Verdaccio Code Review
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/openiap-workflows .claude/skills/openiap-workflows && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.claude/skills/openiap-workflows into .claude/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hyodotdev/openiap/tree/main/.claude/skills/openiap-workflowsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/openiap-workflows .agents/skills/openiap-workflows && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.claude/skills/openiap-workflows into .agents/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/openiap-workflows .cursor/skills/openiap-workflows && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.claude/skills/openiap-workflows into .cursor/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hyodotdev/openiap.git --path .claude/skills/openiap-workflows--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/openiap-workflows .gemini/skills/openiap-workflows && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.claude/skills/openiap-workflows into .gemini/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hyodotdev/openiap openiap-workflowsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/openiap-workflows .github/skills/openiap-workflows && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.claude/skills/openiap-workflows into .github/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/openiap-workflows .opencode/skills/openiap-workflows && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.claude/skills/openiap-workflows into .opencode/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
openiap-workflowsA skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…
Openiap Workflows is an agent skill from hyodotdev/openiap. Use for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge, verify-all, e2e-tests, stable or prerelease package releases, resolve-issue, commit/push/PR, generated type sync, package-specific checks, GitHub review threads, and project conventions from AGENTS.md.
Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Pull requests, Hooks and plugins and End-to-end testing. It works with GitHub. The repository describes itself as: Standardized protocol for in-app purchases across all platforms — backed by Meta & Amazon. The licence is MIT.
Read from SKILL.md and the folder at commit 64158e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Openiap Workflows loads about 766 tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 270 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hyodotdev/openiap at commit 64158e8, republished under its MIT licence (© hyodotdev). 270 words, ~766 tokens.
.claude/skills/openiap-workflows/SKILL.md (or your agent's skills folder).The canonical workflow definitions live in .claude/commands/*.md and the
shared operating rules live in .codex/skills/openiap-workflows/SKILL.md.
Follow both; this file only adds the Claude Code specifics.
When the user asks in natural language, execute the matching workflow by reading the command file (or invoke the slash command directly when available):
.claude/commands/review-pr.md
(/review-pr), including its single-round Codex fallback when CodeRabbit
cannot review the current head, and its
.claude/skills/review-self/SKILL.md fallback when Codex is unavailable too;
do not invoke other review bots, and remove temporary CodeRabbit trigger and terminal
skip/unavailable top-level comments when the loop is clean.claude/commands/audit-code.md (/audit-code).claude/commands/audit-security.md (/audit-security).claude/commands/audit-iapkit.md (/audit-iapkit).claude/commands/compile-knowledge.md (/compile-knowledge).claude/commands/resolve-issue.md (/resolve-issue).claude/commands/verify-all.md (/verify-all).claude/commands/e2e-tests.md (/e2e-tests).claude/commands/e2e-tests-google.md (/e2e-tests-google).claude/commands/e2e-tests-apple.md (/e2e-tests-apple).claude/commands/release.md (/release).claude/commands/commit.md (/commit).codex/skills/openiap-workflows/SKILL.md and apply them as written; they
are agent-agnostic rules, not Codex-only rules.$skill syntax, the equivalent in Claude Code is
the matching skill in .claude/skills/ or the slash command in
.claude/commands/.review-pr falls back to review-self, follow the canonical
single-round override and leave reviewer requests, thread handling, and
polling ownership with review-pr.© hyodotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/openiap-workflows of hyodotdev/openiap.
Open the folder on GitHubat commit 64158e8
Openiap Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Openiap Workflows this skillhyodotdev/openiap | 154 | — | ~766 | Automated safety check: Pass | MIT | |
| Verdaccio Code Reviewverdaccio/verdaccio | 18k | — | ~853 | Automated safety check: Pass | MIT | |
| Address Issuenubjs/nub | 4.4k | — | ~2.6k | Automated safety check: Pass | MIT | |
| GitHub Actions Hardeninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Simplify And Harden CIpskoett/pskoett-ai-skills | 310 | — | ~1.1k | Automated safety check: Pass | None | |
| Qv Devops PR Reviewtetherto/qvac | 674 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 |
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
nubjs/nub
End-to-end playbook for working a GitHub issue (or bug-fix PR) on nubjs/nub: triage → acknowledge an external report with an "Investigating" comment → reproduce it yourself → SIZE it → fix it at…
github/awesome-copilot
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
pskoett/pskoett-ai-skills
CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).
tetherto/qvac
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
TanStack/ai
Treats bug-fix pull requests as invasive and untrusted. An agent skill from TanStack/ai.
hyodotdev/openiap
Run the full OpenIAP device matrix — six frameworks across iOS, Google Play, Amazon Appstore, Meta Horizon, and VegaOS — driving real hardware over adb and xcrun, and report one row per cell with…
hyodotdev/openiap
A skill your agent uses for OpenIAP documentation generation work, especially the release-note card each PR carries in packages/docs/src/pages/docs/updates/releases.tsx, written as already published…
hyodotdev/openiap
Manage OpenIAP's OpenCollective presence, including profile copy, slug/link migrations, sponsor/backer recognition, update posts, and README/docs sponsor assets.
hyodotdev/openiap
Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.
hyodotdev/openiap
Run the Apple half of the OpenIAP device matrix — six frameworks plus the native package on iOS — on a physical iPhone and report one row per cell with evidence.
hyodotdev/openiap
Run the Android half of the OpenIAP device matrix — six frameworks across Google Play, Amazon Appstore, and Meta Horizon, plus VegaOS — on real hardware and report one row per cell with evidence.
Works with
Categories
A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…. Openiap Workflows is an agent skill from hyodotdev/openiap.md.
Openiap Workflows fits situations like: including review-pr; compile-knowledge; prerelease package releases; generated type sync.
Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-code`. Or copy the skill folder (.claude/skills/openiap-workflows in hyodotdev/openiap) into .claude/skills/openiap-workflows in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a codex`. Or copy the skill folder (.claude/skills/openiap-workflows in hyodotdev/openiap) into .agents/skills/openiap-workflows in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hyodotdev/openiap --skill openiap-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openiap-workflows, .gemini/skills/openiap-workflows, .github/skills/openiap-workflows and .opencode/skills/openiap-workflows in your project.
SKILL.md names no scripts, command-line tools or credentials: Openiap Workflows is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Openiap Workflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 766 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Openiap Workflows: Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Address Issue (nubjs/nub, 4.4k stars), GitHub Actions Hardening (github/awesome-copilot, 40k stars) and Simplify And Harden CI (pskoett/pskoett-ai-skills, 310 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hyodotdev (a GitHub organization) maintains it in hyodotdev/openiap, which has 154 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 6, 2026.
Source: hyodotdev/openiap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.