upstream

A release-monitoring workflow for Claude Code, a coding assistant made by Anthropic. It compares new releases with Sequant and reports compatibility concerns, breaking changes, and deprecations.

In plain words
What is it for?
Use it to inspect Claude Code releases, assess their effect on Sequant, create issues for urgent compatibility problems, and record possible improvements.
Why use it?
It helps maintainers notice upstream changes that could break existing workflows or require updates.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/sequant-io/sequant/upstream
Any agent
npx skills add sequant-io/sequant --skill upstream
Clone the repo
git clone --depth 1 https://github.com/sequant-io/sequant

Made for: Claude Code, Codex.

Per session 36 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,906 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00036 $0.02906
Opus 5 $0.00018 $0.01453
Sonnet 5 $0.00007 $0.00581
Haiku 4.5 $0.00004 $0.00291

Measured yesterday against content hash 825c9b4801e1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

upstream scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/upstream/SKILL.md · 420 lines

How it starts

The opening of the file, as written. The whole thing — 420 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Local overrides (read this first). Before following any instruction below, check whether .claude/.local/skills/upstream/overrides.md exists. If it does, read it and treat its contents as authoritative: its instructions take precedence over anything in this skill they conflict with. This is the supported way to tailor /upstream without forking it — overrides.md lives under .claude/.local/, which sequant update and sync never overwrite.

Upstream: Claude Code Release Tracking

You are the "Upstream Assessment Agent" for the sequant repository.

Purpose

When invoked as /upstream, your job is to:

  1. Fetch Claude Code release information from the public GitHub repo
  2. Analyze changes against sequant's current capabilities baseline
  3. Detect relevant changes using keyword matching and regex patterns
  4. Skip out-of-scope changes (configured in baseline.json outOfScope)
  5. Generate a structured compatibility assessment report with Actionable and Informational sections
  6. Auto-create GitHub issues for breaking changes, deprecations, new tools, and hook changes
  7. List opportunities in the assessment report for human triage (no individual issues created)

Invocation

# Analyze latest release
/upstream

# Analyze specific version
/upstream v2.1.29

# Analyze all releases since version
/upstream --since v2.1.25

# Dry-run mode (no issues created)
/upstream --dry-run

# Help
/upstream --help

Assessment Process

1. Parse Arguments

Parse the command arguments to determine:

  • Target version: Specific version (e.g., v2.1.29) or latest
  • Since version: If --since flag provided, assess all versions since that release
  • Dry-run mode: If --dry-run flag, generate report but skip issue creation
  • Help: If --help flag, show usage instructions

2. Fetch Release Data

Fetch release information from the public Claude Code repository:

# Get latest release
gh release view --repo anthropics/claude-code --json tagName,name,body,publishedAt

# Get specific version
gh release view v2.1.29 --repo anthropics/claude-code --json tagName,name,body,publishedAt

# List releases for --since support
gh release list --repo anthropics/claude-code --limit 50 --json tagName,publishedAt

Read the full file on GitHub · 420 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 420 lines · 36 tokens per session scan A 825c9b4801e1

Subscribe to this mod's changes

upstream is a skill published in the GitHub repository sequant-io/sequant (1 stars, last pushed 2d ago), licensed MIT. It adds 36 tokens to every session and 2,906 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

agent-estate

Perpetual autonomous work loop for Claude Code — no end condition, no memory regression, no context overfill. Maintains a persistent ledger across all sessions.

MercuriusDream/agent-estate · 36 tokens

citation-audit

Zero-context verification that every bibliographic entry in the paper is real, correctly attributed, and used in a context the cited paper actually supports — catching hallucinated authors, wrong years, fabricated venues, version mismatches, and wrong-context citations. Use when user says "审查引用", "check citations"…

wanshuiyin/Auto-claude-code-research-in-sleep · 86 tokens

paper-illustration

Generate publication-quality AI illustrations for academic papers using Gemini image generation. Creates architecture diagrams, method illustrations with Claude-supervised iterative refinement loop. Use when user says "生成图表", "画架构图", "AI绘图", "paper illustration", "generate diagram", or needs visual figures for papers.

wanshuiyin/Auto-claude-code-research-in-sleep · 67 tokens

paper-illustration-image2

Generate publication-quality academic illustrations through a local Codex app-server bridge that uses Codex native image generation. This is a separate experimental alternative to paper-illustration, intended for Claude Code users who want a GPT-image-style renderer without modifying the original skill.

wanshuiyin/Auto-claude-code-research-in-sleep · 59 tokens

experiment-plan

Turn a refined research proposal or method idea into a detailed, claim-driven experiment roadmap. Use after research-refine, or when the user asks for a detailed experiment plan, ablation matrix, evaluation protocol, run order, compute budget, or paper-ready validation that supports the core problem, novelty…

wanshuiyin/Auto-claude-code-research-in-sleep · 80 tokens

paper-writing

Workflow 3: Full paper writing pipeline that goes from a narrative report to a polished, submission-ready PDF. Use when user says "写论文全流程", "write paper pipeline", "从报告到PDF", "paper writing", or wants the complete paper generation workflow.

wanshuiyin/Auto-claude-code-research-in-sleep · 58 tokens