Agent skill

Release Openclaw Mac

by openclaw in openclaw/openclaw

Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.

MITAuto-check passed

Install Release Openclaw Mac

skills CLI
$ npx skills add openclaw/openclaw --skill release-openclaw-mac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/openclaw release-openclaw-mac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release-openclaw-mac .claude/skills/release-openclaw-mac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-openclaw-mac
GitHub stars
392k
Token cost
~2k tokens
SKILL.md length
911 words
Files
1
Skills in repo
93
Repo updated
First seen
Licence
MIT

At a glance

Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.

  • SKILL.md covers Release authorization, Credentials, 1Password and GitHub Secrets, plus 4 more sections
  • Calls gh and xcrun; needs APP_STORE_CONNECT_KEY_ID

What it does

Release Openclaw Mac is an agent skill from openclaw/openclaw. Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with macOS and GitHub. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.

Example prompts

  • “/release-openclaw-mac”

What it can do on your machine

Read from SKILL.md and the folder at commit 1eb5970. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • xcrun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • APP_STORE_CONNECT_KEY_ID

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Openclaw Mac loads about 2k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 911 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/openclaw at commit 1eb5970, republished under its MIT licence (© openclaw). 911 words, ~2,038 tokens.

Download SKILL.mdSave it as .claude/skills/release-openclaw-mac/SKILL.md (or your agent's skills folder).
name
release-openclaw-mac
description
Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.

OpenClaw Mac Release

Use with $release-openclaw-maintainer, $release-openclaw-ci, $one-password, and $release-private if it exists when stable macOS assets, release-ops mac preflight, notarization, appcast promotion, or mac release recovery is involved.

This is a regular stable-release skill. Do not invoke it for extended-stable; that track's GitHub Release carries shared validation evidence but does not inherit macOS assets or appcast promotion.

Release authorization

An explicit stable or full release request includes macOS publication unless the operator limits its scope. Continue through validation, signing, notarization, promotion, and verification without asking for separate macOS consent. Keep the exact release identity and all artifact checks. macOS publication runs in parallel with npm and never blocks it; a mac failure does not hold the npm/ClawHub release, GitHub release finalization, or main closeout. Fix it in parallel.

Follow the current owner-configured environment policy. Do not invent an extra reviewer requirement or recreate an obsolete one. If GitHub still enforces an approval, report the actual rule and resolve it through its owner; policy changes require explicit organization-owner direction and verified active admin membership. Never impersonate a reviewer, fabricate approval, or use another signing path to bypass an enforced rule.

Credentials

  • Resolve Peter-owned ASC item refs, key ids, issuer ids, and service-token provenance from $release-private.
  • Fields: private_key_p8, key_id, issuer_id.
  • Stale/revoked key symptom: xcrun notarytool submit fails with HTTP status code: 401. Unauthenticated.
  • Validate candidate ASC credentials with xcrun notarytool history before setting GitHub secrets.

1Password

  • Use $one-password: all op work inside one persistent tmux session, no secret output.
  • Use the service-token guidance from $release-private when available.
  • If a service token fails, run status-only checks: token present/length and op whoami; never print token values.
  • If desktop app auth is needed but Touch ID is unavailable, set OP_BIOMETRIC_UNLOCK_ENABLED=false for the manual op account add --signin path.

GitHub Secrets

Target release-ops repo environment: openclaw/releases, env mac-release.

Set only after local notary auth validation:

  • APP_STORE_CONNECT_API_KEY_P8
  • APP_STORE_CONNECT_KEY_ID
  • APP_STORE_CONNECT_ISSUER_ID

Do not update these from mixed sources. All three ASC fields must come from the same 1Password item.

Workflow Shape

  • openclaw/openclaw is the public product repo. Its GitHub Releases page is where macOS assets are ultimately attached.
  • openclaw/openclaw macos-release.yml is public handoff validation only. It never signs, notarizes, or uploads macOS assets, regardless of preflight_only.
  • openclaw/releases is the restricted release-ops repo. Its macOS workflows sign, notarize, validate, and promote assets onto the openclaw/openclaw GitHub release.
  • Public release branch may carry mac-only packaging fixes after the stable tag/npm are already live.
  • Use source_ref=release/YYYY.M.PATCH for release-ops mac preflight/validation when building that branch variation.
  • Keep tag=vYYYY.M.PATCH pointing at the original stable release commit.
  • Real mac publish must reuse:
    • a successful release-ops mac preflight run for the same tag/source SHA
    • a successful release-ops mac validation run for the same tag/source SHA
  • Release-ops preflight and real publish use the mac-release environment for signing and promotion secrets and its main-only deployment policy. The authorized release operator continues under that environment's current rules.
  • If preflight source SHA differs from tag SHA, validation must also use the same source_ref; promotion rejects mismatched proof.

Notarization

  • OpenClaw uses scripts/notarize-mac-artifact.sh.
  • xcrun notarytool submit should use --no-s3-acceleration; accelerated upload can surface misleading 401s even when notarytool history succeeds.
  • If signing succeeds but notarization fails immediately with 401, check ASC key freshness first.
  • If notarization stays in progress for several minutes after key-file write, that is normal Apple wait time; do not edit blindly.
Show full SKILL.md (357 more words)Show less

Dispatch

The public handoff workflow validates the tag, source, build, and package metadata before publication. It does not require a GitHub release page because it does not upload assets. Keep this validation before the real publish workflow. The core publisher owns GitHub release finalization; macOS promotion attaches its verified assets to that release whether it is still a draft or already public, so it never waits for the npm flip.

Public handoff validation:

bash
gh workflow run macos-release.yml --repo openclaw/openclaw \
  --ref release/YYYY.M.PATCH \
  -f tag=vYYYY.M.PATCH \
  -f preflight_only=true \
  -f public_release_branch=release/YYYY.M.PATCH
  • Use the public release branch as the workflow ref so the Actions list displays release/YYYY.M.PATCH, matching prior stable macOS handoff runs.
  • Do not use --ref main or --ref vYYYY.M.PATCH for this public handoff validation. The workflow checks out the tag from the tag input internally.

Release-ops preflight:

bash
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
  -f tag=vYYYY.M.PATCH \
  -f source_ref=release/YYYY.M.PATCH \
  -f preflight_only=true \
  -f smoke_test_only=false \
  -f allow_late_calver_recovery=false \
  -f public_release_branch=release/YYYY.M.PATCH

Follow the run through signing and notarization under the configured environment policy. Record the successful preflight run id; an approval pause is not a successful preflight.

Resume is the default. Re-dispatching the same preflight command after a failure (notary outage, DMG packaging, collector) resumes every variant from the newest checkpoint left by a failed or cancelled main dispatch for the same tag and source SHA; only variants without a checkpoint rebuild. The run log prints Resuming <variant> from run <id> attempt <n> or Building <variant>. ignore_checkpoints=true forces fresh builds. Pass resume_notarization_run_id, resume_notarization_run_attempt, and resume_notarization_variant only to pin one specific run, or for checkpoints made before the resume index existed (macos-resume-<tag>-<variant>-<sha> artifacts). Prefer gh run rerun <run-id> --failed --repo openclaw/releases when the failed job is still in the current run.

Release-ops validation for a branch-variation preflight:

bash
gh workflow run openclaw-macos-validate.yml --repo openclaw/releases --ref main \
  -f tag=vYYYY.M.PATCH \
  -f source_ref=release/YYYY.M.PATCH

Record the successful validation run id.

Real publish:

bash
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
  -f tag=vYYYY.M.PATCH \
  -f preflight_only=false \
  -f smoke_test_only=false \
  -f preflight_run_id=<successful-preflight-run> \
  -f validate_run_id=<successful-validation-run> \
  -f allow_late_calver_recovery=false \
  -f public_release_branch=release/YYYY.M.PATCH

Follow promotion through asset upload and appcast publication under the same release authorization and current environment policy.

  • Release-ops openclaw/releases publish/validate workflows run from their own trusted main workflow ref. Real publish has a guard that rejects any other workflow ref. That displayed main ref is expected; the public OpenClaw source is selected by tag and optional source_ref.

Verify

  • gh release view vYYYY.M.PATCH --repo openclaw/openclaw shows zip, dmg, dSYM zip; once the npm publisher has flipped it: not draft, not prerelease.
  • Public main appcast.xml points at OpenClaw-YYYY.M.PATCH.zip.
  • Appcast entry has sparkle:version, sparkle:shortVersionString, length, and sparkle:edSignature.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/release-openclaw-mac of openclaw/openclaw.

Open the folder on GitHubat commit 1eb5970

Compare with similar skills

Release Openclaw Mac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Openclaw Mac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Openclaw Mac this skillopenclaw/openclaw392k—~2kAutomated safety check: PassMIT
Mole CLI Release Flowtw93/Mole70k—~2.5kAutomated safety check: PassGPL-3.0
Release Easydicttisfeng/Easydict15k—~810Automated safety check: PassGPL-3.0
Releaseeugene1g/agent-safehouse2.1k—~3.5kAutomated safety check: PassApache-2.0
Cherry Studio Regression TestsCherryHQ/cherry-studio52k—~1.2kAutomated safety check: PassAGPL-3.0
Kane CLI Browser TestingLambdaTest/kane-cli247—~8.4kAutomated safety check: PassApache-2.0

Similar skills

  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    70k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Release Easydict

    tisfeng/Easydict

    编排 Easydict macOS 的 draft、publish、release 和 resume,整理英文 GitHub Release 内容,并处理发布后的 Issue 跟进及本地清理。不用于一般的发布流程设计讨论。

    15k GitHub stars~810 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Release

    eugene1g/agent-safehouse

    Run the local Agent Safehouse release flow: inspect commits since the last published release, propose the next SemVer version and changelog, present a dry-run for confirmation, then update…

    2.1k GitHub stars~3.5k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Cherry Studio Regression Tests

    CherryHQ/cherry-studio

    Runs Cherry Studio's critical-path regression suite as deterministic Playwright E2E tests through a GitHub workflow on macOS and Windows runners.

    52k GitHub stars~1.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Kane CLI Browser Testing

    LambdaTest/kane-cli

    Drives a real browser through the kane-cli tool and designs requirement-linked test suites from a PRD or a plain description, with mobile and cloud-grid runs.

    247 GitHub stars~8.4k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Release

    notepadqq/notepadqq

    Release a new Notepadqq version. An agent skill from notepadqq/notepadqq.

    2.3k GitHub stars~2k tokensUpdated 3 days ago
    MobileAuto-check passed

More from openclaw/openclaw

All 93 skills in this repo
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Tmux

    openclaw/openclaw

    Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.

    392k GitHub starsUsed in 2 repos~640 tokens
    Auto-check passed
  • Feishu Doc

    openclaw/openclaw

    Feishu document read/write workflows. An agent skill from openclaw/openclaw.

    392k GitHub stars~516 tokensUpdated today
    Auto-check passed
  • Openclaw PR Maintainer

    openclaw/openclaw

    Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.

    392k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Browser Automation

    openclaw/openclaw

    A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.

    392k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Clawsweeper

    openclaw/openclaw

    A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…

    392k GitHub stars~3k tokensUpdated today
    Auto-check passed

Works with

Questions about Release Openclaw Mac

What does Release Openclaw Mac do?

Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion. Release Openclaw Mac is an agent skill from openclaw/openclaw. Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.

How do I install Release Openclaw Mac in Claude Code?

Run `npx skills add openclaw/openclaw --skill release-openclaw-mac -a claude-code`. Or copy the skill folder (.agents/skills/release-openclaw-mac in openclaw/openclaw) into .claude/skills/release-openclaw-mac in your project. Claude Code loads it when a task matches its description.

How do I install Release Openclaw Mac in Codex?

Run `npx skills add openclaw/openclaw --skill release-openclaw-mac -a codex`. Or copy the skill folder (.agents/skills/release-openclaw-mac in openclaw/openclaw) into .agents/skills/release-openclaw-mac in your project. Codex loads it when a task matches its description.

Can I use Release Openclaw Mac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill release-openclaw-mac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-openclaw-mac, .gemini/skills/release-openclaw-mac, .github/skills/release-openclaw-mac and .opencode/skills/release-openclaw-mac in your project.

What does Release Openclaw Mac need to run?

Going by SKILL.md and its folder, Release Openclaw Mac needs the command-line tools its instructions call (gh and xcrun) and credentials named APP_STORE_CONNECT_KEY_ID.

Does Release Openclaw Mac access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release Openclaw Mac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Openclaw Mac use?

Release Openclaw Mac is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Openclaw Mac use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Openclaw Mac?

Skills that share tags, products or a category with Release Openclaw Mac: Mole CLI Release Flow (tw93/Mole, 70k stars), Release Easydict (tisfeng/Easydict, 15k stars), Release (eugene1g/agent-safehouse, 2.1k stars) and Cherry Studio Regression Tests (CherryHQ/cherry-studio, 52k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Openclaw Mac?

openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,610 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 8, 2026.

Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.