Cursor BYOK Desktop Release
leookun/cursor-byok
Guides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled.
Bump version, build, and release Noah for the current platform.
$ npx skills add noahapp/noah-for-tinkerers --skill release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install noahapp/noah-for-tinkerers release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/noahapp/noah-for-tinkerers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/release .claude/skills/release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release" agent skill from https://github.com/noahapp/noah-for-tinkerers/tree/main/.claude/skills/release into .claude/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/noahapp/noah-for-tinkerers/tree/main/.claude/skills/releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add noahapp/noah-for-tinkerers --skill release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install noahapp/noah-for-tinkerers release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/noahapp/noah-for-tinkerers.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/release .agents/skills/release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release" agent skill from https://github.com/noahapp/noah-for-tinkerers/tree/main/.claude/skills/release into .agents/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add noahapp/noah-for-tinkerers --skill release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install noahapp/noah-for-tinkerers release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/noahapp/noah-for-tinkerers.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/release .cursor/skills/release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release" agent skill from https://github.com/noahapp/noah-for-tinkerers/tree/main/.claude/skills/release into .cursor/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/noahapp/noah-for-tinkerers.git --path .claude/skills/release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add noahapp/noah-for-tinkerers --skill release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install noahapp/noah-for-tinkerers release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/noahapp/noah-for-tinkerers.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/release .gemini/skills/release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/noahapp/noah-for-tinkerers/tree/main/.claude/skills/release into .gemini/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install noahapp/noah-for-tinkerers releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add noahapp/noah-for-tinkerers --skill release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/noahapp/noah-for-tinkerers.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/release .github/skills/release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/noahapp/noah-for-tinkerers/tree/main/.claude/skills/release into .github/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add noahapp/noah-for-tinkerers --skill release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install noahapp/noah-for-tinkerers release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/noahapp/noah-for-tinkerers.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/release .opencode/skills/release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/noahapp/noah-for-tinkerers/tree/main/.claude/skills/release into .opencode/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
releaseBump version, build, and release Noah for the current platform.
Release is an agent skill from noahapp/noah-for-tinkerers. Bump version, build, and release Noah for the current platform. Handles signing keys, version bumps across all config files, testing, committing, pushing, and uploading to GitHub Releases.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud. It works with GitHub and Tauri. The repository describes itself as: Noah -- fixing your computer issues. The licence is AGPL-3.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d5e3a81. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitnodecargosshpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, git, ssh and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
TAURI_SIGNING_PRIVATE_KEYAPPLE_PASSWORDTAURI_SIGNING_PRIVATE_KEY_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Release loads about 1.3k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 547 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from noahapp/noah-for-tinkerers at commit d5e3a81, republished under its AGPL-3.0 licence (© noahapp). 547 words, ~1,284 tokens.
.claude/skills/release/SKILL.md (or your agent's skills folder).Cut a release: Mac locally (universal binary), Windows + Linux via GitHub Actions.
cargo test — abort if any fail.git status — warn if there are uncommitted changes unrelated to the release.pnpm-lock.yaml and Cargo.lock are committed and in sync with their respective manifest files. If either is modified/untracked, commit them first. Out-of-sync lockfiles cause --frozen-lockfile failures.The version lives in three files that must stay in sync:
apps/desktop/src-tauri/Cargo.toml (version = "X.Y.Z")apps/desktop/src-tauri/tauri.conf.json ("version": "X.Y.Z")apps/desktop/package.json ("version": "X.Y.Z")After editing Cargo.toml, run cargo check to update Cargo.lock, then stage it too.
Determine the bump type from context:
If the user specifies a bump type or target version, use that. Otherwise ask.
Update all three files + Cargo.lock, then commit:
Bump version to X.Y.Z
<one-line summary of what changed since last release>Push the commit before building (CI needs the latest code).
Two key families are required:
TAURI_SIGNING_PRIVATE_KEY) — signs the updater manifest so existing installs can auto-updateAPPLE_*) — code-signs and notarizes the .dmg/.app so Gatekeeper accepts it on first launch# Updater signing
export TAURI_SIGNING_PRIVATE_KEY="$(cat ~/.tauri/noah.key)"
export TAURI_SIGNING_PRIVATE_KEY_PASSWORD="searchformeaning"
# Apple code signing + notarization (required for a Gatekeeper-clean dmg)
export APPLE_SIGNING_IDENTITY="Developer ID Application: You Xu (2VGY8SHNYJ)"
export APPLE_ID="xu.leaps@gmail.com"
export APPLE_PASSWORD="<app-specific password from appleid.apple.com>"
export APPLE_TEAM_ID="2VGY8SHNYJ"
node scripts/release.mjs --upload --skip-installThe APPLE_* vars are typically already set in the shell (.zshenv). If you see ==> APPLE_SIGNING_IDENTITY not set or ==> APPLE_ID/APPLE_PASSWORD/APPLE_TEAM_ID not set in the script's output, the build will succeed but the resulting .dmg will be unsigned — abort and export the missing vars before re-running, otherwise users hit Gatekeeper warnings.
This builds a universal macOS binary (ARM + Intel via --target universal-apple-darwin), signs with the Apple Developer ID, submits to Apple for notarization, staples the ticket, and uploads the .dmg + .tar.gz (with updater signature) to GitHub Releases. The latest.json registers both darwin-aarch64 and darwin-x86_64 for the updater.
The release script automatically:
x86_64-apple-darwin Rust target if missingtarget/universal-apple-darwin/release/bundle/After the Mac build uploads and creates the release, trigger CI for Windows and Linux:
gh workflow run release.yml --field tag=vX.Y.ZThis runs .github/workflows/release.yml which builds on both windows-latest and ubuntu-22.04 in parallel, then uploads artifacts (NSIS .exe, MSI .msi, deb, rpm, AppImage) to the same GitHub release.
Monitor progress:
gh run list --workflow=release.yml --limit 1
gh run watch # live tailSigning secrets (TAURI_SIGNING_PRIVATE_KEY, TAURI_SIGNING_PRIVATE_KEY_PASSWORD) are configured as GitHub repo secrets — no manual setup needed per build.
If CI is broken, Windows can still be built manually on the Windows machine:
ssh xulea@100.87.199.115cd C:\Users\xulea\src\itman && git pull && node scripts/release.mjs --build
(Ensure signing key is at ~/.tauri/noah.key and PATH includes cargo, node, pnpm)gh release upload vX.Y.Z /tmp/Noah_*.exe /tmp/Noah_*.msi --clobbergit pushgh run list --workflow=release.yml --limit 1release.yml is workflow_dispatch only (manual trigger). Free tier: 2,000 min/month; a typical release uses ~30 min (10 min Windows ×2 + 10 min Linux ×1).ci.yml is also workflow_dispatch only (test-only, no builds).--skip-install flag skips pnpm install in the release script (saves time when deps haven't changed). Omit it if dependencies were recently added.© noahapp, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/release of noahapp/noah-for-tinkerers.
Open the folder on GitHubat commit d5e3a81
Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Release this skillnoahapp/noah-for-tinkerers | 127 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | |
| Cursor BYOK Desktop Releaseleookun/cursor-byok | 3.2k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Desktop Release PreflightEynzof/Hermes-CN-Desktop | 1.7k | — | ~1.6k | Automated safety check: Notes | Custom licence | |
| Release Publishbkywksj/knowledge-base | 330 | — | ~6.2k | Automated safety check: Pass | Custom licence | |
| Yaak Changelogmountain-loop/yaak | 19k | — | ~1.6k | Automated safety check: Pass | MIT | |
| GreptimeDB Release RunbookGreptimeTeam/greptimedb | 6.7k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
leookun/cursor-byok
Guides releases of the Cursor BYOK desktop app on GitHub, with strict rules on who may publish and how version tags, updater manifests and signing are handled.
Eynzof/Hermes-CN-Desktop
Use BEFORE preparing or publishing any Hermes Agent CN Desktop release (new installer, version bump, GitHub Release, or publishing a new build to users).
bkywksj/knowledge-base
发布 Tauri 桌面应用新版本,处理版本号同步、Git tag、GitHub Actions 构建、Release 仓库产物同步、Cloudflare R2 上传、update.json 生成、自动更新发布和文档站重建。
mountain-loop/yaak
Create or edit Yaak changelogs. An agent skill from mountain-loop/yaak.
GreptimeTeam/greptimedb
Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.
d-kimuson/claude-code-viewer
Run the claude-code-viewer release flow end-to-end. An agent skill from d-kimuson/claude-code-viewer.
Categories
Bump version, build, and release Noah for the current platform. Release is an agent skill from noahapp/noah-for-tinkerers. Bump version, build, and release Noah for the current platform.
Release fits situations like: devOps & Cloud work in your project.
Run `npx skills add noahapp/noah-for-tinkerers --skill release -a claude-code`. Or copy the skill folder (.claude/skills/release in noahapp/noah-for-tinkerers) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add noahapp/noah-for-tinkerers --skill release -a codex`. Or copy the skill folder (.claude/skills/release in noahapp/noah-for-tinkerers) into .agents/skills/release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add noahapp/noah-for-tinkerers --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.
Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (gh, git, node, cargo, ssh and pnpm) and credentials named TAURI_SIGNING_PRIVATE_KEY, APPLE_PASSWORD and TAURI_SIGNING_PRIVATE_KEY_PASSWORD. Our summary lists: A credential in TAURI_SIGNING_PRIVATE_KEY.
SKILL.md contains no URLs. Its commands use gh, git and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Release is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Release: Cursor BYOK Desktop Release (leookun/cursor-byok, 3.2k stars), Desktop Release Preflight (Eynzof/Hermes-CN-Desktop, 1.7k stars), Release Publish (bkywksj/knowledge-base, 330 stars) and Yaak Changelog (mountain-loop/yaak, 19k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
noahapp (a GitHub organization) maintains it in noahapp/noah-for-tinkerers, which has 127 GitHub stars. The repository was last updated on August 11, 2026.
Source: noahapp/noah-for-tinkerers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.