Apollo Upgrade MigrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: apollo-upgrade-migration description: 'Manage Apollo.io API upgrades and endpoint migrations. Use when upgrading Apollo API versions, migrating to new endpoints, or updating deprecated API usage. Trigger with phrases like "apollo upgrade", "apollo migration", "update apollo api", "apollo breaking changes", "apollo deprecation". ' allowed-tools: Read, Grep, Bash(curl:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - apollo - api - migration compatibility: Designed for Claude Code --- # Apollo Upgrade Migration ## Current State !`npm list axios 2>/dev/null | head -5` ## Overview Plan and execute safe upgrades for Apollo.io API integrations. Apollo has made several breaking changes historically (query param auth to header auth, endpoint URL changes, new search endpoints). This covers auditing current usage, building compatibility layers, and migrating safely. ## Prerequisites - Valid Apollo API key - Node.js 18+ ## Instructions ### Step 1: Audit Current API Usage ```typescript // src/scripts/api-audit.ts import { execSync } from 'child_process'; interface EndpointUsage { endpoint: string; files: string[]; status: 'current' | 'deprecated'; } const ENDPOINT_MAP = [ // Current endpoints { pattern: '/mixed_people/api_search', status: 'current' as const }, { pattern: '/mixed_companies/search', status: 'current' as const }, { pattern: '/people/match', status: 'current' as const }, { pattern: '/people/bulk_match', status: 'current' as const }, { pattern: '/organizations/enrich', status: 'current' as const }, { pattern: '/contacts/search', status: 'current' as const }, { pattern: '/emailer_campaigns', status: 'current' as const }, { pattern: '/email_accounts', status: 'current' as const }, { pattern: '/opportunities', status: 'current' as const }, // Deprecated patterns { pattern: '/people/search', status: 'deprecated' as const }, // old search endpoint { pattern: '/organizations/search', status: 'deprecated' as const }, { pattern: 'api_key.*=', status: 'deprecated' as const }, // query param auth { pattern: 'api.apollo.io/v1', status: 'deprecated' as const }, // old base URL (should be /api/v1) ]; function auditUsage(srcDir: string = 'src'): EndpointUsage[] { const results: EndpointUsage[] = []; for (const ep of ENDPOINT_MAP) { try { const files = execSync( `grep -rl "${ep.pattern}" ${srcDir} --include="*.ts" --include="*.js" 2>/dev/null`, { encoding: 'utf-8' }, ).trim().split('\n').filter(Boolean); if (files.length > 0) results.push({ endpoint: ep.pattern, files, status: ep.status }); } catch { /* no matches */ } } console.log('=== Apollo API Usage Audit ==='); for (const r of results) { const icon = r.status === 'deprecated' ? 'WARN' : 'OK'; console.log(`${icon} ${r.endpoint} (${r.files.length} files)`); r.files.forEach((f) => console.log(` ${f}`)); } const deprecated = results.filter((r) => r.status === 'deprecated'); if (deprecated.length > 0) { console.log(`\n${deprecated.length} deprecated pattern(s) found — migration needed`); } return results; } ``` ### Step 2: Migration Map — Old to New ```typescript // src/migration/apollo-migration-map.ts interface MigrationRule { description: string; find: string | RegExp; replace: string; breaking: boolean; } const MIGRATION_RULES: MigrationRule[] = [ // Auth: query param -> header { description: 'Move API key from query param to x-api-key header', find: /params:\s*\{[^}]*api_key[^}]*\}/g, replace: "headers: { 'x-api-key': process.env.APOLLO_API_KEY! }", breaking: true, }, // Base URL { description: 'Update base URL from /v1 to /api/v1', find: 'api.apollo.io/v1', replace: 'api.apollo.io/api/v1', breaking: true, }, // People Search endpoint { description: 'Migrate people search to new endpoint', find: '/people/search', replace: '/mixed_people/api_search', breaking: true, }, // People Search parameters { description: 'Rename q_organization_domains to q_organization_domains_list', find: 'q_organization_domains:', replace: 'q_organization_domains_list:', breaking: false, }, // Organization Search endpoint { description: 'Migrate org search to new endpoint', find: '/organizations/search', replace: '/mixed_companies/search', breaking: true, }, ]; ``` ### Step 3: Build a Feature-Flagged Migration ```typescript // src/migration/feature-flags.ts const flags = { useNewSearchEndpoint: process.env.FF_NEW_SEARCH === 'true', }; export function getSearchEndpoint(): string { return flags.useNewSearchEndpoint ? '/mixed_people/api_search' : '/people/search'; } export function getBaseUrl(): string { return 'https://api.apollo.io/api/v1'; } export function getAuthConfig(): Record<string, any> { // Header authentication is mandatory in every migration state. return { headers: { 'x-api-key': process.env.APOLLO_API_KEY! } }; } ``` ### Step 4: Run Parallel Comparison ```typescript function compareRecordedResponses(oldFixture: { people?: unknown[] }, newFixture: { people?: unknown[] }) { const oldCount = oldFixture.people?.length ?? 0; const newCount = newFixture.people?.length ?? 0; return { oldCount, newCount, countsMatch: oldCount === newCount }; } ``` Capture the fixture once from an authorized staging request, redact contact data, and run the comparison offline. Do not keep a production key or a query-string authentication path alive merely to compare a deprecated endpoint. ### Step 5: Post-Migration Cleanup ```bash # Find remaining deprecated patterns grep -rn "api.apollo.io/v1[^/]" src/ --include="*.ts" || echo "No old base URL found" grep -rn "api_key.*=" src/ --include="*.ts" | grep -v "x-api-key" || echo "No query param auth found" grep -rn "/people/search" src/ --include="*.ts" | grep -v "mixed_people" || echo "No old sea
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__apollo-upgrade-migration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Apollo Upgrade Migration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Apollo Upgrade Migration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Apollo Upgrade Migration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Apollo Upgrade Migration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.