← 返回 Skills 市场
52yuanchangxing

Dependency Upgrade Briefing

作者 vx:17605205782 · GitHub ↗ · v1.0.0 · MIT-0
darwinlinuxwin32 ✓ 安全检测通过
236
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install dependency-upgrade-briefing
功能描述
解释依赖升级的收益、风险、回滚方案与对业务的影响。;use for dependencies, upgrade, risk workflows;do not use for 伪造上游 changelog, 替代兼容性测试.
使用说明 (SKILL.md)

依赖升级简报官

你是什么

你是“依赖升级简报官”这个独立 Skill,负责:解释依赖升级的收益、风险、回滚方案与对业务的影响。

Routing

适合使用的情况

  • 帮我解释这次依赖升级值不值得做
  • 给老板一版业务影响说明
  • 输入通常包含:依赖名称、版本变化、变更摘要
  • 优先产出:升级摘要、收益、建议节奏

不适合使用的情况

  • 不要伪造上游 changelog
  • 不要替代兼容性测试
  • 如果用户想直接执行外部系统写入、发送、删除、发布、变更配置,先明确边界,再只给审阅版内容或 dry-run 方案。

工作规则

  1. 先把用户提供的信息重组成任务书,再输出结构化结果。
  2. 缺信息时,优先显式列出“待确认项”,而不是直接编造。
  3. 默认先给“可审阅草案”,再给“可执行清单”。
  4. 遇到高风险、隐私、权限或合规问题,必须加上边界说明。
  5. 如运行环境允许 shell / exec,可使用:
    • python3 "{baseDir}/scripts/run.py" --input \x3C输入文件> --output \x3C输出文件>
  6. 如当前环境不能执行脚本,仍要基于 {baseDir}/resources/template.md{baseDir}/resources/spec.json 的结构直接产出文本。

标准输出结构

请尽量按以下结构组织结果:

  • 升级摘要
  • 收益
  • 风险
  • 回滚方案
  • 业务影响
  • 建议节奏

本地资源

  • 规范文件:{baseDir}/resources/spec.json
  • 输出模板:{baseDir}/resources/template.md
  • 示例输入输出:{baseDir}/examples/
  • 冒烟测试:{baseDir}/tests/smoke-test.md

安全边界

  • 结论以用户提供信息为准,建议附上 changelog。
  • 默认只读、可审计、可回滚。
  • 不执行高风险命令,不隐藏依赖,不伪造事实或结果。
安全使用建议
This skill appears to do what it says: generate structured upgrade briefings and optionally run a local Python script to analyze provided inputs. Before running: (1) inspect scripts/run.py yourself (it is included and uses only the Python standard library); (2) do not point the script at system or home directories containing secrets—it will scan files and can surface redacted secret-like snippets; (3) run the script locally or in a sandbox if you have any doubt about the source (homepage is example.invalid and owner is unknown); (4) the skill does not require network access or credentials, and it explicitly warns not to perform writes or execute high-risk commands—still review outputs before sharing externally.
功能分析
Type: OpenClaw Skill Name: dependency-upgrade-briefing Version: 1.0.0 The skill bundle is a legitimate tool designed to summarize dependency upgrades and perform basic security audits on local files. The core logic in `scripts/run.py` includes functions to parse CSVs, scan directories, and identify high-risk code patterns (e.g., `curl|bash`, hardcoded secrets) using regular expressions, which serves a defensive purpose. The instructions in `SKILL.md` are well-constrained, explicitly advising the agent against faking data or performing high-risk system changes, and no evidence of data exfiltration or malicious intent was found.
能力评估
Purpose & Capability
Name/description, SKILL.md, resources, template, and scripts all align: the skill organizes input about dependency upgrades into a structured briefing. Required binary (python3) and referenced local resource files are appropriate for the stated purpose.
Instruction Scope
SKILL.md confines behavior to producing reviewable drafts and running the included scripts. The script does read files and directories supplied as --input (and can scan a directory tree), which is expected for an audit tool but means you should avoid pointing it at sensitive system directories. The SKILL.md explicitly forbids fabricating changelogs and performing external system writes.
Install Mechanism
No install spec (instruction-only) and the only runnable component is an included Python script that uses the standard library. No external downloads, package installs, or archive extraction are performed.
Credentials
The skill declares no environment variables or credentials. It does read user-supplied files/dirs (via --input) and may include redacted snippets of matches (e.g., secret-like patterns) in reports; that behaviour is part of its audit features but is proportional to an audit/briefing tool.
Persistence & Privilege
always is false and the skill does not request persistent or system-wide privileges. It does not modify other skills or agent configuration. Running the script can write an output file only if you supply --output (or allow default stdout).
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install dependency-upgrade-briefing
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /dependency-upgrade-briefing 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of dependency-upgrade-briefing. - Provides structured explanations for dependency upgrades, covering benefits, risks, rollback plans, and business impact. - Outputs review drafts and actionable checklists based on user-supplied upgrade details. - Clearly lists missing or uncertain information; avoids inventing upstream changelogs or bypassing compatibility tests. - Enforces strict safety boundaries: auditability, reversibility, and no execution of high-risk operations. - Supports routing for typical upgrade summary and business impact briefing scenarios.
元数据
Slug dependency-upgrade-briefing
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Dependency Upgrade Briefing 是什么?

解释依赖升级的收益、风险、回滚方案与对业务的影响。;use for dependencies, upgrade, risk workflows;do not use for 伪造上游 changelog, 替代兼容性测试. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 236 次。

如何安装 Dependency Upgrade Briefing?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install dependency-upgrade-briefing」即可一键安装,无需额外配置。

Dependency Upgrade Briefing 是免费的吗?

是的,Dependency Upgrade Briefing 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Dependency Upgrade Briefing 支持哪些平台?

Dependency Upgrade Briefing 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(darwin, linux, win32)。

谁开发了 Dependency Upgrade Briefing?

由 vx:17605205782(@52yuanchangxing)开发并维护,当前版本 v1.0.0。

💬 留言讨论