Desktop Release Preflight
Eynzof/Hermes-CN-Desktop
Use BEFORE preparing or publishing any Hermes Agent CN Desktop release (new installer, version bump, GitHub Release, or publishing a new build to users).
Guides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled.
$ npx skills add leookun/cursor-byok --skill release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install leookun/cursor-byok release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/leookun/cursor-byok.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release .claude/skills/release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release" agent skill from https://github.com/leookun/cursor-byok/tree/main/.agents/skills/release into .claude/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/leookun/cursor-byok/tree/main/.agents/skills/releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add leookun/cursor-byok --skill release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install leookun/cursor-byok release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leookun/cursor-byok.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/release .agents/skills/release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release" agent skill from https://github.com/leookun/cursor-byok/tree/main/.agents/skills/release into .agents/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add leookun/cursor-byok --skill release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install leookun/cursor-byok release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leookun/cursor-byok.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/release .cursor/skills/release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release" agent skill from https://github.com/leookun/cursor-byok/tree/main/.agents/skills/release into .cursor/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/leookun/cursor-byok.git --path .agents/skills/release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add leookun/cursor-byok --skill release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install leookun/cursor-byok release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leookun/cursor-byok.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/release .gemini/skills/release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/leookun/cursor-byok/tree/main/.agents/skills/release into .gemini/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install leookun/cursor-byok releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add leookun/cursor-byok --skill release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/leookun/cursor-byok.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/release .github/skills/release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/leookun/cursor-byok/tree/main/.agents/skills/release into .github/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add leookun/cursor-byok --skill release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install leookun/cursor-byok release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/leookun/cursor-byok.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/release .opencode/skills/release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/leookun/cursor-byok/tree/main/.agents/skills/release into .opencode/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
releaseGuides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled.
Releases go through the repository's release workflow in GitHub Actions and must keep two updater formats working: latest.json for Tauri clients and update.json for older legacy clients. Only the repository author may authorize a live release, which the agent confirms by checking that the GitHub CLI is logged in as that user. Pushing a version tag, rerunning the release workflow and publishing or editing a GitHub Release all count as publication, while pushing a release commit to main only prepares one. Without authorization the agent limits itself to inspection, local edits, validation and a release-ready commit or branch.
Versions follow SemVer tags such as v0.1.0, with beta tags like v0.1.0-beta.1 published as normal GitHub Releases rather than prereleases, because the update clients read the latest-release download path. Windows beta builds use the NSIS bundle since MSI rejects non-numeric prerelease identifiers. Releases come only from a tag whose commit is on origin/main, desktop versions must match across manifests and locks, and a published version is never republished. Existing tags and releases are not deleted or moved without separate permission, and the signing key is never printed or committed.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9a8fde2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmghgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
TAURI_SIGNING_PRIVATE_KEYTAURI_SIGNING_PRIVATE_KEY_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cursor BYOK Desktop Release loads about 1.3k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 654 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from leookun/cursor-byok at commit 9a8fde2, republished under its MIT licence (© leookun). 654 words, ~1,304 tokens.
.claude/skills/release/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Release through .github/workflows/release.yml. Preserve both updater formats: Tauri uses latest.json; legacy v0.0.49 clients use update.json.
leookun, may authorize a live release.gh api user --jq .login returns leookun.v* tag, rerunning the release workflow, and publishing or editing a GitHub Release. Pushing a release commit to main only prepares the release and must never trigger publication by itself..tauri/cursor-byok.key anywhere except the repository's TAURI_SIGNING_PRIVATE_KEY Actions Secret when the author explicitly requests that secret configuration.prerelease: false for every release and publish the completed release as Latest.vMAJOR.MINOR.PATCH for a stable tag, for example v0.1.0.vMAJOR.MINOR.PATCH-beta.N for a test tag, for example v0.1.0-beta.1. A beta is still a normal GitHub Release, not a GitHub prerelease. Make its title or body visibly say Beta./releases/latest/download/ path, which excludes GitHub prereleases.beta.1; do not weaken the SemVer tag to accommodate MSI.v* tag whose commit is contained in origin/main. The tag must equal v<version> from the desktop manifests.main pushes and manual workflow dispatch disabled as release triggers. The author pushes the matching tag only after the release commit is present on origin/main.Keep the desktop version identical in the manifests and their locks:
cursor-byok/
├── Cargo.lock
├── apps/desktop/
│ ├── package.json
│ ├── package-lock.json
│ └── src-tauri/
│ ├── Cargo.toml
│ └── tauri.conf.json
├── scripts/cursor-proto/proto/
│ ├── agent_v1.proto
│ └── aiserver_v1.proto
└── .github/workflows/release.ymlThe two listed Proto files are required build inputs and must be committed. Keep the other locally extracted Proto files ignored unless the build starts depending on them.
Inspect git status, fetch origin/main, and preserve unrelated user changes. Confirm the release commit is based on the current remote head.
Choose stable or beta numbering explicitly. Update the desktop version in both manifests and lockfiles; do not change the independent cursor-server version merely to release the desktop app.
Confirm the updater public key in tauri.conf.json matches .tauri/cursor-byok.key.pub without exposing the private key.
Confirm TAURI_SIGNING_PRIVATE_KEY exists in GitHub Actions. TAURI_SIGNING_PRIVATE_KEY_PASSWORD must be absent when the local key has no password.
Confirm neither the intended tag nor Release already exists.
From apps/desktop, run:
npm run check
npm run tauri:build -- --debug --no-bundleValidate the workflow YAML and inspect the staged diff. Ensure .tauri/, unrelated local files, and unrelated user changes are not staged.
Use the tauri-action@v1 input uploadUpdaterJson: true; includeUpdaterJson is not a valid v1 input.
After the author explicitly authorizes publication:
main. Confirm the release commit is present in origin/main; this push must not start the release workflow.v0.1.0-beta.1, and push only that tag. This tag push is the publication trigger.Release desktop app run through completion. Report the run URL and stop on failure; diagnose locally before asking the author to authorize another live attempt.v<version> exists, is published rather than draft, has prerelease: false, and is the repository's Latest release.latest.json, and the legacy platform archives plus update.json.© leookun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/release of leookun/cursor-byok.
Open the folder on GitHubat commit 9a8fde2
Cursor BYOK Desktop Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cursor BYOK Desktop Release this skillleookun/cursor-byok | 3.2k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Desktop Release PreflightEynzof/Hermes-CN-Desktop | 1.7k | — | ~1.6k | Automated safety check: Notes | Custom licence | |
| OpenWork Release Processdifferent-ai/openwork | 24k | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| AI News RadarLearnPrompt/ai-news-radar | 1.8k | — | ~2.5k | Automated safety check: Notes | MIT | |
| Cline Desktop App Releasecline/cline | 70k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Use Vercel Actionamondnet/vercel-action | 765 | — | ~2.7k | Automated safety check: Pass | MIT |
Eynzof/Hermes-CN-Desktop
Use BEFORE preparing or publishing any Hermes Agent CN Desktop release (new installer, version bump, GitHub Release, or publishing a new build to users).
different-ai/openwork
Cuts an OpenWork desktop release through a tag-driven GitHub Actions workflow that makes no commits, with pre-tag checks on open fix PRs and verification afterward.
LearnPrompt/ai-news-radar
A skill your agent uses when working on AI News Radar, 24 小时 AI 更新雷达, AI 更新雷达, 伯乐Skill, or Scout Skill: finding high-signal AI/tech sources, adding RSS/OPML/GitHub feeds, checking source health…
cline/cline
Covers preparing, tagging and publishing a Cline desktop app release on the stable, beta or nightly channel through the desktop-publish GitHub workflow.
amondnet/vercel-action
Wire amondnet/vercel-action into a GitHub Actions workflow to deploy Vercel projects from CI.
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
leookun/cursor-byok
Guides changes to the cursor-byok server so provider conversation history stays append-only and each turn's history remains an exact prefix of the next, protecting prefix caches.
leookun/cursor-byok
Guides SQLite schema changes in the Cursor BYOK server, keeping SQLx migrations, the Rust store, API contracts and fixtures aligned.
leookun/cursor-byok
Sets the rules for building the Cursor BYOK desktop app's React and Tauri frontend, especially its HTTP boundary and component state architecture.
leookun/cursor-byok
Standardizes how a desktop app's UI lets a person choose one or more already-configured AI models, through a single grouped dropdown component.
leookun/cursor-byok
Rules for localizing the Cursor BYOK desktop app: the global t() function, complete locale catalogs, system-language selection and the scan-and-check commands.
leookun/cursor-byok
Rules for building dropdowns, popovers, tooltips and menus in the desktop app with @floating-ui/dom, covering portals, positioning, dismissal and ARIA state.
Works with
Categories
Guides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled. json for older legacy clients. Only the repository author may authorize a live release, which the agent confirms by checking that the GitHub CLI is logged in as that user.
Cursor BYOK Desktop Release fits situations like: bumping the desktop version and preparing a release commit; troubleshooting a failed GitHub Actions release run; checking updater manifests and signing before publishing; running a release-readiness check without publishing.
Run `npx skills add leookun/cursor-byok --skill release -a claude-code`. Or copy the skill folder (.agents/skills/release in leookun/cursor-byok) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add leookun/cursor-byok --skill release -a codex`. Or copy the skill folder (.agents/skills/release in leookun/cursor-byok) into .agents/skills/release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add leookun/cursor-byok --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.
Going by SKILL.md and its folder, Cursor BYOK Desktop Release needs the command-line tools its instructions call (npm, gh and git) and credentials named TAURI_SIGNING_PRIVATE_KEY and TAURI_SIGNING_PRIVATE_KEY_PASSWORD. Our summary lists: GitHub CLI signed in as the repository author, for live releases; The cursor-byok repository with its release workflow.
SKILL.md contains no URLs. Its commands use npm, gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cursor BYOK Desktop Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cursor BYOK Desktop Release: Desktop Release Preflight (Eynzof/Hermes-CN-Desktop, 1.7k stars), OpenWork Release Process (different-ai/openwork, 24k stars), AI News Radar (LearnPrompt/ai-news-radar, 1.8k stars) and Cline Desktop App Release (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
leookun (a GitHub user) maintains it in leookun/cursor-byok, which has 3,151 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on September 28, 2026.
Source: leookun/cursor-byok on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.