Agent skill

Senpi Release Publishing

by code-yeongyu in code-yeongyu/senpi

Walks the canonical CalVer release flow for senpi, from a clean main checkout through changelog audit, checks, tag push, GitHub Release and npm publishing.

MITAuto-check passedDevelopment

Install Senpi Release Publishing

skills CLI
$ npx skills add code-yeongyu/senpi --skill release-publish -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install code-yeongyu/senpi release-publish --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/code-yeongyu/senpi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/agent/skills/release-publish .claude/skills/release-publish && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-publish
GitHub stars
470
Token cost
~1.7k tokens
SKILL.md length
834 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Walks the canonical CalVer release flow for senpi, from a clean main checkout through changelog audit, checks, tag push, GitHub Release and npm publishing.

  • Cutting a CalVer release of senpi
  • SKILL.md covers Canonical release flow, Pre-flight checklist, Publish watch and Gate disambiguation, plus 4 more sections
  • Calls npm, gh and node; needs UPSTREAM_AUTOMATION_TOKEN
  • Pushing a release tag and publishing the GitHub Release

What it does

A checklist for releasing the senpi project. From a clean main checkout, scripts/release.mjs runs after confirming the branch and worktree, validating the CalVer version, auditing the changelog and writing product-facing release notes with scripts/release-notes.mjs. It then runs npm run check, npm run build and CI=1 npm test, creates the release commit and tag, adds a next-cycle changelog commit and pushes main and the tag.

Pre-flight rules include using a clean dedicated clone when the main checkout has foreign state, never disturbing other people's work, and never rerunning release.mjs after the tag is pushed. npm publishing is delegated: the tag pipeline dispatches a publish-npm.yml workflow in publish-only mode, which is what npm's trusted publisher matches, and the public GitHub Release waits for that run. After the push, the build-binaries workflow run is watched.

When your agent uses it

  • Cutting a CalVer release of senpi
  • Pushing a release tag and publishing the GitHub Release
  • Publishing packages to npm through the trusted workflow
  • Recovering a release that failed before the tag push

Example prompts

  • “Release senpi with the canonical CalVer flow.”
  • “Run the pre-flight checklist before we push the release tag.”
  • “Watch the build-binaries run after the tag push and report the result.”

Requirements

  • A clean main checkout of the senpi repository
  • Node and npm
  • The gh CLI, used to watch workflow runs

What it can do on your machine

Read from SKILL.md and the folder at commit 0fa9139. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • gh
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • UPSTREAM_AUTOMATION_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Senpi Release Publishing loads about 1.7k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 834 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from code-yeongyu/senpi at commit 0fa9139, republished under its MIT licence (© code-yeongyu). 834 words, ~1,670 tokens.

Download SKILL.mdSave it as .claude/skills/release-publish/SKILL.md (or your agent's skills folder).
name
release-publish
description
Release, publish, CalVer tag push, npm publish, 배포, 릴리즈 for senpi. Use for the canonical release flow, GitHub tag/release publication, and npm publishing.

Release Publish

Use this skill when releasing senpi with the canonical CalVer flow, pushing a release tag, publishing the GitHub Release, or publishing packages to npm.

Canonical release flow

Run scripts/release.mjs from a clean main checkout.

  • Confirm you are on main.
  • Confirm the worktree is clean.
  • Confirm the release version is a valid CalVer.
  • Run the changelog audit before release.
  • Make only product-facing release notes from packages/coding-agent/CHANGELOG.md via scripts/release-notes.mjs.
  • Skip housekeeping, upstream-sync, and generated-catalog-only entries.
  • Duplicate user-facing ai/agent/tui changes into the coding-agent changelog.
  • Run npm run check.
  • Run npm run build.
  • Run CI=1 npm test.
  • Create the release commit.
  • Create the release tag.
  • Create the next-cycle changelog commit.
  • Push main and the tag.

Pre-flight checklist

  • Read the current release rules in AGENTS.md and scripts/AGENTS.md.
  • Use a clean dedicated clone if the main checkout has foreign state.
  • Never clean, stash, or otherwise disturb other people's work.
  • Use the protected-main path when needed; UPSTREAM_AUTOMATION_TOKEN exists for authenticated protected-main pushes.
  • npm publish is delegated: the tag pipeline's publish-npm job no longer publishes — it dispatches publish-npm.yml in publish-only mode (the proven route from the v2026.7.28-x and v2026.8.4 recoveries) and gates the public GitHub Release on that run's success. npm's trusted publisher matches the publish-npm.yml workflow identity only; never reintroduce a direct publish or an environment: on the publish path (the environment subject is what npm rejects).
  • Do not rerun scripts/release.mjs after the tag has been pushed.
  • If checks fail before the tag push, fix first, then re-release from the beginning.
  • Treat E404 noise for @code-yeongyu/senpi-orchestrator as non-fatal.
  • Use node scripts/release-notes.mjs / the cl.md audit before publishing notes.
  • Keep release notes product-facing only.

Publish watch

After tag push, watch the build-binaries workflow run (find the run id via gh run list --workflow=build-binaries.yml --branch main --limit 1 --json databaseId -q '.[0].databaseId').

The publish-npm job dispatches publish-npm.yml in publish-only mode, prints the dispatched run URL, waits up to 60 minutes, and fails if the publish run fails. There is no environment approval gate on the publish path — the old npm-publish environment subject is exactly what npm's trusted-publisher registration rejects.

Never consider the release done before publish-npm and publish-github-release complete and the GitHub Release is non-draft. If the publish job fails, recover with gh workflow run publish-npm.yml -f version=<v> -f publish-only=true, never by rerunning release.mjs.

Gate disambiguation

These are separate controls and must not be conflated:

  • GitHub Environment approval: removed from the publish path (the npm-publish environment subject is what npm rejects); the unused environment may remain in repo settings harmlessly.
  • npm OIDC trusted publishing: the npm-side trusted publishing path used by the job.
  • npm lifecycle-script review: the npm approve-scripts --allow-scripts-pending trust review, which is not publish approval.
  • Protected-main authorization: the authenticated push path for protected main, which is distinct from publish approval.
Show full SKILL.md (380 more words)Show less

Hazards and hard rules

  • Protected-main push failures are expected if the token path is wrong; use UPSTREAM_AUTOMATION_TOKEN for the authenticated release push path.
  • The tag pipeline publishes only through the dispatched publish-npm.yml identity (see Pre-flight checklist). If npm-side config changes, re-verify with a dry_run dispatch before the next release.
  • Never rerun scripts/release.mjs after the tag is pushed. If publishing fails, recover from the existing tag workflow.
  • If a check or test fails before the tag push, stop and fix the issue, then re-release. Do not try to salvage a bad release by continuing past the failure.
  • E404 noise for @code-yeongyu/senpi-orchestrator is not a release failure.
  • An npm PUT 404 during npm publish can be a false negative: the publish may have landed anyway (observed live on 2026-07-28 with @code-yeongyu/senpi@2026.7.28-2 — the job failed but the version exists). ALWAYS verify with npm view <pkg> versions --json before treating a publish error as real, before rerunning anything, and before declaring a release failed.
  • A failed publish-npm job skips publish-github-release and triggers the draft-cleanup path; check gh release view v<version> before recovering — the release may already be live. Recover only through the existing tag workflow, never by rerunning release.mjs.
  • If the main checkout has foreign state, use a clean dedicated clone/worktree. Never clean or stash someone else's work.

Release notes provenance

  • Extract notes only from packages/coding-agent/CHANGELOG.md via scripts/release-notes.mjs.
  • Keep changelog entries product-facing.
  • Run the cl.md audit before release.
  • Skip housekeeping, upstream-sync, and generated-catalog-only changes.
  • Duplicate user-facing ai, agent, and tui changes into the coding-agent changelog so the release notes stay complete.

Post-release verification checklist

  • build-binaries is complete.
  • stage-github-release is complete.
  • publish-npm is complete.
  • publish-github-release is complete.
  • The npm registry resolves the published version.
  • The GitHub Release is published and non-draft.

Notes

  • The canonical release path is scripts/release.mjs from clean main.
  • The approval checkpoint is mandatory for the normal tag-driven release.
  • Publishing today goes through the publish-npm.yml publish-only dispatch (see the known-broken note above), NOT the tag pipeline's environment-gated job.
  • If the tag pipeline's publish-npm fails after stage-github-release succeeded, the cleanup path deletes the draft release; the build assets survive as the run's release-assets-v<tag> artifact — re-create the release with gh release create <tag> --verify-tag --draft --title <tag> --notes-file RELEASE_NOTES.md <assets> and publish with gh release edit <tag> --draft=false after verifying npm view shows every package.

© code-yeongyu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/agent/skills/release-publish of code-yeongyu/senpi.

Open the folder on GitHubat commit 0fa9139

Compare with similar skills

Senpi Release Publishing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Senpi Release Publishing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Senpi Release Publishing this skillcode-yeongyu/senpi470—~1.7kAutomated safety check: PassMIT
Cline CLI Release Publishercline/cline70k—~3.4kAutomated safety check: WarnApache-2.0
Ccb GitHubSeemSeam/claude_codex_bridge3.5k—~4.9kAutomated safety check: PassCustom licence
npm Release Via GitHub Actionsjmfederico/pi-web861—~2.9kAutomated safety check: PassMIT
Automate npm Releasejd-solanki/slidev-theme-dracula161—~626Automated safety check: PassNone
ClickUp CLI Release Processkrodak/clickup-cli120—~906Automated safety check: WarnMIT

Similar skills

  • Walks through releasing the Cline CLI package to npm: release notes, version bump, matching git tag, and either the GitHub workflow or a local publish.

    70k GitHub stars~3.4k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Ccb GitHub

    SeemSeam/claude_codex_bridge

    Maintain this CCB project's GitHub-facing release and npm publication surface.

    3.5k GitHub stars~4.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…

    861 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Automate npm Release

    jd-solanki/slidev-theme-dracula

    Automate npm package publishing via GitHub Actions for single-package repos and independent monorepo packages, including bumpp version tags, GitHub release notes, trusted publishing, provenance, and…

    161 GitHub stars~626 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • ClickUp CLI Release Process

    krodak/clickup-cli

    Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.

    120 GitHub stars~906 tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    69k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed

More from code-yeongyu/senpi

  • Senpi Agent QA Harness

    code-yeongyu/senpi

    Checks changes to the senpi coding agent by driving the real CLI from source in an isolated sandbox, over RPC, terminal UI, mock model and CLI smoke channels.

    470 GitHub stars~2.7k tokensUpdated today
    Auto-check: notes
  • Merge Upstream into Fork

    code-yeongyu/senpi

    Syncs a fork branch with its upstream remote using a history-preserving merge commit, with no rebase and no force push.

    470 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Bun 1.4 Builtins Guide

    code-yeongyu/senpi

    Points the agent at Bun 1.4 built-in APIs before it installs an npm package, so image, browser, markdown, cron, PTY and test work uses what Bun already ships.

    470 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Worker brief for implementing one pre-assigned feature in the senpi todotools built-in extension, with strict scope, typing, testing and git-safety rules.

    470 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • GPT Image Prompt Guide

    code-yeongyu/senpi

    Prompt-crafting guide for gpt-image-2.5: which image tool to call, which model to pick, and how to write prompts, edit with references and refine over turns.

    470 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Tmux Manual QA Worker

    code-yeongyu/senpi

    Runs one manual QA scenario for the todo continuation feature in the real ./pi-test.sh CLI inside tmux, captures scrollback and checks a deterministic count marker.

    470 GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Senpi Release Publishing

What does Senpi Release Publishing do?

Walks the canonical CalVer release flow for senpi, from a clean main checkout through changelog audit, checks, tag push, GitHub Release and npm publishing. A checklist for releasing the senpi project.mjs.

When should I use Senpi Release Publishing?

Senpi Release Publishing fits situations like: cutting a CalVer release of senpi; pushing a release tag and publishing the GitHub Release; publishing packages to npm through the trusted workflow; recovering a release that failed before the tag push.

How do I install Senpi Release Publishing in Claude Code?

Run `npx skills add code-yeongyu/senpi --skill release-publish -a claude-code`. Or copy the skill folder (.github/agent/skills/release-publish in code-yeongyu/senpi) into .claude/skills/release-publish in your project. Claude Code loads it when a task matches its description.

How do I install Senpi Release Publishing in Codex?

Run `npx skills add code-yeongyu/senpi --skill release-publish -a codex`. Or copy the skill folder (.github/agent/skills/release-publish in code-yeongyu/senpi) into .agents/skills/release-publish in your project. Codex loads it when a task matches its description.

Can I use Senpi Release Publishing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add code-yeongyu/senpi --skill release-publish -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-publish, .gemini/skills/release-publish, .github/skills/release-publish and .opencode/skills/release-publish in your project.

What does Senpi Release Publishing need to run?

Going by SKILL.md and its folder, Senpi Release Publishing needs the command-line tools its instructions call (npm, gh and node) and credentials named UPSTREAM_AUTOMATION_TOKEN. Our summary lists: A clean main checkout of the senpi repository; Node and npm; The gh CLI, used to watch workflow runs.

Does Senpi Release Publishing access the network?

SKILL.md contains no URLs. Its commands use npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Senpi Release Publishing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Senpi Release Publishing use?

Senpi Release Publishing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Senpi Release Publishing use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Senpi Release Publishing?

Skills that share tags, products or a category with Senpi Release Publishing: Cline CLI Release Publisher (cline/cline, 70k stars), Ccb GitHub (SeemSeam/claude_codex_bridge, 3.5k stars), npm Release Via GitHub Actions (jmfederico/pi-web, 861 stars) and Automate npm Release (jd-solanki/slidev-theme-dracula, 161 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Senpi Release Publishing?

code-yeongyu (a GitHub user) maintains it in code-yeongyu/senpi, which has 470 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.

Source: code-yeongyu/senpi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.