Juicebox Upgrade MigrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Install
Commands as the repository documents them. They are shown, not run.
npm install @juicebox/[email protected]
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: juicebox-upgrade-migration description: 'Plan Juicebox SDK upgrades. Trigger: "upgrade juicebox", "juicebox migration". ' allowed-tools: Read, Write, Edit, Bash(npm:*) version: 1.16.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - recruiting - juicebox compatibility: Designed for Claude Code --- # Juicebox Upgrade & Migration ## Overview Juicebox is an AI-powered people search and analysis platform used for recruiting and market research. The API provides endpoints for dataset management, people searches, and AI-generated analyses. Tracking API versions is essential because Juicebox evolves its search query syntax, dataset schema, and analysis output format — upgrading without testing can break saved search filters, corrupt dataset imports, and change the structure of AI-generated candidate profiles that downstream systems consume. ## Version Detection ```typescript const JUICEBOX_BASE = "https://api.juicebox.work/v1"; async function detectJuiceboxVersion(apiKey: string): Promise<void> { const res = await fetch(`${JUICEBOX_BASE}/datasets`, { headers: { Authorization: `Bearer ${apiKey}`, "Content-Type": "application/json" }, }); const version = res.headers.get("x-juicebox-api-version") ?? "v1"; console.log(`Juicebox API version: ${version}`); // Check for deprecated search parameters const searchRes = await fetch(`${JUICEBOX_BASE}/search`, { method: "POST", headers: { Authorization: `Bearer ${apiKey}`, "Content-Type": "application/json" }, body: JSON.stringify({ query: "test", limit: 1 }), }); const deprecation = searchRes.headers.get("x-deprecated-params"); if (deprecation) console.warn(`Deprecated search params: ${deprecation}`); } ``` ## Migration Checklist - [ ] Review Juicebox changelog for API breaking changes - [ ] Audit codebase for hardcoded dataset field names - [ ] Verify search query syntax — filter operators may have changed - [ ] Check analysis output format for new or renamed fields - [ ] Update dataset import schema if column mapping changed - [ ] Test people search result structure (profile fields, enrichment data) - [ ] Validate pagination — cursor-based vs. offset may have changed - [ ] Update SDK version in `package.json` and verify type compatibility - [ ] Check webhook payloads for analysis completion events - [ ] Run integration tests with sample dataset to verify search quality ## Schema Migration ```typescript // Juicebox search results evolved: flat profile → enriched profile with sources interface OldSearchResult { id: string; name: string; title: string; company: string; email?: string; linkedin_url?: string; } interface NewSearchResult { id: string; profile: { full_name: string; current_title: string; current_company: { name: string; domain: string }; emails: Array<{ address: string; type: "work" | "personal"; verified: boolean }>; social: { linkedin?: string; twitter?: string }; }; match_score: number; enrichment_sources: string[]; } function migrateSearchResult(old: OldSearchResult): NewSearchResult { return { id: old.id, profile: { full_name: old.name, current_title: old.title, current_company: { name: old.company, domain: "" }, emails: old.email ? [{ address: old.email, type: "work", verified: false }] : [], social: { linkedin: old.linkedin_url }, }, match_score: 0, enrichment_sources: [], }; } ``` ## Rollback Strategy ```typescript class JuiceboxClient { private currentVersion: "v1" | "v2"; constructor(private apiKey: string, version: "v1" | "v2" = "v2") { this.currentVersion = version; } async search(query: string, filters?: Record<string, any>): Promise<any> { try { const res = await fetch(`https://api.juicebox.work/${this.currentVersion}/search`, { method: "POST", headers: { Authorization: `Bearer ${this.apiKey}`, "Content-Type": "application/json" }, body: JSON.stringify({ query, filters }), }); if (!res.ok) throw new Error(`Juicebox search ${res.status}`); return await res.json(); } catch (err) { if (this.currentVersion === "v2") { console.warn("Falling back to Juicebox API v1"); this.currentVersion = "v1"; return this.search(query, filters); } throw err; } } } ``` ## Error Handling | Migration Issue | Symptom | Fix | |----------------|---------|-----| | Search filter syntax changed | `400 Bad Request` with `invalid filter operator` | Update filter syntax to new query DSL format | | Dataset schema mismatch | Import succeeds but columns mapped incorrectly | Re-map dataset columns using `/datasets/schema` endpoint | | Profile field restructured | Code crashes accessing `result.name` (now `result.profile.full_name`) | Update all property access paths to new nested structure | | Analysis format changed | AI analysis output missing expected sections | Update parser for new structured analysis response | | Rate limit reduced | `429 Too Many Requests` on previously working batch sizes | Reduce batch size and implement request queuing | ## Prerequisites - An approved change record, version inventory, synthetic sandbox dataset, source/destination allowlists, suppression controls, compatibility test plan, and tested rollback release. ## Instructions 1. Back up configuration metadata without copying records, then run the migration against synthetic fixtures in staging. 2. Validate schema, authorization, redaction, suppression, retention, and `contacts_exported=0`; reject unapproved sources or destinations. 3. Promote through a bounded canary only after owner approval; halt on drift and restore the prior version/configuration immediately. 4. Retain only a redacted migration receipt and delete staged fixtures and temporary access at completion. ## Output Produce a migration receipt with versions, environment, fixture classification, compatibility re
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__juicebox-upgrade-migration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Juicebox Upgrade Migration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Juicebox Upgrade Migration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Juicebox Upgrade Migration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Juicebox Upgrade Migration work with?
Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.