Frontmcp Production Readiness
agentfront/frontmcp
Pre-production audit, hardening, and go-live checklists for FrontMCP servers.
Step-by-step release checklist for Squad — prevents v0.8.22-style disasters
$ npx skills add FritzAndFriends/SharpSite --skill release-process -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install FritzAndFriends/SharpSite release-process --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/FritzAndFriends/SharpSite.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.copilot/skills/release-process .claude/skills/release-process && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release-process" agent skill from https://github.com/FritzAndFriends/SharpSite/tree/main/.copilot/skills/release-process into .claude/skills/release-process/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-process", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/FritzAndFriends/SharpSite/tree/main/.copilot/skills/release-processType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add FritzAndFriends/SharpSite --skill release-process -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install FritzAndFriends/SharpSite release-process --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FritzAndFriends/SharpSite.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.copilot/skills/release-process .agents/skills/release-process && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release-process" agent skill from https://github.com/FritzAndFriends/SharpSite/tree/main/.copilot/skills/release-process into .agents/skills/release-process/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-process", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FritzAndFriends/SharpSite --skill release-process -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install FritzAndFriends/SharpSite release-process --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FritzAndFriends/SharpSite.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.copilot/skills/release-process .cursor/skills/release-process && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release-process" agent skill from https://github.com/FritzAndFriends/SharpSite/tree/main/.copilot/skills/release-process into .cursor/skills/release-process/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-process", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/FritzAndFriends/SharpSite.git --path .copilot/skills/release-process--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add FritzAndFriends/SharpSite --skill release-process -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install FritzAndFriends/SharpSite release-process --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FritzAndFriends/SharpSite.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.copilot/skills/release-process .gemini/skills/release-process && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release-process" agent skill from https://github.com/FritzAndFriends/SharpSite/tree/main/.copilot/skills/release-process into .gemini/skills/release-process/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-process", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install FritzAndFriends/SharpSite release-processInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add FritzAndFriends/SharpSite --skill release-process -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/FritzAndFriends/SharpSite.git skills-src && mkdir -p .github/skills && cp -r skills-src/.copilot/skills/release-process .github/skills/release-process && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release-process" agent skill from https://github.com/FritzAndFriends/SharpSite/tree/main/.copilot/skills/release-process into .github/skills/release-process/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-process", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FritzAndFriends/SharpSite --skill release-process -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install FritzAndFriends/SharpSite release-process --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FritzAndFriends/SharpSite.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.copilot/skills/release-process .opencode/skills/release-process && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release-process" agent skill from https://github.com/FritzAndFriends/SharpSite/tree/main/.copilot/skills/release-process into .opencode/skills/release-process/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-process", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
release-processStep-by-step release checklist for Squad — prevents v0.8.22-style disasters
Release Process is an agent skill from FritzAndFriends/SharpSite. Step-by-step release checklist for Squad — prevents v0.8.22-style disasters
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Deployment and Feature launches and release readiness. It works with npm. The repository describes itself as: A basic CMS built with .NET 9 and Blazor. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c35e5e0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmghnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NPM_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Release Process loads about 3.3k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 1,173 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from FritzAndFriends/SharpSite at commit c35e5e0, republished under its MIT licence (© FritzAndFriends). 1,173 words, ~3,300 tokens.
.claude/skills/release-process/SKILL.md (or your agent's skills folder).This is the definitive release runbook for Squad. Born from the v0.8.22 release disaster (4-part semver mangled by npm, draft release never triggered publish, wrong NPM_TOKEN type, 6+ hours of broken latest dist-tag).
Rule: No agent releases Squad without following this checklist. No exceptions. No improvisation.
Before starting ANY release work, validate the following:
Rule: Only 3-part semver (major.minor.patch) or prerelease (major.minor.patch-tag.N) are valid. 4-part versions (0.8.21.4) are NOT valid semver and npm will mangle them.
# Check version is valid semver
node -p "require('semver').valid('0.8.22')"
# Output: '0.8.22' = valid
# Output: null = INVALID, STOP
# For prerelease versions
node -p "require('semver').valid('0.8.23-preview.1')"
# Output: '0.8.23-preview.1' = validIf semver.valid() returns null: STOP. Fix the version. Do NOT proceed.
Rule: NPM_TOKEN must be an Automation token (no 2FA required). User tokens with 2FA will fail in CI with EOTP errors.
# Check token type (requires npm CLI authenticated)
npm token listLook for:
read-write tokens with NO 2FA requirement = Automation token (correct)How to create an Automation token:
NPM_TOKENIf using a User token: STOP. Create an Automation token first.
Rule: Release from main branch. Ensure clean state, no uncommitted changes, latest from origin.
# Ensure on main and clean
git checkout main
git pull origin main
git status # Should show: "nothing to commit, working tree clean"
# Check tag doesn't already exist
git tag -l "v0.8.22"
# Output should be EMPTY. If tag exists, release already done or collision.If tag exists: STOP. Either release was already done, or there's a collision. Investigate before proceeding.
Rule: bump-build.mjs is for dev builds ONLY. It must NOT run during release builds (it increments build numbers, creating 4-part versions).
# Set env var to skip bump-build.mjs
export SKIP_BUILD_BUMP=1
# Verify it's set
echo $SKIP_BUILD_BUMP
# Output: 1For Windows PowerShell:
$env:SKIP_BUILD_BUMP = "1"If not set: bump-build.mjs will run and mutate versions. This causes disasters (see v0.8.22).
Update version in all 3 package.json files (root + both workspaces) in lockstep.
# Set target version (no 'v' prefix)
VERSION="0.8.22"
# Validate it's valid semver BEFORE proceeding
node -p "require('semver').valid('$VERSION')"
# Must output the version string, NOT null
# Update all 3 package.json files
npm version $VERSION --workspaces --include-workspace-root --no-git-tag-version
# Verify all 3 match
grep '"version"' package.json packages/squad-sdk/package.json packages/squad-cli/package.json
# All 3 should show: "version": "0.8.22"Checkpoint: All 3 package.json files have identical versions. Run semver.valid() one more time to be sure.
# Commit version bump
git add package.json packages/squad-sdk/package.json packages/squad-cli/package.json
git commit -m "chore: bump version to $VERSION
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>"
# Create tag (with 'v' prefix)
git tag -a "v$VERSION" -m "Release v$VERSION"
# Push commit and tag
git push origin main
git push origin "v$VERSION"Checkpoint: Tag created and pushed. Verify with git tag -l "v$VERSION".
CRITICAL: Release must be published, NOT draft. Draft releases don't trigger publish.yml workflow.
# Create GitHub Release (NOT draft)
gh release create "v$VERSION" \
--title "v$VERSION" \
--notes "Release notes go here" \
--latest
# Verify release is PUBLISHED (not draft)
gh release view "v$VERSION"
# Output should NOT contain "(draft)"If output contains (draft): STOP. Delete the release and recreate without --draft flag.
# If you accidentally created a draft, fix it:
gh release edit "v$VERSION" --draft=falseCheckpoint: Release is published (NOT draft). The release: published event fired and triggered publish.yml.
The publish.yml workflow should start automatically within 10 seconds of release creation.
# Watch workflow runs
gh run list --workflow=publish.yml --limit 1
# Get detailed status
gh run view --logExpected flow:
publish-sdk job runs → publishes @bradygaster/squad-sdkpublish-cli job runs → publishes @bradygaster/squad-cliIf workflow fails: Check the logs. Common issues:
Checkpoint: Both jobs succeeded. Workflow shows green checkmarks.
Manually verify both packages are on npm with correct latest dist-tag.
# Check SDK
npm view @bradygaster/squad-sdk version
# Output: 0.8.22
npm dist-tag ls @bradygaster/squad-sdk
# Output should show: latest: 0.8.22
# Check CLI
npm view @bradygaster/squad-cli version
# Output: 0.8.22
npm dist-tag ls @bradygaster/squad-cli
# Output should show: latest: 0.8.22If versions don't match: Something went wrong. Check workflow logs. DO NOT proceed with GitHub Release announcement until npm is correct.
Checkpoint: Both packages show correct version. latest dist-tags point to the new version.
Verify packages can be installed from npm (real-world smoke test).
# Create temp directory
mkdir /tmp/squad-release-test && cd /tmp/squad-release-test
# Test SDK installation
npm init -y
npm install @bradygaster/squad-sdk
node -p "require('@bradygaster/squad-sdk/package.json').version"
# Output: 0.8.22
# Test CLI installation
npm install -g @bradygaster/squad-cli
squad --version
# Output: 0.8.22
# Cleanup
cd -
rm -rf /tmp/squad-release-testIf installation fails: npm registry issue or package metadata corruption. DO NOT announce release until this works.
Checkpoint: Both packages install cleanly. Versions match.
After main release, sync dev to the next preview version.
# Checkout dev
git checkout dev
git pull origin dev
# Bump to next preview version (e.g., 0.8.23-preview.1)
NEXT_VERSION="0.8.23-preview.1"
# Validate semver
node -p "require('semver').valid('$NEXT_VERSION')"
# Must output the version string, NOT null
# Update all 3 package.json files
npm version $NEXT_VERSION --workspaces --include-workspace-root --no-git-tag-version
# Commit
git add package.json packages/squad-sdk/package.json packages/squad-cli/package.json
git commit -m "chore: bump dev to $NEXT_VERSION
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>"
# Push
git push origin devCheckpoint: dev branch now shows next preview version. Future dev builds will publish to @preview dist-tag.
If publish.yml workflow fails or needs to be bypassed, use workflow_dispatch to manually trigger publish.
# Trigger manual publish
gh workflow run publish.yml -f version="0.8.22"
# Monitor the run
gh run watchRule: Only use this if automated publish failed. Always investigate why automation failed and fix it for next release.
If a release is broken and needs to be rolled back:
WARNING: npm unpublish is time-limited (24 hours) and leaves the version slot burned. Only use if version is critically broken.
# Unpublish (requires npm owner privileges)
npm unpublish @bradygaster/squad-sdk@0.8.22
npm unpublish @bradygaster/squad-cli@0.8.22Preferred approach: Mark version as deprecated, publish a hotfix.
# Deprecate broken version
npm deprecate @bradygaster/squad-sdk@0.8.22 "Broken release, use 0.8.22.1 instead"
npm deprecate @bradygaster/squad-cli@0.8.22 "Broken release, use 0.8.22.1 instead"
# Publish hotfix version
# (Follow this runbook with version 0.8.22.1)# Delete GitHub Release
gh release delete "v0.8.22" --yes
# Delete tag locally and remotely
git tag -d "v0.8.22"
git push origin --delete "v0.8.22"# Revert version bump commit
git checkout main
git revert HEAD
git push origin mainCheckpoint: Tag and release deleted. main branch reverted. npm packages deprecated or unpublished.
Symptom: Workflow fails with EOTP error.
Root cause: NPM_TOKEN is a User token with 2FA enabled. CI can't provide OTP.
Fix: Replace NPM_TOKEN with an Automation token (no 2FA). See "NPM_TOKEN Verification" above.
Symptom: Verify step fails with 404 even though publish succeeded.
Root cause: npm registry propagation delay (5-30 seconds).
Fix: Verify step now has retry loop (5 attempts, 15s interval). Should auto-resolve. If not, wait 2 minutes and re-run workflow.
Symptom: Verify step fails with "Package version (X) does not match target version (Y)".
Root cause: package.json version doesn't match the tag version.
Fix: Ensure all 3 package.json files were updated in Step 1. Re-run npm version if needed.
Symptom: Published version on npm doesn't match package.json (e.g., 0.8.21.4 became 0.8.2-1.4).
Root cause: 4-part versions are NOT valid semver. npm's parser misinterprets them.
Fix: NEVER use 4-part versions. Only 3-part (0.8.22) or prerelease (0.8.23-preview.1). Run semver.valid() before ANY commit.
Symptom: Release created but publish.yml never ran.
Root cause: Release was created as a draft. Draft releases don't emit release: published event.
Fix: Edit release and change to published: gh release edit "v$VERSION" --draft=false. Workflow should trigger immediately.
Before starting ANY release, confirm:
node -p "require('semver').valid('VERSION')" returns the version string (NOT null)npm token list shows read-write without OTP requirementgit status shows "nothing to commit, working tree clean"git tag -l "vVERSION" returns emptySKIP_BUILD_BUMP=1 is set: echo $SKIP_BUILD_BUMP returns 1Before creating GitHub Release:
grep '"version"' package.json packages/*/package.jsongit log origin/main..main returns emptygit ls-remote --tags origin vVERSION returns the tag SHAAfter GitHub Release:
gh release view "vVERSION" output doesn't contain "(draft)"gh run list --workflow=publish.yml --limit 1 shows "in_progress"After workflow completes:
npm view @bradygaster/squad-sdk version returns correct versionnpm view @bradygaster/squad-cli version returns correct versionlatest tags correct: npm dist-tag ls @bradygaster/squad-sdk shows latest: VERSIONnpm install @bradygaster/squad-cli succeedsAfter dev sync:
git show dev:package.json | grep version shows next previewThis skill was created after the v0.8.22 release disaster. Full retrospective: .squad/decisions/inbox/keaton-v0822-retrospective.md
Key learnings:
Never again.
© FritzAndFriends, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .copilot/skills/release-process of FritzAndFriends/SharpSite.
Open the folder on GitHubat commit c35e5e0
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in FritzAndFriends/SharpSite, which our catalogue first saw on October 7, 2026.
Release Process next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Release Process this skillFritzAndFriends/SharpSite | 145 | 1 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Frontmcp Production Readinessagentfront/frontmcp | 146 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 | |
| Release MaintainerUndertone0809/rudder | 292 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Devops Rollout Plangithub/awesome-copilot | 40k | 1 repos | ~999 | Automated safety check: Pass | MIT | |
| Release Engineeringmajiayu000/spellbook | 286 | — | ~511 | Automated safety check: Pass | MIT | |
| Release Readinesspetrkindlmann/qa-skills | 165 | — | ~6.7k | Automated safety check: Pass | MIT |
agentfront/frontmcp
Pre-production audit, hardening, and go-live checklists for FrontMCP servers.
Undertone0809/rudder
A skill your agent uses when inspecting, preparing, executing, recovering, or verifying Rudder releases across npm, GitHub Releases, Desktop assets, tags, dist-tags, changelogs, Discord…
github/awesome-copilot
Generate comprehensive rollout plans with preflight checks, step-by-step deployment, verification signals, rollback procedures, and communication plans for infrastructure and application changes
majiayu000/spellbook
Plan and verify software releases with versioning, changelogs, release branches, feature flags, canaries, migration gates, rollback, deployment checks, and release readiness.
petrkindlmann/qa-skills
Validate release readiness with evidence-based go/no-go decisions.
Myriad-Dreamin/typst.ts
Guide Reflexo/typst.ts release preparation and operator handoffs.
FritzAndFriends/SharpSite
How to write comprehensive architectural proposals that drive alignment before code is written
FritzAndFriends/SharpSite
Platform detection and adaptive spawning for CLI vs VS Code vs other surfaces
FritzAndFriends/SharpSite
How to coordinate with squads on different machines using git as transport
FritzAndFriends/SharpSite
Microsoft Style Guide + Squad-specific documentation patterns
FritzAndFriends/SharpSite
Shifts Layer 3 model selection to cost-optimized alternatives when economy mode is active.
FritzAndFriends/SharpSite
PAO workflow for scanning, drafting, and presenting community responses with human review gate
Works with
Step-by-step release checklist for Squad — prevents v0.8.22-style disasters. Release Process is an agent skill from FritzAndFriends/SharpSite.
Release Process fits situations like: tasks that involve Deployment; tasks that involve Feature launches and release readiness.
Run `npx skills add FritzAndFriends/SharpSite --skill release-process -a claude-code`. Or copy the skill folder (.copilot/skills/release-process in FritzAndFriends/SharpSite) into .claude/skills/release-process in your project. Claude Code loads it when a task matches its description.
Run `npx skills add FritzAndFriends/SharpSite --skill release-process -a codex`. Or copy the skill folder (.copilot/skills/release-process in FritzAndFriends/SharpSite) into .agents/skills/release-process in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FritzAndFriends/SharpSite --skill release-process -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-process, .gemini/skills/release-process, .github/skills/release-process and .opencode/skills/release-process in your project.
Going by SKILL.md and its folder, Release Process needs the command-line tools its instructions call (git, npm, gh and node) and credentials named NPM_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN.
SKILL.md contains no URLs. Its commands use git, npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Release Process is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Release Process: Frontmcp Production Readiness (agentfront/frontmcp, 146 stars), Release Maintainer (Undertone0809/rudder, 292 stars), Devops Rollout Plan (github/awesome-copilot, 40k stars) and Release Engineering (majiayu000/spellbook, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
FritzAndFriends (a GitHub organization) maintains it in FritzAndFriends/SharpSite, which has 145 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on April 30, 2026.
Source: FritzAndFriends/SharpSite on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.