Agent skill

Cursor BYOK Desktop Release

by leookun in leookun/cursor-byok

Guides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled.

MITAuto-check passedDevOps & Cloud

Install Cursor BYOK Desktop Release

skills CLI
$ npx skills add leookun/cursor-byok --skill release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install leookun/cursor-byok release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/leookun/cursor-byok.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release .claude/skills/release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release
GitHub stars
3.2k
Token cost
~1.3k tokens
SKILL.md length
654 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Guides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled.

  • Works in 8 steps: Inspect git status, fetch origin/main,… → Choose stable or beta numbering… → Confirm the updater public key in… → …
  • Bumping the desktop version and preparing a release commit
  • SKILL.md covers Publication authority, Version and GitHub Release…, Release sources and Prepare and validate, plus 1 more section
  • Calls npm, gh and git; needs TAURI_SIGNING_PRIVATE_KEY and TAURI_SIGNING_PRIVATE_KEY_PASSWORD

What it does

Releases go through the repository's release workflow in GitHub Actions and must keep two updater formats working: latest.json for Tauri clients and update.json for older legacy clients. Only the repository author may authorize a live release, which the agent confirms by checking that the GitHub CLI is logged in as that user. Pushing a version tag, rerunning the release workflow and publishing or editing a GitHub Release all count as publication, while pushing a release commit to main only prepares one. Without authorization the agent limits itself to inspection, local edits, validation and a release-ready commit or branch.

Versions follow SemVer tags such as v0.1.0, with beta tags like v0.1.0-beta.1 published as normal GitHub Releases rather than prereleases, because the update clients read the latest-release download path. Windows beta builds use the NSIS bundle since MSI rejects non-numeric prerelease identifiers. Releases come only from a tag whose commit is on origin/main, desktop versions must match across manifests and locks, and a published version is never republished. Existing tags and releases are not deleted or moved without separate permission, and the signing key is never printed or committed.

When your agent uses it

  • Bumping the desktop version and preparing a release commit
  • Troubleshooting a failed GitHub Actions release run
  • Checking updater manifests and signing before publishing
  • Running a release-readiness check without publishing

Example prompts

  • “Check whether the repository is ready for a stable release and list anything blocking it.”
  • “The release workflow failed on the Windows build. Find out why.”
  • “Prepare the version bump and release notes for the next beta, but do not push a tag.”

Requirements

  • GitHub CLI signed in as the repository author, for live releases
  • The cursor-byok repository with its release workflow

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Inspect git status, fetch origin/main, and preserve unrelated user changes. Confirm the release commit is based on the current remote head.
  2. Choose stable or beta numbering explicitly. Update the desktop version in both manifests and lockfiles; do not change the independent…
  3. Confirm the updater public key in tauri.conf.json matches .tauri/cursor-byok.key.pub without exposing the private key.
  4. Confirm TAURI_SIGNING_PRIVATE_KEY exists in GitHub Actions. TAURI_SIGNING_PRIVATE_KEY_PASSWORD must be absent when the local key has no…
  5. Confirm neither the intended tag nor Release already exists.
  6. From apps/desktop, run
  7. Validate the workflow YAML and inspect the staged diff. Ensure .tauri/, unrelated local files, and unrelated user changes are not staged.
  8. Use the tauri-action@v1 input uploadUpdaterJson: true; includeUpdaterJson is not a valid v1 input.

What it can do on your machine

Read from SKILL.md and the folder at commit 9a8fde2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TAURI_SIGNING_PRIVATE_KEY
    • TAURI_SIGNING_PRIVATE_KEY_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cursor BYOK Desktop Release loads about 1.3k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 654 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from leookun/cursor-byok at commit 9a8fde2, republished under its MIT licence (© leookun). 654 words, ~1,304 tokens.

Download SKILL.mdSave it as .claude/skills/release/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
release
description
Prepare, authorize, publish, troubleshoot, and verify Cursor BYOK desktop GitHub Releases. Use for version bumps, release tags, GitHub Actions release runs, updater manifests, signing, or release-readiness checks.

Desktop release

Release through .github/workflows/release.yml. Preserve both updater formats: Tauri uses latest.json; legacy v0.0.49 clients use update.json.

Publication authority

  • Only the repository author, GitHub user leookun, may authorize a live release.
  • Before any live mutation, require an explicit release instruction from the author in the current task and verify gh api user --jq .login returns leookun.
  • Treat all of these as publication actions: pushing a v* tag, rerunning the release workflow, and publishing or editing a GitHub Release. Pushing a release commit to main only prepares the release and must never trigger publication by itself.
  • Without that authorization, restrict work to inspection, local edits, validation, and a release-ready commit or branch. Do not infer publication permission from requests such as “prepare”, “check”, or “ready to release”.
  • Never print, commit, or upload .tauri/cursor-byok.key anywhere except the repository's TAURI_SIGNING_PRIVATE_KEY Actions Secret when the author explicitly requests that secret configuration.
  • Never delete, replace, or move an existing tag or published Release without separate explicit authorization.

Version and GitHub Release policy

  • Do not use GitHub prereleases. Keep prerelease: false for every release and publish the completed release as Latest.
  • Use vMAJOR.MINOR.PATCH for a stable tag, for example v0.1.0.
  • Use standard SemVer vMAJOR.MINOR.PATCH-beta.N for a test tag, for example v0.1.0-beta.1. A beta is still a normal GitHub Release, not a GitHub prerelease. Make its title or body visibly say Beta.
  • This normal-Release rule is required because both installed update clients resolve assets through GitHub's /releases/latest/download/ path, which excludes GitHub prereleases.
  • Windows beta builds must use the NSIS bundle. WiX/MSI rejects nonnumeric prerelease identifiers such as beta.1; do not weaken the SemVer tag to accommodate MSI.
  • Release only from a v* tag whose commit is contained in origin/main. The tag must equal v<version> from the desktop manifests.
  • Keep ordinary main pushes and manual workflow dispatch disabled as release triggers. The author pushes the matching tag only after the release commit is present on origin/main.
  • Never republish an already published version. Select a new version instead.

Release sources

Keep the desktop version identical in the manifests and their locks:

text
cursor-byok/
├── Cargo.lock
├── apps/desktop/
│   ├── package.json
│   ├── package-lock.json
│   └── src-tauri/
│       ├── Cargo.toml
│       └── tauri.conf.json
├── scripts/cursor-proto/proto/
│   ├── agent_v1.proto
│   └── aiserver_v1.proto
└── .github/workflows/release.yml

The two listed Proto files are required build inputs and must be committed. Keep the other locally extracted Proto files ignored unless the build starts depending on them.

Show full SKILL.md (293 more words)Show less

Prepare and validate

  1. Inspect git status, fetch origin/main, and preserve unrelated user changes. Confirm the release commit is based on the current remote head.

  2. Choose stable or beta numbering explicitly. Update the desktop version in both manifests and lockfiles; do not change the independent cursor-server version merely to release the desktop app.

  3. Confirm the updater public key in tauri.conf.json matches .tauri/cursor-byok.key.pub without exposing the private key.

  4. Confirm TAURI_SIGNING_PRIVATE_KEY exists in GitHub Actions. TAURI_SIGNING_PRIVATE_KEY_PASSWORD must be absent when the local key has no password.

  5. Confirm neither the intended tag nor Release already exists.

  6. From apps/desktop, run:

    bash
    npm run check
    npm run tauri:build -- --debug --no-bundle
  7. Validate the workflow YAML and inspect the staged diff. Ensure .tauri/, unrelated local files, and unrelated user changes are not staged.

  8. Use the tauri-action@v1 input uploadUpdaterJson: true; includeUpdaterJson is not a valid v1 input.

Publish and verify

After the author explicitly authorizes publication:

  1. Commit only the reviewed release set and push it to main. Confirm the release commit is present in origin/main; this push must not start the release workflow.
  2. Create the matching tag on that commit, for example v0.1.0-beta.1, and push only that tag. This tag push is the publication trigger.
  3. Follow the triggered Release desktop app run through completion. Report the run URL and stop on failure; diagnose locally before asking the author to authorize another live attempt.
  4. Verify v<version> exists, is published rather than draft, has prerelease: false, and is the repository's Latest release.
  5. Verify the Release contains signed Tauri updater artifacts plus latest.json, and the legacy platform archives plus update.json.
  6. For a beta, report clearly that it is a test version even though GitHub represents it as a normal Latest Release.

© leookun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/release of leookun/cursor-byok.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 9a8fde2

Compare with similar skills

Cursor BYOK Desktop Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cursor BYOK Desktop Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cursor BYOK Desktop Release this skillleookun/cursor-byok3.2k—~1.3kAutomated safety check: PassMIT
Desktop Release PreflightEynzof/Hermes-CN-Desktop1.7k—~1.6kAutomated safety check: NotesCustom licence
OpenWork Release Processdifferent-ai/openwork24k—~2.3kAutomated safety check: PassCustom licence
AI News RadarLearnPrompt/ai-news-radar1.8k—~2.5kAutomated safety check: NotesMIT
Cline Desktop App Releasecline/cline70k—~4.5kAutomated safety check: PassApache-2.0
Use Vercel Actionamondnet/vercel-action765—~2.7kAutomated safety check: PassMIT

Similar skills

  • Desktop Release Preflight

    Eynzof/Hermes-CN-Desktop

    Use BEFORE preparing or publishing any Hermes Agent CN Desktop release (new installer, version bump, GitHub Release, or publishing a new build to users).

    1.7k GitHub stars~1.6k tokensUpdated 16 days ago
    DevOps & CloudAuto-check: notes
  • OpenWork Release Process

    different-ai/openwork

    Cuts an OpenWork desktop release through a tag-driven GitHub Actions workflow that makes no commits, with pre-tag checks on open fix PRs and verification afterward.

    24k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AI News Radar

    LearnPrompt/ai-news-radar

    A skill your agent uses when working on AI News Radar, 24 小时 AI 更新雷达, AI 更新雷达, 伯乐Skill, or Scout Skill: finding high-signal AI/tech sources, adding RSS/OPML/GitHub feeds, checking source health…

    1.8k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Covers preparing, tagging and publishing a Cline desktop app release on the stable, beta or nightly channel through the desktop-publish GitHub workflow.

    70k GitHub stars~4.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Use Vercel Action

    amondnet/vercel-action

    Wire amondnet/vercel-action into a GitHub Actions workflow to deploy Vercel projects from CI.

    765 GitHub stars~2.7k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from leookun/cursor-byok

  • Cursor BYOK Prefix Stability

    leookun/cursor-byok

    Guides changes to the cursor-byok server so provider conversation history stays append-only and each turn's history remains an exact prefix of the next, protecting prefix caches.

    3.2k GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check passed
  • Cursor BYOK Database Schema

    leookun/cursor-byok

    Guides SQLite schema changes in the Cursor BYOK server, keeping SQLx migrations, the Rust store, API contracts and fixtures aligned.

    3.2k GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check passed
  • Cursor BYOK Frontend Guide

    leookun/cursor-byok

    Sets the rules for building the Cursor BYOK desktop app's React and Tauri frontend, especially its HTTP boundary and component state architecture.

    3.2k GitHub stars~1.9k tokensUpdated 9 days ago
    Auto-check passed
  • Model Selection Component

    leookun/cursor-byok

    Standardizes how a desktop app's UI lets a person choose one or more already-configured AI models, through a single grouped dropdown component.

    3.2k GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check passed
  • Desktop i18n for Cursor BYOK

    leookun/cursor-byok

    Rules for localizing the Cursor BYOK desktop app: the global t() function, complete locale catalogs, system-language selection and the scan-and-check commands.

    3.2k GitHub stars~508 tokensUpdated 9 days ago
    Auto-check passed
  • Floating UI Overlays

    leookun/cursor-byok

    Rules for building dropdowns, popovers, tooltips and menus in the desktop app with @floating-ui/dom, covering portals, positioning, dismissal and ARIA state.

    3.2k GitHub stars~496 tokensUpdated 9 days ago
    Auto-check passed

Questions about Cursor BYOK Desktop Release

What does Cursor BYOK Desktop Release do?

Guides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled. json for older legacy clients. Only the repository author may authorize a live release, which the agent confirms by checking that the GitHub CLI is logged in as that user.

When should I use Cursor BYOK Desktop Release?

Cursor BYOK Desktop Release fits situations like: bumping the desktop version and preparing a release commit; troubleshooting a failed GitHub Actions release run; checking updater manifests and signing before publishing; running a release-readiness check without publishing.

How do I install Cursor BYOK Desktop Release in Claude Code?

Run `npx skills add leookun/cursor-byok --skill release -a claude-code`. Or copy the skill folder (.agents/skills/release in leookun/cursor-byok) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.

How do I install Cursor BYOK Desktop Release in Codex?

Run `npx skills add leookun/cursor-byok --skill release -a codex`. Or copy the skill folder (.agents/skills/release in leookun/cursor-byok) into .agents/skills/release in your project. Codex loads it when a task matches its description.

Can I use Cursor BYOK Desktop Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add leookun/cursor-byok --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.

What does Cursor BYOK Desktop Release need to run?

Going by SKILL.md and its folder, Cursor BYOK Desktop Release needs the command-line tools its instructions call (npm, gh and git) and credentials named TAURI_SIGNING_PRIVATE_KEY and TAURI_SIGNING_PRIVATE_KEY_PASSWORD. Our summary lists: GitHub CLI signed in as the repository author, for live releases; The cursor-byok repository with its release workflow.

Does Cursor BYOK Desktop Release access the network?

SKILL.md contains no URLs. Its commands use npm, gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cursor BYOK Desktop Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cursor BYOK Desktop Release use?

Cursor BYOK Desktop Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cursor BYOK Desktop Release use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cursor BYOK Desktop Release?

Skills that share tags, products or a category with Cursor BYOK Desktop Release: Desktop Release Preflight (Eynzof/Hermes-CN-Desktop, 1.7k stars), OpenWork Release Process (different-ai/openwork, 24k stars), AI News Radar (LearnPrompt/ai-news-radar, 1.8k stars) and Cline Desktop App Release (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cursor BYOK Desktop Release?

leookun (a GitHub user) maintains it in leookun/cursor-byok, which has 3,151 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on September 28, 2026.

Source: leookun/cursor-byok on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.