App Store Preflight Skills
truongduy2611/app-store-preflight-skills
Scan an iOS/macOS Xcode project for common App Store rejection patterns before submission.
Ship an accepted, soaked KeeForge candidate across iOS, Mac App Store, and direct Mac.
$ npx skills add KeeForge/KeeForge --skill ship-release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install KeeForge/KeeForge ship-release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/KeeForge/KeeForge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ship-release .claude/skills/ship-release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ship-release" agent skill from https://github.com/KeeForge/KeeForge/tree/main/.agents/skills/ship-release into .claude/skills/ship-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship-release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/KeeForge/KeeForge/tree/main/.agents/skills/ship-releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add KeeForge/KeeForge --skill ship-release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install KeeForge/KeeForge ship-release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KeeForge/KeeForge.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/ship-release .agents/skills/ship-release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ship-release" agent skill from https://github.com/KeeForge/KeeForge/tree/main/.agents/skills/ship-release into .agents/skills/ship-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship-release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add KeeForge/KeeForge --skill ship-release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install KeeForge/KeeForge ship-release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KeeForge/KeeForge.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/ship-release .cursor/skills/ship-release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ship-release" agent skill from https://github.com/KeeForge/KeeForge/tree/main/.agents/skills/ship-release into .cursor/skills/ship-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship-release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/KeeForge/KeeForge.git --path .agents/skills/ship-release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add KeeForge/KeeForge --skill ship-release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install KeeForge/KeeForge ship-release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KeeForge/KeeForge.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/ship-release .gemini/skills/ship-release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ship-release" agent skill from https://github.com/KeeForge/KeeForge/tree/main/.agents/skills/ship-release into .gemini/skills/ship-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship-release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install KeeForge/KeeForge ship-releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add KeeForge/KeeForge --skill ship-release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/KeeForge/KeeForge.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/ship-release .github/skills/ship-release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ship-release" agent skill from https://github.com/KeeForge/KeeForge/tree/main/.agents/skills/ship-release into .github/skills/ship-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship-release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add KeeForge/KeeForge --skill ship-release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install KeeForge/KeeForge ship-release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KeeForge/KeeForge.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/ship-release .opencode/skills/ship-release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ship-release" agent skill from https://github.com/KeeForge/KeeForge/tree/main/.agents/skills/ship-release into .opencode/skills/ship-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship-release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ship-releaseShip an accepted, soaked KeeForge candidate across iOS, Mac App Store, and direct Mac.
Ship Release is an agent skill from KeeForge/KeeForge. Ship an accepted, soaked KeeForge candidate across iOS, Mac App Store, and direct Mac. Verify the recorded artifact identities and soak evidence, coordinate App Store review, create the shipped tag after approval and final go, publish the exact artifacts, and reconcile released issues. Use when asked to ship or promote a soaked build; never create a replacement candidate here.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Mobile, covering App store release. It works with iOS, macOS and App Store Connect. The repository describes itself as: KeePass-compatible password manager for iPhone, iPad, and Mac. The licence is GPL-3.0.
Read from SKILL.md and the folder at commit 2959200. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ship Release loads about 2.3k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 1,087 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from KeeForge/KeeForge at commit 2959200, republished under its GPL-3.0 licence (© KeeForge). 1,087 words, ~2,336 tokens.
.claude/skills/ship-release/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Read the shared release contract and soak guidance, then follow this workflow.
Use this skill when the user decides to ship, after the soak guidance signals have been reported to them.
Do not re-check the CI gates here. All cloud gates and local gates were read and adjudicated in candidate gates, and accepting them is what allowed the build to reach external testers in the first place (invariant 3). That verdict is release preparation's job and it is final: do not poll Xcode Cloud or GitHub Actions check runs for the RC commit, do not reopen gate-adjudication.md, and do not treat a test action that was red but accepted as a flake — or a later re-run of either workflow — as a reason to stop. The soaked binary already carries the verdict. If it turns out a gate was never accepted, you are not in production shipping; go back to candidate gates.
Record explicitly, and state it back to the user before proceeding:
rc/{version}-b{repoBuild} tag and commit SHA. The tag identifies the commit; each
platform-specific TestFlight number identifies its binary, and neither is required to equal the
repo build.CFBundleVersion, zip hash, and notarization ID.Each TestFlight build number here is the build you will select for its platform in App Store Connect. If either does not match the build distributed and soaked, stop — something is out of sync. Do not substitute a newer build.
If CHANGELOG.md's ## v{version} ({date}) no longer matches the actual ship date, fix it on the
release branch now. This is a documentation-only change and does not require a new build — the
changelog is not compiled into the binary. Merge that correction to main before the audit below.
Because backports and the date correction are merges, this is an exact check rather than a judgement call:
git fetch origin --tags
git merge-base --is-ancestor origin/release/{major}.{minor} origin/main \
&& echo "main contains the release branch" \
|| git log --oneline origin/main..origin/release/{major}.{minor}If the check fails, the listed commits are on the release branch and not on main. Run merge-back guidance to
merge them before shipping. Do not ship with an unmerged fix.
Invoke publish-app-store-version once for iOS and once for macOS. Attach the exact soaked
TestFlight build numbers from the manifest, save the platform-specific metadata/screenshots, and
stage each platform independently through Ready for Review, then stop. Do not submit either
platform yet. If the user later requests submission, obtain separate explicit action-time
confirmation immediately before each platform's API submission request; confirmation for one
platform does not authorize the other. Configure both records for manual release and leave approved
versions held. v{version} does not exist yet.
If Apple requests a metadata-only correction, fix only that platform's record. If Apple requests a code change, return to candidate respin and respin all three artifacts. Never substitute a newer unsoaked build.
Wait until both App Store submissions have code approval and the user gives the final coordinated
go decision. Record that non-secret decision/evidence and completed soak observations in the
manifest: set each platform's appStoreReviewState, preserve the separate beta reviewState, and
record each soak's accepted verdict/evidence, metrics, or owner-accepted exceptions. Then validate
the ship evidence. Then create v{version} on the accepted RC commit; it triggers no build and records
the code that actually shipped. Include any accepted soak exception in the tag message.
ci_scripts/candidate_manifest.py validate \
--manifest scratch/release-manifests/{version}-b{repoBuild}.json --mode shipgit fetch origin --tags
rc_tag='rc/{version}-b{repoBuild}'
rc_commit=$(git rev-list -n1 "$rc_tag")
git tag -a 'v{version}' -m 'Release v{version} — shipped RC '"$rc_tag" "$rc_commit"
git push origin 'refs/tags/v{version}'Keep every rc/* tag. They are the audit trail of the candidates, including the ones that were
replaced.
If git fetch origin --tags reports ! [rejected] ... (would clobber existing tag), a local tag
has drifted from the remote. The remote is authoritative for released tags: inspect both sides,
then realign with git fetch origin --tags --force.
release branch cut put the changelog section, the What's New content, and MARKETING_VERSION on main before the
cut, and the merge-back guidance merges carried each candidate's repo build across. Verify rather than redo:
main's MARKETING_VERSION is {version} on all four targets: KeeForge, KeeForgeAutoFill,
KeeForgeMac, and KeeForgeMacAutoFill.main's CURRENT_PROJECT_VERSION is the accepted repoBuild on all four targets, and the
direct artifact's CFBundleVersion is also that repoBuild. Do not compare either value with
the platform-specific TestFlight build numbers.main's CHANGELOG.md has the ## v{version} section, with an empty ## Unreleased above it
ready for the next cycle.CURRENT_PROJECT_VERSION is not checked against either TestFlight number. Xcode Cloud manages
platform-specific build numbers and may override the project value. The repo value must still be
globally unique and increasing and must equal the direct build's CFBundleVersion; build-number selection and Bump the build number
guarantee that. The manifest is the authoritative mapping between the repo build, both TestFlight
numbers, and the direct artifact.
Fix any real drift with a single -s commit on main, then push.
After v{version} exists and both platform records are approved, manually release iOS and native
macOS at the coordinated time. Publish the verified GitHub Release/direct zip, then publish the
production Sparkle appcast last. Verify live installs, migration, AutoFill, WebDAV, channel
boundaries, and both App Store version/build numbers; preserve the completed non-secret manifest.
Keep the release branch. It is where {version}.1 will come from.
After production verification succeeds, audit
KeeForge project 1 for issues whose Status is
Pending Release. Establish the shipped boundary from the dereferenced v{version} tag, then
identify the implementation commit or merged pull request for each pending issue. Move an issue to
Released only when its implementation is reachable from that tag and the promised behavior
actually shipped on its intended platform. A changelog entry is useful corroboration but is not
required for internal tasks or refactors.
Do not infer release from the issue being closed, from its milestone, or from the implementation
being present on current main: work merged after the shipped tag stays Pending Release. Present
the exact move/leave list with the tag-containment evidence and obtain confirmation immediately
before changing project fields unless the user already explicitly authorized this reconciliation.
For the write, invoke keeforge-github-issues, follow its live-project preflight, change only the
Status field, and read every changed project item back to verify it now says Released. Do not
close or otherwise edit the issues as part of this step.
© KeeForge, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/ship-release of KeeForge/KeeForge.
Open the folder on GitHubat commit 2959200
Ship Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ship Release this skillKeeForge/KeeForge | 114 | — | ~2.3k | Automated safety check: Pass | GPL-3.0 | |
| App Store Preflight Skillstruongduy2611/app-store-preflight-skills | 1.4k | — | ~1.4k | Automated safety check: Pass | MIT | |
| OdevioOdevio/Odevio-CLI | 423 | — | ~7.6k | Automated safety check: Pass | MIT | |
| Releasevaayne/mori | 303 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Asc Xcode Buildrorkai/app-store-connect-cli-skills | 1.1k | 2 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Releasemovieclaw/MovieClaw | 146 | — | ~2.6k | Automated safety check: Pass | Custom licence |
truongduy2611/app-store-preflight-skills
Scan an iOS/macOS Xcode project for common App Store rejection patterns before submission.
Odevio/Odevio-CLI
Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.
vaayne/mori
Release workflow for Mori macOS workspace terminal and MoriRemote iOS app.
rorkai/app-store-connect-cli-skills
Build, archive, generate export options, export, upload, and manage Xcode version/build numbers with the current asc xcode helpers.
movieclaw/MovieClaw
发布 movieclaw 新版本。当用户要求发版、发布新版本、打 tag、发布 NER 模型、发布 Docker 镜像,或打包上传 iOS App 到 TestFlight / App Store、补传发版附件(IPA、Mac 转码器、Mac 版 App)时使用。涵盖版本号三处同步、应用/模型/镜像/iOS 的完整流程、可选附件失败补救与检查清单。
kmworks/kmreader
Coordinate the KMReader App Store release workflow. An agent skill from kmworks/kmreader.
KeeForge/KeeForge
Prepare and publish an already-built KeeForge iOS or macOS version through the App Store Connect API using an API key.
KeeForge/KeeForge
Assess KeeForge test quality, redundant coverage, and test-support complexity; audit a selected subsystem or apply an authoring checklist while changing tests.
KeeForge/KeeForge
Create, edit, comment on, close, reopen, classify, or change project fields for issues in KeeForge/KeeForge.
KeeForge/KeeForge
Statically review KeeForge changes since a shipped release for behavior risks, documentation inconsistencies, i18n gaps, and missing test coverage.
KeeForge/KeeForge
Prepare the first KeeForge candidate for a new marketing version, including minor/major releases and patches or hotfixes to shipped versions.
KeeForge/KeeForge
Replace an unshipped KeeForge candidate after a fix on an existing release branch.
Works with
Categories
Ship an accepted, soaked KeeForge candidate across iOS, Mac App Store, and direct Mac. Ship Release is an agent skill from KeeForge/KeeForge. Ship an accepted, soaked KeeForge candidate across iOS, Mac App Store, and direct Mac.
Ship Release fits situations like: promote a soaked build; never create a replacement candidate here.
Run `npx skills add KeeForge/KeeForge --skill ship-release -a claude-code`. Or copy the skill folder (.agents/skills/ship-release in KeeForge/KeeForge) into .claude/skills/ship-release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add KeeForge/KeeForge --skill ship-release -a codex`. Or copy the skill folder (.agents/skills/ship-release in KeeForge/KeeForge) into .agents/skills/ship-release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add KeeForge/KeeForge --skill ship-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ship-release, .gemini/skills/ship-release, .github/skills/ship-release and .opencode/skills/ship-release in your project.
Going by SKILL.md and its folder, Ship Release needs the command-line tools its instructions call (git).
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ship Release is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ship Release: App Store Preflight Skills (truongduy2611/app-store-preflight-skills, 1.4k stars), Odevio (Odevio/Odevio-CLI, 423 stars), Release (vaayne/mori, 303 stars) and Asc Xcode Build (rorkai/app-store-connect-cli-skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
KeeForge (a GitHub organization) maintains it in KeeForge/KeeForge, which has 114 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: KeeForge/KeeForge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.