Agent skill

npm Package Publisher

by klaudworks in klaudworks/universal-skills

Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish.

MITAuto-check passedDevelopment

Install npm Package Publisher

skills CLI
$ npx skills add klaudworks/universal-skills --skill npm-publisher -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install klaudworks/universal-skills npm-publisher --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/klaudworks/universal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agent/skills/npm-publisher .claude/skills/npm-publisher && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
npm-publisher
GitHub stars
181
Token cost
~923 tokens
SKILL.md length
412 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish.

  • Works in 7 steps: Stage All Changes → Commit the Changes → Determine Version Type → …
  • Publishing a new version of an npm package
  • SKILL.md covers Overview, Release Workflow, Error Handling and Best Practices, plus 1 more section
  • Calls git, npm and gh

What it does

A fixed release sequence for the agent. It stages and commits pending changes with a meaningful message and no coding-agent attribution, decides on a patch, minor or major bump (asking you or inferring it from the diff), runs `npm version`, which updates package.json and creates a commit and a tag, and pushes commits and tags to the remote.

Publishing itself happens in CI: GitHub Actions publishes to npm when the new tag arrives. The agent waits about 30 seconds, checks the run with `gh run list`, and then tests the published version, clearing the npx cache first if needed. The skill also lists fixes for common failures: uncommitted changes blocking `npm version`, a rejected push (pull with rebase and retry), a failed CI run (read the logs with `gh run view --log`, fix the cause and cut a new patch) and a version that already exists.

When your agent uses it

  • Publishing a new version of an npm package
  • Bumping the version and tagging a release
  • Checking that a tag-triggered GitHub Actions publish succeeded
  • Recovering from a rejected push or a failed release run

Example prompts

  • “Release a new patch version of this package to npm.”
  • “Bump the minor version, push the tag and confirm the publish workflow passed.”
  • “Deploy to npm; my changes are still uncommitted.”
  • “The npm publish run failed on CI; check the logs and tell me what went wrong.”

Requirements

  • A package.json project in a Git repository
  • A GitHub Actions workflow that publishes to npm on new tags
  • The `gh` CLI for checking workflow runs

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Stage All Changes
  2. Commit the Changes
  3. Determine Version Type
  4. Bump Version
  5. Push Commits and Tags
  6. Verify Publishing
  7. Test the New Version

What it can do on your machine

Read from SKILL.md and the folder at commit 75e8629. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • gh
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm, gh and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

npm Package Publisher loads about 923 tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 412 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~923

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from klaudworks/universal-skills at commit 75e8629, republished under its MIT licence (© klaudworks). 412 words, ~923 tokens.

Download SKILL.mdSave it as .claude/skills/npm-publisher/SKILL.md (or your agent's skills folder).
name
npm-publisher
description
This skill must be loaded via the skill tool when the user mentions anything related to publishing or release an npm package. It contains essential knowledge about the complete release workflow. Things a user might say are Publish the npm package,Release a new version,Deploy to npm,Create a new release,Bump the version and publish

NPM Publisher

Overview

This skill provides a complete workflow for publishing npm packages with automated CI/CD. It handles version bumping, git tagging, and triggering automated npm publishing through GitHub Actions.

Release Workflow

Follow this workflow when releasing a new version with unstaged changes:

Step 1: Stage All Changes

Stage all pending changes:

bash
git add .
Step 2: Commit the Changes

Commit with a meaningful message describing what changed:

bash
git commit -m "$(cat <<'EOF'
<Description of changes>

<Optional: more details>
EOF
)"

Important: Never add attributions to a coding agent in commit messages.

Step 3: Determine Version Type

Ask the user which type of version bump is appropriate, or infer from the changes:

  • patch - Bug fixes (3.0.2 → 3.0.3)
  • minor - New features (3.0.3 → 3.1.0)
  • major - Breaking changes (3.1.0 → 4.0.0)

If unclear, analyze the git diff to determine the appropriate version type based on:

  • Bug fixes only → patch
  • New features without breaking changes → minor
  • Breaking changes or major refactors → major
Step 4: Bump Version

Bump the version using npm:

bash
npm version <patch|minor|major>

This command will:

  • Increment the version in package.json
  • Create a git commit with the version bump
  • Create a git tag (e.g., v3.0.3)
Step 5: Push Commits and Tags

Push both commits and tags to the remote repository:

bash
git push && git push --tags
Step 6: Verify Publishing

After pushing, publishing happens automatically through CI/CD:

  1. GitHub Actions automatically publishes to npm when a new tag is pushed
  2. Wait approximately 30 seconds for CI to complete
  3. Verify the release succeeded:
bash
gh run list --limit 1
Step 7: Test the New Version

After CI completes successfully, verify the published version:

bash
# Clear npx cache if needed
npx clear-npx-cache

# Test the new version (replace 'universal-skills' with the actual package name)
npx <package-name> --version

Error Handling

Show full SKILL.md (171 more words)Show less
Common Issues

Uncommitted changes error:

  • Ensure all changes are committed before running npm version
  • Use git status to check for uncommitted changes

Push rejected:

  • Pull latest changes with git pull --rebase
  • Resolve any conflicts
  • Retry the push

CI/CD failure:

  • Check GitHub Actions logs: gh run view --log
  • Common causes: failing tests, missing credentials, npm registry issues
  • Fix the issue and create a new patch release if needed

Version already exists:

  • Check if the version was already published: npm view <package-name> versions
  • Bump to the next version if needed

Best Practices

  1. Always review changes before publishing with git status and git diff
  2. Run tests before publishing to catch issues early
  3. Write meaningful commit messages that explain the "why" not just the "what"
  4. Use semantic versioning consistently to manage user expectations
  5. Verify the release by testing the published package

Pre-Release Checklist

Before starting the release workflow, ensure:

  • All tests pass
  • Build succeeds without errors
  • Breaking changes are documented
  • Dependencies are up to date
  • No sensitive information in commits

© klaudworks, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agent/skills/npm-publisher of klaudworks/universal-skills.

Open the folder on GitHubat commit 75e8629

Compare with similar skills

npm Package Publisher next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

npm Package Publisher compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
npm Package Publisher this skillklaudworks/universal-skills181—~923Automated safety check: PassMIT
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
Push and PyPI Releaseliaohch3/claude-tap3.3k—~509Automated safety check: PassMIT
CI Automationjeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: NotesMIT
PR Createposit-dev/skills535—~4.3kAutomated safety check: WarnMIT
CI Triageandymai/brepjs115—~3.8kAutomated safety check: PassApache-2.0

Similar skills

  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Push and PyPI Release

    liaohch3/claude-tap

    Pushes the current work to GitHub and, when pending commits change code, bumps the version in pyproject.toml so CI publishes a new PyPI release.

    3.3k GitHub stars~509 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • CI Automation

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses when running GitHub Actions locally, creating task runner recipes, generating changelogs from git history, managing GitHub PRs/issues/releases programmatically, or creating…

    2.8k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • PR Create

    posit-dev/skills

    Creates a pull request from current changes, monitors GitHub CI, and debugs any failures until CI passes.

    535 GitHub stars~4.3k tokensUpdated 3 days ago
    DevelopmentAuto-check: warnings
  • CI Triage

    andymai/brepjs

    This skill should be used when a brepjs GitHub Actions job is red or behaving oddly on github.com (a remote CI run, not a local pre-commit/pre-push hook) — "CI failed", "ci-pass is failing", "npm ci…

    115 GitHub stars~3.8k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.6k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed

Questions about npm Package Publisher

What does npm Package Publisher do?

Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish. A fixed release sequence for the agent.json and creates a commit and a tag, and pushes commits and tags to the remote.

When should I use npm Package Publisher?

npm Package Publisher fits situations like: publishing a new version of an npm package; bumping the version and tagging a release; checking that a tag-triggered GitHub Actions publish succeeded; recovering from a rejected push or a failed release run.

How do I install npm Package Publisher in Claude Code?

Run `npx skills add klaudworks/universal-skills --skill npm-publisher -a claude-code`. Or copy the skill folder (.agent/skills/npm-publisher in klaudworks/universal-skills) into .claude/skills/npm-publisher in your project. Claude Code loads it when a task matches its description.

How do I install npm Package Publisher in Codex?

Run `npx skills add klaudworks/universal-skills --skill npm-publisher -a codex`. Or copy the skill folder (.agent/skills/npm-publisher in klaudworks/universal-skills) into .agents/skills/npm-publisher in your project. Codex loads it when a task matches its description.

Can I use npm Package Publisher in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add klaudworks/universal-skills --skill npm-publisher -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm-publisher, .gemini/skills/npm-publisher, .github/skills/npm-publisher and .opencode/skills/npm-publisher in your project.

What does npm Package Publisher need to run?

Going by SKILL.md and its folder, npm Package Publisher needs the command-line tools its instructions call (git, npm, gh and npx). Our summary lists: A package.json project in a Git repository; A GitHub Actions workflow that publishes to npm on new tags; The `gh` CLI for checking workflow runs.

Does npm Package Publisher access the network?

SKILL.md contains no URLs. Its commands use git, npm, gh and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is npm Package Publisher safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does npm Package Publisher use?

npm Package Publisher is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does npm Package Publisher use?

About 923 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to npm Package Publisher?

Skills that share tags, products or a category with npm Package Publisher: ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Push and PyPI Release (liaohch3/claude-tap, 3.3k stars), CI Automation (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and PR Create (posit-dev/skills, 535 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains npm Package Publisher?

klaudworks (a GitHub user) maintains it in klaudworks/universal-skills, which has 181 GitHub stars. The repository was last updated on January 14, 2026.

Source: klaudworks/universal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.