Agent skill

Openiap Workflows

by hyodotdev in hyodotdev/openiap

A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…

MITAuto-check passedAgent Workflows

Install Openiap Workflows

skills CLI
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hyodotdev/openiap openiap-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/openiap-workflows .claude/skills/openiap-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openiap-workflows
GitHub stars
154
Token cost
~766 tokens
SKILL.md length
270 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…

  • Including review-pr
  • SKILL.md covers Command Mapping and Claude Code Notes
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Compile-knowledge

What it does

Openiap Workflows is an agent skill from hyodotdev/openiap. Use for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge, verify-all, e2e-tests, stable or prerelease package releases, resolve-issue, commit/push/PR, generated type sync, package-specific checks, GitHub review threads, and project conventions from AGENTS.md.

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Pull requests, Hooks and plugins and End-to-end testing. It works with GitHub. The repository describes itself as: Standardized protocol for in-app purchases across all platforms — backed by Meta & Amazon. The licence is MIT.

When your agent uses it

  • Including review-pr
  • Compile-knowledge
  • Prerelease package releases
  • Generated type sync

Example prompts

  • “/openiap-workflows”

What it can do on your machine

Read from SKILL.md and the folder at commit 64158e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openiap Workflows loads about 766 tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~766

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hyodotdev/openiap at commit 64158e8, republished under its MIT licence (© hyodotdev). 270 words, ~766 tokens.

Download SKILL.mdSave it as .claude/skills/openiap-workflows/SKILL.md (or your agent's skills folder).
name
openiap-workflows
description
Use for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge, verify-all, e2e-tests, stable or prerelease package releases, resolve-issue, commit/push/PR, generated type sync, package-specific checks, GitHub review threads, and project conventions from AGENTS.md.

OpenIAP Workflows (Claude Code)

The canonical workflow definitions live in .claude/commands/*.md and the shared operating rules live in .codex/skills/openiap-workflows/SKILL.md. Follow both; this file only adds the Claude Code specifics.

Command Mapping

When the user asks in natural language, execute the matching workflow by reading the command file (or invoke the slash command directly when available):

  • Review PR comments / fix review feedback → .claude/commands/review-pr.md (/review-pr), including its single-round Codex fallback when CodeRabbit cannot review the current head, and its .claude/skills/review-self/SKILL.md fallback when Codex is unavailable too; do not invoke other review bots, and remove temporary CodeRabbit trigger and terminal skip/unavailable top-level comments when the loop is clean
  • Audit code against knowledge rules → .claude/commands/audit-code.md (/audit-code)
  • Audit supply-chain security / SBOM → .claude/commands/audit-security.md (/audit-security)
  • Reconcile IAPKit with OpenIAP → .claude/commands/audit-iapkit.md (/audit-iapkit)
  • Compile knowledge / rebuild AI context → .claude/commands/compile-knowledge.md (/compile-knowledge)
  • Resolve a GitHub issue → .claude/commands/resolve-issue.md (/resolve-issue)
  • Verify all / monorepo health check → .claude/commands/verify-all.md (/verify-all)
  • Device-backed E2E regression → .claude/commands/e2e-tests.md (/e2e-tests)
  • Android device-backed E2E regression → .claude/commands/e2e-tests-google.md (/e2e-tests-google)
  • Apple device-backed E2E regression → .claude/commands/e2e-tests-apple.md (/e2e-tests-apple)
  • Stable or RC/next releases → .claude/commands/release.md (/release)
  • Commit, push, or create PR → .claude/commands/commit.md (/commit)

Claude Code Notes

  • Read the "Source Of Truth", "Internal Workflow Change Guard", "Non-Negotiables", and "GitHub Review Threads" sections of .codex/skills/openiap-workflows/SKILL.md and apply them as written; they are agent-agnostic rules, not Codex-only rules.
  • Where that file says to use the Codex Chrome Extension, use Claude's browser tooling (Claude in Chrome / Playwright) instead.
  • Where that file mentions $skill syntax, the equivalent in Claude Code is the matching skill in .claude/skills/ or the slash command in .claude/commands/.
  • When review-pr falls back to review-self, follow the canonical single-round override and leave reviewer requests, thread handling, and polling ownership with review-pr.

© hyodotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/openiap-workflows of hyodotdev/openiap.

Open the folder on GitHubat commit 64158e8

Compare with similar skills

Openiap Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openiap Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openiap Workflows this skillhyodotdev/openiap154—~766Automated safety check: PassMIT
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT
Address Issuenubjs/nub4.4k—~2.6kAutomated safety check: PassMIT
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Simplify And Harden CIpskoett/pskoett-ai-skills310—~1.1kAutomated safety check: PassNone
Qv Devops PR Reviewtetherto/qvac674—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated today
    DevelopmentAuto-check passed
  • Address Issue

    nubjs/nub

    End-to-end playbook for working a GitHub issue (or bug-fix PR) on nubjs/nub: triage → acknowledge an external report with an "Investigating" comment → reproduce it yourself → SIZE it → fix it at…

    4.4k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Simplify And Harden CI

    pskoett/pskoett-ai-skills

    CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).

    310 GitHub stars~1.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Qv Devops PR Review

    tetherto/qvac

    PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

    674 GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Bugfix PR

    TanStack/ai

    Treats bug-fix pull requests as invasive and untrusted. An agent skill from TanStack/ai.

    3.2k GitHub stars~4.8k tokensUpdated today
    DevelopmentAuto-check passed

More from hyodotdev/openiap

All 19 skills in this repo
  • E2E Matrix Runner

    hyodotdev/openiap

    Run the full OpenIAP device matrix — six frameworks across iOS, Google Play, Amazon Appstore, Meta Horizon, and VegaOS — driving real hardware over adb and xcrun, and report one row per cell with…

    154 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check: notes
  • Generate Doc

    hyodotdev/openiap

    A skill your agent uses for OpenIAP documentation generation work, especially the release-note card each PR carries in packages/docs/src/pages/docs/updates/releases.tsx, written as already published…

    154 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Opencollective Steward

    hyodotdev/openiap

    Manage OpenIAP's OpenCollective presence, including profile copy, slug/link migrations, sponsor/backer recognition, update posts, and README/docs sponsor assets.

    154 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Iapkit E2E Martie

    hyodotdev/openiap

    Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.

    154 GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • E2E Matrix Runner Apple

    hyodotdev/openiap

    Run the Apple half of the OpenIAP device matrix — six frameworks plus the native package on iOS — on a physical iPhone and report one row per cell with evidence.

    154 GitHub stars~501 tokensUpdated yesterday
    Auto-check passed
  • E2E Matrix Runner Google

    hyodotdev/openiap

    Run the Android half of the OpenIAP device matrix — six frameworks across Google Play, Amazon Appstore, and Meta Horizon, plus VegaOS — on real hardware and report one row per cell with evidence.

    154 GitHub stars~574 tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Openiap Workflows

What does Openiap Workflows do?

A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…. Openiap Workflows is an agent skill from hyodotdev/openiap.md.

When should I use Openiap Workflows?

Openiap Workflows fits situations like: including review-pr; compile-knowledge; prerelease package releases; generated type sync.

How do I install Openiap Workflows in Claude Code?

Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-code`. Or copy the skill folder (.claude/skills/openiap-workflows in hyodotdev/openiap) into .claude/skills/openiap-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Openiap Workflows in Codex?

Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a codex`. Or copy the skill folder (.claude/skills/openiap-workflows in hyodotdev/openiap) into .agents/skills/openiap-workflows in your project. Codex loads it when a task matches its description.

Can I use Openiap Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hyodotdev/openiap --skill openiap-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openiap-workflows, .gemini/skills/openiap-workflows, .github/skills/openiap-workflows and .opencode/skills/openiap-workflows in your project.

What does Openiap Workflows need to run?

SKILL.md names no scripts, command-line tools or credentials: Openiap Workflows is instructions for the agent only.

Does Openiap Workflows access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Openiap Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openiap Workflows use?

Openiap Workflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openiap Workflows use?

About 766 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openiap Workflows?

Skills that share tags, products or a category with Openiap Workflows: Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Address Issue (nubjs/nub, 4.4k stars), GitHub Actions Hardening (github/awesome-copilot, 40k stars) and Simplify And Harden CI (pskoett/pskoett-ai-skills, 310 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openiap Workflows?

hyodotdev (a GitHub organization) maintains it in hyodotdev/openiap, which has 154 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 6, 2026.

Source: hyodotdev/openiap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.