deps-upgrade¶
Survey a project's current dependency manifest for available upgrades and propose a prioritized upgrade plan — classifying each outdated dependency by semver bump (patch/minor/major) and flagging breaking-change signals, grounded in real signals (major bump, local CHANGELOG) rather than guesses. It reviews the manifest and any opted-in outdated output read-only (no upgrade, no manifest edit, no install) and outputs an advisory plan. Distinct from dependency-reviewer, which reviews dependency CHANGES in a diff.
At a glance¶
| Model | inherits the session's |
| Tools | Read Grep Glob Bash |
| Author | navjyotnishant |
| Source | agents/deps-upgrade.md |
Returns content — does not write files
Like all but two of the agents, this one returns its output to the skill that spawned it, and the skill writes the file. It holds no write tools, so it cannot modify the repo even if asked to.
When it runs¶
The deps-upgrade skill read package.json and (on opt-in) ran npm outdated.
what should I upgrade?
The skill spawns this agent with the manifest + outdated output; it classifies risk and returns a prioritized upgrade plan, upgrading nothing itself.
What it returns¶
- A survey table: package · current · latest (or
?) · bump class · breaking-change signal. - The prioritized plan (safe now / review-then / plan-a-migration), each item with its one-line rationale.
- A one-line summary: N patches, M minors, K majors; whether "latest" came from a live check or is unknown (no-network).
- Never an upgrade command executed — the plan is advice. You may include the exact command the user could run, clearly marked as theirs to run.
Spawned by¶
Derived, not declared
No agent file records which skills call it — this list is recovered from the skill definitions at build time, so it cannot go stale.
See the /deps-upgrade pipeline for where this fits in the whole run.