All skills
simota avatar

/shift

@e307415
by shingo imotasimota/agent-skills85 stars
15

Orchestrating migrations, upgrades, and modernization across frameworks, libraries, APIs, databases, and dependencies. Generates codemods, applies Strangler Fig, verifies equivalence, plans rollback.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/shift

This session only. Nothing lands on disk.

referencedependency-health-scan.md

≈479 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Dependency Health Scan

Scan Commands

# Check for outdated packages
npm outdated

# Check for security vulnerabilities
npm audit

# Find unused dependencies
npx depcheck

# Check bundle size impact
npx bundlephobia <package-name>

# Analyze package size
npx cost-of-modules

# Check for deprecated packages
npx npm-check

Automated Health Check Script

#!/bin/bash
# dependency-health.sh

echo "=== Dependency Health Check ==="

echo "\n📦 Outdated Packages:"
npm outdated --json | jq -r 'to_entries[] | "\(.key): \(.value.current) → \(.value.latest)"'

echo "\n🔒 Security Vulnerabilities:"
npm audit --json | jq '.metadata.vulnerabilities'

echo "\n🗑️ Unused Dependencies:"
npx depcheck --json | jq '.dependencies, .devDependencies'

echo "\n📊 Bundle Size (top 10):"
npx cost-of-modules --less --no-install | head -15

Health Check Matrix

Check Tool Frequency Action
Outdated (patch) npm outdated Weekly Auto-update
Outdated (minor) npm outdated Monthly Review + update
Outdated (major) npm outdated Quarterly Plan migration
Security (low/moderate) npm audit Weekly Review
Security (high/critical) npm audit Immediate Fix now
Unused dependencies depcheck Monthly Remove
Deprecated packages npm-check Monthly Plan replacement

Package.json Analysis Checklist

Direct Dependencies

  • All packages actively maintained (last commit < 1 year)
  • No known security vulnerabilities
  • No deprecated packages
  • Bundle size reasonable for use case

DevDependencies

  • Build tools up to date
  • Linters/formatters consistent
  • Test frameworks current

Potential Issues

  • Duplicate functionality (e.g., lodash + ramda)
  • Heavy packages for simple tasks
  • Packages with native alternatives

Source: SKILL.md on GitHub

1 warning13d4 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The 'shift' skill is a highly structured framework for orchestrating software migrations and modernization. It provides comprehensive documentation and automation strategies for framework jumps (React 19, Next.js 16, Svelte 5, Spring Boot 4), language transitions (JS to TS, Python 2 to 3), and database evolution. The skill emphasizes best practices like the Strangler Fig pattern, AST-based codemods, and behavioral equivalence testing. No malicious patterns, obfuscation, or unauthorized data access were detected; the skill proactively includes security advisories regarding compromised packages (e.g., the 2026 Axios supply chain alert) and promotes the use of official, trusted migration tools.

  • Socket13d

    1 alert: gptAnomaly

  • Snyk13d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e307415. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/shift