Verdaccio Code Review
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge…
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/openiap-workflows .claude/skills/openiap-workflows && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/openiap-workflows into .claude/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hyodotdev/openiap/tree/main/.codex/skills/openiap-workflowsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/openiap-workflows .agents/skills/openiap-workflows && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/openiap-workflows into .agents/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/openiap-workflows .cursor/skills/openiap-workflows && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/openiap-workflows into .cursor/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hyodotdev/openiap.git --path .codex/skills/openiap-workflows--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/openiap-workflows .gemini/skills/openiap-workflows && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/openiap-workflows into .gemini/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hyodotdev/openiap openiap-workflowsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/openiap-workflows .github/skills/openiap-workflows && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/openiap-workflows into .github/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hyodotdev/openiap --skill openiap-workflows -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hyodotdev/openiap openiap-workflows --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/openiap-workflows .opencode/skills/openiap-workflows && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "openiap-workflows" agent skill from https://github.com/hyodotdev/openiap/tree/main/.codex/skills/openiap-workflows into .opencode/skills/openiap-workflows/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openiap-workflows", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
openiap-workflowsA skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge…
Openiap Workflows is an agent skill from hyodotdev/openiap. Use for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge, verify-all, e2e-tests, stable or prerelease package releases, resolve-issue, commit/push/PR, generated type sync, package-specific checks, GitHub review threads, and project conventions from AGENTS.md.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Development, covering Pull requests, Monorepo tooling and Security review. It works with GitHub. The repository describes itself as: Standardized protocol for in-app purchases across all platforms — backed by Meta & Amazon. The licence is MIT.
Read from SKILL.md and the folder at commit 75aa01c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Openiap Workflows loads about 2k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 984 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hyodotdev/openiap at commit 75aa01c, republished under its MIT licence (© hyodotdev). 984 words, ~2,011 tokens.
.claude/skills/openiap-workflows/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill when the user asks the agent to perform an OpenIAP repo workflow that
previously lived under .claude/commands, such as reviewing a PR, resolving an
issue, auditing code, compiling knowledge, running device-backed E2E regression,
verifying the monorepo, or committing and opening a PR.
Before changing code, read the root AGENTS.md; CLAUDE.md and GEMINI.md
are symlinks to it in this repo, while Grok, Codex, and Muse consume
AGENTS.md directly. Then read the relevant detailed files:
knowledge/internal/*.mdpackages/*/CONVENTION.mdlibraries/*/AGENTS.md.claude/commands/*.mdDo not duplicate or reinterpret those rules when a file already covers the specific package or workflow.
You do not need Claude slash-command syntax. If the user says any of these natural-language requests, execute the matching workflow:
.claude/commands/review-pr.md. CodeRabbit is the only external reviewer that
posts to the PR; do not invoke other review bots. If CodeRabbit cannot review
the current head, run the single-round Codex fallback that command defines;
read .codex/skills/review-self/SKILL.md and run its single-round review-pr
fallback only when Codex is unavailable too. At the clean end of the loop, remove the
temporary CodeRabbit trigger and terminal skip/unavailable top-level comments
exactly as defined by the command workflow..claude/commands/audit-code.md..claude/commands/audit-security.md..claude/commands/audit-iapkit.md..claude/commands/compile-knowledge.md..claude/commands/resolve-issue.md..claude/commands/verify-all.md..claude/commands/e2e-tests.md..claude/commands/e2e-tests-google.md..claude/commands/e2e-tests-apple.md..claude/commands/release.md..claude/commands/commit.md.When a command file gives a sequence, follow it unless the user's newest instruction narrows the scope.
For e2e-tests, an unqualified request means the full regression matrix in the
command file, including native packages, framework libraries, build-only
platform rows, connected-device rows, and explicit blocked/unsupported rows.
A request naming one platform runs only that half's scoped file.
Internal agent/workflow-only changes include .claude/commands/,
.claude/skills/, .codex/skills/, .cursor/rules/, AGENTS.md,
CLAUDE.md, GEMINI.md, and agent automation notes. Do not create a branch,
push, or open a PR for those changes unless the user explicitly asks to publish,
PR, or merge them.
If a user asks to update an internal workflow and does not explicitly ask for a PR, keep the change local and report the changed files. If a PR is already open for an internal workflow because the user explicitly requested it, add appropriate labels before merging.
knowledge/internal/03-coding-style.md.knowledge/internal/06-git-deployment.md. Private maintainer conversation
language must never leak into issue, PR, review, release, or commit prose.knowledge/internal/04-platform-packages.md..claude/commands/release.md for the all-workflow preflight. If a
post-merge stable release reveals a CI-only blocker, pause the train, inspect
all remaining workflows, and group confirmed repairs into one recovery PR;
never create package-by-package or symptom-by-symptom recovery PRs.bun audit:docs or the documented audit
command before pushing.openiap-versions.json
or from a nearby release block.knowledge/internal/05-docs-patterns.md#release-note-completeness-gate.main as stable-only and next as an on-demand prerelease branch.
Never run an RC/next release from main, a stable release from next, or a
production docs deploy from next. Run bun run audit:release-state before
release work.Preview comment or PR body attachment. Never commit one-off preview media,
including under .github/pr-previews/; keep it in a temporary or ignored
local path and delete it after verifying the GitHub attachment. If browser or
extension permissions block the attachment, stop and ask the maintainer to
enable uploads instead of force-adding a Git fallback. Use the Codex Chrome
Extension for web/docs/dashboard previews when applicable.<type>(<scope>): <subject>..claude/commands/commit.md: use meaningful semantic prefixes such as
feat/, fix/, ci/, docs/, test/, chore/, or refactor/. Do not
use generic agent/tool prefixes such as codex/.For PR review feedback, use the GitHub app tools or gh as needed to inspect
inline review threads. Fix valid findings in the current PR, reply to the
specific inline comment with the plain commit hash, and resolve only threads
that are fixed or outdated per .claude/commands/review-pr.md.
Do not call a PR clean merely because CodeRabbit skipped or failed. Do not
replace it with another external review bot. Use the head-specific Codex
fallback required by the command workflow — or the review-self fallback when
Codex is unavailable too — and include its clean result in the completion gate.
Do not reply with "will address later" for valid correctness or operational findings. Implement the fix in the current PR unless the finding is wrong on the merits, and explain the concrete repo evidence when pushing back.
© hyodotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/openiap-workflows of hyodotdev/openiap.
Open the folder on GitHubat commit 75aa01c
Openiap Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Openiap Workflows this skillhyodotdev/openiap | 154 | — | ~2k | Automated safety check: Pass | MIT | |
| Verdaccio Code Reviewverdaccio/verdaccio | 18k | — | ~853 | Automated safety check: Pass | MIT | |
| Address Issuenubjs/nub | 4.4k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Acreadiness Generate Instructionsgithub/awesome-copilot | 40k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Simplify And Harden CIpskoett/pskoett-ai-skills | 311 | — | ~1.1k | Automated safety check: Pass | None | |
| Qv Devops PR Reviewtetherto/qvac | 681 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 |
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
nubjs/nub
End-to-end playbook for working a GitHub issue (or bug-fix PR) on nubjs/nub: triage → acknowledge an external report with an "Investigating" comment → reproduce it yourself → SIZE it → fix it at…
github/awesome-copilot
Generate tailored AI agent instruction files via AgentRC instructions command.
pskoett/pskoett-ai-skills
CI-only Simplify & Harden workflow for pull requests using gh-aw (GitHub Agentic Workflows).
tetherto/qvac
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
mariadb-operator/mariadb-operator
Perform a structured maintainer-style PR review for the mariadb-operator repository.
hyodotdev/openiap
Run the full OpenIAP device matrix — six frameworks across iOS, Google Play, Amazon Appstore, Meta Horizon, and VegaOS — driving real hardware over adb and xcrun, and report one row per cell with…
hyodotdev/openiap
A skill your agent uses for OpenIAP documentation generation work, especially the release-note card each PR carries in packages/docs/src/pages/docs/updates/releases.tsx, written as already published…
hyodotdev/openiap
Manage OpenIAP's OpenCollective presence, including profile copy, slug/link migrations, sponsor/backer recognition, update posts, and README/docs sponsor assets.
hyodotdev/openiap
Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.
hyodotdev/openiap
Run the Apple half of the OpenIAP device matrix — six frameworks plus the native package on iOS — on a physical iPhone and report one row per cell with evidence.
hyodotdev/openiap
Run the Android half of the OpenIAP device matrix — six frameworks across Google Play, Amazon Appstore, and Meta Horizon, plus VegaOS — on real hardware and report one row per cell with evidence.
Works with
Categories
A skill your agent uses for OpenIAP monorepo work that should follow the repository's shared agent workflows, including review-pr, audit-code, audit-security, audit-iapkit, compile-knowledge…. Openiap Workflows is an agent skill from hyodotdev/openiap.md.
Openiap Workflows fits situations like: openIAP monorepo work that should follow the repositorys shared agent workflows; including review-pr; compile-knowledge; prerelease package releases.
Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a claude-code`. Or copy the skill folder (.codex/skills/openiap-workflows in hyodotdev/openiap) into .claude/skills/openiap-workflows in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hyodotdev/openiap --skill openiap-workflows -a codex`. Or copy the skill folder (.codex/skills/openiap-workflows in hyodotdev/openiap) into .agents/skills/openiap-workflows in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hyodotdev/openiap --skill openiap-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openiap-workflows, .gemini/skills/openiap-workflows, .github/skills/openiap-workflows and .opencode/skills/openiap-workflows in your project.
Going by SKILL.md and its folder, Openiap Workflows needs the command-line tools its instructions call (bun).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Openiap Workflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Openiap Workflows: Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Address Issue (nubjs/nub, 4.4k stars), Acreadiness Generate Instructions (github/awesome-copilot, 40k stars) and Simplify And Harden CI (pskoett/pskoett-ai-skills, 311 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hyodotdev (a GitHub organization) maintains it in hyodotdev/openiap, which has 154 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.
Source: hyodotdev/openiap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.