upgrade-advisor
Evaluates whether and how to upgrade a tool.
What this skill does for you
Evaluates whether and how to upgrade a tool, framework, library, or dependency. Discovers the pinned version(s), finds the latest released and latest installable version, reads the changelog across the whole version delta, and grep-classifies each breaking change and deprecation against real codebase usage, so the report covers only what applies here plus features worth adopting. Handles security/CVE- and end-of-life-driven upgrades; emits a safe / stay-put / blocked / needs-work verdict, investigate-only by default. Also verifies an already-done upgrade by auditing the runtime's error surface, catching latent breakage the changelog delta cannot reveal. Use when the user asks to upgrade, bump, or update a tool or dependency, mentions its new release or latest version, asks whether an upgrade is safe or worth it, or just upgraded and wants to know what broke. Triggers include "upgrade", "bump", "update dependency", "breaking changes", "is it safe to upgrade", "just upgraded", "what broke after the upgrade".
Quoted from the skill description in the pinned sourceWho made it
Use it with Edge
Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the upgrade-advisor skill from vtmocanu/skills.
Paste it into Claude, ChatGPT, Codex or Cursor.
Or read the skill source first.
Security evidence
| Scanner | Date | Result | Findings |
|---|---|---|---|
| Edge static checks | 2026-09-27 | Pass | 0 |
| Cisco skill-scanner | 2026-09-27 | Pass | 0 |
| Semgrep Edge rules | 2026-09-27 | Pass | 0 |
Static scans check the code, not how well the skill works.
Scanner scope, raw findings and mirrored provider records
Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: 89396fb2e13afda11587ab61c1e7639161cca6e0. Raw findings: . Counted findings: .
Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: 89396fb2e13afda11587ab61c1e7639161cca6e0. Raw findings: 1. Counted findings: .
Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: 89396fb2e13afda11587ab61c1e7639161cca6e0. Raw findings: . Counted findings: .
Source and licence
- Repository
- https://github.com/vtmocanu/skills
- Pinned skill file
- View source at revision
- Revision
- 89396fb2e13afda11587ab61c1e7639161cca6e0
- Package hash
- sha256:9f61eb40dff69257579be02e7b669c4c8adca74735e78c9bb4f2b67a54caaba3
- Licence
- MIT