Agent skill

Versioning Policy

by bradygaster in bradygaster/squad

SemVer rules for Squad's stable, preview, insider, and local package versions

MITAuto-check passed

Install Versioning Policy

skills CLI
$ npx skills add bradygaster/squad --skill versioning-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bradygaster/squad versioning-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bradygaster/squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.squad-templates/skills/versioning-policy .claude/skills/versioning-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
versioning-policy
GitHub stars
3.3k
Token cost
~1.2k tokens
SKILL.md length
548 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

SemVer rules for Squad's stable, preview, insider, and local package versions

  • Works in 7 steps: Supported versions → Package versions stay in lockstep → Prerelease workspace dependency rule → …
  • SKILL.md covers Context, 1. Supported versions, 2. Package versions stay in… and 3. Prerelease workspace…, plus 5 more sections
  • Calls npm

What it does

Versioning Policy is an agent skill from bradygaster/squad. SemVer rules for Squad's stable, preview, insider, and local package versions

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm. The repository describes itself as: Squad: AI agent teams for any project. The licence is MIT.

Example prompts

  • “/versioning-policy”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Supported versions
  2. Package versions stay in lockstep
  3. Prerelease workspace dependency rule
  4. Local build versions are ephemeral
  5. Release lifecycle
  6. Ownership
  7. CI enforcement

What it can do on your machine

Read from SKILL.md and the folder at commit 1fd7e03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Versioning Policy loads about 1.2k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 548 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bradygaster/squad at commit 1fd7e03, republished under its MIT licence (© bradygaster). 548 words, ~1,196 tokens.

Download SKILL.mdSave it as .claude/skills/versioning-policy/SKILL.md (or your agent's skills folder).
name
versioning-policy
description
SemVer rules for Squad's stable, preview, insider, and local package versions
domain
release, versioning, npm, CI
confidence
high
source
earned (PR #640 workspace resolution incident and automated release channels)

Context

Squad publishes @bradygaster/squad-sdk and @bradygaster/squad-cli from one npm workspace. Their versions and the root version move together. A mismatched prerelease dependency can make npm silently resolve an older registry SDK instead of the local workspace.

1. Supported versions

UseVersionCommitted branch
Stable releaseMAJOR.MINOR.PATCHmain, and briefly dev during promotion
Preview releaseMAJOR.MINOR.PATCH-preview.Ndev
Insider snapshotMAJOR.MINOR.PATCH-insider.NGenerated by the insider workflow
Local buildMAJOR.MINOR.PATCH-build.NNever committed

preview is a release channel, not a branch. Stable promotion merges a sanitized release tree directly from dev to main.

2. Package versions stay in lockstep

These versions must always be identical:

  • package.json
  • packages/squad-sdk/package.json
  • packages/squad-cli/package.json
  • the corresponding workspace entries in package-lock.json

Use the workspace-aware version command:

bash
npm version "$VERSION" --workspaces --include-workspace-root --no-git-tag-version

Never edit only one package version.

3. Prerelease workspace dependency rule

The CLI depends on the SDK through a SemVer range. SemVer deliberately excludes prereleases unless the comparator names a prerelease with the same base version. For example, >=0.13.0 does not match 0.14.0-preview.1.

For every committed preview version, set both the CLI manifest and lockfile dependency floor to that exact preview:

bash
npm pkg set "dependencies.@bradygaster/squad-sdk=>=$VERSION" \
  --workspace @bradygaster/squad-cli
npm install --package-lock-only

For VERSION=0.14.0-preview.1, the required range is >=0.14.0-preview.1. Before stable promotion, change the version and floor to 0.14.0 / >=0.14.0; never leave a prerelease floor in a stable release.

This rule prevents the PR #640 failure mode, where the build succeeded against a stale published SDK rather than the workspace SDK.

4. Local build versions are ephemeral

scripts/bump-build.mjs may create -build.N versions for local development.

  • Never commit a -build.N version.
  • The script skips itself when CI=true or SKIP_BUILD_BUMP=1.
  • If a build changes manifests locally, restore the intended release source versions before committing.

5. Release lifecycle

  1. On a release-preparation branch from dev, set the next X.Y.Z-preview.N version and matching SDK dependency floor.
  2. Merge to dev, wait for CI, and dispatch squad-release.yml from dev.
  3. Repeat with a new immutable preview version when another candidate is needed.
  4. Dispatch squad-insider-publish.yml whenever an on-demand development snapshot is needed; it computes the next immutable X.Y.Z-insider.N.
  5. Prepare stable X.Y.Z and its stable SDK dependency floor on dev.
  6. Dispatch squad-promote.yml; it sanitizes dev, pushes main, and explicitly dispatches the stable release.
  7. Open the next preview-version PR for continued development.

A preview such as 0.14.0-preview.1 is never renamed or converted in place. Stable 0.14.0 is a separate immutable package version and GitHub tag.

Show full SKILL.md (163 more words)Show less

6. Ownership

The current Release Manager owns release version changes. Other agents may update versions only when explicitly assigned release work or when reverting an accidentally committed local -build.N version.

7. CI enforcement

CI verifies:

  • root, SDK, and CLI versions match;
  • package-lock workspace versions match;
  • committed prereleases use approved preview or insider identifiers;
  • a preview CLI dependency and lockfile entry equal >=VERSION;
  • stable source does not retain a prerelease dependency floor; and
  • workspace packages resolve through local links rather than stale registry packages.

Release workflows repeat the dependency checks before creating a tag or publishing.

Quick reference

RuleSummary
InsiderThe workflow generates X.Y.Z-insider.N from the stable base version
PreviewCommit X.Y.Z-preview.N to dev for an on-demand prerelease
StableOnly X.Y.Z may release from main
SyncRoot, SDK, CLI, and lockfile workspace versions must match
DependencyPreview CLI range and lockfile entry must be >=VERSION
Local build-build.N is local-only and never committed
OwnershipThe current Release Manager owns planned release version changes

© bradygaster, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .squad-templates/skills/versioning-policy of bradygaster/squad.

Open the folder on GitHubat commit 1fd7e03

Compare with similar skills

Versioning Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Versioning Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Versioning Policy this skillbradygaster/squad3.3k—~1.2kAutomated safety check: PassMIT
Defuddlekepano/obsidian-skills49k12 repos~208Automated safety check: PassMIT
Vercel Deploybytedance/deer-flow83k10 repos~797Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k1 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 12 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    83k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 8 repos~613 tokens
    DevelopmentAuto-check passed

More from bradygaster/squad

All 31 skills in this repo
  • Fact Checking

    bradygaster/squad

    Review and validate claims using counter-hypothesis testing.

    3.3k GitHub stars~503 tokensUpdated today
    Auto-check passed
  • Architectural Review

    bradygaster/squad

    How to review PRs for architectural quality — module boundaries, dependency direction, export surface, pattern consistency

    3.3k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Archival Integrity

    bradygaster/squad

    Preserve content when moving entries between tracked Squad state files

    3.3k GitHub stars~735 tokensUpdated today
    Auto-check passed
  • CI Validation Gates

    bradygaster/squad

    Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

    3.3k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • CLI Wiring

    bradygaster/squad

    Checklist and patterns for wiring new CLI commands into cli-entry.ts

    3.3k GitHub stars~501 tokensUpdated today
    Auto-check passed
  • Enables squad agents on different machines to share work via git-based task queuing

    3.3k GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Questions about Versioning Policy

What does Versioning Policy do?

SemVer rules for Squad's stable, preview, insider, and local package versions. Versioning Policy is an agent skill from bradygaster/squad.

How do I install Versioning Policy in Claude Code?

Run `npx skills add bradygaster/squad --skill versioning-policy -a claude-code`. Or copy the skill folder (.squad-templates/skills/versioning-policy in bradygaster/squad) into .claude/skills/versioning-policy in your project. Claude Code loads it when a task matches its description.

How do I install Versioning Policy in Codex?

Run `npx skills add bradygaster/squad --skill versioning-policy -a codex`. Or copy the skill folder (.squad-templates/skills/versioning-policy in bradygaster/squad) into .agents/skills/versioning-policy in your project. Codex loads it when a task matches its description.

Can I use Versioning Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bradygaster/squad --skill versioning-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/versioning-policy, .gemini/skills/versioning-policy, .github/skills/versioning-policy and .opencode/skills/versioning-policy in your project.

What does Versioning Policy need to run?

Going by SKILL.md and its folder, Versioning Policy needs the command-line tools its instructions call (npm). Our summary lists: Node.js.

Does Versioning Policy access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Versioning Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Versioning Policy use?

Versioning Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Versioning Policy use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Versioning Policy?

Skills that share tags, products or a category with Versioning Policy: Defuddle (kepano/obsidian-skills, 49k stars), Vercel Deploy (bytedance/deer-flow, 83k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars) and Knap Markdown Templates (kepano/obsidian-skills, 49k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Versioning Policy?

bradygaster (a GitHub user) maintains it in bradygaster/squad, which has 3,257 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.

Source: bradygaster/squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.