Agent skill

Release Process

by bradygaster in bradygaster/squad

Prepare, publish, recover, and verify Squad insider, preview, and stable releases

MITAuto-check passedDevOps & Cloud

Install Release Process

skills CLI
$ npx skills add bradygaster/squad --skill release-process -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bradygaster/squad release-process --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bradygaster/squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.squad-templates/skills/release-process .claude/skills/release-process && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-process
GitHub stars
3.3k
Token cost
~2.4k tokens
SKILL.md length
973 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Prepare, publish, recover, and verify Squad insider, preview, and stable releases

  • Works in 7 steps: Never create release tags or GitHub… → Never reuse a version. A preview such as… → Keep the root, SDK, and CLI versions… → …
  • Tasks that involve Deployment
  • SKILL.md covers Non-negotiable rules, Required credentials, Human release-trigger boundary and Prepare a release, plus 6 more sections
  • Calls gh, npm and git; needs NPM_TOKEN and HOMEBREW_TAP_TOKEN

What it does

Release Process is an agent skill from bradygaster/squad. Prepare, publish, recover, and verify Squad insider, preview, and stable releases

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. It works with GitHub, Homebrew and npm. The repository describes itself as: Squad: AI agent teams for any project. The licence is MIT.

When your agent uses it

  • Tasks that involve Deployment

Example prompts

  • “/release-process”

Requirements

  • Node.js
  • A credential in NPM_TOKEN
  • A credential in HOMEBREW_TAP_TOKEN

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Never create release tags or GitHub Releases manually. squad-release.yml
  2. Never reuse a version. A preview such as 0.14.0-preview.1 and stable
  3. Keep the root, SDK, and CLI versions identical.
  4. Set the CLI's SDK dependency floor to >=VERSION; prerelease workspaces do
  5. Add an exact ## [VERSION] entry to CHANGELOG.md.
  6. Merge release preparation to dev and wait for CI before dispatching.
  7. Keep separate Homebrew casks and WinGet identifiers for each channel.

What it can do on your machine

Read from SKILL.md and the folder at commit d2364df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • git
    • node
    • npx
    • brew
    • winget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm, git and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN
    • HOMEBREW_TAP_TOKEN
    • WINGET_CREATE_GITHUB_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Process loads about 2.4k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 973 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bradygaster/squad at commit d2364df, republished under its MIT licence (© bradygaster). 973 words, ~2,401 tokens.

Download SKILL.mdSave it as .claude/skills/release-process/SKILL.md (or your agent's skills folder).
name
release-process
description
Prepare, publish, recover, and verify Squad insider, preview, and stable releases
domain
release
confidence
high
source
earned

Release Process

This is the canonical Squad release runbook. Squad has three release channels and two long-lived branches:

SourceVersionGitHubnpmStandaloneHomebrew/WinGet
Insider dispatch from devGenerated X.Y.Z-insider.NPrereleaseinsiderYesYes
Release dispatch from devX.Y.Z-preview.NPrereleasepreviewYesYes
Push to main by promotion workflowX.Y.ZStable/latestlatestYesYes

The repository does not use a staging preview branch. Preview is a release channel, not a branch.

Non-negotiable rules

  1. Never create release tags or GitHub Releases manually. squad-release.yml creates both.
  2. Never reuse a version. A preview such as 0.14.0-preview.1 and stable 0.14.0 are separate immutable releases.
  3. Keep the root, SDK, and CLI versions identical.
  4. Set the CLI's SDK dependency floor to >=VERSION; prerelease workspaces do not match an older stable range.
  5. Add an exact ## [VERSION] entry to CHANGELOG.md.
  6. Merge release preparation to dev and wait for CI before dispatching.
  7. Keep separate Homebrew casks and WinGet identifiers for each channel.

Required credentials

Configure these GitHub Actions secrets:

  • NPM_TOKEN: an automation-capable npm publish token that does not require an interactive OTP.
  • HOMEBREW_TAP_TOKEN: a classic GitHub PAT with public_repo, owned by an account that has write access to bradygaster/homebrew-squad.
  • WINGET_CREATE_GITHUB_TOKEN: a classic GitHub PAT with public_repo, owned by the account that maintains tamirdresher/winget-pkgs.

Human release-trigger boundary

Agents may prepare versions, run validation, and recommend exact commands, but agents must never execute or dispatch live publication, promotion, or recovery workflows. Only a human executes the real trigger for these live workflows: squad-release.yml, squad-agents-ai-release.yml, squad-insider-publish.yml, squad-promote.yml with dry_run=false, squad-version-promote.yml, squad-npm-publish.yml, or squad-standalone-release.yml. Treat squad-promote.yml --ref dev -f dry_run=true as human-only too: the workflow still has actions: write and contents: write, checks out dev with the workflow token, installs dependencies, and runs the release build and tests. Do not describe any GitHub Actions release workflow as agent-safe once it has write-capable credentials or a dispatch path. Stop with verified commands and evidence for a human to run; human approval alone does not authorize an agent to fire the trigger.

Prepare a release

Verify dev and main share ancestry before changing versions:

bash
git fetch origin dev main
git merge-base origin/dev origin/main

If that command returns no commit, stop and repair ancestry in a separate PR.

Choose a unique SemVer version and update all package manifests:

bash
VERSION=0.14.0-preview.1
npm version "$VERSION" --workspaces --include-workspace-root --no-git-tag-version
npm pkg set "dependencies.@bradygaster/squad-sdk=>=$VERSION" \
  --workspace @bradygaster/squad-cli
npm install --package-lock-only

This updates the root package, both workspaces, and the lockfile. Confirm:

bash
node -p "require('semver').valid('$VERSION')"
grep '"version"' package.json packages/squad-sdk/package.json packages/squad-cli/package.json
grep -F "## [$VERSION]" CHANGELOG.md
SKIP_BUILD_BUMP=1 npm run build
npx vitest run

The validation build must not mutate package versions or the lockfile; check git diff -- package.json packages/squad-sdk/package.json packages/squad-cli/package.json package-lock.json afterward and stop if any version-only change appears.

Release preparation lands through a normal PR to dev. Do not push directly to main.

Publish a preview release

Preview versions must contain a prerelease suffix, for example 0.14.0-preview.1.

After the release-preparation PR is merged and dev CI is green:

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
VERSION=0.14.0-preview.1
gh workflow run squad-release.yml \
  --ref dev \
  -f confirm_tag="v$VERSION"
gh run watch

The workflow:

  1. Requires the dispatch ref to be dev.
  2. Rejects a stable X.Y.Z version.
  3. Creates v$VERSION and a GitHub prerelease.
  4. Publishes both npm packages with --tag preview.
  5. Uploads six standalone archives and SHA256SUMS.txt.
  6. Updates the squad-preview Homebrew cask and bradygaster.Squad.Preview WinGet package.

Install the resulting preview:

bash
npm install -g @bradygaster/squad-cli@preview

The same preview is available through brew install --cask squad-preview and winget install --id bradygaster.Squad.Preview --exact.

Publish an insider release

Start an on-demand snapshot from dev:

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
gh workflow run squad-insider-publish.yml --ref dev -f dry_run=false
gh run watch

The workflow computes the next immutable X.Y.Z-insider.N version, publishes npm insider, creates a GitHub prerelease, uploads standalone bundles, updates the squad-insider Homebrew cask, and opens or reuses the bradygaster.Squad.Insider WinGet PR.

Show full SKILL.md (371 more words)Show less

Publish a stable release

Stable versions must be exactly X.Y.Z. Prepare and merge the stable version to dev, then human-only validate the sanitized merge without changing main:

bash
gh workflow run squad-promote.yml --ref dev -f dry_run=true
gh run watch

Do not treat this as an agent-safe command. It still checks out dev with workflow credentials and runs repository build/test logic. Only a human should fire it. Start the real promotion:

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
gh workflow run squad-promote.yml --ref dev -f dry_run=false
gh run watch

squad-promote.yml:

  1. Merges origin/dev directly into main.
  2. Removes .ai-team/, .squad/, .ai-team-templates/, team-docs/, and docs/proposals/ from the release tree.
  3. Rejects unresolved conflicts, prerelease versions, mismatched package versions, and missing changelog entries.
  4. Installs dependencies, builds, and runs release tests.
  5. Pushes main and explicitly dispatches squad-release.yml.

The explicit dispatch is required because GitHub suppresses push-triggered workflow runs for commits authenticated with GITHUB_TOKEN. The release workflow creates the stable tag and GitHub Release, publishes npm latest, uploads standalone archives, updates Homebrew, and opens or reuses the WinGet PR.

Verify publication

Use insider, preview, or latest for DIST_TAG:

bash
VERSION=0.14.0
DIST_TAG=latest

npm view @bradygaster/squad-sdk "dist-tags.$DIST_TAG"
npm view @bradygaster/squad-cli "dist-tags.$DIST_TAG"
gh release view "v$VERSION"

The npm values must equal VERSION. The GitHub Release must contain:

text
squad-linux-x64.tar.gz
squad-linux-arm64.tar.gz
squad-darwin-x64.tar.gz
squad-darwin-arm64.tar.gz
squad-win32-x64.zip
squad-win32-arm64.zip
SHA256SUMS.txt

For every release, also verify the channel's Homebrew cask (squad, squad-preview, or squad-insider) and WinGet identifier (bradygaster.Squad, .Preview, or .Insider) reference the new version.

Recovery

The top-level release workflow intentionally does not republish after its tag already exists. Rerun the failed child job, or dispatch the reusable workflow from the branch that owns that release channel while building from the immutable tag.

Stable recovery:

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
VERSION=0.14.0
gh workflow run squad-npm-publish.yml --ref main \
  -f version="$VERSION" -f source_ref="v$VERSION"
gh workflow run squad-standalone-release.yml --ref main \
  -f upload=true -f release_tag="v$VERSION" -f source_ref="v$VERSION"

Preview recovery:

Human-only reference command: this live publish workflow must be run by a human. Agents must stop, hand off, and not execute it directly.

bash
VERSION=0.14.0-preview.1
gh workflow run squad-npm-publish.yml --ref dev \
  -f version="$VERSION" -f source_ref="v$VERSION"
gh workflow run squad-standalone-release.yml --ref dev \
  -f upload=true -f release_tag="v$VERSION" -f source_ref="v$VERSION"

Publication is idempotent. Existing package versions and release assets are verified rather than overwritten. npm publication fails instead of silently moving latest or preview away from an existing version.

After a stable release

Prepare the next development version in a normal PR to dev:

bash
NEXT_VERSION=0.15.0-preview.1
npm version "$NEXT_VERSION" --workspaces --include-workspace-root --no-git-tag-version
npm pkg set "dependencies.@bradygaster/squad-sdk=>=$NEXT_VERSION" \
  --workspace @bradygaster/squad-cli
npm install --package-lock-only

Do not merge main back into dev; the promotion commit already has dev as its parent, while the stripped internal state intentionally remains only on dev.

© bradygaster, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .squad-templates/skills/release-process of bradygaster/squad.

Open the folder on GitHubat commit d2364df

Compare with similar skills

Release Process next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Process compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Process this skillbradygaster/squad3.3k—~2.4kAutomated safety check: PassMIT
ClickUp CLI Release Processkrodak/clickup-cli120—~906Automated safety check: WarnMIT
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0
Release Flowromankurnovskii/BrewMate301—~976Automated safety check: PassMIT
Release Allpaperboytm/spool592—~1.1kAutomated safety check: PassCustom licence
Mecatl Release Cuttingstacklok/mecatl218—~4kAutomated safety check: PassApache-2.0

Similar skills

  • ClickUp CLI Release Process

    krodak/clickup-cli

    Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.

    120 GitHub stars~906 tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated 13 days ago
    DevOps & CloudAuto-check passed
  • Release Flow

    romankurnovskii/BrewMate

    Automate the full application release flow for BrewMate, including committing local changes, bumping version, waiting for GitHub Actions release build, and pushing the in-repo cask update…

    301 GitHub stars~976 tokensUpdated 10 days ago
    DevOps & CloudAuto-check passed
  • Release All

    paperboytm/spool

    Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.

    592 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Mecatl Release Cutting

    stacklok/mecatl

    Cuts a tagged mecatl release by dispatching the release-PR workflow, merging the bot's pull request and verifying the tag, images, Helm chart, signed archives and Homebrew formula.

    218 GitHub stars~4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Release

    paperclipai/paperclip

    Coordinate a full Paperclip release across engineering verification, npm, GitHub, smoke testing, and announcement follow-up.

    98k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check passed

More from bradygaster/squad

All 31 skills in this repo
  • Fact Checking

    bradygaster/squad

    Review and validate claims using counter-hypothesis testing.

    3.3k GitHub stars~503 tokensUpdated yesterday
    Auto-check passed
  • Architectural Review

    bradygaster/squad

    How to review PRs for architectural quality — module boundaries, dependency direction, export surface, pattern consistency

    3.3k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Archival Integrity

    bradygaster/squad

    Preserve content when moving entries between tracked Squad state files

    3.3k GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • CI Validation Gates

    bradygaster/squad

    Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

    3.3k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • CLI Wiring

    bradygaster/squad

    Checklist and patterns for wiring new CLI commands into cli-entry.ts

    3.3k GitHub stars~501 tokensUpdated yesterday
    Auto-check passed
  • Enables squad agents on different machines to share work via git-based task queuing

    3.3k GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Release Process

What does Release Process do?

Prepare, publish, recover, and verify Squad insider, preview, and stable releases. Release Process is an agent skill from bradygaster/squad.

When should I use Release Process?

Release Process fits situations like: tasks that involve Deployment.

How do I install Release Process in Claude Code?

Run `npx skills add bradygaster/squad --skill release-process -a claude-code`. Or copy the skill folder (.squad-templates/skills/release-process in bradygaster/squad) into .claude/skills/release-process in your project. Claude Code loads it when a task matches its description.

How do I install Release Process in Codex?

Run `npx skills add bradygaster/squad --skill release-process -a codex`. Or copy the skill folder (.squad-templates/skills/release-process in bradygaster/squad) into .agents/skills/release-process in your project. Codex loads it when a task matches its description.

Can I use Release Process in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bradygaster/squad --skill release-process -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-process, .gemini/skills/release-process, .github/skills/release-process and .opencode/skills/release-process in your project.

What does Release Process need to run?

Going by SKILL.md and its folder, Release Process needs the command-line tools its instructions call (gh, npm, git, node, npx and brew) and credentials named NPM_TOKEN, HOMEBREW_TAP_TOKEN, WINGET_CREATE_GITHUB_TOKEN and GITHUB_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN; A credential in HOMEBREW_TAP_TOKEN.

Does Release Process access the network?

SKILL.md contains no URLs. Its commands use gh, npm, git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release Process safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Process use?

Release Process is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Process use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Process?

Skills that share tags, products or a category with Release Process: ClickUp CLI Release Process (krodak/clickup-cli, 120 stars), Reflexo Release (Myriad-Dreamin/typst.ts, 1.2k stars), Release Flow (romankurnovskii/BrewMate, 301 stars) and Release All (paperboytm/spool, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Process?

bradygaster (a GitHub user) maintains it in bradygaster/squad, which has 3,256 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 6, 2026.

Source: bradygaster/squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.