Agent skill

Openiap Workflows

by hyodotdev in hyodotdev/openiap

A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge…

MITAuto-check passedDevelopment

Install Openiap Workflows

skills CLI
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hyodotdev/openiap openiap-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/openiap-workflows .claude/skills/openiap-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openiap-workflows
GitHub stars
154
Token cost
~2k tokens
SKILL.md length
984 words
Files
2
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge…

  • OpenIAP monorepo work that should follow the repositorys shared agent workflows
  • SKILL.md covers Source Of Truth, Command Mapping, Internal Workflow Change Guard and Non-Negotiables, plus 1 more section
  • Calls bun
  • Including review-pr

What it does

Openiap Workflows is an agent skill from hyodotdev/openiap. Use for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge, verify-all, e2e-tests, stable or prerelease package releases, resolve-issue, commit/push/PR, generated type sync, package-specific checks, GitHub review threads, and project conventions from AGENTS.md.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Pull requests, Monorepo tooling and Security review. It works with GitHub. The repository describes itself as: Standardized protocol for in-app purchases across all platforms — backed by Meta & Amazon. The licence is MIT.

When your agent uses it

  • OpenIAP monorepo work that should follow the repositorys shared agent workflows
  • Including review-pr
  • Compile-knowledge
  • Prerelease package releases

Example prompts

  • “/openiap-workflows”

What it can do on your machine

Read from SKILL.md and the folder at commit 75aa01c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openiap Workflows loads about 2k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 984 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hyodotdev/openiap at commit 75aa01c, republished under its MIT licence (© hyodotdev). 984 words, ~2,011 tokens.

Download SKILL.mdSave it as .claude/skills/openiap-workflows/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
openiap-workflows
description
Use for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge, verify-all, e2e-tests, stable or prerelease package releases, resolve-issue, commit/push/PR, generated type sync, package-specific checks, GitHub review threads, and project conventions from AGENTS.md.

OpenIAP Workflows

Use this skill when the user asks the agent to perform an OpenIAP repo workflow that previously lived under .claude/commands, such as reviewing a PR, resolving an issue, auditing code, compiling knowledge, running device-backed E2E regression, verifying the monorepo, or committing and opening a PR.

Source Of Truth

Before changing code, read the root AGENTS.md; CLAUDE.md and GEMINI.md are symlinks to it in this repo, while Grok, Codex, and Muse consume AGENTS.md directly. Then read the relevant detailed files:

  • Package and library rules: knowledge/internal/*.md
  • Package conventions: packages/*/CONVENTION.md
  • Library conventions: libraries/*/AGENTS.md
  • Workflow details: .claude/commands/*.md

Do not duplicate or reinterpret those rules when a file already covers the specific package or workflow.

Command Mapping

You do not need Claude slash-command syntax. If the user says any of these natural-language requests, execute the matching workflow:

  • Review PR comments, fix review feedback, or "review-pr": read .claude/commands/review-pr.md. CodeRabbit is the only external reviewer that posts to the PR; do not invoke other review bots. If CodeRabbit cannot review the current head, run the single-round Codex fallback that command defines; read .codex/skills/review-self/SKILL.md and run its single-round review-pr fallback only when Codex is unavailable too. At the clean end of the loop, remove the temporary CodeRabbit trigger and terminal skip/unavailable top-level comments exactly as defined by the command workflow.
  • Audit code, check latest APIs, or "audit-code": read .claude/commands/audit-code.md.
  • Audit SBOM quality, release provenance, workflow permissions, or supply-chain/security posture: read .claude/commands/audit-security.md.
  • Reconcile the IAPKit site with OpenIAP, audit kit docs, or check whether IAPKit reflects a spec/store update: read .claude/commands/audit-iapkit.md.
  • Compile knowledge or rebuild AI context: read .claude/commands/compile-knowledge.md.
  • Resolve a GitHub issue: read .claude/commands/resolve-issue.md.
  • Verify all, health check, or pre-PR verification: read .claude/commands/verify-all.md.
  • E2E tests, device regression, connected-device purchase flow checks, or "e2e-tests": read .claude/commands/e2e-tests.md.
  • Android E2E tests, Play/Amazon/Horizon/VegaOS regression, or "e2e-tests-google": read .claude/commands/e2e-tests-google.md.
  • Apple E2E tests, iOS regression, or "e2e-tests-apple": read .claude/commands/e2e-tests-apple.md.
  • Stable releases, RC/next releases, registry publication, or package deploys: read .claude/commands/release.md.
  • Commit, push, or create PR: read .claude/commands/commit.md.

When a command file gives a sequence, follow it unless the user's newest instruction narrows the scope.

For e2e-tests, an unqualified request means the full regression matrix in the command file, including native packages, framework libraries, build-only platform rows, connected-device rows, and explicit blocked/unsupported rows. A request naming one platform runs only that half's scoped file.

Internal Workflow Change Guard

Internal agent/workflow-only changes include .claude/commands/, .claude/skills/, .codex/skills/, .cursor/rules/, AGENTS.md, CLAUDE.md, GEMINI.md, and agent automation notes. Do not create a branch, push, or open a PR for those changes unless the user explicitly asks to publish, PR, or merge them.

If a user asks to update an internal workflow and does not explicitly ask for a PR, keep the change local and report the changed files. If a PR is already open for an internal workflow because the user explicitly requested it, add appropriate labels before merging.

Show full SKILL.md (513 more words)Show less

Non-Negotiables

  • Apply the canonical KISS/SSOT release criteria in knowledge/internal/03-coding-style.md.
  • Before any public GitHub write, apply the English-only communication guard in knowledge/internal/06-git-deployment.md. Private maintainer conversation language must never leak into issue, PR, review, release, or commit prose.
  • Read relevant knowledge and package convention files before editing package or library code.
  • Never hand-edit generated files unless the workflow explicitly says to verify generated output after running the generator.
  • For GraphQL schema/API changes, follow the SDK Parity Checklist in knowledge/internal/04-platform-packages.md.
  • Run the package-specific verification commands for touched paths.
  • For dependency modernization release trains, keep the entire train in one PR and follow .claude/commands/release.md for the all-workflow preflight. If a post-merge stable release reveals a CI-only blocker, pause the train, inspect all remaining workflows, and group confirmed repairs into one recovery PR; never create package-by-package or symptom-by-symptom recovery PRs.
  • For Android package work, compile Play, Horizon, and Amazon variants when relevant.
  • For docs/API/type docs changes, run bun audit:docs or the documented audit command before pushing.
  • For release-note package lists, verify versions from package metadata and GitHub release tags; never infer framework versions from openiap-versions.json or from a nearby release block.
  • Before creating or updating a PR, declaring review clean, or releasing, apply knowledge/internal/05-docs-patterns.md#release-note-completeness-gate.
  • Treat main as stable-only and next as an on-demand prerelease branch. Never run an RC/next release from main, a stable release from next, or a production docs deploy from next. Run bun run audit:release-state before release work.
  • For PRs with new features, visible behavior changes, UI changes, docs pages, example flows, or developer workflows, record the actual changed surface, compress the video to under 10 MB, and upload it to the GitHub PR as a Preview comment or PR body attachment. Never commit one-off preview media, including under .github/pr-previews/; keep it in a temporary or ignored local path and delete it after verifying the GitHub attachment. If browser or extension permissions block the attachment, stop and ask the maintainer to enable uploads instead of force-adding a Git fallback. Use the Codex Chrome Extension for web/docs/dashboard previews when applicable.
  • Keep commits in Angular Conventional Commits format: <type>(<scope>): <subject>.
  • When creating branches for commit/push/PR workflows, follow .claude/commands/commit.md: use meaningful semantic prefixes such as feat/, fix/, ci/, docs/, test/, chore/, or refactor/. Do not use generic agent/tool prefixes such as codex/.

GitHub Review Threads

For PR review feedback, use the GitHub app tools or gh as needed to inspect inline review threads. Fix valid findings in the current PR, reply to the specific inline comment with the plain commit hash, and resolve only threads that are fixed or outdated per .claude/commands/review-pr.md.

Do not call a PR clean merely because CodeRabbit skipped or failed. Do not replace it with another external review bot. Use the head-specific Codex fallback required by the command workflow — or the review-self fallback when Codex is unavailable too — and include its clean result in the completion gate.

Do not reply with "will address later" for valid correctness or operational findings. Implement the fix in the current PR unless the finding is wrong on the merits, and explain the concrete repo evidence when pushing back.

© hyodotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/openiap-workflows of hyodotdev/openiap.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 75aa01c

Compare with similar skills

Openiap Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openiap Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openiap Workflows this skillhyodotdev/openiap154—~2kAutomated safety check: PassMIT
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT
Address Issuenubjs/nub4.4k—~2.6kAutomated safety check: PassMIT
Acreadiness Generate Instructionsgithub/awesome-copilot40k1 repos~2.1kAutomated safety check: PassMIT
Simplify And Harden CIpskoett/pskoett-ai-skills311—~1.1kAutomated safety check: PassNone
Qv Devops PR Reviewtetherto/qvac681—~2.5kAutomated safety check: PassApache-2.0

Similar skills

  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Address Issue

    nubjs/nub

    End-to-end playbook for working a GitHub issue (or bug-fix PR) on nubjs/nub: triage → acknowledge an external report with an "Investigating" comment → reproduce it yourself → SIZE it → fix it at…

    4.4k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Acreadiness Generate Instructions

    github/awesome-copilot

    Official

    Generate tailored AI agent instruction files via AgentRC instructions command.

    40k GitHub starsUsed in 1 repo~2.1k tokens
    DevelopmentAuto-check passed
  • Simplify And Harden CI

    pskoett/pskoett-ai-skills

    CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).

    311 GitHub stars~1.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Qv Devops PR Review

    tetherto/qvac

    PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

    681 GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Mariadb Operator PR Review

    mariadb-operator/mariadb-operator

    Perform a structured maintainer-style PR review for the mariadb-operator repository.

    1k GitHub stars~3.3k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from hyodotdev/openiap

All 19 skills in this repo
  • E2E Matrix Runner

    hyodotdev/openiap

    Run the full OpenIAP device matrix — six frameworks across iOS, Google Play, Amazon Appstore, Meta Horizon, and VegaOS — driving real hardware over adb and xcrun, and report one row per cell with…

    154 GitHub stars~3.4k tokensUpdated today
    Auto-check: notes
  • Generate Doc

    hyodotdev/openiap

    A skill your agent uses for OpenIAP documentation generation work, especially the release-note card each PR carries in packages/docs/src/pages/docs/updates/releases.tsx, written as already published…

    154 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Opencollective Steward

    hyodotdev/openiap

    Manage OpenIAP's OpenCollective presence, including profile copy, slug/link migrations, sponsor/backer recognition, update posts, and README/docs sponsor assets.

    154 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Iapkit E2E Martie

    hyodotdev/openiap

    Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.

    154 GitHub stars~5.4k tokensUpdated today
    Auto-check: notes
  • E2E Matrix Runner Apple

    hyodotdev/openiap

    Run the Apple half of the OpenIAP device matrix — six frameworks plus the native package on iOS — on a physical iPhone and report one row per cell with evidence.

    154 GitHub stars~501 tokensUpdated today
    Auto-check passed
  • E2E Matrix Runner Google

    hyodotdev/openiap

    Run the Android half of the OpenIAP device matrix — six frameworks across Google Play, Amazon Appstore, and Meta Horizon, plus VegaOS — on real hardware and report one row per cell with evidence.

    154 GitHub stars~574 tokensUpdated today
    Auto-check passed

Works with

Questions about Openiap Workflows

What does Openiap Workflows do?

A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge…. Openiap Workflows is an agent skill from hyodotdev/openiap.md.

When should I use Openiap Workflows?

Openiap Workflows fits situations like: openIAP monorepo work that should follow the repositorys shared agent workflows; including review-pr; compile-knowledge; prerelease package releases.

How do I install Openiap Workflows in Claude Code?

Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-code`. Or copy the skill folder (.codex/skills/openiap-workflows in hyodotdev/openiap) into .claude/skills/openiap-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Openiap Workflows in Codex?

Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a codex`. Or copy the skill folder (.codex/skills/openiap-workflows in hyodotdev/openiap) into .agents/skills/openiap-workflows in your project. Codex loads it when a task matches its description.

Can I use Openiap Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hyodotdev/openiap --skill openiap-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openiap-workflows, .gemini/skills/openiap-workflows, .github/skills/openiap-workflows and .opencode/skills/openiap-workflows in your project.

What does Openiap Workflows need to run?

Going by SKILL.md and its folder, Openiap Workflows needs the command-line tools its instructions call (bun).

Does Openiap Workflows access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Openiap Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openiap Workflows use?

Openiap Workflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openiap Workflows use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openiap Workflows?

Skills that share tags, products or a category with Openiap Workflows: Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Address Issue (nubjs/nub, 4.4k stars), Acreadiness Generate Instructions (github/awesome-copilot, 40k stars) and Simplify And Harden CI (pskoett/pskoett-ai-skills, 311 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openiap Workflows?

hyodotdev (a GitHub organization) maintains it in hyodotdev/openiap, which has 154 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: hyodotdev/openiap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.