Agent skill

Verifying Store Release

by gilgold in gilgold/tabox

Use before any Tabox store release — before merging a release branch to main, when asked "are we good to ship / good to go / release-ready", or before publishing to the Chrome Web Store or Edge…

Custom licenceAuto-check: warnings

Install Verifying Store Release

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add gilgold/tabox --skill verifying-store-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gilgold/tabox verifying-store-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gilgold/tabox.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verifying-store-release .claude/skills/verifying-store-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verifying-store-release
GitHub stars
116
Token cost
~1.8k tokens
SKILL.md length
614 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Custom licence

At a glance

Use before any Tabox store release — before merging a release branch to main, when asked "are we good to ship / good to go / release-ready", or before publishing to the Chrome Web Store or Edge…

  • Works in 5 steps: Production, not sandbox → Git identity — gilgold, never gil-wix → No Wix npm registry URLs → …
  • SKILL.md covers Overview, Checklist and Verdict rules
  • Calls yarn, git and gh; reaches clients2.google.com; needs PADDLE_CLIENT_TOKEN and PADDLE_WEBHOOK_SECRET

What it does

Verifying Store Release is an agent skill from gilgold/tabox. Use before any Tabox store release — before merging a release branch to main, when asked "are we good to ship / good to go / release-ready", or before publishing to the Chrome Web Store or Edge Add-ons.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Wix. The repository describes itself as: Tabox is a browser extension for Chrome and Chromium based browsers. It lets you save all your open tabs and groups into a collection that you can later click to reopen.

Example prompts

  • “are we good to ship / good to go / release-ready”
  • “/verifying-store-release”

Requirements

  • A credential in PADDLE_CLIENT_TOKEN
  • A credential in PADDLE_WEBHOOK_SECRET

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Production, not sandbox
  2. Git identity — gilgold, never gil-wix
  3. No Wix npm registry URLs
  4. No secrets in the bundle
  5. Release mechanics

What it can do on your machine

Read from SKILL.md and the folder at commit 4161ada. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • git
    • gh
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • clients2.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PADDLE_CLIENT_TOKEN
    • PADDLE_WEBHOOK_SECRET
    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verifying Store Release loads about 1.8k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 614 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:70
    arn.lock .yarnrc.yml server/.yarnrc.yml .npmrc server/.npmrc 2>/dev/null
  • NoteMentions a .env fileSKILL.md:93
    dled. Local `chrome/api-keys*.json` and `.env*` files are gitignored and not copied (CopyPlugin glob is `chrome/*.js`);

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 614 words (~1,840 tokens).

“Merging to main IS publishing: .github/workflows/release.yml builds and pushes to both stores on every push to main. This checklist is the last gate before that. Run every section; report a verdict only after all commands have actually run.”

— opening of SKILL.md by gilgold, Custom licence
name
verifying-store-release

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/verifying-store-release of gilgold/tabox.

Open the folder on GitHubat commit 4161ada

Compare with similar skills

Verifying Store Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verifying Store Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verifying Store Release this skillgilgold/tabox116—~1.8kAutomated safety check: WarnCustom licence
Engine E2Ewix/react-native-navigation13k—~1.1kAutomated safety check: PassMIT
Linkyee Plugin BuilderZhgChgLi/linkyee180—~1.9kAutomated safety check: NotesMIT
Linkyee Style DesignerZhgChgLi/linkyee180—~4.4kAutomated safety check: NotesMIT
Mergeremotion-dev/remotion63k—~508Automated safety check: PassCustom licence
Merge Upsymfony/symfony31k—~4kAutomated safety check: PassMIT

Similar skills

  • Engine E2E

    wix/react-native-navigation

    Official

    Run Wix Engine (mobile-apps-engine) iOS E2E tests locally to validate RNN changes.

    13k GitHub stars~1.1k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Linkyee Plugin Builder

    ZhgChgLi/linkyee

    A skill your agent uses when the user wants to add dynamic data (GitHub stars, latest blog posts, weather, follower counts, repo activity, anything fetched from a URL) to their linkyee site by…

    180 GitHub stars~1.9k tokensUpdated today
    Writing & ContentAuto-check: notes
  • Linkyee Style Designer

    ZhgChgLi/linkyee

    A skill your agent uses when the user wants to design, customize, or generate a custom visual theme for their linkyee site (a Hexo-like LinkTree-style static site).

    180 GitHub stars~4.4k tokensUpdated today
    Frontend & DesignAuto-check: notes
  • Merge

    remotion-dev/remotion

    Official

    Wait for a Remotion pull request to become mergeable, handle merge conflicts, distinguish genuine CI failures from flakes, rerun flaky checks through the flake skill, and merge the PR.

    63k GitHub stars~508 tokensUpdated today
    DevelopmentAuto-check passed
  • Merge Up

    symfony/symfony

    Cascade-merge maintained Symfony branches from oldest to newest (e.g.

    31k GitHub stars~4k tokensUpdated today
    DevelopmentAuto-check passed
  • Merge

    alirezarezvani/claude-skills

    Merge the winning agent's branch into base, archive losers, and clean up worktrees.

    28k GitHub stars~587 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

Works with

Questions about Verifying Store Release

What does Verifying Store Release do?

Use before any Tabox store release — before merging a release branch to main, when asked "are we good to ship / good to go / release-ready", or before publishing to the Chrome Web Store or Edge…. Verifying Store Release is an agent skill from gilgold/tabox. Use before any Tabox store release — before merging a release branch to main, when asked "are we good to ship / good to go / release-ready", or before publishing to the Chrome Web Store or Edge Add-ons.

How do I install Verifying Store Release in Claude Code?

Run `npx skills add gilgold/tabox --skill verifying-store-release -a claude-code`. Or copy the skill folder (.claude/skills/verifying-store-release in gilgold/tabox) into .claude/skills/verifying-store-release in your project. Claude Code loads it when a task matches its description.

How do I install Verifying Store Release in Codex?

Run `npx skills add gilgold/tabox --skill verifying-store-release -a codex`. Or copy the skill folder (.claude/skills/verifying-store-release in gilgold/tabox) into .agents/skills/verifying-store-release in your project. Codex loads it when a task matches its description.

Can I use Verifying Store Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gilgold/tabox --skill verifying-store-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verifying-store-release, .gemini/skills/verifying-store-release, .github/skills/verifying-store-release and .opencode/skills/verifying-store-release in your project.

What does Verifying Store Release need to run?

Going by SKILL.md and its folder, Verifying Store Release needs the command-line tools its instructions call (yarn, git, gh and curl) and credentials named PADDLE_CLIENT_TOKEN, PADDLE_WEBHOOK_SECRET and JWT_SECRET. Our summary lists: A credential in PADDLE_CLIENT_TOKEN; A credential in PADDLE_WEBHOOK_SECRET.

Does Verifying Store Release access the network?

SKILL.md names 1 domain. In commands or code: clients2.google.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Verifying Store Release safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Verifying Store Release use?

Verifying Store Release has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Verifying Store Release use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verifying Store Release?

Skills that share tags, products or a category with Verifying Store Release: Engine E2E (wix/react-native-navigation, 13k stars), Linkyee Plugin Builder (ZhgChgLi/linkyee, 180 stars), Linkyee Style Designer (ZhgChgLi/linkyee, 180 stars) and Merge (remotion-dev/remotion, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verifying Store Release?

gilgold (a GitHub user) maintains it in gilgold/tabox, which has 116 GitHub stars. The repository was last updated on September 29, 2026.

Source: gilgold/tabox on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.