Agent skill

Cut Release

by layer5io in layer5io/sistent

Runbook for cutting a release of @sistent/sistent to npm. An agent skill from layer5io/sistent.

Apache-2.0Auto-check passedDevOps & Cloud

Install Cut Release

skills CLI
$ npx skills add layer5io/sistent --skill cut-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install layer5io/sistent cut-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/layer5io/sistent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cut-release .claude/skills/cut-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cut-release
GitHub stars
138
Token cost
~1.4k tokens
SKILL.md length
633 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runbook for cutting a release of @sistent/sistent to npm. An agent skill from layer5io/sistent.

  • Works in 4 steps: A PR merges to master →… → You publish the draft Release. The tag… → Publishing emits release: published →… → …
  • Asked to cut a release
  • SKILL.md covers The release chain (what…, Procedure, Verify and What NOT to do, plus 1 more section
  • Calls npm and gh

What it does

Cut Release is an agent skill from layer5io/sistent. Runbook for cutting a release of @sistent/sistent to npm. Use when asked to "cut a release", "release Sistent", "publish a new version", or "ship the next @sistent/sistent". The flow is: wait for Release Drafter to fold the merged PR into the draft release, then publish that draft - Release Drafter has already set the version (from the merged PR's labels) and the notes, and release.yml handles the npm publish (OIDC provenance) and the auto-merged version-bump-back.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering OAuth and OpenID Connect and Runbooks and postmortems. It works with npm. The licence is Apache-2.0.

When your agent uses it

  • Asked to cut a release
  • Release Sistent
  • Publish a new version
  • Ship the next @sistent/sistent

Example prompts

  • “cut a release”
  • “release Sistent”
  • “publish a new version”
  • “/cut-release”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. A PR merges to master → release-drafter.yml runs and updates the draft GitHub Release: it folds that PR into the changelog and computes…
  2. You publish the draft Release. The tag (e.g. v0.21.31) becomes the version source of truth.
  3. Publishing emits release: published → release.yml: sets package.json#version from the tag, npm ci → npm run build → npm publish…
  4. notify-dependents.yml fires on the publish workflow's success and bumps downstream consumers (e.g. meshery, meshery-cloud) to the new…

What it can do on your machine

Read from SKILL.md and the folder at commit 672bc14. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cut Release loads about 1.4k tokens when it runs. Until then it costs about 120 tokens; SKILL.md has 633 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from layer5io/sistent at commit 672bc14, republished under its Apache-2.0 licence (© layer5io). 633 words, ~1,434 tokens.

Download SKILL.mdSave it as .claude/skills/cut-release/SKILL.md (or your agent's skills folder).
name
cut-release
description
Runbook for cutting a release of @sistent/sistent to npm. Use when asked to "cut a release", "release Sistent", "publish a new version", or "ship the next @sistent/sistent". The flow is: wait for Release Drafter to fold the merged PR into the draft release, then publish that draft - Release Drafter has already set the version (from the merged PR's labels) and the notes, and release.yml handles the npm publish (OIDC provenance) and the auto-merged version-bump-back.
user-invocable
true

Cut a Sistent Release

Publishes a new version of the @sistent/sistent npm package. Releasing is automation-driven and requires no manual preparation: Release Drafter already computes the next version and writes the release notes, and the publish workflow does the rest. You do not run npm publish, bump package.json, write release notes, or create a git tag by hand.

  • Package: @sistent/sistent (public, scope @sistent), published with npm provenance via OIDC trusted publishing.
  • Release branch: master (protected — requires PR approval).
  • Workflows: .github/workflows/release-drafter.yml maintains the draft Release; .github/workflows/release.yml ("Publish Node.js Package") does the npm publish, then opens and auto-merges the version-bump-back PR; notify-dependents.yml updates downstream consumers after a successful publish.

The release chain (what actually happens)

  1. A PR merges to master → release-drafter.yml runs and updates the draft GitHub Release: it folds that PR into the changelog and computes the next version from the PR's labels (major / minor / patch, defaulting to patch when unlabelled).
  2. You publish the draft Release. The tag (e.g. v0.21.31) becomes the version source of truth.
  3. Publishing emits release: published → release.yml: sets package.json#version from the tag, npm ci → npm run build → npm publish --provenance --access public, then opens the release/version-bump/vX.Y.Z PR and auto-merges it so master's package.json/package-lock.json track the published version without sitting idle.
  4. notify-dependents.yml fires on the publish workflow's success and bumps downstream consumers (e.g. meshery, meshery-cloud) to the new version.

Procedure

The only human step is publishing the drafted release - Release Drafter has already done the versioning and notes.

  1. Wait for Release Drafter to fold your merged PR into the draft. After the PR merges to master, release-drafter.yml runs (a few seconds). Confirm the draft now reflects the merged PR and shows the intended next version:

    bash
    gh release list --repo layer5io/sistent          # find the draft (isDraft = true)
    gh release view <vX.Y.Z> --repo layer5io/sistent  # confirm version + notes

    If the version bump is wrong, it's driven by the merged PR's labels - relabel and let Release Drafter re-draft; do not hand-edit the tag. Which label a breaking change gets is the pre-1.0 rule in AGENTS.md's Releasing section.

    Relabelling alone does not re-draft: release-drafter.yml runs on push to master, so nothing re-runs it after the merge. Re-run it by hand once the label is right:

    bash
    gh workflow run release-drafter.yml --repo layer5io/sistent --ref master

    Then re-check the draft with gh release view before publishing.

  2. Publish the draft Release. That's it. No version editing, no notes, no tagging:

    bash
    gh release edit <vX.Y.Z> --repo layer5io/sistent --draft=false --latest

    Publishing triggers release.yml, which publishes to npm and auto-merges the version-bump-back PR.

A label-driven minor or major has never actually been drafted in this repo. Until the config change alongside this note, the name and tag templates interpolated $NEXT_PATCH_VERSION, so version-resolver was inert and every v0.21.* release drafted as a patch regardless of labels (v0.21.0 and the boundaries below it were created by hand). The first non-patch draft is worth confirming against step 1 before publishing rather than assuming.

Show full SKILL.md (207 more words)Show less

Verify

  1. Watch the publish workflow to success:
    bash
    gh run watch --repo layer5io/sistent \
      "$(gh run list --repo layer5io/sistent --workflow release.yml --limit 1 --json databaseId --jq '.[0].databaseId')"
  2. Confirm the version is live on npm:
    bash
    npm view @sistent/sistent version
  3. Confirm the release/version-bump/vX.Y.Z PR auto-merged (it should close on its own) and that notify-dependents opened the downstream consumer bump PRs.

What NOT to do

  • ❌ Don't npm publish locally or npm version-tag by hand — the workflow owns publishing (with provenance) and the version comes from the release tag.
  • ❌ Don't edit the draft's version or release notes - Release Drafter owns both; fix PR labels instead.
  • ❌ Don't publish expecting an unmerged PR to be included — the release ships master's current state; merge first, then let Release Drafter update the draft.
  • ❌ Don't republish an already-published npm version — npm publishes are effectively permanent; cut a new patch instead.

Permissions note

Publishing a release deploys to the public npm registry — an irreversible, outward-facing action, and it runs against a protected branch. Restricted agent / CI sessions can be blocked from publishing releases and merging protected branches (e.g. 403 "not permitted for this session type"); in that case, hand the publish step to a maintainer with release rights rather than attempting to force it.

© layer5io, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cut-release of layer5io/sistent.

Open the folder on GitHubat commit 672bc14

Compare with similar skills

Cut Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cut Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cut Release this skilllayer5io/sistent138—~1.4kAutomated safety check: PassApache-2.0
Releasenubjs/nub4.4k—~7.6kAutomated safety check: PassMIT
npm Trusted Publishingpr-pm/prpm122—~781Automated safety check: PassMIT
Procore Incident Runbookjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Releasing Blancbnfy/blanc111—~2.9kAutomated safety check: NotesMIT
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT

Similar skills

  • Release

    nubjs/nub

    Cut a Nub patch release end-to-end in one invocation. An agent skill from nubjs/nub.

    4.4k GitHub stars~7.6k tokensUpdated today
    DevelopmentAuto-check passed
  • A skill your agent uses when setting up npm publishing with GitHub Actions - provides trusted publishing with OIDC, provenance attestations, and monorepo configuration

    122 GitHub stars~781 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Procore Incident Runbook

    jeremylongshore/tons-of-skills-marketplace

    Analyze, triage, and recover a Procore integration incident across provider health, OAuth, company routing, permissions, rate limits, webhooks, files, and synchronization gaps.

    2.8k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Releasing Blanc

    bnfy/blanc

    Full runbook for cutting a Blanc desktop release — scripts/release.sh mechanics and its required BLANCRELEASE env vars, macOS notarization via 1Password, the Touch ID provisioning profile and…

    111 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Convex Self Hosting

    waynesutton/markdown-site

    Integrate Convex static self hosting into existing apps using the latest upstream instructions from get-convex/self-hosting every time.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed

More from layer5io/sistent

  • Chrome Devtools Axi

    layer5io/sistent

    Control a Chrome browser session through the chrome-devtools-axi CLI - navigate, snapshot, click, fill forms, run JavaScript, inspect console and network, take screenshots, audit performance.

    138 GitHub starsUsed in 2 repos~989 tokens
    Auto-check passed
  • Gh Axi

    layer5io/sistent

    Operate GitHub through the gh-axi CLI - issues, pull requests, workflow runs, workflows, releases, repositories, labels, Projects (v2), Actions secrets and variables, search, and raw API access.

    138 GitHub stars~1.3k tokensUpdated 5 days ago
    Auto-check passed
  • Quota Axi

    layer5io/sistent

    Report local Claude, Codex, Cursor, GitHub Copilot, and Grok quota windows via the quota-axi CLI - remaining percentages, reset times, and provider status read from local auth sources, with no…

    138 GitHub stars~956 tokensUpdated 5 days ago
    Auto-check passed
  • Lavish

    layer5io/sistent

    Turn complex or visual agent responses into rich, reviewable HTML artifacts the user can annotate and send feedback on, using the lavish-axi CLI.

    138 GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check: warnings
  • Iterate PR

    layer5io/sistent

    Iterate on a PR until CI passes. An agent skill from layer5io/sistent.

    138 GitHub stars~5.4k tokensUpdated 5 days ago
    Auto-check: warnings

Works with

Questions about Cut Release

What does Cut Release do?

Runbook for cutting a release of @sistent/sistent to npm. An agent skill from layer5io/sistent. Cut Release is an agent skill from layer5io/sistent. Runbook for cutting a release of @sistent/sistent to npm.

When should I use Cut Release?

Cut Release fits situations like: asked to cut a release; release Sistent; publish a new version; ship the next @sistent/sistent.

How do I install Cut Release in Claude Code?

Run `npx skills add layer5io/sistent --skill cut-release -a claude-code`. Or copy the skill folder (.agents/skills/cut-release in layer5io/sistent) into .claude/skills/cut-release in your project. Claude Code loads it when a task matches its description.

How do I install Cut Release in Codex?

Run `npx skills add layer5io/sistent --skill cut-release -a codex`. Or copy the skill folder (.agents/skills/cut-release in layer5io/sistent) into .agents/skills/cut-release in your project. Codex loads it when a task matches its description.

Can I use Cut Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add layer5io/sistent --skill cut-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cut-release, .gemini/skills/cut-release, .github/skills/cut-release and .opencode/skills/cut-release in your project.

What does Cut Release need to run?

Going by SKILL.md and its folder, Cut Release needs the command-line tools its instructions call (npm and gh). Our summary lists: Node.js.

Does Cut Release access the network?

SKILL.md contains no URLs. Its commands use npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cut Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cut Release use?

Cut Release is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cut Release use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cut Release?

Skills that share tags, products or a category with Cut Release: Release (nubjs/nub, 4.4k stars), npm Trusted Publishing (pr-pm/prpm, 122 stars), Procore Incident Runbook (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Releasing Blanc (bnfy/blanc, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cut Release?

layer5io (a GitHub organization) maintains it in layer5io/sistent, which has 138 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 2, 2026.

Source: layer5io/sistent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.