Upgrade "@multiverse-io/stardust-react" and/or "@multiverse-io/stardust" in any consumer repo — auto-detects repo structure, runs safe upgrade workflow with visual validation and regression handling. Supports single-repo and fleet (multi-repo wave) modes.
62
78%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The skill's Inputs explicitly instruct the agent to "check latest on GitHub/npm" for target_version (SKILL.md Inputs section), which requires fetching public third‑party package metadata/changelogs that the agent must read and that can materially influence upgrade decisions.