Mole CLI Release Flow
tw93/Mole
Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.
Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.
$ npx skills add openclaw/openclaw --skill release-openclaw-mac -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openclaw/openclaw release-openclaw-mac --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release-openclaw-mac .claude/skills/release-openclaw-mac && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release-openclaw-mac" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac into .claude/skills/release-openclaw-mac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-openclaw-mac", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-macType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openclaw/openclaw --skill release-openclaw-mac -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openclaw/openclaw release-openclaw-mac --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/release-openclaw-mac .agents/skills/release-openclaw-mac && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release-openclaw-mac" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac into .agents/skills/release-openclaw-mac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-openclaw-mac", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill release-openclaw-mac -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openclaw/openclaw release-openclaw-mac --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/release-openclaw-mac .cursor/skills/release-openclaw-mac && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release-openclaw-mac" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac into .cursor/skills/release-openclaw-mac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-openclaw-mac", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openclaw/openclaw.git --path .agents/skills/release-openclaw-mac--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openclaw/openclaw --skill release-openclaw-mac -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openclaw/openclaw release-openclaw-mac --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/release-openclaw-mac .gemini/skills/release-openclaw-mac && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release-openclaw-mac" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac into .gemini/skills/release-openclaw-mac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-openclaw-mac", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openclaw/openclaw release-openclaw-macInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openclaw/openclaw --skill release-openclaw-mac -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/release-openclaw-mac .github/skills/release-openclaw-mac && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release-openclaw-mac" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac into .github/skills/release-openclaw-mac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-openclaw-mac", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill release-openclaw-mac -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openclaw/openclaw release-openclaw-mac --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/release-openclaw-mac .opencode/skills/release-openclaw-mac && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release-openclaw-mac" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/release-openclaw-mac into .opencode/skills/release-openclaw-mac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-openclaw-mac", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
release-openclaw-macRun or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.
Release Openclaw Mac is an agent skill from openclaw/openclaw. Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with macOS and GitHub. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.
Read from SKILL.md and the folder at commit 1eb5970. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghxcrunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
APP_STORE_CONNECT_KEY_IDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Release Openclaw Mac loads about 2k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 911 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openclaw/openclaw at commit 1eb5970, republished under its MIT licence (© openclaw). 911 words, ~2,038 tokens.
.claude/skills/release-openclaw-mac/SKILL.md (or your agent's skills folder).Use with $release-openclaw-maintainer, $release-openclaw-ci, $one-password, and $release-private if it exists when stable macOS assets, release-ops mac preflight, notarization, appcast promotion, or mac release recovery is involved.
This is a regular stable-release skill. Do not invoke it for extended-stable; that track's GitHub Release carries shared validation evidence but does not inherit macOS assets or appcast promotion.
An explicit stable or full release request includes macOS publication unless the operator limits its scope. Continue through validation, signing, notarization, promotion, and verification without asking for separate macOS consent. Keep the exact release identity and all artifact checks. macOS publication runs in parallel with npm and never blocks it; a mac failure does not hold the npm/ClawHub release, GitHub release finalization, or main closeout. Fix it in parallel.
Follow the current owner-configured environment policy. Do not invent an extra reviewer requirement or recreate an obsolete one. If GitHub still enforces an approval, report the actual rule and resolve it through its owner; policy changes require explicit organization-owner direction and verified active admin membership. Never impersonate a reviewer, fabricate approval, or use another signing path to bypass an enforced rule.
$release-private.private_key_p8, key_id, issuer_id.xcrun notarytool submit fails with HTTP status code: 401. Unauthenticated.xcrun notarytool history before setting GitHub secrets.$one-password: all op work inside one persistent tmux session, no secret output.$release-private when available.op whoami; never print token values.OP_BIOMETRIC_UNLOCK_ENABLED=false for the manual op account add --signin path.Target release-ops repo environment: openclaw/releases, env mac-release.
Set only after local notary auth validation:
APP_STORE_CONNECT_API_KEY_P8APP_STORE_CONNECT_KEY_IDAPP_STORE_CONNECT_ISSUER_IDDo not update these from mixed sources. All three ASC fields must come from the same 1Password item.
openclaw/openclaw is the public product repo. Its GitHub Releases page is
where macOS assets are ultimately attached.openclaw/openclaw macos-release.yml is public handoff validation only.
It never signs, notarizes, or uploads macOS assets, regardless of
preflight_only.openclaw/releases is the restricted release-ops repo. Its macOS workflows
sign, notarize, validate, and promote assets onto the
openclaw/openclaw GitHub release.source_ref=release/YYYY.M.PATCH for release-ops mac preflight/validation when building that branch variation.tag=vYYYY.M.PATCH pointing at the original stable release commit.mac-release environment for
signing and promotion secrets and its main-only deployment policy. The
authorized release operator continues under that environment's current rules.source_ref; promotion rejects mismatched proof.scripts/notarize-mac-artifact.sh.xcrun notarytool submit should use --no-s3-acceleration; accelerated upload can surface misleading 401s even when notarytool history succeeds.The public handoff workflow validates the tag, source, build, and package metadata before publication. It does not require a GitHub release page because it does not upload assets. Keep this validation before the real publish workflow. The core publisher owns GitHub release finalization; macOS promotion attaches its verified assets to that release whether it is still a draft or already public, so it never waits for the npm flip.
Public handoff validation:
gh workflow run macos-release.yml --repo openclaw/openclaw \
--ref release/YYYY.M.PATCH \
-f tag=vYYYY.M.PATCH \
-f preflight_only=true \
-f public_release_branch=release/YYYY.M.PATCHrelease/YYYY.M.PATCH, matching prior stable macOS handoff runs.--ref main or --ref vYYYY.M.PATCH for this public handoff
validation. The workflow checks out the tag from the tag input internally.Release-ops preflight:
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
-f tag=vYYYY.M.PATCH \
-f source_ref=release/YYYY.M.PATCH \
-f preflight_only=true \
-f smoke_test_only=false \
-f allow_late_calver_recovery=false \
-f public_release_branch=release/YYYY.M.PATCHFollow the run through signing and notarization under the configured environment policy. Record the successful preflight run id; an approval pause is not a successful preflight.
Resume is the default. Re-dispatching the same preflight command after a
failure (notary outage, DMG packaging, collector) resumes every variant from
the newest checkpoint left by a failed or cancelled main dispatch for the same
tag and source SHA; only variants without a checkpoint rebuild. The run log
prints Resuming <variant> from run <id> attempt <n> or Building <variant>.
ignore_checkpoints=true forces fresh builds. Pass resume_notarization_run_id,
resume_notarization_run_attempt, and resume_notarization_variant only to pin
one specific run, or for checkpoints made before the resume index existed
(macos-resume-<tag>-<variant>-<sha> artifacts). Prefer
gh run rerun <run-id> --failed --repo openclaw/releases when the failed job is
still in the current run.
Release-ops validation for a branch-variation preflight:
gh workflow run openclaw-macos-validate.yml --repo openclaw/releases --ref main \
-f tag=vYYYY.M.PATCH \
-f source_ref=release/YYYY.M.PATCHRecord the successful validation run id.
Real publish:
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
-f tag=vYYYY.M.PATCH \
-f preflight_only=false \
-f smoke_test_only=false \
-f preflight_run_id=<successful-preflight-run> \
-f validate_run_id=<successful-validation-run> \
-f allow_late_calver_recovery=false \
-f public_release_branch=release/YYYY.M.PATCHFollow promotion through asset upload and appcast publication under the same release authorization and current environment policy.
openclaw/releases publish/validate workflows run from their own
trusted main workflow ref. Real publish has a guard that rejects any other
workflow ref. That displayed main ref is expected; the public OpenClaw
source is selected by tag and optional source_ref.gh release view vYYYY.M.PATCH --repo openclaw/openclaw shows zip, dmg, dSYM zip; once the npm publisher has flipped it: not draft, not prerelease.main appcast.xml points at OpenClaw-YYYY.M.PATCH.zip.sparkle:version, sparkle:shortVersionString, length, and sparkle:edSignature.© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/release-openclaw-mac of openclaw/openclaw.
Open the folder on GitHubat commit 1eb5970
Release Openclaw Mac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Release Openclaw Mac this skillopenclaw/openclaw | 392k | — | ~2k | Automated safety check: Pass | MIT | |
| Mole CLI Release Flowtw93/Mole | 70k | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | |
| Release Easydicttisfeng/Easydict | 15k | — | ~810 | Automated safety check: Pass | GPL-3.0 | |
| Releaseeugene1g/agent-safehouse | 2.1k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Cherry Studio Regression TestsCherryHQ/cherry-studio | 52k | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | |
| Kane CLI Browser TestingLambdaTest/kane-cli | 247 | — | ~8.4k | Automated safety check: Pass | Apache-2.0 |
tw93/Mole
Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.
tisfeng/Easydict
编排 Easydict macOS 的 draft、publish、release 和 resume,整理英文 GitHub Release 内容,并处理发布后的 Issue 跟进及本地清理。不用于一般的发布流程设计讨论。
eugene1g/agent-safehouse
Run the local Agent Safehouse release flow: inspect commits since the last published release, propose the next SemVer version and changelog, present a dry-run for confirmation, then update…
CherryHQ/cherry-studio
Runs Cherry Studio's critical-path regression suite as deterministic Playwright E2E tests through a GitHub workflow on macOS and Windows runners.
LambdaTest/kane-cli
Drives a real browser through the kane-cli tool and designs requirement-linked test suites from a PRD or a plain description, with mobile and cloud-grid runs.
notepadqq/notepadqq
Release a new Notepadqq version. An agent skill from notepadqq/notepadqq.
openclaw/openclaw
Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.
openclaw/openclaw
Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.
openclaw/openclaw
Feishu document read/write workflows. An agent skill from openclaw/openclaw.
openclaw/openclaw
Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.
openclaw/openclaw
A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.
openclaw/openclaw
A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…
Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion. Release Openclaw Mac is an agent skill from openclaw/openclaw. Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.
Run `npx skills add openclaw/openclaw --skill release-openclaw-mac -a claude-code`. Or copy the skill folder (.agents/skills/release-openclaw-mac in openclaw/openclaw) into .claude/skills/release-openclaw-mac in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openclaw/openclaw --skill release-openclaw-mac -a codex`. Or copy the skill folder (.agents/skills/release-openclaw-mac in openclaw/openclaw) into .agents/skills/release-openclaw-mac in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill release-openclaw-mac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-openclaw-mac, .gemini/skills/release-openclaw-mac, .github/skills/release-openclaw-mac and .opencode/skills/release-openclaw-mac in your project.
Going by SKILL.md and its folder, Release Openclaw Mac needs the command-line tools its instructions call (gh and xcrun) and credentials named APP_STORE_CONNECT_KEY_ID.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Release Openclaw Mac is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Release Openclaw Mac: Mole CLI Release Flow (tw93/Mole, 70k stars), Release Easydict (tisfeng/Easydict, 15k stars), Release (eugene1g/agent-safehouse, 2.1k stars) and Cherry Studio Regression Tests (CherryHQ/cherry-studio, 52k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,610 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 8, 2026.
Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.