objectstack-upgrade

A guided process for upgrading an ObjectStack metadata project between major protocol versions. It runs automated conversions, then handles choices and custom code that automation cannot convert safely.

In plain words
What is it for?
Use it to migrate ObjectStack metadata, review conversion leftovers, update custom code and documentation, and finish with validation and a readable acceptance report.
Why use it?
Major-version upgrades can leave behind retired APIs, outdated instructions, or decisions that require human judgment. This process makes those remaining changes explicit and checks the finished project.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/objectstack-ai/objectstack/objectstack-upgrade
Any agent
npx skills add objectstack-ai/objectstack --skill objectstack-upgrade
Clone the repo
git clone --depth 1 https://github.com/objectstack-ai/objectstack

Made for: Claude Code, Codex.

Per session 209 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 8,130 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00209 $0.08130
Opus 5 $0.00105 $0.04065
Sonnet 5 $0.00042 $0.01626
Haiku 4.5 $0.00021 $0.00813

Measured yesterday against content hash 2f35e0ce23b5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

objectstack-upgrade scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/objectstack-upgrade/SKILL.md · 697 lines

How it starts

The opening of the file, as written. The whole thing — 697 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Upgrading an ObjectStack metadata project across a protocol major

This skill turns one session into an upgrade agent working on somebody else's metadata project. It has one job: take a project authored against protocol N and leave it authored against the current major, with the change proved rather than asserted.

preflight → mechanical chain → semantic residue → acceptance report

The upgrade is deliberately split into three layers, and the split is the whole design. Two of them are not yours.

Layer Who owns it What it is
1 · Mechanical The CLI. You invoke it, you never re-implement it. os migrate meta replays the ADR-0087 conversion chain: deterministic, idempotent, fixture-tested, per-hop attributable.
2 · Semantic residue You, with the project's owner. Everything a conversion cannot express: intent choices, custom code calling retired APIs, prose that still teaches the old shape.
3 · Acceptance The gates. Typed + parse-gated metadata, a green validate, and a report a human can read.

⛔ The boundary — read this before the first command

Never hand-write a rewrite the chain already applies. If a key was renamed, the conversion table knows the rename; running the chain attributes each rewrite to a hop and proves the result is schema-valid. A hand-edit does neither, and it silently diverges the moment the chain gains an entry.

Never add a tolerant read to make old metadata load. No ?? alias, no "accept both spellings" branch, no coercion in the project's own code. A key was retired because nothing enforced it or because exactly one spelling survives; re-admitting the old one at the consumer is how the defect the retirement closed comes back inside the customer's repo, where no gate can see it.

Never resolve a residue item by guessing the owner's intent. The residue exists precisely because it is a business decision. The rule for when you decide alone and when you ask is in Layer 2 — it is the most important paragraph in this skill.

Read the full file on GitHub · 697 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 697 lines · 209 tokens per session scan A 2f35e0ce23b5

Subscribe to this mod's changes

objectstack-upgrade is a skill published in the GitHub repository objectstack-ai/objectstack (45 stars, last pushed yesterday), licensed Apache-2.0. It adds 209 tokens to every session and 8,130 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

ontotect

Systematic ontology engineering for designing, constructing, reviewing, repairing, optimizing, refactoring, validating, documenting, and governing ontologies, vocabularies, taxonomies, knowledge graphs, semantic models, and mappings. Use for RDF/RDFS, OWL 2, SKOS, SHACL, SPARQL, OBO, Turtle, JSON-LD, RDF/XML…

Moonweave-AI/Ontotect · 152 tokens

mykg

Run mykg knowledge-graph commands inside Claude Code from one slash command /mykg. The user describes intent in natural language (extract, append, resume, approve, walkthrough, parse-docs, fetch-web, query); the skill parses intent, builds the right mykg CLI command from the live --help output, confirms, runs it, and…

SenolIsci/mykg · 173 tokens

mykg-github-pages

Set up and maintain the GitHub Pages site for the mykg repo (SenolIsci/mykg) — a purpose-built pages/ folder (landing page adapted from README.md, blog posts, diagrams), built by a GitHub Actions workflow that runs Jekyll and deploys the result to a gh-pages branch. Use whenever the user wants to publish project…

SenolIsci/mykg · 228 tokens

networkx

Build, analyze, and visualize networks and graphs using NetworkX (Python). Use this skill whenever the user wants to: create graphs or networks, analyze graph properties, compute centrality measures, find shortest paths, detect communities, run graph algorithms, convert graphs to/from matrices or dataframes, visualize…

SenolIsci/mykg · 163 tokens

design-architecture

Reviews the current codebase architecture and proposes improvements using four parallel specialist subagents: System Architect, Software Architect, Data Architect, and an Adversarial Architect that red-teams failure paths, LLM adversarial output scenarios, silent corruption risks, and invariant bypasses. Each subagent…

SenolIsci/mykg · 195 tokens

exchange-recovery

Accident Request (用户输入事故请求) ↓ Think (分析事故 → 决策恢复策略) ↓ Risk Evaluate (评估数据覆盖风险) ↓ Plan (列出Exchange服务器 → 查找备份时间点 → 浏览备份邮件 → 生成恢复任务) ↓ Act (执行恢复任务 → 产生恢复作业 → 验证Exchange可用性) ↓ Report (生成恢复报告:状态 + 数据统计 + 时效评估).

openbkn-ai/bkn-foundry · 0 tokens