Agent skill

Release Process

by bradygaster in bradygaster/squad

Operate Squad's automated insider, preview, and stable release channels safely

MITAuto-check passedDevOps & Cloud

Install Release Process

skills CLI
$ npx skills add bradygaster/squad --skill release-process -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bradygaster/squad release-process --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bradygaster/squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.copilot/skills/release-process .claude/skills/release-process && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-process
GitHub stars
3.3k
Token cost
~1.5k tokens
SKILL.md length
616 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Operate Squad's automated insider, preview, and stable release channels safely

  • Tasks that involve Deployment
  • SKILL.md covers Preconditions, Preview, Insider and Stable, plus 2 more sections
  • Calls gh, npm and git; needs NPM_TOKEN and HOMEBREW_TAP_TOKEN

What it does

Release Process is an agent skill from bradygaster/squad. Operate Squad's automated insider, preview, and stable release channels safely

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. It works with npm, GitHub and Homebrew. The repository describes itself as: Squad: AI agent teams for any project. The licence is MIT.

When your agent uses it

  • Tasks that involve Deployment

Example prompts

  • “/release-process”

Requirements

  • Node.js
  • A credential in NPM_TOKEN
  • A credential in HOMEBREW_TAP_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit d2364df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • git
    • node
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm, git and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN
    • HOMEBREW_TAP_TOKEN
    • WINGET_CREATE_GITHUB_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Process loads about 1.5k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 616 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bradygaster/squad at commit d2364df, republished under its MIT licence (© bradygaster). 616 words, ~1,495 tokens.

Download SKILL.mdSave it as .claude/skills/release-process/SKILL.md (or your agent's skills folder).
name
release-process
description
Operate Squad's automated insider, preview, and stable release channels safely
domain
release-management
confidence
high
source
team-decision

Squad Release Process

Read .squad/skills/release-process/SKILL.md for the canonical runbook and recovery commands. The operational model is:

ReleaseTriggerRequired versionResult
InsiderManual squad-insider-publish.yml dispatch from devGenerated X.Y.Z-insider.NGitHub prerelease, npm insider, standalone archives, Homebrew, WinGet
PreviewManual squad-release.yml dispatch from devX.Y.Z-preview.NGitHub prerelease, npm preview, standalone archives, Homebrew, WinGet
StableManual squad-promote.yml dispatch from devX.Y.ZSanitized main push, GitHub stable release, npm latest, standalone archives, Homebrew, WinGet

There is no staging preview branch. Do not create tags or GitHub Releases manually.

Human release-trigger boundary: use the canonical runbook for exact commands. Agents may prepare, validate, and present commands, but agents must never execute or dispatch any live publication, promotion, or recovery workflow: squad-release.yml, squad-agents-ai-release.yml, squad-insider-publish.yml, squad-promote.yml with dry_run=false, squad-version-promote.yml, squad-npm-publish.yml, or squad-standalone-release.yml. Treat squad-promote.yml --ref dev -f dry_run=true as human-only too: it has actions: write and contents: write, checks out dev with the workflow token, installs dependencies, and runs build and test steps. Do not describe any GitHub Actions release workflow as agent-safe once it has write-capable credentials or a dispatch path. Only a human executes those triggers; human approval alone does not authorize an agent to fire them.

Preconditions

Before either channel:

bash
git fetch origin dev main
git merge-base origin/dev origin/main
grep '"version"' package.json packages/squad-sdk/package.json packages/squad-cli/package.json
node -p "require('./packages/squad-cli/package.json').dependencies['@bradygaster/squad-sdk']"
grep -F "## [$VERSION]" CHANGELOG.md
SKIP_BUILD_BUMP=1 npm run build
npx vitest run

The validation build must not mutate package versions or the lockfile; check git diff -- package.json packages/squad-sdk/package.json packages/squad-cli/package.json package-lock.json afterward and stop if any version-only change appears.

The ancestry command must return a commit, all three versions must match, the CLI SDK dependency floor must be >=VERSION, and the changelog must contain the exact release version.

Required Actions secrets:

  • NPM_TOKEN: automation-capable npm publish token.
  • HOMEBREW_TAP_TOKEN: classic PAT with public_repo from a collaborator with write access to bradygaster/homebrew-squad.
  • WINGET_CREATE_GITHUB_TOKEN: classic PAT with public_repo for tamirdresher/winget-pkgs.

Preview

After a PR sets an immutable prerelease version on dev and CI passes:

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
VERSION=0.14.0-preview.1
gh workflow run squad-release.yml --ref dev -f confirm_tag="v$VERSION"
gh run watch

The release workflow rejects stable versions on manual dispatch, creates a GitHub prerelease, publishes npm preview, and uploads standalone bundles. It also updates the squad-preview Homebrew cask and bradygaster.Squad.Preview WinGet package. The activation pin and insider-tag promotion remain stable-only.

Show full SKILL.md (260 more words)Show less

Insider

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
gh workflow run squad-insider-publish.yml --ref dev -f dry_run=false
gh run watch

The workflow computes the next X.Y.Z-insider.N version, publishes npm insider, creates the GitHub prerelease and standalone archives, updates squad-insider in Homebrew, and opens or reuses the bradygaster.Squad.Insider WinGet PR.

Stable

After a PR replaces the preview version with X.Y.Z on dev and CI passes:

Human-only validation dispatch: this workflow still checks out dev with repo/workflow credentials and runs build and test logic. Agents must stop and hand off; only a human should fire it.

bash
gh workflow run squad-promote.yml --ref dev -f dry_run=true
gh run watch

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
gh workflow run squad-promote.yml --ref dev -f dry_run=false
gh run watch

Promotion merges dev directly into main, strips internal team state, validates the release tree, builds it, runs tests, and pushes main. It then explicitly dispatches squad-release.yml because GITHUB_TOKEN pushes do not start another workflow. The release creates the tag and stable GitHub Release and directly invokes npm and standalone publication.

Verify

bash
npm view @bradygaster/squad-sdk dist-tags.preview
npm view @bradygaster/squad-cli dist-tags.preview
npm view @bradygaster/squad-sdk dist-tags.latest
npm view @bradygaster/squad-cli dist-tags.latest
gh release view "v$VERSION"

Use the tag for the channel being released. Verify the GitHub Release contains all six OS/architecture archives and SHA256SUMS.txt. Every release must update its channel-specific Homebrew cask and create or reuse a WinGet PR.

Recovery

Do not recreate or overwrite the tag. Rerun a failed child job, or dispatch the reusable npm/standalone workflow with source_ref=v$VERSION. Use --ref dev for previews and --ref main for stable releases. The canonical runbook contains the exact commands.

After a stable release, prepare the next X.Y.Z-preview.1 version in a normal PR to dev.

© bradygaster, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .copilot/skills/release-process of bradygaster/squad.

Open the folder on GitHubat commit d2364df

Compare with similar skills

Release Process next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Process compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Process this skillbradygaster/squad3.3k—~1.5kAutomated safety check: PassMIT
ClickUp CLI Release Processkrodak/clickup-cli120—~906Automated safety check: WarnMIT
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0
Release Flowromankurnovskii/BrewMate301—~976Automated safety check: PassMIT
Release Allpaperboytm/spool592—~1.1kAutomated safety check: PassCustom licence
Mecatl Release Cuttingstacklok/mecatl218—~4kAutomated safety check: PassApache-2.0

Similar skills

  • ClickUp CLI Release Process

    krodak/clickup-cli

    Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.

    120 GitHub stars~906 tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated 13 days ago
    DevOps & CloudAuto-check passed
  • Release Flow

    romankurnovskii/BrewMate

    Automate the full application release flow for BrewMate, including committing local changes, bumping version, waiting for GitHub Actions release build, and pushing the in-repo cask update…

    301 GitHub stars~976 tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed
  • Release All

    paperboytm/spool

    Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.

    592 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Mecatl Release Cutting

    stacklok/mecatl

    Cuts a tagged mecatl release by dispatching the release-PR workflow, merging the bot's pull request and verifying the tag, images, Helm chart, signed archives and Homebrew formula.

    218 GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release

    paperclipai/paperclip

    Coordinate a full Paperclip release across engineering verification, npm, GitHub, smoke testing, and announcement follow-up.

    98k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check passed

More from bradygaster/squad

All 31 skills in this repo
  • Fact Checking

    bradygaster/squad

    Review and validate claims using counter-hypothesis testing.

    3.3k GitHub stars~503 tokensUpdated yesterday
    Auto-check passed
  • Architectural Review

    bradygaster/squad

    How to review PRs for architectural quality — module boundaries, dependency direction, export surface, pattern consistency

    3.3k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Archival Integrity

    bradygaster/squad

    Preserve content when moving entries between tracked Squad state files

    3.3k GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • CI Validation Gates

    bradygaster/squad

    Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

    3.3k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • CLI Wiring

    bradygaster/squad

    Checklist and patterns for wiring new CLI commands into cli-entry.ts

    3.3k GitHub stars~501 tokensUpdated yesterday
    Auto-check passed
  • Enables squad agents on different machines to share work via git-based task queuing

    3.3k GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Release Process

What does Release Process do?

Operate Squad's automated insider, preview, and stable release channels safely. Release Process is an agent skill from bradygaster/squad.

When should I use Release Process?

Release Process fits situations like: tasks that involve Deployment.

How do I install Release Process in Claude Code?

Run `npx skills add bradygaster/squad --skill release-process -a claude-code`. Or copy the skill folder (.copilot/skills/release-process in bradygaster/squad) into .claude/skills/release-process in your project. Claude Code loads it when a task matches its description.

How do I install Release Process in Codex?

Run `npx skills add bradygaster/squad --skill release-process -a codex`. Or copy the skill folder (.copilot/skills/release-process in bradygaster/squad) into .agents/skills/release-process in your project. Codex loads it when a task matches its description.

Can I use Release Process in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bradygaster/squad --skill release-process -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-process, .gemini/skills/release-process, .github/skills/release-process and .opencode/skills/release-process in your project.

What does Release Process need to run?

Going by SKILL.md and its folder, Release Process needs the command-line tools its instructions call (gh, npm, git, node and npx) and credentials named NPM_TOKEN, HOMEBREW_TAP_TOKEN, WINGET_CREATE_GITHUB_TOKEN and GITHUB_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN; A credential in HOMEBREW_TAP_TOKEN.

Does Release Process access the network?

SKILL.md contains no URLs. Its commands use gh, npm, git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release Process safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Process use?

Release Process is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Process use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Process?

Skills that share tags, products or a category with Release Process: ClickUp CLI Release Process (krodak/clickup-cli, 120 stars), Reflexo Release (Myriad-Dreamin/typst.ts, 1.2k stars), Release Flow (romankurnovskii/BrewMate, 301 stars) and Release All (paperboytm/spool, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Process?

bradygaster (a GitHub user) maintains it in bradygaster/squad, which has 3,256 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 6, 2026.

Source: bradygaster/squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.