Create Saleor Package
saleor/apps
Scaffold a new shared package in the saleor-apps monorepo under ./packages/.
Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo.
$ npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Comfy-Org/ComfyUI_frontend publishing-a-new-package --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/publishing-a-new-package .claude/skills/publishing-a-new-package && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "publishing-a-new-package" agent skill from https://github.com/Comfy-Org/ComfyUI_frontend/tree/main/.claude/skills/publishing-a-new-package into .claude/skills/publishing-a-new-package/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "publishing-a-new-package", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Comfy-Org/ComfyUI_frontend/tree/main/.claude/skills/publishing-a-new-packageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Comfy-Org/ComfyUI_frontend publishing-a-new-package --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/publishing-a-new-package .agents/skills/publishing-a-new-package && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "publishing-a-new-package" agent skill from https://github.com/Comfy-Org/ComfyUI_frontend/tree/main/.claude/skills/publishing-a-new-package into .agents/skills/publishing-a-new-package/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "publishing-a-new-package", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Comfy-Org/ComfyUI_frontend publishing-a-new-package --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/publishing-a-new-package .cursor/skills/publishing-a-new-package && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "publishing-a-new-package" agent skill from https://github.com/Comfy-Org/ComfyUI_frontend/tree/main/.claude/skills/publishing-a-new-package into .cursor/skills/publishing-a-new-package/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "publishing-a-new-package", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Comfy-Org/ComfyUI_frontend.git --path .claude/skills/publishing-a-new-package--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Comfy-Org/ComfyUI_frontend publishing-a-new-package --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/publishing-a-new-package .gemini/skills/publishing-a-new-package && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "publishing-a-new-package" agent skill from https://github.com/Comfy-Org/ComfyUI_frontend/tree/main/.claude/skills/publishing-a-new-package into .gemini/skills/publishing-a-new-package/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "publishing-a-new-package", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Comfy-Org/ComfyUI_frontend publishing-a-new-packageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/publishing-a-new-package .github/skills/publishing-a-new-package && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "publishing-a-new-package" agent skill from https://github.com/Comfy-Org/ComfyUI_frontend/tree/main/.claude/skills/publishing-a-new-package into .github/skills/publishing-a-new-package/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "publishing-a-new-package", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Comfy-Org/ComfyUI_frontend publishing-a-new-package --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Comfy-Org/ComfyUI_frontend.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/publishing-a-new-package .opencode/skills/publishing-a-new-package && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "publishing-a-new-package" agent skill from https://github.com/Comfy-Org/ComfyUI_frontend/tree/main/.claude/skills/publishing-a-new-package into .opencode/skills/publishing-a-new-package/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "publishing-a-new-package", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
publishing-a-new-packagePublishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo.
Publishing A New Package is an agent skill from Comfy-Org/ComfyUI_frontend. Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo. Covers workflow scaffolding, the first-publish 404, catalog: rewriting, trusted publishing, and the consumer smoke test. Use when adding a package to packages/, publishing to npm for the first time, or when an npm publish workflow fails.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Project scaffolding, QA and bug reports and Monorepo tooling. It works with npm. The repository describes itself as: Official front-end implementation of ComfyUI. The licence is GPL-3.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f9be289. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmpnpmjqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
registry.npmjs.orgAlso links to:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NPM_TOKENNODE_AUTH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Publishing A New Package loads about 1.8k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 938 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Comfy-Org/ComfyUI_frontend at commit f9be289, republished under its GPL-3.0 licence (© Comfy-Org). 938 words, ~1,822 tokens.
.claude/skills/publishing-a-new-package/SKILL.md (or your agent's skills folder).Getting a package onto npm is not done when the workflow goes green. It is done when someone in another repo can install it and it works. Most of the failures below happen after the "publish succeeded" line.
A brand-new package name will fail the first CI publish unless the token was scoped for it, and the error does not say so. npm returns:
[E404] 404 Not Found - PUT https://registry.npmjs.org/@comfyorg%2fyour-packageA 404 on PUT means the token may publish existing packages in the scope but
may not create a new name — a granular token whose write access is a
hand-picked package list cannot include a package that does not exist yet. It
reads like "the package doesn't exist" — which is true and irrelevant — and
sends you looking for a workflow bug that isn't there. --access public is
already set; the registry URL is already right.
Two ways out, both fine:
@comfyorg scope — the narrowest
grant that can create a new name, and preferable to all-packages access —
then re-run the workflow.Trusted publishing (OIDC) cannot bootstrap either — npm requires the package to exist before a trusted publisher can be configured (npm/cli#8544). So the ordering is always: first publish by token → configure trusted publisher → switch CI to OIDC.
npm publish from this repoWorkspace packages use pnpm catalog specifiers:
"dependencies": { "@iconify/utils": "catalog:" }pnpm publish rewrites those to real ranges when it packs. npm publish ships
the literal string "catalog:", and every consumer install breaks. The tarball
looks fine locally either way — the damage only shows up in the consumer.
Check before you publish anything:
cd packages/<name>
pnpm pack --pack-destination /tmp
tar -xzOf /tmp/comfyorg-<name>-<version>.tgz package/package.json | jq .dependenciesEvery value must be a real range. If you see catalog:, you used the wrong tool.
Copy the four-workflow set from an existing package such as design-system:
| Workflow | Role |
|---|---|
publish-<pkg>.yaml | workflow_call + workflow_dispatch; does the publish |
publish-<pkg>-on-merge.yaml | fires on merged PR with the Release label |
version-bump-<pkg>.yaml | dispatch → opens a version PR labelled Release |
ci-<pkg>-pack.yaml | on PR — typecheck + assert tarball contents |
The pack check must allowlist package.json, LICENSE, and README.md.
npm force-includes all three regardless of the files field, so a guard that
only permits the first two rejects any package that has a readme.
peerDependencies, not devDependencies. A devDependency
tells the consumer nothing../package.json. Tooling reads it; an exports map that omits it
throws ERR_PACKAGE_PATH_NOT_EXPORTED.files against the exports map. Every path in exports must be
covered by files, or the target is simply absent from the tarball. Nothing
catches this at install time — neither npm pack nor npm install resolves
export targets — so it surfaces as a consumer resolution error the first time
something imports that entry.Run the version-bump workflow → it opens a PR labelled Release → merge it →
publish-<pkg>-on-merge publishes and posts to Slack. A manual dispatch at an
already-published version is a no-op: the Check if version already on npm
step finds it and skips. If you want to test the pipeline, you need a new
version number.
This is the step people skip, and it is the only one that finds real problems.
In a different repo — ideally one on npm rather than pnpm, since that is the
path where catalog: would explode:
npm install @comfyorg/<name>Then import it somewhere real, build, and grep the build output to confirm the
thing you imported actually reached the bundle. Import every entry in the
exports map while you are there — a subpath whose target never made it into
the tarball fails only here. A green build proves the import resolved; it does
not prove the values landed. For CSS, point the check at the consumer's own
build output — the path below is Nuxt's, so substitute whatever your consumer
emits:
grep -o -- "--your-token:[^;]*" .output/public/_nuxt/*.cssOpen that consumer change as a PR and keep the preview link — it is the evidence that the publish worked end to end.
Once the package exists, configure it on npmjs.com under package settings:
publish-<pkg>.yaml), not the on-merge wrapper.environment:. A mismatch fails every publish.npm publish only. npm stage publish publishes unlisted pending
manual approval; we do not use it.Then grant OIDC at both workflow layers — the caller job that does
uses: ./.github/workflows/publish-<pkg>.yaml, and the publish job inside the
reusable workflow. A called workflow can never hold more than the calling job
does, so setting this on the inner job alone leaves it with no token and the
publish quietly falls back to NPM_TOKEN:
permissions:
contents: read
id-token: writeKeep NODE_AUTH_TOKEN in place until an OIDC publish has actually succeeded.
[WARN] Skipped OIDC in the log means it silently fell back to the token —
treat that as a failure to chase down, not a warning to scroll past. Suspect
pnpm/action-setup first: every workflow here still pins v4.4.0
(fc06bc1257f339d1d5d8b3a19a8cae5388b55320), the version that broke pnpm's OIDC
publish in pnpm#11513 — closed once
the reporter bumped the action, not by a pnpm release. Only after a real OIDC
publish should you tighten the org to require 2FA and disallow tokens; doing it
earlier removes the only working path.
Post the npm link, the install line, and the consumer PR preview link. "It's published" is not actionable; "here is the import and here is it working" is.
© Comfy-Org, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/publishing-a-new-package of Comfy-Org/ComfyUI_frontend.
Open the folder on GitHubat commit f9be289
Publishing A New Package next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Publishing A New Package this skillComfy-Org/ComfyUI_frontend | 2.1k | — | ~1.8k | Automated safety check: Pass | GPL-3.0 | |
| Create Saleor Packagesaleor/apps | 162 | — | ~608 | Automated safety check: Pass | Custom licence | |
| Creating Luna Appmizchi/luna.mbt | 173 | — | ~1.4k | Automated safety check: Pass | None | |
| Adk Readme WriterBrainDAO/adk-ts | 119 | — | ~2.6k | Automated safety check: Notes | MIT | |
| Add New Packageremotion-dev/remotion | 63k | — | ~777 | Automated safety check: Notes | Custom licence | |
| Nodejs CLI Best Practiceslirantal/nodejs-cli-apps-best-practices | 4.1k | — | ~2k | Automated safety check: Pass | CC-BY-SA-4.0 |
saleor/apps
Scaffold a new shared package in the saleor-apps monorepo under ./packages/.
mizchi/luna.mbt
A skill your agent uses when scaffolding a new standalone CSR app that uses luna (@lunaui/luna) outside the luna.mbt monorepo — running npx @lunaui/luna new, choosing TSX vs MoonBit, or fixing a…
BrainDAO/adk-ts
ADK-TS README specialist. An agent skill from BrainDAO/adk-ts.
remotion-dev/remotion
Add a new package to the Remotion monorepo, including package scaffolding, monorepo registration, documentation, build scripts, and release checklist updates.
lirantal/nodejs-cli-apps-best-practices
Guide and audit Node.js CLI application development against 41 established best practices covering UX, distribution, interoperability, accessibility, testing, error handling, development setup…
handsontable/handsontable
Builds two throwaway HTML test pages for a Handsontable pull request, one on the released CDN version and one on the local build, to compare behavior side by side.
Comfy-Org/ComfyUI_frontend
Adds deprecation warnings for renamed or removed properties/APIs.
Comfy-Org/ComfyUI_frontend
Replay recorded agent conversations as Playwright tests against the real chat panel and canvas.
Comfy-Org/ComfyUI_frontend
Transforms raw Playwright codegen output into ComfyUI convention-compliant tests.
Comfy-Org/ComfyUI_frontend
Dispatches the comment-sicko subagent to hunt gratuitous comments in a PR/diff, triages its raw findings, and posts a polite, professional writeup.
Comfy-Org/ComfyUI_frontend
Diagnoses and fixes flaky Playwright e2e tests by replacing race-prone patterns with retry-safe alternatives.
Comfy-Org/ComfyUI_frontend
Ships performance fixes with CI-proven improvement using stacked PRs.
Works with
Categories
Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo. Publishing A New Package is an agent skill from Comfy-Org/ComfyUI_frontend. Publishes a new package from this monorepo to npm under @comfyorg and proves it is consumable from another repo.
Publishing A New Package fits situations like: adding a package to packages/; publishing to npm for the first time; an npm publish workflow fails.
Run `npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a claude-code`. Or copy the skill folder (.claude/skills/publishing-a-new-package in Comfy-Org/ComfyUI_frontend) into .claude/skills/publishing-a-new-package in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a codex`. Or copy the skill folder (.claude/skills/publishing-a-new-package in Comfy-Org/ComfyUI_frontend) into .agents/skills/publishing-a-new-package in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Comfy-Org/ComfyUI_frontend --skill publishing-a-new-package -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/publishing-a-new-package, .gemini/skills/publishing-a-new-package, .github/skills/publishing-a-new-package and .opencode/skills/publishing-a-new-package in your project.
Going by SKILL.md and its folder, Publishing A New Package needs the command-line tools its instructions call (npm, pnpm and jq) and credentials named NPM_TOKEN and NODE_AUTH_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN; A credential in NODE_AUTH_TOKEN.
SKILL.md names 2 domains. In commands or code: registry.npmjs.org; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Publishing A New Package is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Publishing A New Package: Create Saleor Package (saleor/apps, 162 stars), Creating Luna App (mizchi/luna.mbt, 173 stars), Adk Readme Writer (BrainDAO/adk-ts, 119 stars) and Add New Package (remotion-dev/remotion, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Comfy-Org (a GitHub organization) maintains it in Comfy-Org/ComfyUI_frontend, which has 2,056 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 9, 2026.
Source: Comfy-Org/ComfyUI_frontend on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.