Git Workflow and Versioning
addyosmani/agent-skills
Sets git habits for every change: short-lived branches, atomic commits with descriptive messages, clean pull requests, plus versioning, tagging and changelogs for releases.
Run OpenIAP's complete change-to-production loop from the latest origin/main: implement and verify with the docs and release note in the PR, stabilize with review-self, open and review a PR until…
$ npx skills add hyodotdev/openiap --skill loop-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hyodotdev/openiap loop-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/loop-review .claude/skills/loop-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "loop-review" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/loop-review into .claude/skills/loop-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loop-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hyodotdev/openiap/tree/main/.codex/skills/loop-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hyodotdev/openiap --skill loop-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hyodotdev/openiap loop-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/loop-review .agents/skills/loop-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "loop-review" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/loop-review into .agents/skills/loop-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loop-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hyodotdev/openiap --skill loop-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hyodotdev/openiap loop-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/loop-review .cursor/skills/loop-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "loop-review" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/loop-review into .cursor/skills/loop-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loop-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hyodotdev/openiap.git --path .codex/skills/loop-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hyodotdev/openiap --skill loop-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hyodotdev/openiap loop-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/loop-review .gemini/skills/loop-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "loop-review" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/loop-review into .gemini/skills/loop-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loop-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hyodotdev/openiap loop-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hyodotdev/openiap --skill loop-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/loop-review .github/skills/loop-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "loop-review" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/loop-review into .github/skills/loop-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loop-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hyodotdev/openiap --skill loop-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hyodotdev/openiap loop-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/loop-review .opencode/skills/loop-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "loop-review" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/loop-review into .opencode/skills/loop-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "loop-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
loop-reviewRun OpenIAP's complete change-to-production loop from the latest origin/main: implement and verify with the docs and release note in the PR, stabilize with review-self, open and review a PR until…
Loop Review is an agent skill from hyodotdev/openiap. Run OpenIAP's complete change-to-production loop from the latest origin/main: implement and verify with the docs and release note in the PR, stabilize with review-self, open and review a PR until its exact head is clean, merge, return to an exact clean main, release affected stable packages sequentially, verify the release note, and deploy production docs.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Development, covering Changelog and release notes and Pull requests. It works with Git. The repository describes itself as: Standardized protocol for in-app purchases across all platforms — backed by Meta & Amazon. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 64158e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Loop Review loads about 2.9k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 1,642 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hyodotdev/openiap at commit 64158e8, republished under its MIT licence (© hyodotdev). 1,642 words, ~2,924 tokens.
.claude/skills/loop-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Own one OpenIAP change from a fresh main baseline through verified production
delivery. Use the repository workflows as SSOT instead of duplicating their
detailed commands.
Read these before acting:
AGENTS.md.codex/skills/openiap-workflows/SKILL.md.codex/skills/review-self/SKILL.md.codex/skills/ship-release/SKILL.md.codex/skills/generate-doc/SKILL.md.claude/commands/commit.md.claude/commands/review-pr.md.claude/commands/release.mdCheck what the change touches before reading any of them from the branch:
git diff --name-only "$(git merge-base origin/main HEAD)"..HEADIf the change is in scope of "A PR Must Not Rewrite The Rules That Judge It" in
.claude/commands/review-pr.md, read every file above — and that section
itself — from the recorded merge base for the whole run. That section defines
the scope; do not restate it here.
Load package conventions and specialized skills required by the changed paths
the same way.
An explicit $loop-review invocation or explicit natural-language request for
this complete loop authorizes the in-scope commit, push, PR, review replies,
thread resolution, merge, affected stable package releases, release-note and
workflow-documentation commits directly to main, and production docs
deployment. It does not authorize
prereleases, unrelated cleanup, destructive recovery, or product-code commits
directly to main.
Before editing task files:
git status --short --branch. Preserve every existing change.git fetch origin, switch
to main, and run git pull --ff-only --no-tags origin main.main equals origin/main, then create a semantic branch named
according to .claude/commands/commit.md.Never start new implementation on a stale local main. If invoked for work
already in progress, do not manually switch branches, stash, reset, or discard
it. Treat that as a resumed loop, verify its recorded or merge-base baseline,
and use the repository's guarded rebase-main workflow when an update from
origin/main is needed; that workflow owns its safeguard stash and branch
transitions. Stop for direction if an update would overwrite unrelated user
work.
Implement the requested scope and run the checks required by each touched path.
Keep generated files, documentation, previews, and knowledge context in sync
through their canonical workflows. A change to a published package also updates
the guides it affects and the release card for the next version, written as
already published with $generate-doc. Apply
knowledge/internal/05-docs-patterns.md#release-note-completeness-gate before
opening the PR and after scope changes. Do not proceed while the working diff
has a known failing required check.
Once it works, clean it up before review: apply "Clean Up Once It Works" in
knowledge/internal/03-coding-style.md to the diff and to smells met along the
way, without waiting to be asked, then rerun the affected checks.
Run $review-self immediately against the complete base-to-working-tree diff.
Fix every validated in-scope finding and rerun affected verification. Continue
with five-minute recurring wake-ups until two consecutive complete snapshots are
clean, as defined by the review-self skill.
Do not emulate recurring review with a shell sleep loop. Keep the loop state out of tracked files. Any material diff change resets the consecutive-clean count.
Follow .claude/commands/commit.md --all --pr:
main.Record the PR number and exact head SHA. A push invalidates all prior clean review coverage.
Run .claude/commands/review-pr.md immediately, then re-enter it every five
minutes through the product's recurring wake-up mechanism.
For every round:
review-pr, and $review-self only if Codex is unavailable too;
never substitute a review bot that posts to the PR.Clean means all of the following hold for the same head SHA, judged by the criteria on the merge base when the branch edits them:
$review-self when Codex is unavailable too;Device-backed regression needs real hardware, store accounts, and sandbox purchases, so this loop cannot run it unattended. Decide whether the change requires it before merging, not after.
Require $e2e-tests when the diff touches any of:
packages/apple/, packages/google/, or packages/kit/;libraries/<sdk>/ implementation, example app, or podspec/gradle/csproj
manifest;specs/client/src/*.graphql or the generated types synced from it;When it is required, stop without merging even if the PR is otherwise clean. Report the exact regression-matrix rows the diff implicates and hand back to the user. The loop does not merge such a change on its own authority.
Exactly two things clear the gate, and both are recorded on the PR before any merge:
$e2e-tests run covering the implicated rows, with its result posted.A clean CI run is not a substitute: CI does not exercise purchase dialogs, store accounts, or device wiring.
When it is not required, say so explicitly in the final report and name the paths that justify it. Silence here reads as an untested merge.
A change confined to documentation, repository automation, agent workflows, or release/security tooling does not need device regression.
Immediately before merging, refetch the PR and confirm its head still equals the clean reviewed SHA. Use the repository-supported merge method, defaulting to a squash merge with branch deletion when no stricter policy applies. Never bypass branch protection or merge a stale, pending, or failing head.
After merge:
MERGED and record the merge commit.review-pr.git branch -D after that proof; never use
it for an unverified branch or discard unrelated work.main, fetch origin/main, and run
git pull --ff-only --no-tags origin main only when doing so cannot disturb
other work.HEAD equals origin/main and the worktree is clean before any
release action.Follow .codex/skills/ship-release/SKILL.md as the release SSOT:
openiap-versions.json.main; after each release-bot
commit, fast-forward main again. Do not start the next release until the
GitHub Release and public registry or downloadable artifact are verified.$generate-doc, then run $review-self over that
docs diff until two consecutive five-minute snapshots are clean. Any edit
resets the count.main. If review finds a product-code fix, return it to the PR
loop instead of committing that fix directly to main. Do not open a PR for
this post-release docs-only commit.main equal to origin/main, run npm run deploy, then
verify the production release page and generated documentation assets.main, fast-forward once more if a release workflow changed it,
and verify HEAD == origin/main with a clean worktree.ship-release before ending the loop.Report the PR, merge commit, final checks, review coverage, released and skipped packages, public registry evidence, docs commit and deployment, shipped-comment URLs, and any remaining manual follow-up.
Stop without merging when a required choice lacks authority, the same finding survives two fix attempts, an access blocker repeats under the source workflow's threshold, the change requires device regression that has not been run, or the exact head cannot satisfy the clean gate. Report the concrete blocker; never describe a pending or partially reviewed PR as clean.
After merge, stop the shipping phase when an affected release fails, its public
artifact cannot be verified, production docs cannot be verified, or continuing
would require a code change outside the reviewed PR. Preserve every successful
release and report the exact resume point. If the user requests docs before
package publication, use the explicit flag documented in
knowledge/internal/06-git-deployment.md#deploying-documentation. If the train
will not resume, trim the card to what published through steps 4 and 5 first.
© hyodotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/loop-review of hyodotdev/openiap.
Open the folder on GitHubat commit 64158e8
Loop Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Loop Review this skillhyodotdev/openiap | 154 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Git Workflow and Versioningaddyosmani/agent-skills | 102k | 2 repos | ~3.5k | Automated safety check: Notes | MIT | |
| Verdaccio Pull Request Workflowverdaccio/verdaccio | 18k | — | ~1.9k | Automated safety check: Pass | MIT | |
| pybind11 Release Preparationpybind/pybind11 | 18k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| AionUi Version BumpiOfficeAI/AionUi | 33k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| ScottPlot Changelog EntryScottPlot/ScottPlot | 6.8k | — | ~366 | Automated safety check: Pass | MIT |
addyosmani/agent-skills
Sets git habits for every change: short-lived branches, atomic commits with descriptive messages, clean pull requests, plus versioning, tagging and changelogs for releases.
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
pybind/pybind11
Opens the pybind11 release-preparation pull request: picking the release base, bumping the version in common.h and integrating the changelog, following docs/release.rst.
iOfficeAI/AionUi
Automates an AionUi release: checks the latest AionCore release and its artifacts, updates package.json, writes the changelog, opens a PR and tags the release.
ScottPlot/ScottPlot
Adds or updates a single concise changelog bullet in CHANGELOG.md for exactly the current branch's ScottPlot pull request, leaving all other text untouched.
icebear0828/codex-proxy
Package the current working changes into a standards-compliant codex-proxy pull request: branch hygiene, commit message linting, CHANGELOG prompt, conventional commit, push, and gh pr create against…
hyodotdev/openiap
Run the full OpenIAP device matrix — six frameworks across iOS, Google Play, Amazon Appstore, Meta Horizon, and VegaOS — driving real hardware over adb and xcrun, and report one row per cell with…
hyodotdev/openiap
A skill your agent uses for OpenIAP documentation generation work, especially the release-note card each PR carries in packages/docs/src/pages/docs/updates/releases.tsx, written as already published…
hyodotdev/openiap
Manage OpenIAP's OpenCollective presence, including profile copy, slug/link migrations, sponsor/backer recognition, update posts, and README/docs sponsor assets.
hyodotdev/openiap
Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.
hyodotdev/openiap
Run the Apple half of the OpenIAP device matrix — six frameworks plus the native package on iOS — on a physical iPhone and report one row per cell with evidence.
hyodotdev/openiap
Run the Android half of the OpenIAP device matrix — six frameworks across Google Play, Amazon Appstore, and Meta Horizon, plus VegaOS — on real hardware and report one row per cell with evidence.
Works with
Categories
Run OpenIAP's complete change-to-production loop from the latest origin/main: implement and verify with the docs and release note in the PR, stabilize with review-self, open and review a PR until…. Loop Review is an agent skill from hyodotdev/openiap. Run OpenIAP's complete change-to-production loop from the latest origin/main: implement and verify with the docs and release note in the PR, stabilize with review-self, open and review a PR until its exact head is clean, merge, return to an exact clean main, release affected stable packages sequentially, verify the release note, and deploy production docs.
Loop Review fits situations like: tasks that involve Changelog and release notes; tasks that involve Pull requests.
Run `npx skills add hyodotdev/openiap --skill loop-review -a claude-code`. Or copy the skill folder (.codex/skills/loop-review in hyodotdev/openiap) into .claude/skills/loop-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hyodotdev/openiap --skill loop-review -a codex`. Or copy the skill folder (.codex/skills/loop-review in hyodotdev/openiap) into .agents/skills/loop-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hyodotdev/openiap --skill loop-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/loop-review, .gemini/skills/loop-review, .github/skills/loop-review and .opencode/skills/loop-review in your project.
Going by SKILL.md and its folder, Loop Review needs the command-line tools its instructions call (git and npm).
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Loop Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Loop Review: Git Workflow and Versioning (addyosmani/agent-skills, 102k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), pybind11 Release Preparation (pybind/pybind11, 18k stars) and AionUi Version Bump (iOfficeAI/AionUi, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hyodotdev (a GitHub organization) maintains it in hyodotdev/openiap, which has 154 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 6, 2026.
Source: hyodotdev/openiap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.