ZCF Release Automation
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish.
$ npx skills add klaudworks/universal-skills --skill npm-publisher -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install klaudworks/universal-skills npm-publisher --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/klaudworks/universal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agent/skills/npm-publisher .claude/skills/npm-publisher && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "npm-publisher" agent skill from https://github.com/klaudworks/universal-skills/tree/main/.agent/skills/npm-publisher into .claude/skills/npm-publisher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-publisher", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/klaudworks/universal-skills/tree/main/.agent/skills/npm-publisherType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add klaudworks/universal-skills --skill npm-publisher -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install klaudworks/universal-skills npm-publisher --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/klaudworks/universal-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agent/skills/npm-publisher .agents/skills/npm-publisher && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "npm-publisher" agent skill from https://github.com/klaudworks/universal-skills/tree/main/.agent/skills/npm-publisher into .agents/skills/npm-publisher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-publisher", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add klaudworks/universal-skills --skill npm-publisher -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install klaudworks/universal-skills npm-publisher --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/klaudworks/universal-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agent/skills/npm-publisher .cursor/skills/npm-publisher && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "npm-publisher" agent skill from https://github.com/klaudworks/universal-skills/tree/main/.agent/skills/npm-publisher into .cursor/skills/npm-publisher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-publisher", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/klaudworks/universal-skills.git --path .agent/skills/npm-publisher--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add klaudworks/universal-skills --skill npm-publisher -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install klaudworks/universal-skills npm-publisher --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/klaudworks/universal-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agent/skills/npm-publisher .gemini/skills/npm-publisher && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "npm-publisher" agent skill from https://github.com/klaudworks/universal-skills/tree/main/.agent/skills/npm-publisher into .gemini/skills/npm-publisher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-publisher", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install klaudworks/universal-skills npm-publisherInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add klaudworks/universal-skills --skill npm-publisher -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/klaudworks/universal-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agent/skills/npm-publisher .github/skills/npm-publisher && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "npm-publisher" agent skill from https://github.com/klaudworks/universal-skills/tree/main/.agent/skills/npm-publisher into .github/skills/npm-publisher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-publisher", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add klaudworks/universal-skills --skill npm-publisher -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install klaudworks/universal-skills npm-publisher --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/klaudworks/universal-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agent/skills/npm-publisher .opencode/skills/npm-publisher && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "npm-publisher" agent skill from https://github.com/klaudworks/universal-skills/tree/main/.agent/skills/npm-publisher into .opencode/skills/npm-publisher/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm-publisher", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
npm-publisherReleases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish.
A fixed release sequence for the agent. It stages and commits pending changes with a meaningful message and no coding-agent attribution, decides on a patch, minor or major bump (asking you or inferring it from the diff), runs `npm version`, which updates package.json and creates a commit and a tag, and pushes commits and tags to the remote.
Publishing itself happens in CI: GitHub Actions publishes to npm when the new tag arrives. The agent waits about 30 seconds, checks the run with `gh run list`, and then tests the published version, clearing the npx cache first if needed. The skill also lists fixes for common failures: uncommitted changes blocking `npm version`, a rejected push (pull with rebase and retry), a failed CI run (read the logs with `gh run view --log`, fix the cause and cut a new patch) and a version that already exists.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 75e8629. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmghnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm, gh and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
npm Package Publisher loads about 923 tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 412 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from klaudworks/universal-skills at commit 75e8629, republished under its MIT licence (© klaudworks). 412 words, ~923 tokens.
.claude/skills/npm-publisher/SKILL.md (or your agent's skills folder).This skill provides a complete workflow for publishing npm packages with automated CI/CD. It handles version bumping, git tagging, and triggering automated npm publishing through GitHub Actions.
Follow this workflow when releasing a new version with unstaged changes:
Stage all pending changes:
git add .Commit with a meaningful message describing what changed:
git commit -m "$(cat <<'EOF'
<Description of changes>
<Optional: more details>
EOF
)"Important: Never add attributions to a coding agent in commit messages.
Ask the user which type of version bump is appropriate, or infer from the changes:
If unclear, analyze the git diff to determine the appropriate version type based on:
Bump the version using npm:
npm version <patch|minor|major>This command will:
Push both commits and tags to the remote repository:
git push && git push --tagsAfter pushing, publishing happens automatically through CI/CD:
gh run list --limit 1After CI completes successfully, verify the published version:
# Clear npx cache if needed
npx clear-npx-cache
# Test the new version (replace 'universal-skills' with the actual package name)
npx <package-name> --versionUncommitted changes error:
npm versiongit status to check for uncommitted changesPush rejected:
git pull --rebaseCI/CD failure:
gh run view --logVersion already exists:
npm view <package-name> versionsgit status and git diffBefore starting the release workflow, ensure:
© klaudworks, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agent/skills/npm-publisher of klaudworks/universal-skills.
Open the folder on GitHubat commit 75e8629
npm Package Publisher next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| npm Package Publisher this skillklaudworks/universal-skills | 181 | — | ~923 | Automated safety check: Pass | MIT | |
| ZCF Release AutomationUfoMiao/zcf | 6.1k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Push and PyPI Releaseliaohch3/claude-tap | 3.3k | — | ~509 | Automated safety check: Pass | MIT | |
| CI Automationjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.4k | Automated safety check: Notes | MIT | |
| PR Createposit-dev/skills | 535 | — | ~4.3k | Automated safety check: Warn | MIT | |
| CI Triageandymai/brepjs | 115 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 |
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
liaohch3/claude-tap
Pushes the current work to GitHub and, when pending commits change code, bumps the version in pyproject.toml so CI publishes a new PyPI release.
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses when running GitHub Actions locally, creating task runner recipes, generating changelogs from git history, managing GitHub PRs/issues/releases programmatically, or creating…
posit-dev/skills
Creates a pull request from current changes, monitors GitHub CI, and debugs any failures until CI passes.
andymai/brepjs
This skill should be used when a brepjs GitHub Actions job is red or behaving oddly on github.com (a remote CI run, not a local pre-commit/pre-push hook) — "CI failed", "ci-pass is failing", "npm ci…
modem-dev/hunk
Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.
Works with
Categories
Releases an npm package by committing changes, bumping the version with npm version, pushing the tag and checking the GitHub Actions publish. A fixed release sequence for the agent.json and creates a commit and a tag, and pushes commits and tags to the remote.
npm Package Publisher fits situations like: publishing a new version of an npm package; bumping the version and tagging a release; checking that a tag-triggered GitHub Actions publish succeeded; recovering from a rejected push or a failed release run.
Run `npx skills add klaudworks/universal-skills --skill npm-publisher -a claude-code`. Or copy the skill folder (.agent/skills/npm-publisher in klaudworks/universal-skills) into .claude/skills/npm-publisher in your project. Claude Code loads it when a task matches its description.
Run `npx skills add klaudworks/universal-skills --skill npm-publisher -a codex`. Or copy the skill folder (.agent/skills/npm-publisher in klaudworks/universal-skills) into .agents/skills/npm-publisher in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add klaudworks/universal-skills --skill npm-publisher -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm-publisher, .gemini/skills/npm-publisher, .github/skills/npm-publisher and .opencode/skills/npm-publisher in your project.
Going by SKILL.md and its folder, npm Package Publisher needs the command-line tools its instructions call (git, npm, gh and npx). Our summary lists: A package.json project in a Git repository; A GitHub Actions workflow that publishes to npm on new tags; The `gh` CLI for checking workflow runs.
SKILL.md contains no URLs. Its commands use git, npm, gh and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
npm Package Publisher is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 923 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with npm Package Publisher: ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Push and PyPI Release (liaohch3/claude-tap, 3.3k stars), CI Automation (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and PR Create (posit-dev/skills, 535 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
klaudworks (a GitHub user) maintains it in klaudworks/universal-skills, which has 181 GitHub stars. The repository was last updated on January 14, 2026.
Source: klaudworks/universal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.