跳到主要内容
知仓学习社ZHICANG

speckit-updater

speckit-updater,来自 Microck/ordinary-claude-skills 的 agent 技能。

读凭据写文件执行命令联网读文件严重 1 · 高危 44Microck/ordinary-claude-skills

它会碰到什么

扫了多少142 个文本文件,1653 KB
它会碰到什么读凭据写文件执行命令联网读文件
命中总数240 处
命中统计严重 1 · 高 44 · 中 81 · 低 9

这个仓库里自带 24 个测试样本文件(有些技能仓会放故意的恶意样本做演示),它们不计入上面的能力与命中。

逐条看命中(30 条严重或高危)
  • 严重 specs/014-pr-validation-enhancement/data-model.md:309cred-paths
    "file": ".env.example",
  • scripts/generate-fingerprints.ps1:29cred-envread
    $env:GITHUB_PAT = "ghp_..."
  • scripts/generate-fingerprints.ps1:42cred-envread
    [string]$GithubToken = $(if ($env:GITHUB_TOKEN) { $env:GITHUB_TOKEN } else { $env:GITHUB_PAT }),
  • scripts/generate-fingerprints.ps1:42cred-envread
    [string]$GithubToken = $(if ($env:GITHUB_TOKEN) { $env:GITHUB_TOKEN } else { $env:GITHUB_PAT }),
  • scripts/generate-fingerprints.ps1:42cred-envread
    [string]$GithubToken = $(if ($env:GITHUB_TOKEN) { $env:GITHUB_TOKEN } else { $env:GITHUB_PAT }),
  • scripts/generate-fingerprints.ps1:167cred-envread
    $tempBase = Join-Path $env:TEMP "speckit-fingerprints"
  • scripts/helpers/Invoke-PreUpdateValidation.ps1:42cred-envread
    $claudeCommandsDir = Join-Path $env:USERPROFILE ".claude\commands"
  • scripts/update-orchestrator.ps1:665cred-envread
    $tempFile = Join-Path $env:TEMP "current-$(Get-Random).txt"
  • specs/011-fix-install-proceed-flag/quickstart.md:191fs-destructive
    Remove-Item "C:\temp\test-*" -Recurse -Force -ErrorAction SilentlyContinue
  • specs/011-fix-install-proceed-flag/quickstart.md:230fs-destructive
    Remove-Item "C:\temp\test-fresh-install" -Recurse -Force -ErrorAction SilentlyContinue
  • specs/011-fix-install-proceed-flag/quickstart.md:231fs-destructive
    Remove-Item "C:\temp\test-existing-speckit" -Recurse -Force -ErrorAction SilentlyContinue
  • specs/011-fix-install-proceed-flag/quickstart.md:232fs-destructive
    Remove-Item "C:\temp\test-direct-proceed" -Recurse -Force -ErrorAction SilentlyContinue
  • specs/013-e2e-smart-merge-test/quickstart.md:320fs-destructive
    Remove-Item -Path "C:\Temp\e2e-tests\test-*" -Recurse -Force
  • specs/013-e2e-smart-merge-test/quickstart.md:524fs-destructive
    Remove-Item -Path "C:\Temp\e2e-tests\test-*" -Recurse -Force
  • specs/015-plugin-distribution/quickstart.md:295fs-destructive
    Remove-Item -Recurse -Force "$env:USERPROFILE\.claude\skills\speckit-updater"
  • specs/015-plugin-distribution/quickstart.md:309fs-destructive
    Remove-Item -Recurse -Force "$env:USERPROFILE\.claude\skills\speckit-updater"
  • tests/integration/GitHubToken.Tests.ps1:28cred-envread
    $script:hasTestToken = -not [string]::IsNullOrWhiteSpace($env:GITHUB_TEST_TOKEN)
  • tests/integration/GitHubToken.Tests.ps1:35cred-envread
    Write-Host "  To enable: Set `$env:GITHUB_TEST_TOKEN to a valid GitHub Personal Access Token" -ForegroundColor Yellow
  • tests/integration/GitHubToken.Tests.ps1:43cred-envread
    $originalToken = $env:GITHUB_PAT
  • tests/integration/GitHubToken.Tests.ps1:47cred-envread
    $env:GITHUB_PAT = $env:GITHUB_TEST_TOKEN
  • tests/integration/GitHubToken.Tests.ps1:47cred-envread
    $env:GITHUB_PAT = $env:GITHUB_TEST_TOKEN
  • tests/integration/GitHubToken.Tests.ps1:59cred-envread
    $env:GITHUB_PAT = $originalToken
  • tests/integration/GitHubToken.Tests.ps1:64cred-envread
    $originalToken = $env:GITHUB_PAT
  • tests/integration/GitHubToken.Tests.ps1:67cred-envread
    $env:GITHUB_PAT = $env:GITHUB_TEST_TOKEN
  • tests/integration/GitHubToken.Tests.ps1:67cred-envread
    $env:GITHUB_PAT = $env:GITHUB_TEST_TOKEN
  • tests/integration/GitHubToken.Tests.ps1:77cred-envread
    $env:GITHUB_PAT = $originalToken
  • tests/integration/GitHubToken.Tests.ps1:84cred-envread
    $originalToken = $env:GITHUB_PAT
  • tests/integration/GitHubToken.Tests.ps1:88cred-envread
    $env:GITHUB_PAT = $null
  • tests/integration/GitHubToken.Tests.ps1:93cred-envread
    $env:GITHUB_PAT = $env:GITHUB_TEST_TOKEN
  • tests/integration/GitHubToken.Tests.ps1:93cred-envread
    $env:GITHUB_PAT = $env:GITHUB_TEST_TOKEN

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

SpecKit Safe Update

This skill provides safe update capabilities for GitHub SpecKit installations, preserving customizations while applying template updates.

Installation: Available via plugin (/plugin marketplace add NotMyself/claude-plugins then /plugin install speckit-updater) or manual Git clone. See [README.md](../../README.md#installation) for details.

What to do when this skill is invoked

When the user invokes /speckit-updater, you should:

  1. Run the update orchestrator script without any flags (conversational mode):
   pwsh -NoProfile -Command "& 'C:\Users\bobby\.claude\skills\speckit-updater\scripts\update-wrapper.ps1'"
  1. Parse the output for markers:
  • [PROMPT_FOR_APPROVAL] - Update scenario (existing SpecKit installation)
  • [PROMPT_FOR_INSTALL] - Fresh installation scenario (no .specify/ directory)
  1. For Updates ([PROMPT_FOR_APPROVAL] marker found):
  • Present the Markdown summary showing:
  • Current version vs. available version
  • Files to update/add/remove
  • Conflicts detected (if any)
  • Files preserved (customized)
  • Backup location
  • Custom commands
  • Ask the user for approval to proceed with the update
  • If approved, re-run with -Proceed flag
  • If declined, inform the user the update was cancelled
  1. For Fresh Installations ([PROMPT_FOR_INSTALL] marker found):
  • Present a natural installation offer to the user, such as:
  • "SpecKit is not currently installed in this project. Would you like me to install it?"
  • "I can install the latest SpecKit templates for you. This will create the .specify/ directory structure and download the templates from GitHub."
  • Do NOT mention the -Proceed flag to the user (this is an implementation detail)
  • If user approves (says "yes", "proceed", "install it", etc.), re-run with -Proceed flag
  • If user declines, inform them the installation was cancelled
  1. Execute approved action by re-running with -Proceed flag:
   pwsh -NoProfile -Command "& 'C:\Users\bobby\.claude\skills\speckit-updater\scripts\update-wrapper.ps1' -Proceed"

Special cases:

  • If user requests -CheckOnly: run with that flag and show the report
  • If user requests -Rollback: run with that flag and confirm restoration
  • If user requests specific -Version: include that parameter

Commands

/speckit-updater

Updates SpecKit templates, commands, and scripts while preserving customizations.

Usage:

  • /speckit-updater - Interactive update/install with conversational approval workflow (recommended for Claude Code)
  • /speckit-updater -Proceed - Proceed with update/install after approval (used by Claude after user confirms)
  • /speckit-updater -CheckOnly - Check for updates without applying
  • /speckit-updater -Version v0.0.72 - Update to specific version
  • /speckit-updater -Force - Force overwrite SpecKit files (preserves custom commands)
  • /speckit-updater -Rollback - Restore from previous backup
  • /speckit-updater -Auto - DEPRECATED: Use conversational workflow instead (shows warning, maps to -Proceed)

Fresh Installation (No .specify/ directory):

  • First invocation shows installation offer with [PROMPT_FOR_INSTALL] marker
  • Claude Code presents natural question to user (e.g., "Would you like me to install SpecKit?")
  • User approves via conversational response (e.g., "yes", "proceed", "install it")
  • Claude re-invokes with -Proceed flag automatically (implementation detail hidden from user)
  • Script creates .specify/ structure, downloads templates, creates manifest
  • Exit code 0 throughout (awaiting approval is not an error)
  • Consistent with update flow: both use conversational approval workflow

Process:

  1. Validates prerequisites (Git installed, clean Git state, write permissions)
  2. Loads or creates manifest (.specify/manifest.json)
  3. Fetches target version from GitHub Releases API
  4. Compares file hashes to identify customizations
  5. Creates timestamped backup
  6. Applies selective updates preserving customized files
  7. Opens VSCode merge editor for conflicts (Flow A: one at a time)
  8. Automatically invokes /speckit.constitution for constitution updates
  9. Updates manifest with new version
  10. Manages backup retention (keeps last 5)

When you invoke this command, I will:

  1. Execute the update-orchestrator.ps1 script
  2. Parse output for markers ([PROMPT_FOR_APPROVAL] for updates, [PROMPT_FOR_INSTALL] for fresh installations)
  3. For updates: Present Markdown summary of proposed changes
  4. For installations: Ask naturally if you want to install SpecKit (without mentioning -Proceed flag)
  5. Wait for your approval via chat conversation
  6. After approval: automatically re-invoke with -Proceed flag to execute
  7. Guide you through conflict resolution one file at a time (updates only)
  8. Open VSCode diff/merge tools as needed (updates only)
  9. Report results with detailed summary

Conversational Workflow: The skill uses a two-step approval process:

  • Step 1: Outputs summary → script exits → waits for approval
  • Step 2: After approval, Claude re-invokes with -Proceed → applies updates

Requirements:

  • Git installed and in PATH
  • Internet connection for fetching updates from GitHub
  • Write permissions to .specify/ and .claude/ directories
  • Clean or staged Git working directory

The script is located at: {skill_path}/scripts/update-wrapper.ps1 (entry point) and {skill_path}/scripts/update-orchestrator.ps1 (main logic)

Entry point command:

pwsh -NoProfile -Command "& '{skill_path}/scripts/update-wrapper.ps1' [parameters]"

Note: Both PowerShell-style (-CheckOnly) and Linux-style (--check-only) flags are supported via the wrapper script.

Features

  • Customization Preservation: Automatically detects and preserves user customizations using normalized file hashing
  • Intelligent Conflict Resolution: Guides through conflicts one-at-a-time with 4 options: merge editor, keep mine, use new, skip
  • Version Tracking: Maintains .specify/manifest.json with file hashes, version info, and backup history
  • Automatic Backups: Creates timestamped backups in .specify/backups/ with automatic retention management
  • Fail-Fast with Rollback: Automatically rolls back on any error, restoring pre-update state
  • Dry-Run Mode: --check-only shows exactly what would change without applying updates
  • Constitution Integration: Notifies when constitution template has updates (run /speckit.constitution)
  • Custom Command Safety: User-created commands never overwritten, even with --force

Architecture

Modules

  • HashUtils: Normalized hashing (handles line endings, trailing whitespace, BOM)
  • VSCodeIntegration: Context detection, Quick Pick, diff/merge editor integration
  • GitHubApiClient: GitHub Releases API interaction (unauthenticated, 60 req/hour)
  • ManifestManager: Manifest CRUD operations with caching
  • BackupManager: Backup creation, restoration, and retention management
  • ConflictDetector: File state analysis and conflict detection

Workflow

  1. Prerequisites validation (critical checks must pass, warnings allow continuation)
  2. Manifest loading/creation (safe default: assume all files customized if no manifest)
  3. GitHub API query for target version
  4. File state analysis (6 actions: add/remove/merge/preserve/update/skip)
  5. User confirmation with change preview
  6. Backup creation (timestamped, excludes backups directory)
  7. Selective file updates (fail-fast with automatic rollback)
  8. Conflict resolution (Flow A: one-at-a-time, VSCode merge editor)
  9. Manifest update (version, file hashes, customization flags)
  10. Backup cleanup (keep 5 most recent, requires confirmation)
  11. Detailed summary display

Exit Codes

| Code | Meaning |

|------|---------|

| 0 | Success |

| 1 | General error |

| 2 | Prerequisites not met |

| 3 | Network/API error |

| 4 | Git error |

| 5 | User cancelled |

| 6 | Rollback required (automatic) |

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 398
本站分层T2
该仓技能数2148
原文件路径skills_categorized/automation-tools/claude-win11-speckit-update-skill/skills/speckit-updater/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2148 个技能

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 speckit-updater 的技能。它们内容并不相同,别混用: