Cut a Bonfire release — beta or stable. An agent skill from AHouseOfBards/Bonfire-JellyProfiles.

MITAuto-check passedDevelopment

Install Release

skills CLI
$ npx skills add AHouseOfBards/Bonfire-JellyProfiles --skill release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AHouseOfBards/Bonfire-JellyProfiles release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AHouseOfBards/Bonfire-JellyProfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/release .claude/skills/release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release
GitHub stars
125
Token cost
~1.2k tokens
SKILL.md length
493 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Cut a Bonfire release — beta or stable. An agent skill from AHouseOfBards/Bonfire-JellyProfiles.

  • Works in 6 steps: Pick the channel → Bump both versions → Add the manifest entry — on the… → …
  • Publishing a version
  • SKILL.md covers Before anything, 1. Pick the channel, 2. Bump both versions and 3. Add the manifest entry — on…, plus 4 more sections
  • Calls git, curl and node

What it does

Release is an agent skill from AHouseOfBards/Bonfire-JellyProfiles. Cut a Bonfire release — beta or stable. Use whenever publishing a version, bumping InformationalVersion, adding a manifest entry, or tagging. Covers the channel routing that decides which manifest a build lands in, the three ways the workflow refuses a release, the rebase the bot's checksum commit forces, and the end-to-end verification that proves the bytes users install actually work.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: Bonfire is a Jellyfin plugin that adds profiles on a per user basis to Jellyfin. Built with AI Assistance. Designed to work with any Jellyfin client that is a web client or a… The licence is MIT.

When your agent uses it

  • Publishing a version
  • Bumping InformationalVersion
  • Adding a manifest entry

Example prompts

  • “/release”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Pick the channel
  2. Bump both versions
  3. Add the manifest entry — on the channel's branch
  4. Commit, push, tag
  5. The bot pushes back
  6. Verify what users actually get

What it can do on your machine

Read from SKILL.md and the folder at commit 0a2e8cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • curl
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release loads about 1.2k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 493 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from AHouseOfBards/Bonfire-JellyProfiles at commit 0a2e8cb, republished under its MIT licence (© AHouseOfBards). 493 words, ~1,224 tokens.

Download SKILL.mdSave it as .claude/skills/release/SKILL.md (or your agent's skills folder).
name
release
description
Cut a Bonfire release — beta or stable. Use whenever publishing a version, bumping InformationalVersion, adding a manifest entry, or tagging. Covers the channel routing that decides which manifest a build lands in, the three ways the workflow refuses a release, the rebase the bot's checksum commit forces, and the end-to-end verification that proves the bytes users install actually work.

Releasing Bonfire

Every step here exists because skipping it broke something. Two releases shipped with a placeholder checksum and could not be installed; one version was published to both manifests and offered users a blind choice between a working entry and a broken one; and 1.5.2 shipped a client script that never ran, past a syntax check that passed.

Before anything

tests/run.sh          # 34 harnesses, ~1,450 assertions. Not optional.

node --check Web/profiles.js is necessary and not sufficient — it passed against the defect that made 1.5.2 and 1.5.3 dead on arrival.

1. Pick the channel

<InformationalVersion> in Jellyfin.Profiles.csproj is the only place a pre-release label can live, because Jellyfin requires a purely numeric assembly version. It alone decides everything downstream:

InformationalVersionManifestBranchGitHub release
1.6.0-beta (also -alpha, -rc)beta manifestbetaprerelease
1.6.0stable manifestmainlatest

The stable manifest is a curated list of milestones that every install polls. A beta pushed there is offered to everyone as an upgrade.

2. Bump both versions

xml
<Version>1.6.0</Version>                          <!-- numeric only -->
<InformationalVersion>1.6.0-beta</InformationalVersion>

3. Add the manifest entry — on the channel's branch

The workflow fails if the entry is missing. It does not create one.

json
{
  "version": "1.6.0.0",                    // four parts
  "changelog": "…",
  "targetAbi": "10.11.0.0",
  "sourceUrl": ".../releases/download/v1.6.0/Jellyfin.Profiles.zip",
  "checksum": "0",                         // placeholder; the workflow stamps it
  "timestamp": "2026-08-27T00:00:00Z"
}

A version lives in exactly one manifest. Both files declare the same plugin GUID, so Jellyfin merges them for anyone subscribed to both. A version in both keeps its placeholder checksum in one copy and offers an install that fails the checksum. The workflow checks this and refuses.

Release-note format, which Jellyfin renders as Markdown in the update dialog and the workflow reuses as the GitHub release body:

**Beta release** — please report issues on GitHub.

**Fixed**

- The symptom, in the user's words, one line. (#23)

**Changed**

- One line.

Bold section headers, blank line after each header or the list will not render, the symptom rather than the mechanism, issue number in brackets. Reasoning goes in the commit message. If a release changes nothing a user can see, say so in one line rather than dressing up internals.

Show full SKILL.md (197 more words)Show less

4. Commit, push, tag

git add -A && git commit          # separate "release: X manifest entry" commit
git push origin beta
git tag -a v1.6.0 -m "…"          # MUST equal <Version> exactly
git push origin v1.6.0

The workflow cross-checks the tag against <Version> and refuses a mismatch, because the tag drives the release URL while the csproj version drives which manifest entry gets the checksum — if they drift it stamps the wrong entry.

5. The bot pushes back

The workflow commits ci: update manifest checksum for vX [skip ci] to the channel branch. Your next push will be rejected as non-fast-forward.

git fetch origin && git rebase origin/beta

Do this before any further work. It has caught me out on consecutive releases.

6. Verify what users actually get

Do not trust the workflow's own green tick. Check the bytes:

bash
curl -sL -o rel.zip ".../releases/download/v1.6.0/Jellyfin.Profiles.zip"
md5sum rel.zip                                    # must equal the live manifest checksum
curl -s ".../beta/manifest.json" | head           # the live feed, not your local file

Then confirm the shipped script actually runs — extract profiles.js from the downloaded DLL by reflection and run the startup test against it:

node tests/js/inject.test.js <extracted-profiles.js>

This is the step that would have caught 1.5.2. The DLL also reports its own version: check AssemblyInformationalVersionAttribute reads what you intended.

Cutting stable from beta

See [[bonfire-release-process]] in memory for the exact merge sequence — it was confirmed by doing 1.5.0 and has traps that are not obvious. The short version: the stable manifest on main is curated, so promoting a beta means adding a new milestone entry there, not copying the beta entry across.

© AHouseOfBards, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/release of AHouseOfBards/Bonfire-JellyProfiles.

Open the folder on GitHubat commit 0a2e8cb

Compare with similar skills

Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release this skillAHouseOfBards/Bonfire-JellyProfiles125—~1.2kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

Categories

Questions about Release

What does Release do?

Cut a Bonfire release — beta or stable. An agent skill from AHouseOfBards/Bonfire-JellyProfiles. Release is an agent skill from AHouseOfBards/Bonfire-JellyProfiles. Cut a Bonfire release — beta or stable.

When should I use Release?

Release fits situations like: publishing a version; bumping InformationalVersion; adding a manifest entry.

How do I install Release in Claude Code?

Run `npx skills add AHouseOfBards/Bonfire-JellyProfiles --skill release -a claude-code`. Or copy the skill folder (.claude/skills/release in AHouseOfBards/Bonfire-JellyProfiles) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.

How do I install Release in Codex?

Run `npx skills add AHouseOfBards/Bonfire-JellyProfiles --skill release -a codex`. Or copy the skill folder (.claude/skills/release in AHouseOfBards/Bonfire-JellyProfiles) into .agents/skills/release in your project. Codex loads it when a task matches its description.

Can I use Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AHouseOfBards/Bonfire-JellyProfiles --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.

What does Release need to run?

Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (git, curl and node).

Does Release access the network?

SKILL.md contains no URLs. Its commands use git and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release use?

Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release?

Skills that share tags, products or a category with Release: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release?

AHouseOfBards (a GitHub user) maintains it in AHouseOfBards/Bonfire-JellyProfiles, which has 125 GitHub stars. The repository was last updated on October 3, 2026.

Source: AHouseOfBards/Bonfire-JellyProfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.