sync-upstream

A maintenance workflow that compares a project's saved prompts and model settings with those in a Claude Code release. It identifies missing or changed parts and updates the project after approval.

In plain words
What is it for?
Use it when checking a new Claude Code version, reviewing prompt changes, or updating model capability rules and related prompt files.
Why use it?
It helps prevent the project from quietly falling out of sync with the upstream tool. It also separates deliberate differences from accidental drift.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/nklisch/claude-code-modes/sync-upstream
Any agent
npx skills add nklisch/claude-code-modes --skill sync-upstream
Clone the repo
git clone --depth 1 https://github.com/nklisch/claude-code-modes

Made for: Claude Code, Codex.

Per session 83 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,669 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00083 $0.01669
Opus 5 $0.00042 $0.00834
Sonnet 5 $0.00017 $0.00334
Haiku 4.5 $0.00008 $0.00167

Measured 2d ago against content hash 31419909999b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sync-upstream scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/sync-upstream/SKILL.md · 146 lines

How it starts

The opening of the file, as written. The whole thing — 146 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Sync Upstream

Keep prompts/base/, prompts/lean/, the prompt-bundle modifiers, and the model table in src/env.ts aligned with what Claude Code actually sends.

This is an investigation, not a checklist. The sections below describe what has to be true when you're done and the tools available to get there — how you sequence them is yours to judge. Two things are not yours to judge: confirm the target version before doing the work, and get changes approved before applying them.

What "aligned" means

Three prompt shapes exist upstream, assembled by one function that forks on a model-capability predicate. All three matter here:

Shape Who gets it Tracked in
standard head models without lean_prompt prompts/base/
lean head models with lean_prompt prompts/lean/
shared tail everyone, both heads duplicated in both bases
bundle sections models with opus_5_prompt_bundle prompts/modifiers/

Capabilities also drive --base auto, so the model table in src/env.ts is part of the sync, not a side note: a new flagship changes which base users get by default.

references/fragment-map.md holds the current local↔upstream mapping and the marker strings to find each piece. references/intentional-omissions.md holds every difference that is deliberate.

Ground truth and how to reach it

bun run scripts/extract-upstream-prompt.ts [version] pulls named prompt functions into upstream-prompts/. It is the fastest path for what it covers, which is the standard head and not much else. It does not extract the shared tail, the lean head, the bundle sections, or model capabilities.

For anything it misses, grep the release binary directly:

npm pack @anthropic-ai/claude-code-linux-x64@<version> && tar xzf *.tgz   # → package/claude

It's ~275 MB, so slice by byte offset in Python rather than running wide regexes:

data = open("package/claude","rb").read()
i = data.find(b"<marker text>")
print(data[i-4000:i+4000].decode("utf8","replace"))

Read the full file on GitHub · 146 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 146 lines · 83 tokens per session scan A 31419909999b

Subscribe to this mod's changes

sync-upstream is a skill published in the GitHub repository nklisch/claude-code-modes (115 stars, last pushed 24d ago), licensed MIT. It adds 83 tokens to every session and 1,669 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

obra/superpowers · 37 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

babysit-pr

Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…

openai/codex · 114 tokens

imagegen

Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…

openai/codex · 113 tokens