All skills
simota avatar

/shift

@e307415
by shingo imotasimota/agent-skills85 stars
15

Orchestrating migrations, upgrades, and modernization across frameworks, libraries, APIs, databases, and dependencies. Generates codemods, applies Strangler Fig, verifies equivalence, plans rollback.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/shift

This session only. Nothing lands on disk.

referencedeprecation-detection.md

≈658 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Deprecation Detection

npm Audit Commands

npm outdated              # Check for outdated packages
npm audit                 # Security vulnerabilities
npx npm-check -u          # Interactive update
npx depcheck              # Unused dependencies

Signals of Deprecated Libraries

  • No commits in 12+ months
  • Open issues without responses
  • "Deprecated" in README
  • Archived repository
  • Major version behind (e.g., React 16 when 19 exists)

Multi-Ecosystem Detection Commands

Python

pip-audit                          # PyPA official; queries OSV + PyUp Safety DB
pip list --outdated                # All outdated packages
python -W all -c "import <mod>"   # Trigger DeprecationWarning at import time

Note: PEP 594 removed 19 stdlib modules in Python 3.13 (aifc, cgi, crypt, telnetlib, etc.). Source: peps.python.org/pep-0594

Go

govulncheck ./...                  # Google's official Go vulnerability checker
go list -m -u all                  # Show available module upgrades

Note: Go 1.24 deprecated crypto/cipher.NewOFB, NewCFBEncrypter, NewCFBDecrypter (unauthenticated; use AEAD or NewCTR) and runtime.GOROOT(). Source: go.dev/doc/go1.24

Java

./mvnw versions:display-dependency-updates   # Maven: check outdated deps
./gradlew dependencyUpdates                  # Gradle: check outdated deps

Note: JDK 24 permanently disabled SecurityManager (JEP 486). JDK 26 removed Applet API entirely (JEP 504). Sources: openjdk.org/jeps/486, openjdk.org/jeps/504

Node.js / npm

npm outdated              # Check for outdated packages
npm audit                 # Security vulnerabilities
npm audit signatures      # Verify registry signatures (supply chain)
npx npm-check -u          # Interactive update
npx depcheck              # Unused dependencies
node -e "require('util').isArray([])"  # Verify removed APIs (throws in Node 24+)

Note: Node 24 (Active LTS) removed all util.is*() helpers and SlowBuffer. OpenSSL 3.5 defaults reject keys < 2048-bit RSA/DH and < 224-bit ECC. Source: nodejs.org deprecated APIs v22

OSV Scanner (language-agnostic)

osv-scanner scan --lockfile package-lock.json
osv-scanner scan --lockfile requirements.txt
osv-scanner scan --lockfile go.sum

Queries the OSV database aggregating NVD, GitHub Advisory, and ecosystem-specific advisories across npm, PyPI, Go modules, Cargo, Maven, and more.

Source: SKILL.md on GitHub

1 warning13d4 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The 'shift' skill is a highly structured framework for orchestrating software migrations and modernization. It provides comprehensive documentation and automation strategies for framework jumps (React 19, Next.js 16, Svelte 5, Spring Boot 4), language transitions (JS to TS, Python 2 to 3), and database evolution. The skill emphasizes best practices like the Strangler Fig pattern, AST-based codemods, and behavioral equivalence testing. No malicious patterns, obfuscation, or unauthorized data access were detected; the skill proactively includes security advisories regarding compromised packages (e.g., the 2026 Axios supply chain alert) and promotes the use of official, trusted migration tools.

  • Socket13d

    1 alert: gptAnomaly

  • Snyk13d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e307415. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/shift