Agent skill

npm Release

by luochang212 in luochang212/skill-zoo

A skill your agent uses when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli.

MITAuto-check: warningsDevelopment

Install npm Release

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add luochang212/skill-zoo --skill npm-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install luochang212/skill-zoo npm-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/luochang212/skill-zoo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/npm-release .claude/skills/npm-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
npm-release
GitHub stars
117
Token cost
~3.1k tokens
SKILL.md length
1,329 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli.

  • Preparing to publish an npm package from this repository
  • SKILL.md covers Overview, Privacy Guardrails, When to Use and Package Target, plus 8 more sections
  • Calls npm, node and git; reaches registry.npmjs.org and npmjs.com
  • Especially the Skill Zoo CLI package under packages/cli

What it does

npm Release is an agent skill from luochang212/skill-zoo. Use when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli. Also use when npm publish fails because of duplicate versions, npm authentication, browser authentication, dist-tag propagation, tarball contents, bin entry issues, or workspace/lockfile version mismatches.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management and Authentication. It works with npm and Tauri. The repository describes itself as: All-in-One Desktop Agent Skills Utility. Welcome to the Skill Zoo, where all your skills live! The licence is MIT.

When your agent uses it

  • Preparing to publish an npm package from this repository
  • Especially the Skill Zoo CLI package under packages/cli
  • Npm publish fails because of duplicate versions
  • Npm authentication

Example prompts

  • “/npm-release”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 1c7afa6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • node
    • git
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org
    • npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

npm Release loads about 3.1k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 1,329 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteRuns commands with sudoSKILL.md:235
    t-owned files from an old npm bug | Run `sudo chown -R $(id -u):$(id -g) ~/.npm`, or use a temp cache via `--cache /tmp/
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:236
    | `npm login` fails writing `~/.npmrc` (EPERM) | Home dir not writable from the agent sandbox | Log in with `--userconfi

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from luochang212/skill-zoo at commit 1c7afa6, republished under its MIT licence (© luochang212). 1,329 words, ~3,150 tokens.

Download SKILL.mdSave it as .claude/skills/npm-release/SKILL.md (or your agent's skills folder).
name
npm-release
description
Use when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli. Also use when npm publish fails because of duplicate versions, npm authentication, browser authentication, dist-tag propagation, tarball contents, bin entry issues, or workspace/lockfile version mismatches.

npm Release

Overview

Publish an npm package from this repo with local verification, clean package contents, and npm browser authentication. For Skill Zoo today, the npm package is the CLI package in packages/cli; the workspace root is private and is not the package to publish.

Announce at start: "I'm using the npm-release skill to publish the npm package."

Privacy Guardrails

Do not write private npm account details into repo files, skill files, logs, release notes, or final summaries. This includes npm usernames, email addresses, authentication secrets, browser auth URLs, auth IDs, tokens, local npm debug log paths, and machine-specific temporary directories.

It is fine to state generic facts such as "npm required browser authentication" or "the authenticated owner account was permitted." Do not paste the actual authentication URL into a committed file. If a URL is needed transiently, use it only to complete the live browser flow.

When to Use

Use this skill when:

  • The user says "publish npm", "release the npm package", "npm publish", "发 npm", or "发布 npm 包"
  • The package is in a workspace and you need to identify the real publishable package
  • npm publish fails with duplicate version, npm authentication, owner, tarball, or bin problems
  • The user asks whether a package is ready for npm publication
  • A release bump needs to update package metadata and lockfile state consistently

Do not use this skill for:

  • Desktop app GitHub Releases or Homebrew cask releases; use app-release
  • Tauri updater implementation; use tauri-updater
  • Publishing a package you have not locally verified

Package Target

For this repo, start with the CLI package:

bash
cd packages/cli

Confirm the root package is not the target:

bash
node -e "console.log(require('./package.json').private)"
node -e "const p=require('./packages/cli/package.json'); console.log(p.name, p.version, p.bin)"

If the target changes in the future, publish from the directory whose package.json has the public npm name, bin, files, scripts.prepack, and production dependencies.

Preflight

Check the repo instructions and current working tree first:

bash
test -f CLAUDE.md && sed -n '1,220p' CLAUDE.md
test -f AGENTS.md && sed -n '1,220p' AGENTS.md
git status --short

Do not revert or overwrite unrelated changes. If publish-relevant files already have user edits, inspect them and work with the current state.

Check npm registry state before changing versions:

bash
cd packages/cli
npm view skill-zoo version dist-tags --json
npm view skill-zoo versions --json
npm whoami
npm owner ls skill-zoo

If the local version already exists on npm, explain that npm versions are immutable and ask the user which new version to publish before changing files. Do not choose or apply the release version silently.

Version Bump

For the Skill Zoo CLI package, update:

  • packages/cli/package.json
  • bun.lock workspace entry for packages/cli

Ask the user to confirm the exact version before editing release files. If they ask for a recommendation, propose the smallest sensible semver bump and explain why, then wait for confirmation before applying it.

After bumping, search for hardcoded old versions that should follow the package version:

bash
OLD_VERSION=<previous-version>
rg "\"version\": \"${OLD_VERSION}\"|skill-zoo-cli@${OLD_VERSION}|skill-zoo@${OLD_VERSION}" packages/cli bun.lock

Tests should generally depend on CLI_VERSION rather than hardcoding a release version. This prevents a release bump from breaking tests only because an expected metadata string changed.

Required Verification

Run these from packages/cli after any version or release-related change:

bash
npm run typecheck
npm test
npm run build
npm publish --dry-run

The dry-run must show the expected version and tarball contents. For this CLI, expected package contents are small and should normally be:

text
README.md
dist/index.js
package.json
wui/app.js
wui/index.html
wui/styles.css

There is deliberately no dist/index.d.ts. The CLI entry (packages/cli/src/index.ts) is a shebang script that calls runCli() and exports nothing, so the declaration file tsup's --dts emitted contained only the shebang line — a type contract with no types. It was also unreachable: the package declares bin and no main/exports/types, so a consumer's import ... from "skill-zoo" fails with TS2307 before the file is ever read (wiring up types instead yields TS2306: is not a module). Rather than keep a misleading empty file, the build no longer emits declarations. If the CLI ever grows a programmatic API, re-add declarations and the types/exports wiring together.

If extra source, test, repo, log, or private files appear, fix the files whitelist or ignore rules before publishing.

CLI Package Checks

Before publishing a CLI package, verify the executable path matches bin and can start from the built artifact:

bash
cd ../..
sed -n '1,20p' packages/cli/src/index.ts
sed -n '1,20p' packages/cli/dist/index.js
ls -l packages/cli/dist/index.js
node packages/cli/dist/index.js --version
node packages/cli/dist/index.js --help | sed -n '1,120p'

For higher confidence, install the actual tarball in a temporary project and run both binary names:

bash
cd packages/cli
tmp="$(mktemp -d)"
npm pack --pack-destination "$tmp"
mkdir "$tmp/install"
cd "$tmp/install"
npm init -y >/dev/null
npm install "$tmp"/skill-zoo-*.tgz
./node_modules/.bin/skill-zoo --version
./node_modules/.bin/szoo --help | sed -n '1,40p'

Do not commit generated tarballs or temporary install directories.

Publishing

Publish only after typecheck, tests, build, and npm publish --dry-run pass. Before the real npm publish, summarize the package name, version, dist tag, and tarball contents, then ask the user for explicit confirmation.

Log in first. --auth-type=web authenticates npm login, not npm publish — publishing while unauthenticated fails with a 404 that masks the real cause. Ensure a valid token exists (see "Non-TTY browser authentication") before publishing, and drop --auth-type=web from the publish command.

Working directory does not persist between tool calls. Always include cd <path> in the command itself — never assume a previous cd still applies. When publishing from a workspace sub-package, use an absolute cd prefix:

bash
cd /path/to/repo/packages/cli && npm publish --registry https://registry.npmjs.org/

Preferred command after user confirmation:

bash
cd packages/cli
npm publish --registry https://registry.npmjs.org/

If the machine's default registry is a read-only mirror (e.g. registry.npmmirror.com), the explicit --registry https://registry.npmjs.org/ is required — mirrors do not accept publishes.

Show full SKILL.md (538 more words)Show less
Non-TTY browser authentication

Two different steps need browser auth, and npm handles them differently in agent environments (Claude Code, Cowork, CI):

Login — npm login --auth-type=web prints the full https://www.npmjs.com/login?next=/login/cli/<id> URL even without a TTY, so no script wrapper is needed. Just open the printed "Login at:" URL:

bash
npm login --auth-type=web --registry https://registry.npmjs.org/
# then open the printed "Login at:" URL in the user's browser

Publish 2FA (EOTP) — when the account requires 2FA for publishing, npm publish fails with EOTP and prints its auth URL redacted as *** (https://www.npmjs.com/auth/cli/***). Only this step needs a real TTY to reveal the URL. Use script -q /dev/null, and feed it a leading newline because npm's TTY prompt ("Press ENTER to open in the browser...") otherwise blocks before it polls for authentication:

bash
printf '\n' | script -q /dev/null npm publish --registry https://registry.npmjs.org/ 2>&1 &
sleep 8
# grep the real "Authenticate your account at:" URL from output, then:
open "https://www.npmjs.com/auth/cli/<id>"

Extract the URL, open it in the user's browser, and keep the background process alive while they authenticate. If script is unavailable (e.g. a sandbox blocks pty allocation), fall back to --otp <6-digit TOTP>.

Success looks like:

text
+ skill-zoo@X.Y.Z

Post-Publish Verification

Registry reads can briefly lag after publish. Verify both the specific version and the dist tag:

bash
npm view skill-zoo@X.Y.Z version dist.tarball time --json
npm dist-tag ls skill-zoo
npm view skill-zoo versions --json

Treat npm dist-tag ls as the clearer signal for latest when npm view skill-zoo version appears stale immediately after publication.

The final user summary should include:

  • Published package and version
  • Verification commands that passed
  • Registry confirmation, including latest if applicable
  • Local files changed and still uncommitted

Do not include private account identifiers, browser auth URLs, npm auth IDs, authentication secrets, debug log paths, or temporary directory paths in the final summary.

Failure Handling

FailureCauseResponse
You cannot publish over the previously published versionsLocal version already exists on npmAsk the user to confirm the new version, then bump packages/cli/package.json, sync lockfile, and rerun checks
npm publish returns 404 / "do not have permission"Not logged in — --auth-type=web does not authenticate at publish timeRun npm login --auth-type=web --registry https://registry.npmjs.org/ first, then publish
npm error code EOTPAccount requires 2FA for publishingEither get the user's 6-digit TOTP and pass --otp <code>, or complete the browser web-OTP flow (see "Non-TTY browser authentication")
Browser auth URL is ***npm redacted the publish OTP URL in non-TTY outputWrap the publish in script -q /dev/null with a leading newline (see "Non-TTY browser authentication"), extract the real URL, then open it
npm errors with EPERM on the ~/.npm cacheCache dir has root-owned files from an old npm bugRun sudo chown -R $(id -u):$(id -g) ~/.npm, or use a temp cache via --cache /tmp/xxx
npm login fails writing ~/.npmrc (EPERM)Home dir not writable from the agent sandboxLog in with --userconfig /tmp/xxx.npmrc and pass the same --userconfig to npm publish; delete the file afterward
Tests fail after version bumpHardcoded expected versionPrefer asserting against CLI_VERSION
Dry-run includes unexpected filesBad files whitelist or generated artifactsFix package manifest before publishing
Bin command fails after tarball installbin path, shebang, executable bit, or bundle issueFix before publishing and rerun tarball install check
latest appears stale after successRegistry/cache delayQuery npm dist-tag ls and the exact name@version

Command Sequence

Use this as the default release skeleton for skill-zoo CLI:

bash
cd /path/to/repo
git status --short
npm view skill-zoo version dist-tags --json

# ask the user to confirm the exact version, then bump packages/cli/package.json and bun.lock if needed

# log in first (prints the full URL even non-TTY); skip if a valid token already exists
npm login --auth-type=web --registry https://registry.npmjs.org/
# open the printed "Login at:" URL, wait for the user to authenticate

cd /path/to/repo/packages/cli
npm run typecheck
npm test
npm run build
npm publish --dry-run

# summarize dry-run results and ask the user to confirm the real publish
# if the account requires 2FA, the publish OTP URL is redacted as *** — wrap with script:
printf '\n' | script -q /dev/null npm publish --registry https://registry.npmjs.org/ 2>&1 &
# extract the "Authenticate your account at:" URL, open in browser, wait for user

npm view skill-zoo@X.Y.Z version dist.tarball time --json
npm dist-tag ls skill-zoo
npm view skill-zoo versions --json

Keep the package release commit separate from unrelated feature work when possible. If the user's working tree already contains feature changes intended for the release, report them clearly instead of hiding them inside the release summary.

© luochang212, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/npm-release of luochang212/skill-zoo.

Open the folder on GitHubat commit 1c7afa6

Compare with similar skills

npm Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

npm Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
npm Release this skillluochang212/skill-zoo117—~3.1kAutomated safety check: WarnMIT
Flowfile Build and Environment SetupEdwardvaneechoud/Flowfile385—~7.3kAutomated safety check: NotesMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Dependency ResolverArabelaTso/Skills-4-SE253—~3.9kAutomated safety check: NotesApache-2.0
Validator Dependency Upgradeexpress-validator/express-validator6.2k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Flowfile Build and Environment Setup

    Edwardvaneechoud/Flowfile

    Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does.

    385 GitHub stars~7.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Dependency Resolver

    ArabelaTso/Skills-4-SE

    Identify, analyze, and manage software dependencies before deployment.

    253 GitHub stars~3.9k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Validator Dependency Upgrade

    express-validator/express-validator

    Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.

    6.2k GitHub stars~1.2k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Claude Code Version Check

    ykdojo/claude-code-tips

    Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.

    10k GitHub stars~1.8k tokensUpdated 15 days ago
    DevelopmentAuto-check passed

More from luochang212/skill-zoo

  • App Release

    luochang212/skill-zoo

    A skill your agent uses when the user asks to release a new version, ship a build, or publish a Skill Zoo release.

    117 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Tauri Updater

    luochang212/skill-zoo

    A skill your agent uses when adding software auto-update to a Tauri 2 desktop app, or when users ask about tauri-plugin-updater integration, app update checking, distinguishing installer vs portable…

    117 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Worth Fix

    luochang212/skill-zoo

    分析和判断任何论断、报告、想法或需求的真实性、价值与做法。当用户说"这个 bug 是真的吗"、"分析一下这个问题/这个报告/这个说法"、"这个修复值得做吗"、"帮我看下这个建议靠不靠谱",或用户给出一个待评估的 bug 报告、文章摘录、设计提案时使用。先核验、复现、定级、讲清原理、判断是否值得做,而不是直接相信或直接动手改代码。也适用于评估"要不要重构"。

    117 GitHub stars~751 tokensUpdated today
    Auto-check passed

Works with

Questions about npm Release

What does npm Release do?

A skill your agent uses when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli. npm Release is an agent skill from luochang212/skill-zoo. Use when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli.

When should I use npm Release?

npm Release fits situations like: preparing to publish an npm package from this repository; especially the Skill Zoo CLI package under packages/cli; npm publish fails because of duplicate versions; npm authentication.

How do I install npm Release in Claude Code?

Run `npx skills add luochang212/skill-zoo --skill npm-release -a claude-code`. Or copy the skill folder (skills/npm-release in luochang212/skill-zoo) into .claude/skills/npm-release in your project. Claude Code loads it when a task matches its description.

How do I install npm Release in Codex?

Run `npx skills add luochang212/skill-zoo --skill npm-release -a codex`. Or copy the skill folder (skills/npm-release in luochang212/skill-zoo) into .agents/skills/npm-release in your project. Codex loads it when a task matches its description.

Can I use npm Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luochang212/skill-zoo --skill npm-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm-release, .gemini/skills/npm-release, .github/skills/npm-release and .opencode/skills/npm-release in your project.

What does npm Release need to run?

Going by SKILL.md and its folder, npm Release needs the command-line tools its instructions call (npm, node, git and rg). Our summary lists: Node.js.

Does npm Release access the network?

SKILL.md names 2 domains. In commands or code: registry.npmjs.org and npmjs.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is npm Release safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does npm Release use?

npm Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does npm Release use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to npm Release?

Skills that share tags, products or a category with npm Release: Flowfile Build and Environment Setup (Edwardvaneechoud/Flowfile, 385 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Dependabot Alerts Update (livesession/xyd, 114 stars) and Dependency Resolver (ArabelaTso/Skills-4-SE, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains npm Release?

luochang212 (a GitHub user) maintains it in luochang212/skill-zoo, which has 117 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.

Source: luochang212/skill-zoo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.