Agent skill

Meta PR Creation

by cipherstash in cipherstash/stack

How an agent authors branches, commits, and pull requests on cipherstash/stack — naming, signed commits, the changeset/skills/meta-file checklist, and PR body structure with dumbed-down wording.

MITAuto-check passedDevelopment

Install Meta PR Creation

skills CLI
$ npx skills add cipherstash/stack --skill meta-pr-creation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cipherstash/stack meta-pr-creation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cipherstash/stack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/meta-pr-creation .claude/skills/meta-pr-creation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
meta-pr-creation
GitHub stars
157
Token cost
~937 tokens
SKILL.md length
467 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

How an agent authors branches, commits, and pull requests on cipherstash/stack — naming, signed commits, the changeset/skills/meta-file checklist, and PR body structure with dumbed-down wording.

  • Works in 3 steps: Changeset — required when the change… → Skills check — a change to a public API,… → Meta files — adding/removing/renaming a…
  • Committing work
  • SKILL.md covers Branch and commits, Before opening the PR, PR body and Mechanics
  • Calls git, pnpm and gh

What it does

Meta PR Creation is an agent skill from cipherstash/stack. How an agent authors branches, commits, and pull requests on cipherstash/stack — naming, signed commits, the changeset/skills/meta-file checklist, and PR body structure with dumbed-down wording. Use when committing work or opening/updating a PR.

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. It works with Prisma, PostgreSQL and pnpm. The repository describes itself as: Searchable, application-level encryption for building privacy-first apps. The licence is MIT.

When your agent uses it

  • Committing work
  • Opening/updating a PR

Example prompts

  • “/meta-pr-creation”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Changeset — required when the change touches a published package's
  2. Skills check — a change to a public API, CLI surface, or user-facing
  3. Meta files — adding/removing/renaming a package, example, skill, or

What it can do on your machine

Read from SKILL.md and the folder at commit 3eb459b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • pnpm
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, pnpm and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Meta PR Creation loads about 937 tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 467 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~937

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cipherstash/stack at commit 3eb459b, republished under its MIT licence (© cipherstash). 467 words, ~937 tokens.

Download SKILL.mdSave it as .claude/skills/meta-pr-creation/SKILL.md (or your agent's skills folder).
name
meta-pr-creation
description
How an agent authors branches, commits, and pull requests on cipherstash/stack — naming, signed commits, the changeset/skills/meta-file checklist, and PR body structure with dumbed-down wording. Use when committing work or opening/updating a PR.

Authoring PRs as an agent

Internal skill — lives in .claude/skills/ on purpose. skills/ ships to customers inside the stash tarball; this must not.

Branch and commits

  • Branch names are type-prefixed slugs: docs/skill-psl-functional-indexes, fix/…, feat/…, chore/…. Never commit to main.

  • Commit subjects are conventional: type(scope): imperative summary — docs(skills): …, fix(stack-prisma): …. The body explains why and the mechanism, not a list of what changed (the diff shows that). Reference the GitHub issue the commit serves.

  • Commits must be signed. commit.gpgsign is on, but verify before pushing:

    bash
    git log --format='%h %G? %s' main..HEAD   # G = signed, N = unsigned

    An unsigned commit (N) in the stack: git rebase --force-rebase main re-commits everything signed, then git push --force-with-lease. Always --force-with-lease, never bare --force.

Before opening the PR

The authoritative checklist is AGENTS.md § "Adding Features Safely" — read it, don't work from memory. The three most-missed items:

  1. Changeset — required when the change touches a published package's surface, including a skills/-only change (those ship in the stash tarball, so they need a stash patch changeset). A .claude/-only change is internal: no changeset.
  2. Skills check — a change to a public API, CLI surface, or user-facing workflow must fix the affected skills/*/SKILL.md in the same PR (package→skill map in AGENTS.md).
  3. Meta files — adding/removing/renaming a package, example, skill, or subpath export must update AGENTS.md Repository Layout and SECURITY.md.

Then run: pnpm run code:fix, pnpm --filter <pkg> build, pnpm --filter <pkg> test.

Show full SKILL.md (246 more words)Show less

PR body

Same wording rule as meta-issue-creation: dumbed down — assume the reviewer is new to CipherStash, stack, and EQL. Define product terms at first use; say what breaks or improves in the user's world, not just the code's.

Sections, in order:

  • Summary — what and why, two or three plain sentences. Lead with the user-visible effect.
  • Changes — grouped by area, one line each.
  • Verification — exactly what was run and what it showed. Honest: a failing or skipped check is stated, not omitted. "Verified against the 0.17 dist" beats "should work".
  • Related — Closes #N / Refs #N for the GitHub issues this serves; cross-repo refs in full owner/repo#N form.
  • Review notes (optional) — where to look first, and anything deliberately deferred with the reason.

Reference wording traps (same as issues):

  • #N only as a real GitHub issue/PR reference — GitHub autolinks every #N, so "option #2" mints a bogus link. Write "option 2".
  • Never reference internal Linear issues (CIP-…) in PRs, commits, or comments — GitHub is public.

Mechanics

  • Always open as a draft: gh pr create --draft --title '…' --body '…' (title follows the commit-subject convention). Mark it ready for review only when the user says so — either ask, or rely on an explicit "open it ready" / "mark it ready" from them. gh pr ready <number> flips it.
  • Force-pushing a branch with an open PR is fine (rebases, re-signs) — but say so in a PR comment when the rewrite changes more than commit hashes.
  • Don't merge, close, or mark ready-for-review without being asked.

© cipherstash, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/meta-pr-creation of cipherstash/stack.

Open the folder on GitHubat commit 3eb459b

Compare with similar skills

Meta PR Creation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Meta PR Creation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Meta PR Creation this skillcipherstash/stack157—~937Automated safety check: PassMIT
Pull Requestspnpm/pnpm37k—~2.2kAutomated safety check: PassMIT
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Contributingkortix-ai/suna20k1 repos~3kAutomated safety check: WarnCustom licence
Verdaccio PR Reviewverdaccio/verdaccio18k—~1.7kAutomated safety check: PassMIT
Dsh Web Community Plugin Developerzhu1090093659/dsh-web8.5k—~951Automated safety check: PassApache-2.0

Similar skills

  • Pull Requests

    pnpm/pnpm

    Take a change through a pull request in the pnpm repository — opening it, then staying with it after every push until CI is green and the review round is quiet.

    37k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Contributing

    kortix-ai/suna

    The pull request loop for this repo: branch → commit → verify in your own box (local tests + local stack) → PR into main → demo video recorded with agent-browser on the local stack → gh --attach →…

    20k GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check: warnings
  • Verdaccio PR Review

    verdaccio/verdaccio

    Reviews an existing verdaccio/verdaccio pull request end to end, verifies each finding and reports whether it is mergeable, optionally fixing it on the PR branch.

    18k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Develop a DSH community plugin in the contributor's own repository, and register it in the community plugin index owned by the dsh-community-plugins repository — the index is community.json at that…

    8.5k GitHub stars~951 tokensUpdated today
    DevelopmentAuto-check passed
  • Local development guide for the Happy pnpm monorepo: install, build, test and run the CLI, server, Expo app and Tauri desktop packages.

    24k GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from cipherstash/stack

All 14 skills in this repo
  • Meta Issue Creation

    cipherstash/stack

    How an agent files a GitHub issue on cipherstash repos — required structure (Background / Problem / Proposal), dumbed-down wording rules, and pre-filing checks.

    157 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Stash Zerokms

    cipherstash/stack

    The ZeroKMS key model — keysets, clients, client keys, and the grant/revoke lifecycle.

    157 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Stash Deployment

    cipherstash/stack

    Deploy a CipherStash encryption rollout to a live environment without losing data — the multi-deploy ladder (schema-add + dual-write → backfill → read cutover → stop dual-writes → drop plaintext)…

    157 GitHub stars~6.5k tokensUpdated today
    Auto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    Auto-check: warnings
  • Stash Drizzle

    cipherstash/stack

    Integrate CipherStash encryption with Drizzle ORM using @cipherstash/stack-drizzle (EQL v3).

    157 GitHub stars~10k tokensUpdated today
    Auto-check: notes
  • Stash Edge

    cipherstash/stack

    Run CipherStash encryption on edge and non-Node runtimes with the @cipherstash/stack/wasm-inline entry — Deno, Supabase Edge Functions, Cloudflare Workers, and Bun.

    157 GitHub stars~6.4k tokensUpdated today
    Auto-check: notes

Categories

Questions about Meta PR Creation

What does Meta PR Creation do?

How an agent authors branches, commits, and pull requests on cipherstash/stack — naming, signed commits, the changeset/skills/meta-file checklist, and PR body structure with dumbed-down wording. Meta PR Creation is an agent skill from cipherstash/stack. How an agent authors branches, commits, and pull requests on cipherstash/stack — naming, signed commits, the changeset/skills/meta-file checklist, and PR body structure with dumbed-down wording.

When should I use Meta PR Creation?

Meta PR Creation fits situations like: committing work; opening/updating a PR.

How do I install Meta PR Creation in Claude Code?

Run `npx skills add cipherstash/stack --skill meta-pr-creation -a claude-code`. Or copy the skill folder (.claude/skills/meta-pr-creation in cipherstash/stack) into .claude/skills/meta-pr-creation in your project. Claude Code loads it when a task matches its description.

How do I install Meta PR Creation in Codex?

Run `npx skills add cipherstash/stack --skill meta-pr-creation -a codex`. Or copy the skill folder (.claude/skills/meta-pr-creation in cipherstash/stack) into .agents/skills/meta-pr-creation in your project. Codex loads it when a task matches its description.

Can I use Meta PR Creation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cipherstash/stack --skill meta-pr-creation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/meta-pr-creation, .gemini/skills/meta-pr-creation, .github/skills/meta-pr-creation and .opencode/skills/meta-pr-creation in your project.

What does Meta PR Creation need to run?

Going by SKILL.md and its folder, Meta PR Creation needs the command-line tools its instructions call (git, pnpm and gh).

Does Meta PR Creation access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Meta PR Creation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Meta PR Creation use?

Meta PR Creation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Meta PR Creation use?

About 937 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Meta PR Creation?

Skills that share tags, products or a category with Meta PR Creation: Pull Requests (pnpm/pnpm, 37k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Contributing (kortix-ai/suna, 20k stars) and Verdaccio PR Review (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Meta PR Creation?

cipherstash (a GitHub organization) maintains it in cipherstash/stack, which has 157 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 8, 2026.

Source: cipherstash/stack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.