Our review
Upgrades all Python dependencies using uv with a 7-day cooldown, then runs type checking and tests to verify nothing is broken.
Strengths
- Uses uv for fast and reliable dependency resolution
- Enforces a 7-day grace period to reduce supply-chain risks
- Runs mypy and tests to catch regressions
- Commits changes via the /commit skill
Limitations
- Assumes uv and make are already installed
- The 7-day cooldown may delay important security updates
- Some dependency changes may require manual intervention beyond automated checks
Use when you need to refresh Python dependencies in a project and verify compatibility before committing.
Do not use for projects that do not use uv or Python, or when you need to upgrade a specific package only.
Security analysis
SafeThe skill only invokes uv commands to upgrade dependencies, sync the environment, run tests, and type checking. It includes a 7-day cooldown to mitigate supply-chain attacks and checks for conflicts. No destructive, exfiltrating, or obfuscated actions are present.
No concerns found
Examples
Upgrade all Python dependencies in this project and make sure the tests still pass.Run uv lock --upgrade --exclude-newer '7 days' and then sync and run mypy and make test.Update the Python dependencies, check for type errors, and run the test suite. If everything passes, commit the changes.name: upgrade-python-deps description: Upgrade Python dependencies using uv, then run post-upgrade checks to ensure nothing is broken. allowed-tools: [ Bash(uv lock *), Bash(uv sync *), Bash(make test *), Bash(uv run mypy *), ]
Your task
Upgrade all Python dependencies and verify nothing is broken.
Step 1: Upgrade the lock file
Run uv lock --upgrade --exclude-newer "7 days" to upgrade all dependencies to their latest compatible
versions (with a 7-day cooldown to mitigate supply-chain attacks).
Review the output for any resolution errors. If there are conflicts, report them to the user and ask how to proceed before continuing.
Step 2: Sync the environment
Run uv sync to install the upgraded dependencies into the virtual environment.
Step 3: Run post-upgrade checks
Run these checks sequentially, stopping if any step fails:
- Type checking: Run
uv run mypy .and report any new type errors. These may be caused by updated type stubs or changes in library APIs. - Tests: Run
make testto verify the test suite still passes.
Step 4: Summarize and commit
Summarize what was done:
- Which packages were upgraded (notable version changes)
- Whether any type errors were introduced
- Whether all tests passed
- Any issues that need manual attention
If there were failures, present the issues and ask how the user wants to proceed.
If everything passed, ask the user if they'd like to commit the changes. If yes, commit
using the /commit skill.
Next.js App Router Expert
Development
A skill that turns Claude into a Next.js App Router expert.
README Generator
Development
Creates professional and comprehensive README.md files for your projects.
API Documentation Writer
Development
Generates comprehensive API documentation in OpenAPI/Swagger format.