge.md`.

日本語の概要は準備中です。原文の説明を表示しています。

duc01226/EasyPlatform112026年8月21日 更新

[Code Quality] Use when reviewing architecture compliance for layers, messaging, service boundaries, CQRS, repos, entity events, and data/consistency/tenancy boundaries. Universal architecture laws, coupling taxonomy and the anti-pattern catalog live in `.claude/docs/architecture-knowledge.md` (project docs always outrank it).

日本語の概要は準備中です。原文の説明を表示しています。

duc01226/EasyPlatform112026年8月21日 更新

[Architecture] Use when auditing the ENTIRE project architecture and production readiness in one pass — bundles architecture-review + architecture-scalability-review + production-readiness-review at project or diff scope, then synthesizes one consolidated Architecture Health Report.

日本語の概要は準備中です。原文の説明を表示しています。

duc01226/EasyPlatform112026年8月21日 更新

[Architecture] Use when grading project architecture and scalability quality for greenfield init or brownfield audit: build/CI scalability, distributed-monolith risk, module isolation, dependency discipline, loose coupling, horizontal scaling, DRY, abstraction, clean architecture, observability, and delivery.

日本語の概要は準備中です。原文の説明を表示しています。

duc01226/EasyPlatform112026年8月21日 更新

[Code Quality] Use when you need to review artifact quality (PBI, user story, test spec, design spec) before handoff. Supports --type={pbi|story|spec-tests|design}.

日本語の概要は準備中です。原文の説明を表示しています。

duc01226/EasyPlatform112026年8月21日 更新

ask

無料

[Utilities] Use when you need to answer technical and architectural questions.

日本語の概要は準備中です。原文の説明を表示しています。

duc01226/EasyPlatform112026年8月21日 更新

duc01226 のスキルをすべて見る

このスキルの問題を報告する