Agent skill

Ship Release

by hyodotdev in hyodotdev/openiap

Merge a verified OpenIAP PR, release every affected stable package one at a time, verify each public registry, verify the release note the PR carried, stabilize any correction with review-self, and…

MITAuto-check passedDevelopment

Install Ship Release

skills CLI
$ npx skills add hyodotdev/openiap --skill ship-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hyodotdev/openiap ship-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hyodotdev/openiap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/ship-release .claude/skills/ship-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ship-release
GitHub stars
154
Token cost
~1.7k tokens
SKILL.md length
861 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Merge a verified OpenIAP PR, release every affected stable package one at a time, verify each public registry, verify the release note the PR carried, stabilize any correction with review-self, and…

  • Works in 6 steps: Establish the exact release scope → Publish packages sequentially → Verify the release note → …
  • The user explicitly asks for this full post-review shipping workflow
  • SKILL.md covers Authority and required reading, 1. Establish the exact release…, 2. Publish packages sequentially and 3. Verify the release note, plus 4 more sections
  • Calls git, bun and npm

What it does

Ship Release is an agent skill from hyodotdev/openiap. Merge a verified OpenIAP PR, release every affected stable package one at a time, verify each public registry, verify the release note the PR carried, stabilize any correction with review-self, and deploy production docs. Use when the user explicitly asks for this full post-review shipping workflow.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes. The repository describes itself as: Standardized protocol for in-app purchases across all platforms — backed by Meta & Amazon. The licence is MIT.

When your agent uses it

  • The user explicitly asks for this full post-review shipping workflow
  • Tasks that involve Changelog and release notes

Example prompts

  • “/ship-release”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Establish the exact release scope
  2. Publish packages sequentially
  3. Verify the release note
  4. Stabilize and commit a correction
  5. Deploy and verify docs
  6. Leave the shipped comment

What it can do on your machine

Read from SKILL.md and the folder at commit 64158e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • bun
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ship Release loads about 1.7k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 861 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hyodotdev/openiap at commit 64158e8, republished under its MIT licence (© hyodotdev). 861 words, ~1,655 tokens.

Download SKILL.mdSave it as .claude/skills/ship-release/SKILL.md (or your agent's skills folder).
name
ship-release
description
Merge a verified OpenIAP PR, release every affected stable package one at a time, verify each public registry, verify the release note the PR carried, stabilize any correction with review-self, and deploy production docs. Use when the user explicitly asks for this full post-review shipping workflow.

Ship an OpenIAP Release

Complete a verified OpenIAP change from merge through public package and docs delivery. This skill coordinates existing repository workflows; their detailed rules remain the SSOT.

Authority and required reading

This workflow performs public and irreversible actions. Use it only when the user explicitly authorizes the requested merge, package publication, docs deployment, and any direct main push. Missing authority for one stage stops that stage without broadening the others.

Before acting, read:

  • AGENTS.md
  • .codex/skills/openiap-workflows/SKILL.md
  • .claude/commands/release.md
  • .codex/skills/generate-doc/SKILL.md
  • .codex/skills/review-self/SKILL.md
  • .claude/commands/commit.md

Load every convention file and specialized E2E skill required by the changed paths. Never mutate production Convex data.

1. Establish the exact release scope

  1. Confirm the PR is approved, required CI is successful on its exact head, review threads are clear, and any required device gate has passed or has an explicit recorded waiver. Apply knowledge/internal/05-docs-patterns.md#release-note-completeness-gate before merging; fix missing coverage in that PR and revalidate its head.
  2. Merge with the repository-supported method, then fast-forward local main.
  3. Require a clean worktree and verify HEAD equals origin/main.
  4. Classify affected packages from the merged diff. Release only packages with a user-visible or contract-relevant change; do not bump unaffected packages for symmetry.
  5. Select stable SemVer bumps from the actual compatibility impact and run all preflight audits required by .claude/commands/release.md.

2. Publish packages sequentially

Release one affected package at a time in the canonical dependency order in .claude/commands/release.md#stable-release, including the affected protocol and CLI packages. Reapply the completeness gate if the release scope changes.

For each package:

  1. Dispatch the stable release workflow from the exact current main.
  2. Wait for every validation and publication job to finish successfully.
  3. Fast-forward local main and fetch the new tag.
  4. Confirm package metadata, the release tag, and the release commit agree.
  5. Verify the artifact through its public registry or distribution endpoint, including provenance or consumer smoke checks when the workflow supplies them. Registry propagation can lag; poll until the public endpoint returns the new version before starting the next package.

Do not run package releases concurrently. Stop on the first failed gate and report the exact workflow job and package state. If the user requests docs before package publication, use the explicit flag documented in knowledge/internal/06-git-deployment.md#deploying-documentation. If the train will not resume, trim the card to the packages that published through §4.

Godot releases also require the authenticated Godot Asset Library listing to be updated. Prepare the edit when possible, request action-time confirmation before the public form submission, and report it as an explicit remaining manual step when authentication is unavailable. Never reuse credentials supplied for a different service.

3. Verify the release note

The merged PR carried the consolidated release card in packages/docs/src/pages/docs/updates/releases.tsx (see generate-doc). After every package version and public URL is known:

  • Compare each version and link on the card with current package metadata and the published tags, and correct any that differ.
  • Missing package or behavior coverage must have been fixed before publication through the completeness gate; this step verifies the published results.
  • Lead with user-visible behavior, include required migration or platform caveats once, and omit version-bump mechanics.
  • Add no versioned IAPKit entry; it is a service.

If nothing differs, go to §5.

Show full SKILL.md (332 more words)Show less

4. Stabilize and commit a correction

When §3 changed the card, run review-self against the docs diff until two consecutive full snapshots are clean at least five minutes apart. A material change resets the clean count. Run all path-specific validation, including the docs build, docs and release-state audits, skill validation, and git diff --check.

Commit and push through .claude/commands/commit.md. An explicit invocation of this full shipping workflow authorizes the release-note and release-process documentation commit directly on main; do not open a PR for that post-release docs-only commit. Immediately before committing, fast-forward from origin/main and revalidate that the intended files are the only changes. Product-code fixes still return to the normal PR loop.

5. Deploy and verify docs

From a clean local main equal to origin/main:

  1. Run bun run audit:commerce-evidence. If it reports drift, re-record the IAPKit interop per packages/kit/scripts/docs/commerce-interop.md before deploying; the guide page shows the recorded revision either way.
  2. Run npm run deploy and wait for successful production completion.
  3. Fetch the production release page and generated LLM documents with a cache buster. Confirm the new release title, API name, versions, and generated timestamp are present.
  4. Recheck required CI for the final main head and report any still-pending external listing or registry state separately.

6. Leave the shipped comment

After verifying public delivery, leave one short English completion comment on the originating PR and each linked issue resolved by this release, within the user-authorized GitHub follow-up scope. Check existing comments first and avoid duplicates, including on already-closed issues. If no issue is linked, comment on the PR only. A single sentence is enough: Shipped in <package> <version>. Link the verified release or deployment when useful. A merge alone is not proof of shipment. Confirm the posted comment and include its URL in the final report.

Completion report

Report the merged PR and commit, every published version with its public verification, docs commit and deployment result, review-self clean snapshots, the docs release, and any explicitly incomplete external marketplace update.

© hyodotdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/ship-release of hyodotdev/openiap.

Open the folder on GitHubat commit 64158e8

Compare with similar skills

Ship Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ship Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ship Release this skillhyodotdev/openiap154—~1.7kAutomated safety check: PassMIT
Simple Englishmoeru-ai/airi50k2 repos~4.6kAutomated safety check: PassMIT
StarRocks Release NotesStarRocks/starrocks12k—~1.9kAutomated safety check: NotesApache-2.0
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
React Router Release Notes Prepremix-run/react-router57k—~1.1kAutomated safety check: PassMIT
Mole CLI Release Flowtw93/Mole69k—~2.5kAutomated safety check: PassGPL-3.0

Similar skills

  • Simple English

    moeru-ai/airi

    Write or rewrite technical text with the rules of ASD-STE100 Simplified Technical English so it is clear, unambiguous, and free of AI slop.

    50k GitHub starsUsed in 2 repos~4.6k tokens
    DevelopmentAuto-check passed
  • StarRocks Release Notes

    StarRocks/starrocks

    Drafts English release notes for a StarRocks patch release from the PRs merged into its release branch, then opens a documentation PR and hands translation to /translate.

    12k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check: notes
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • React Router Release Notes Prep

    remix-run/react-router

    Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.

    57k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    69k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release

    PrefectHQ/fastmcp

    Cut a FastMCP release end to end. An agent skill from PrefectHQ/fastmcp.

    28k GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from hyodotdev/openiap

All 19 skills in this repo
  • E2E Matrix Runner

    hyodotdev/openiap

    Run the full OpenIAP device matrix — six frameworks across iOS, Google Play, Amazon Appstore, Meta Horizon, and VegaOS — driving real hardware over adb and xcrun, and report one row per cell with…

    154 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check: notes
  • Generate Doc

    hyodotdev/openiap

    A skill your agent uses for OpenIAP documentation generation work, especially the release-note card each PR carries in packages/docs/src/pages/docs/updates/releases.tsx, written as already published…

    154 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Opencollective Steward

    hyodotdev/openiap

    Manage OpenIAP's OpenCollective presence, including profile copy, slug/link migrations, sponsor/backer recognition, update posts, and README/docs sponsor assets.

    154 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Iapkit E2E Martie

    hyodotdev/openiap

    Run IAPKit local receipt-validation E2E with the dev.hyo.martie React Native or Expo examples, the compiled packages/kit server, real Convex, and Apple or Google sandbox purchases.

    154 GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • E2E Matrix Runner Apple

    hyodotdev/openiap

    Run the Apple half of the OpenIAP device matrix — six frameworks plus the native package on iOS — on a physical iPhone and report one row per cell with evidence.

    154 GitHub stars~501 tokensUpdated yesterday
    Auto-check passed
  • E2E Matrix Runner Google

    hyodotdev/openiap

    Run the Android half of the OpenIAP device matrix — six frameworks across Google Play, Amazon Appstore, and Meta Horizon, plus VegaOS — on real hardware and report one row per cell with evidence.

    154 GitHub stars~574 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Ship Release

What does Ship Release do?

Merge a verified OpenIAP PR, release every affected stable package one at a time, verify each public registry, verify the release note the PR carried, stabilize any correction with review-self, and…. Ship Release is an agent skill from hyodotdev/openiap. Merge a verified OpenIAP PR, release every affected stable package one at a time, verify each public registry, verify the release note the PR carried, stabilize any correction with review-self, and deploy production docs.

When should I use Ship Release?

Ship Release fits situations like: the user explicitly asks for this full post-review shipping workflow; tasks that involve Changelog and release notes.

How do I install Ship Release in Claude Code?

Run `npx skills add hyodotdev/openiap --skill ship-release -a claude-code`. Or copy the skill folder (.codex/skills/ship-release in hyodotdev/openiap) into .claude/skills/ship-release in your project. Claude Code loads it when a task matches its description.

How do I install Ship Release in Codex?

Run `npx skills add hyodotdev/openiap --skill ship-release -a codex`. Or copy the skill folder (.codex/skills/ship-release in hyodotdev/openiap) into .agents/skills/ship-release in your project. Codex loads it when a task matches its description.

Can I use Ship Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hyodotdev/openiap --skill ship-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ship-release, .gemini/skills/ship-release, .github/skills/ship-release and .opencode/skills/ship-release in your project.

What does Ship Release need to run?

Going by SKILL.md and its folder, Ship Release needs the command-line tools its instructions call (git, bun and npm).

Does Ship Release access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ship Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ship Release use?

Ship Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ship Release use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ship Release?

Skills that share tags, products or a category with Ship Release: Simple English (moeru-ai/airi, 50k stars), StarRocks Release Notes (StarRocks/starrocks, 12k stars), Cutting A Release (TriliumNext/Trilium, 38k stars) and React Router Release Notes Prep (remix-run/react-router, 57k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ship Release?

hyodotdev (a GitHub organization) maintains it in hyodotdev/openiap, which has 154 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 6, 2026.

Source: hyodotdev/openiap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.