superpowers-sync-upstream

superpowers-sync-upstream is a skill for Claude Code, Codex from christopherarter/superpowers-reasonix. It costs 31 tokens per session (761 once invoked), scanned A, original, MIT.

A maintenance guide for keeping a local port of two upstream code projects aligned with their source repositories. It checks pinned commits and watched files for changes, then guides re-porting and verification.

In plain words
What is it for?
Use it to detect upstream changes, compare revisions, classify added, edited, or removed skills, and update the port’s recorded upstream versions.
Why use it?
It reduces the chance that the port silently falls behind upstream fixes or additions. It also gives a repeatable way to investigate reported drift.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/christopherarter/superpowers-reasonix/superpowers-sync-upstream
Any agent
npx skills add christopherarter/superpowers-reasonix --skill superpowers-sync-upstream
Clone the repo
git clone --depth 1 https://github.com/christopherarter/superpowers-reasonix

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for superpowers-sync-upstream

README.md
[![agentmods](https://agentmods.dev/badge/skills/christopherarter/superpowers-reasonix/superpowers-sync-upstream.svg)](https://agentmods.dev/skills/christopherarter/superpowers-reasonix/superpowers-sync-upstream)
Your own site
<a href="https://agentmods.dev/skills/christopherarter/superpowers-reasonix/superpowers-sync-upstream"><img src="https://agentmods.dev/badge/skills/christopherarter/superpowers-reasonix/superpowers-sync-upstream.svg" alt="Measured on agentmods" height="20"></a>
Per session 31 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 761 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00031 $0.00761
Opus 5 $0.00015 $0.00380
Sonnet 5 $0.00006 $0.00152
Haiku 4.5 $0.00003 $0.00076

Measured 5d ago against content hash 5bf6be7d64e3, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

superpowers-sync-upstream scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/superpowers-sync-upstream/SKILL.md · 57 lines

How it starts

The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Sync Upstream

Re-aligns this port with its two upstreams and re-pins UPSTREAM.json. Run when asked to sync or update from upstream, or after the upstream-drift CI issue fires.

1. Detect

Read UPSTREAM.json for the pinned commits and watched paths, then see what moved:

node .github/scripts/check-upstream-drift.mjs prints which upstreams drifted (read-only).

For full diffs, shallow-fetch and compare from the pins:

git clone --filter=blob:none --no-checkout <obra.repo> /tmp/obra && git -C /tmp/obra diff <obra.lastSyncedCommit>..HEAD -- skills/

git clone --filter=blob:none --no-checkout <reasonix.repo> /tmp/rx && git -C /tmp/rx diff <reasonix.lastVerifiedCommit>..origin/main-v2 -- internal/tool internal/hook internal/skill internal/frontmatter internal/command

Network blocked? web_fetch the GitHub compare page: <repo>/compare/<pinned>...<branch>. This step is read-only; dispatch it to a task subagent and keep only the drift report to save context.

2. Classify content drift

For each changed obra skill, decide edited, new, or removed.

  • New skill: port it only if no native Reasonix tool already covers it (task, review, wait, explore). Otherwise add it to UPSTREAM.json retired with a one-line reason.
  • Removed upstream skill: consider retiring the port equivalent.

3. Re-port

Load superpowers-writing-skills. For each edited or to-be-ported skill, apply the Adaptations rules: snake_case tool names (read_file, edit_file, bash), description rewritten as a forceful imperative within the 130-char index budget, references/* auto-fold, native-tool substitution, path renames (docs/reasonix/...). Preserve the disciplines verbatim: Iron Laws, red-flag tables, RED-GREEN-REFACTOR. Keep bodies lean enough for the flash model.

4. Classify harness drift

Map each changed contract file to the port surface it touches:

  • internal/tool: tool names in every skill body and bench/reasonix.toml
  • internal/hook: AGENTS.md notes and any hook docs
  • internal/frontmatter: all skill frontmatter
  • internal/skill, internal/command: layout, loading, and /name assumptions

Read the full file on GitHub · 57 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 57 lines · 31 tokens per session scan A 5bf6be7d64e3

Subscribe to this mod's changes

superpowers-sync-upstream is a skill published in the GitHub repository christopherarter/superpowers-reasonix (96 stars, last pushed 16d ago), licensed MIT. It adds 31 tokens to every session and 761 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

skill-creator

Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.

CherryHQ/cherry-studio · 64 tokens

gh-pr-review

Automated Cherry Studio review for local branches, PRs, commits, files, architecture docs, and repository skills. Use for code or documentation reviews that need project-specific naming, main/renderer/shared placement and dependency rules, IpcApi and DataApi boundaries, lifecycle/service ownership, renderer hooks…

CherryHQ/cherry-studio · 147 tokens

prepare-release

Prepare a new release by collecting commits, generating bilingual release notes, updating version files, and creating a release branch. Use when asked to prepare/create a release, bump version, or run /prepare-release.

CherryHQ/cherry-studio · 44 tokens

claude-automation-recommender

Analyze a codebase and recommend Claude Code automations (hooks, subagents, skills, plugins, MCP servers). Use when user asks for automation recommendations, wants to optimize their Claude Code setup, mentions improving Claude Code workflows, asks how to first set up Claude Code for a project, or wants to know what…

CherryHQ/cherry-studio · 77 tokens

gh-create-issue

Use when user wants to create a GitHub issue for the current repository. Must read and follow the repository's issue template format.

CherryHQ/cherry-studio · 31 tokens

gh-create-pr

Create or update GitHub pull requests using the repository-required workflow and template compliance. Use when asked to create/open/update a PR so the assistant reads .github/pullrequesttemplate.md, fills every template section, preserves markdown structure exactly, and marks missing data as N/A or None instead of…

CherryHQ/cherry-studio · 65 tokens