Agent skill

Publishing A New Package

by Comfy-Org in Comfy-Org/ComfyUI_frontend

Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo.

GPL-3.0Auto-check passedDevelopment

Install Publishing A New Package

skills CLI
$ npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Comfy-Org/ComfyUI_frontend publishing-a-new-package --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/publishing-a-new-package .claude/skills/publishing-a-new-package && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
publishing-a-new-package
GitHub stars
2.1k
Token cost
~1.8k tokens
SKILL.md length
938 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
GPL-3.0

At a glance

Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo.

  • Works in 2 steps: Give the CI token read+write on the… → Publish once by hand, then make sure the…
  • Adding a package to packages/
  • SKILL.md covers The first publish is different, Never npm publish from this repo, Scaffolding the workflows and Before the first publish, plus 4 more sections
  • Calls npm, pnpm and jq; reaches registry.npmjs.org; needs NPM_TOKEN and NODE_AUTH_TOKEN

What it does

Publishing A New Package is an agent skill from Comfy-Org/ComfyUI_frontend. Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo. Covers workflow scaffolding, the first-publish 404, catalog: rewriting, trusted publishing, and the consumer smoke test. Use when adding a package to packages/, publishing to npm for the first time, or when an npm publish workflow fails.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Project scaffolding, QA and bug reports and Monorepo tooling. It works with npm. The repository describes itself as: Official front-end implementation of ComfyUI. The licence is GPL-3.0.

When your agent uses it

  • Adding a package to packages/
  • Publishing to npm for the first time
  • An npm publish workflow fails

Example prompts

  • “Use the publishing-a-new-package skill to publish a new package from this monorepo to npm under @comfyorg and proves it is consumable from another…”
  • “/publishing-a-new-package”

Requirements

  • Node.js
  • A credential in NPM_TOKEN
  • A credential in NODE_AUTH_TOKEN

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Give the CI token read+write on the whole @comfyorg scope — the narrowest
  2. Publish once by hand, then make sure the CI token covers the new name.

What it can do on your machine

Read from SKILL.md and the folder at commit f9be289. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pnpm
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN
    • NODE_AUTH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Publishing A New Package loads about 1.8k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 938 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Comfy-Org/ComfyUI_frontend at commit f9be289, republished under its GPL-3.0 licence (© Comfy-Org). 938 words, ~1,822 tokens.

Download SKILL.mdSave it as .claude/skills/publishing-a-new-package/SKILL.md (or your agent's skills folder).
name
publishing-a-new-package
description
Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo. Covers workflow scaffolding, the first-publish 404, catalog: rewriting, trusted publishing, and the consumer smoke test. Use when adding a package to packages/, publishing to npm for the first time, or when an npm publish workflow fails.

Publishing a New Package

Getting a package onto npm is not done when the workflow goes green. It is done when someone in another repo can install it and it works. Most of the failures below happen after the "publish succeeded" line.

The first publish is different

A brand-new package name will fail the first CI publish unless the token was scoped for it, and the error does not say so. npm returns:

text
[E404] 404 Not Found - PUT https://registry.npmjs.org/@comfyorg%2fyour-package

A 404 on PUT means the token may publish existing packages in the scope but may not create a new name — a granular token whose write access is a hand-picked package list cannot include a package that does not exist yet. It reads like "the package doesn't exist" — which is true and irrelevant — and sends you looking for a workflow bug that isn't there. --access public is already set; the registry URL is already right.

Two ways out, both fine:

  1. Give the CI token read+write on the whole @comfyorg scope — the narrowest grant that can create a new name, and preferable to all-packages access — then re-run the workflow.
  2. Publish once by hand, then make sure the CI token covers the new name.

Trusted publishing (OIDC) cannot bootstrap either — npm requires the package to exist before a trusted publisher can be configured (npm/cli#8544). So the ordering is always: first publish by token → configure trusted publisher → switch CI to OIDC.

Never npm publish from this repo

Workspace packages use pnpm catalog specifiers:

json
"dependencies": { "@iconify/utils": "catalog:" }

pnpm publish rewrites those to real ranges when it packs. npm publish ships the literal string "catalog:", and every consumer install breaks. The tarball looks fine locally either way — the damage only shows up in the consumer.

Check before you publish anything:

sh
cd packages/<name>
pnpm pack --pack-destination /tmp
tar -xzOf /tmp/comfyorg-<name>-<version>.tgz package/package.json | jq .dependencies

Every value must be a real range. If you see catalog:, you used the wrong tool.

Scaffolding the workflows

Copy the four-workflow set from an existing package such as design-system:

WorkflowRole
publish-<pkg>.yamlworkflow_call + workflow_dispatch; does the publish
publish-<pkg>-on-merge.yamlfires on merged PR with the Release label
version-bump-<pkg>.yamldispatch → opens a version PR labelled Release
ci-<pkg>-pack.yamlon PR — typecheck + assert tarball contents

The pack check must allowlist package.json, LICENSE, and README.md. npm force-includes all three regardless of the files field, so a guard that only permits the first two rejects any package that has a readme.

Before the first publish

  • Write a README. Without one the npm page renders empty, which defeats publishing for another team to discover.
  • Declare peer dependencies. Anything the consumer must supply — Tailwind, Vue — belongs in peerDependencies, not devDependencies. A devDependency tells the consumer nothing.
  • Export ./package.json. Tooling reads it; an exports map that omits it throws ERR_PACKAGE_PATH_NOT_EXPORTED.
  • Check files against the exports map. Every path in exports must be covered by files, or the target is simply absent from the tarball. Nothing catches this at install time — neither npm pack nor npm install resolves export targets — so it surfaces as a consumer resolution error the first time something imports that entry.

Releasing after the first time

Run the version-bump workflow → it opens a PR labelled Release → merge it → publish-<pkg>-on-merge publishes and posts to Slack. A manual dispatch at an already-published version is a no-op: the Check if version already on npm step finds it and skips. If you want to test the pipeline, you need a new version number.

Show full SKILL.md (387 more words)Show less

Prove it is consumable

This is the step people skip, and it is the only one that finds real problems. In a different repo — ideally one on npm rather than pnpm, since that is the path where catalog: would explode:

sh
npm install @comfyorg/<name>

Then import it somewhere real, build, and grep the build output to confirm the thing you imported actually reached the bundle. Import every entry in the exports map while you are there — a subpath whose target never made it into the tarball fails only here. A green build proves the import resolved; it does not prove the values landed. For CSS, point the check at the consumer's own build output — the path below is Nuxt's, so substitute whatever your consumer emits:

sh
grep -o -- "--your-token:[^;]*" .output/public/_nuxt/*.css

Open that consumer change as a PR and keep the preview link — it is the evidence that the publish worked end to end.

Trusted publishing

Once the package exists, configure it on npmjs.com under package settings:

  • Organization / repository / workflow filename — use the reusable workflow that actually runs the publish (publish-<pkg>.yaml), not the on-merge wrapper.
  • Environment name — leave blank unless the publish job declares environment:. A mismatch fails every publish.
  • Allow npm publish only. npm stage publish publishes unlisted pending manual approval; we do not use it.

Then grant OIDC at both workflow layers — the caller job that does uses: ./.github/workflows/publish-<pkg>.yaml, and the publish job inside the reusable workflow. A called workflow can never hold more than the calling job does, so setting this on the inner job alone leaves it with no token and the publish quietly falls back to NPM_TOKEN:

yaml
permissions:
  contents: read
  id-token: write

Keep NODE_AUTH_TOKEN in place until an OIDC publish has actually succeeded. [WARN] Skipped OIDC in the log means it silently fell back to the token — treat that as a failure to chase down, not a warning to scroll past. Suspect pnpm/action-setup first: every workflow here still pins v4.4.0 (fc06bc1257f339d1d5d8b3a19a8cae5388b55320), the version that broke pnpm's OIDC publish in pnpm#11513 — closed once the reporter bumped the action, not by a pnpm release. Only after a real OIDC publish should you tighten the org to require 2FA and disallow tokens; doing it earlier removes the only working path.

Announce it

Post the npm link, the install line, and the consumer PR preview link. "It's published" is not actionable; "here is the import and here is it working" is.

© Comfy-Org, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/publishing-a-new-package of Comfy-Org/ComfyUI_frontend.

Open the folder on GitHubat commit f9be289

Compare with similar skills

Publishing A New Package next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Publishing A New Package compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Publishing A New Package this skillComfy-Org/ComfyUI_frontend2.1k—~1.8kAutomated safety check: PassGPL-3.0
Create Saleor Packagesaleor/apps162—~608Automated safety check: PassCustom licence
Creating Luna Appmizchi/luna.mbt173—~1.4kAutomated safety check: PassNone
Adk Readme WriterBrainDAO/adk-ts119—~2.6kAutomated safety check: NotesMIT
Add New Packageremotion-dev/remotion63k—~777Automated safety check: NotesCustom licence
Nodejs CLI Best Practiceslirantal/nodejs-cli-apps-best-practices4.1k—~2kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Scaffold a new shared package in the saleor-apps monorepo under ./packages/.

    162 GitHub stars~608 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Creating Luna App

    mizchi/luna.mbt

    A skill your agent uses when scaffolding a new standalone CSR app that uses luna (@lunaui/luna) outside the luna.mbt monorepo — running npx @lunaui/luna new, choosing TSX vs MoonBit, or fixing a…

    173 GitHub stars~1.4k tokensUpdated 23 days ago
    DevelopmentAuto-check passed
  • Adk Readme Writer

    BrainDAO/adk-ts

    ADK-TS README specialist. An agent skill from BrainDAO/adk-ts.

    119 GitHub stars~2.6k tokensUpdated 3 mo ago
    DevelopmentAuto-check: notes
  • Add New Package

    remotion-dev/remotion

    Official

    Add a new package to the Remotion monorepo, including package scaffolding, monorepo registration, documentation, build scripts, and release checklist updates.

    63k GitHub stars~777 tokensUpdated today
    Media & CreativeAuto-check: notes
  • Nodejs CLI Best Practices

    lirantal/nodejs-cli-apps-best-practices

    Guide and audit Node.js CLI application development against 41 established best practices covering UX, distribution, interoperability, accessibility, testing, error handling, development setup…

    4.1k GitHub stars~2k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Handsontable Demo Page Generator

    handsontable/handsontable

    Builds two throwaway HTML test pages for a Handsontable pull request, one on the released CDN version and one on the local build, to compare behavior side by side.

    22k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed

More from Comfy-Org/ComfyUI_frontend

All 22 skills in this repo
  • Adding Deprecation Warnings

    Comfy-Org/ComfyUI_frontend

    Adds deprecation warnings for renamed or removed properties/APIs.

    2.1k GitHub stars~775 tokensUpdated today
    Auto-check passed
  • Agent Integration Replay

    Comfy-Org/ComfyUI_frontend

    Replay recorded agent conversations as Playwright tests against the real chat panel and canvas.

    2.1k GitHub stars~805 tokensUpdated today
    Auto-check: notes
  • Codegen Transform

    Comfy-Org/ComfyUI_frontend

    Transforms raw Playwright codegen output into ComfyUI convention-compliant tests.

    2.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Comment Sicko

    Comfy-Org/ComfyUI_frontend

    Dispatches the comment-sicko subagent to hunt gratuitous comments in a PR/diff, triages its raw findings, and posts a polite, professional writeup.

    2.1k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Hardening Flaky E2E Tests

    Comfy-Org/ComfyUI_frontend

    Diagnoses and fixes flaky Playwright e2e tests by replacing race-prone patterns with retry-safe alternatives.

    2.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Perf Fix With Proof

    Comfy-Org/ComfyUI_frontend

    Ships performance fixes with CI-proven improvement using stacked PRs.

    2.1k GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Publishing A New Package

What does Publishing A New Package do?

Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo. Publishing A New Package is an agent skill from Comfy-Org/ComfyUI_frontend. Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo.

When should I use Publishing A New Package?

Publishing A New Package fits situations like: adding a package to packages/; publishing to npm for the first time; an npm publish workflow fails.

How do I install Publishing A New Package in Claude Code?

Run `npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a claude-code`. Or copy the skill folder (.claude/skills/publishing-a-new-package in Comfy-Org/ComfyUI_frontend) into .claude/skills/publishing-a-new-package in your project. Claude Code loads it when a task matches its description.

How do I install Publishing A New Package in Codex?

Run `npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a codex`. Or copy the skill folder (.claude/skills/publishing-a-new-package in Comfy-Org/ComfyUI_frontend) into .agents/skills/publishing-a-new-package in your project. Codex loads it when a task matches its description.

Can I use Publishing A New Package in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/publishing-a-new-package, .gemini/skills/publishing-a-new-package, .github/skills/publishing-a-new-package and .opencode/skills/publishing-a-new-package in your project.

What does Publishing A New Package need to run?

Going by SKILL.md and its folder, Publishing A New Package needs the command-line tools its instructions call (npm, pnpm and jq) and credentials named NPM_TOKEN and NODE_AUTH_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN; A credential in NODE_AUTH_TOKEN.

Does Publishing A New Package access the network?

SKILL.md names 2 domains. In commands or code: registry.npmjs.org; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Publishing A New Package safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Publishing A New Package use?

Publishing A New Package is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Publishing A New Package use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Publishing A New Package?

Skills that share tags, products or a category with Publishing A New Package: Create Saleor Package (saleor/apps, 162 stars), Creating Luna App (mizchi/luna.mbt, 173 stars), Adk Readme Writer (BrainDAO/adk-ts, 119 stars) and Add New Package (remotion-dev/remotion, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Publishing A New Package?

Comfy-Org (a GitHub organization) maintains it in Comfy-Org/ComfyUI_frontend, which has 2,056 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 9, 2026.

Source: Comfy-Org/ComfyUI_frontend on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.