Agent skill

Plugin Release

by NanmiCoder in NanmiCoder/dsh-auto-mode

Package, publish, and distribute DeepSeek Harness (DSH) plugins — npm pack artifact validation, GitHub/npm/hub release-track selection, tarball overrides installs for the unpublished cohort…

MITAuto-check: warningsDevOps & Cloud

Install Plugin Release

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add NanmiCoder/dsh-auto-mode --skill plugin-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NanmiCoder/dsh-auto-mode plugin-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NanmiCoder/dsh-auto-mode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/plugin-release .claude/skills/plugin-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-release
GitHub stars
165
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
793 words
Files
6 (incl. scripts, references)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Package, publish, and distribute DeepSeek Harness (DSH) plugins — npm pack artifact validation, GitHub/npm/hub release-track selection, tarball overrides installs for the unpublished cohort…

  • Works in 6 steps: confirm the target version and release… → pack and validate the artifact → version dependency baseline (alpha era) → …
  • Publishing a plugin
  • SKILL.md covers Step 0: confirm the target…, Step 1: pack and validate the…, Step 2: version dependency… and Step 3: release gate (layer by…, plus 4 more sections
  • Runs JavaScript scripts from its folder; calls npm and pnpm

What it does

Plugin Release is an agent skill from NanmiCoder/dsh-auto-mode. Package, publish, and distribute DeepSeek Harness (DSH) plugins — npm pack artifact validation, GitHub/npm/hub release-track selection, tarball overrides installs for the unpublished cohort (0.1.2-alpha.), and CI/release gates with rollback. Use when publishing a plugin, packing a tarball, wiring a plugin into a profile/hub, or installing an alpha version that is not on npm; show a plan and obtain user confirmation before any publish action.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `SKILL.zh-CN.md`, `references/profile-dependency-management.md` and `references/publish-playbook.md`).

It sits in DevOps & Cloud. It works with npm, DeepSeek, GitHub and pnpm. The repository describes itself as: Safe automatic permissions for DeepSeek Harness. The licence is MIT.

When your agent uses it

  • Publishing a plugin
  • Packing a tarball
  • Wiring a plugin into a profile/hub
  • Installing an alpha version that is not on npm

Example prompts

  • “/plugin-release”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. confirm the target version and release track
  2. pack and validate the artifact
  3. version dependency baseline (alpha era)
  4. release gate (layer by layer; a lower layer must pass before the next one)
  5. release semantic gate (stop publishing if any check fails)
  6. publish and rollback

What it can do on your machine

Read from SKILL.md and the folder at commit 907d663. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plugin Release loads about 1.6k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 793 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:62
    lish artifacts containing credentials, `.npmrc` contents, session logs, or private paths;

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from NanmiCoder/dsh-auto-mode at commit 907d663, republished under its MIT licence (© NanmiCoder). 793 words, ~1,568 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-release/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
plugin-release
description
Package, publish, and distribute DeepSeek Harness (DSH) plugins — npm pack artifact validation, GitHub/npm/hub release-track selection, tarball overrides installs for the unpublished cohort (0.1.2-alpha.*), and CI/release gates with rollback. Use when publishing a plugin, packing a tarball, wiring a plugin into a profile/hub, or installing an alpha version that is not on npm; show a plan and obtain user confirmation before any publish action.

English | 简体中文

plugin-release

Ship developed, tested plugins safely. Publishing is a one-way outbound action — show a plan and obtain confirmation before any actual publish or tag push; this skill does not decide version numbers for you, and it never bumps versions automatically.

Step 0: confirm the target version and release track

Release trackApplies toKey facts
GitHub direct installdsh plugin --profile <p> add github:owner/repoConsumers resolve the default-branch HEAD; publishing = pushing to main — run the full gate before pushing
npm registrynpm publishOfficial release line only; alpha/rc-prefixed @deepseek-ai/* versions are not guaranteed on npm — verify with npm view <pkg> versions before publishing
hub listingregister in the hub catalogRegistration is a separate action and does not replace packaging validation
collectionmember plugins vendored into a pack artifactFollow the owning collection repository's own process

The unpublished cohort (for example a cohort version that was never published to npm — alpha.1 was GitHub-only; alpha.2 through alpha.4 are published under the alpha dist-tag) goes through the overrides flow in references/publish-playbook.md. Do not look for versions that do not exist on npm, and do not switch package managers because of it.

Step 1: pack and validate the artifact

  1. Use the repository's single package manager and lockfile (package-lock.json → npm, pnpm-lock.yaml → pnpm);
  2. Run the full gate (see Step 3), then npm pack / pnpm pack;
  3. Unpack and validate: files covers every runtime relative import and asset; no .ts leftovers in the artifact; the manifest files such as cordis.patch.yml / dsh.plugin.json / SKILL.md are all present;
  4. Install the tarball into an isolated profile for consumption validation (the plugin's row appears in dsh --profile compat --dump-config → the tool is genuinely registered and executes).

Step 2: version dependency baseline (alpha era)

  • devDependencies use the npm release line (currently 0.1.1-rc.2) as the type baseline, so a public repository typechecks after npm install on any machine;
  • peer ranges use a wide range (such as <0.2.0) to cover unpublished alphas/rcs;
  • when code must stay compatible with both the local harness (GitHub tag) and the npm release line, use the dual-compatibility pattern: keep the shape that the npm release line's types require, while the alpha runtime semantics remain unchanged (see the "dual-compatibility pattern" section of the playbook);
  • never write local absolute paths (junction/file:) into a committed package.json.

Step 3: release gate (layer by layer; a lower layer must pass before the next one)

  1. Dependency resolution: the lockfile changes only as expected; no mixed cohorts;
  2. Static: typecheck + plugin tests + build;
  3. Real mount: cold-boot the target host on an isolated profile pinned to an exact DSH tag (never let a mutable master/main masquerade as acceptance), with the entry active and no service left pending. Web Client plugins must additionally verify: the host-advertised resources (the bundle entry from the boot manifest/boot list) are reachable, the bundle registers successfully, the DOM mount completes, and there are no page errors — looking at --dump-config alone does not complete this layer;
  4. Behavior: one core path actually executes (for tool plugins: one message → tool → response; or an equivalent dedicated flow);
  5. Wrapper: verify exit codes and stdout/stderr attribution.
Show full SKILL.md (277 more words)Show less

Step 4: release semantic gate (stop publishing if any check fails)

  1. The GitHub Release tag must equal v${package.json.version};
  2. Whether the version carries a prerelease suffix (the segment after -, before the + build metadata) must match the GitHub Release's prerelease status;
  3. Prereleases may only go to a project-declared non-latest dist-tag (the name is chosen by the project, such as next or alpha — the skill does not hard-code a specific name); only stable versions without a suffix go to latest;
  4. Before a stable publish, query the current latest (npm view <pkg> dist-tags.latest) and refuse to publish when the semver is lower than the existing latest, to prevent moving latest backwards to a lower version.

Step 5: publish and rollback

  • Before publishing: clean commit + tag; record the lockfile and composition baseline hashes;
  • After publishing: reinstall once as a consumer and smoke-test;
  • Rollback: prefer reverting the release (delete the tag / re-point at the old commit); do not publish a "works on both sides" patch to paper over the problem;
  • For unpublished-cohort CI, see the "CI and release gates" section of the playbook (cohort store caching, the NPM_PUBLISH_ENABLED switch).

Safety boundaries

  • Show a plan and obtain confirmation before any publish / tag push / hub registration write; never bump versions automatically;
  • Never publish artifacts containing credentials, .npmrc contents, session logs, or private paths;
  • Do not switch package managers or rewrite a different lockfile; on failure, roll back only the paths owned by this run and report residue.

References

FileContents
references/publish-playbook.mdUnpublished-cohort installation, dual-compatibility pattern, CI/release gates, real pitfall list, and rollback recipes
references/profile-dependency-management.mdProfile install/update recipes: github dependency lock caching, three-place sync on package rename, junction cleanup, and host-upgrade linkage

© NanmiCoder, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/plugin-release of NanmiCoder/dsh-auto-mode.

  • SKILL.md
  • SKILL.zh-CN.md
  • references/profile-dependency-management.md
  • references/publish-playbook.md
  • scripts/verify-release.mjs
  • scripts/verify-release.test.mjs

Open the folder on GitHubat commit 907d663

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in NanmiCoder/dsh-auto-mode, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Plugin Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Release this skillNanmiCoder/dsh-auto-mode1651 repos~1.6kAutomated safety check: WarnMIT
Dsh Web UI Releaseningbainb/deepseek-harness-desktop776—~1.4kAutomated safety check: WarnBSD-3-Clause
OpenGUI Installer for DSHCore-Mate/OpenGUI1.8k—~1.1kAutomated safety check: PassCustom licence
Review Dependenciestobihagemann/turbo406—~1.5kAutomated safety check: PassMIT
Jacky Creator ReleaseJackywxsz/DSH-Creator109—~1.1kAutomated safety check: PassMIT
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT

Similar skills

  • Dsh Web UI Release

    ningbainb/deepseek-harness-desktop

    Release and publish the dsh-web-ui monorepo (DSH Web GUI plugin family + skin collection) — bump all packages to one unified version, commit and tag, push the vX.Y.Z tag that triggers the GitHub…

    776 GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check: warnings
  • OpenGUI Installer for DSH

    Core-Mate/OpenGUI

    Installs and verifies the latest stable OpenGUI release in a DeepSeek Harness web profile on macOS without disturbing existing plugins or settings.

    1.8k GitHub stars~1.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Review Dependencies

    tobihagemann/turbo

    Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

    406 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Jacky Creator Release

    Jackywxsz/DSH-Creator

    Run and strongly accept Jacky Creator's branch-to-release workflow: verify feature branches, merge approved changes, synchronize every version surface, build one immutable artifact, publish…

    109 GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings

More from NanmiCoder/dsh-auto-mode

All 10 skills in this repo
  • Dsh Upgrade Audit

    NanmiCoder/dsh-auto-mode

    Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…

    165 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Plugin Workflow

    NanmiCoder/dsh-auto-mode

    Coordinate multiple DeepSeek Harness plugin Skills across inspection, migration, runtime debugging, heavy dependencies, testing, naming, and release.

    165 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Plugin Write

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when creating a DeepSeek Harness plugin, choosing public names for a new external DSH plugin, validating a dsh-plugin.naming.json manifest, checking reviewed central…

    165 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Plugin Test

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when writing or reviewing tests for DeepSeek Harness plugins, external DSH plugin packages, or package changes in the deepseek-harness repository.

    165 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Dsh Benchmark Case

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when the user hands over a dsh plugin repository (or a real migration commit / version corridor) and wants its upgrade experience extracted into one auto-graded Harbor…

    165 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: warnings
  • Plugin Heavy Dep

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when adding a heavyweight browser dependency (diagram/chart renderers like mermaid, code editors, big wasm-adjacent libs) to a lightweight DSH Web plugin that must stay…

    165 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Categories

Questions about Plugin Release

What does Plugin Release do?

Package, publish, and distribute DeepSeek Harness (DSH) plugins — npm pack artifact validation, GitHub/npm/hub release-track selection, tarball overrides installs for the unpublished cohort…. Plugin Release is an agent skill from NanmiCoder/dsh-auto-mode.), and CI/release gates with rollback.

When should I use Plugin Release?

Plugin Release fits situations like: publishing a plugin; packing a tarball; wiring a plugin into a profile/hub; installing an alpha version that is not on npm.

How do I install Plugin Release in Claude Code?

Run `npx skills add NanmiCoder/dsh-auto-mode --skill plugin-release -a claude-code`. Or copy the skill folder (skills/plugin-release in NanmiCoder/dsh-auto-mode) into .claude/skills/plugin-release in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Release in Codex?

Run `npx skills add NanmiCoder/dsh-auto-mode --skill plugin-release -a codex`. Or copy the skill folder (skills/plugin-release in NanmiCoder/dsh-auto-mode) into .agents/skills/plugin-release in your project. Codex loads it when a task matches its description.

Can I use Plugin Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NanmiCoder/dsh-auto-mode --skill plugin-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-release, .gemini/skills/plugin-release, .github/skills/plugin-release and .opencode/skills/plugin-release in your project.

What does Plugin Release need to run?

Going by SKILL.md and its folder, Plugin Release needs JavaScript for the scripts in its folder and the command-line tools its instructions call (npm and pnpm). Our summary lists: Node.js.

Does Plugin Release access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Plugin Release safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Plugin Release use?

Plugin Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Release use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.3k tokens, read only when the agent opens those files.

What are the alternatives to Plugin Release?

Skills that share tags, products or a category with Plugin Release: Dsh Web UI Release (ningbainb/deepseek-harness-desktop, 776 stars), OpenGUI Installer for DSH (Core-Mate/OpenGUI, 1.8k stars), Review Dependencies (tobihagemann/turbo, 406 stars) and Jacky Creator Release (Jackywxsz/DSH-Creator, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Release?

NanmiCoder (a GitHub user) maintains it in NanmiCoder/dsh-auto-mode, which has 165 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 29, 2026.

Source: NanmiCoder/dsh-auto-mode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.