Agent skill

Openyida Cross Platform Release Guard

by openyida in openyida/openyida

OpenYida 跨端发布风险守卫。当改动涉及浏览器/URL 拉起(openyida login、bridge 页面唤起、resolveBrowserLauncher、openBrowser、spawn 打开浏览器),或用户明确要求检查 Windows/Linux 发布风险时使用。用于静态扫描并拦截「cmd /c start 截断 URL」「open -n 假装开新窗口」等跨端问题;普通版本…

MITAuto-check passed

Install Openyida Cross Platform Release Guard

skills CLI
$ npx skills add openyida/openyida --skill openyida-cross-platform-release-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openyida/openyida openyida-cross-platform-release-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openyida/openyida.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/openyida-cross-platform-release-guard .claude/skills/openyida-cross-platform-release-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openyida-cross-platform-release-guard
GitHub stars
221
Token cost
~637 tokens
SKILL.md length
176 words
Files
1
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

OpenYida 跨端发布风险守卫。当改动涉及浏览器/URL 拉起(openyida login、bridge 页面唤起、resolveBrowserLauncher、openBrowser、spawn 打开浏览器),或用户明确要求检查 Windows/Linux 发布风险时使用。用于静态扫描并拦截「cmd /c start 截断 URL」「open -n 假装开新窗口」等跨端问题;普通版本…

  • Works in 3 steps: 确认 package.json version 与 CHANGELOG… → npm run check:ci 全绿(含发布风险扫描)。 → CHANGELOG 记录本次改动,浏览器/登录/bridge…
  • SKILL.md covers 触发条件, 第一步:跑发布风险静态扫描(必做), 第二步:跨端人工验证清单 and 第三步:发布收尾, plus 1 more section
  • Calls npm and sh

What it does

Openyida Cross Platform Release Guard is an agent skill from openyida/openyida. OpenYida 跨端发布风险守卫。当改动涉及浏览器/URL 拉起(openyida login、bridge 页面唤起、resolveBrowserLauncher、openBrowser、spawn 打开浏览器),或用户明确要求检查 Windows/Linux 发布风险时使用。用于静态扫描并拦截「cmd /c start 截断 URL」「open -n 假装开新窗口」等跨端问题;普通版本 tag 发布请使用 openyida-release。

Its SKILL.md is about 640 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Linux and macOS. The repository describes itself as: Your own personal YiDA AI assistant! The licence is MIT.

Example prompts

  • “/openyida-cross-platform-release-guard”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 确认 package.json version 与 CHANGELOG 顶部版本一致(日期格式 vYYYY.MM.DD,同日多次
  2. npm run check:ci 全绿(含发布风险扫描)。
  3. CHANGELOG 记录本次改动,浏览器/登录/bridge 类改动务必写明受影响平台。

What it can do on your machine

Read from SKILL.md and the folder at commit 4932d0b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • sh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openyida Cross Platform Release Guard loads about 637 tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 176 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~637

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openyida/openyida at commit 4932d0b, republished under its MIT licence (© openyida). 176 words, ~637 tokens.

Download SKILL.mdSave it as .claude/skills/openyida-cross-platform-release-guard/SKILL.md (or your agent's skills folder).
name
openyida-cross-platform-release-guard
description
OpenYida 跨端发布风险守卫。当改动涉及浏览器/URL 拉起(openyida login、bridge 页面唤起、resolveBrowserLauncher、openBrowser、spawn 打开浏览器),或用户明确要求检查 Windows/Linux 发布风险时使用。用于静态扫描并拦截「cmd /c start 截断 URL」「open -n 假装开新窗口」等跨端问题;普通版本 tag 发布请使用 openyida-release。

OpenYida 跨端发布风险守卫

macOS 本地测试跑通 ≠ 发布安全。浏览器/URL 拉起这类代码在 macOS 上正常,却可能在 Windows/Linux 用户侧直接炸掉——因为每个平台的浏览器拉起命令、URL 转义规则、默认浏览器 标识(bundle id / ProgId / .desktop)完全不同,而 CI 只跑纯函数单测,覆盖不到真实系统拉起。

触发条件

  • 改动 lib/auth/oauth-loopback.js、lib/bridge/bridge.js,或任何 resolveBrowserLauncher / openBrowser / spawn(...浏览器...) 相关逻辑。
  • 在 macOS 开发、发布对象包含 Windows / Linux 用户。
  • 用户明确要求对浏览器拉起或 URL 传递改动做跨端发布检查。

第一步:跑发布风险静态扫描(必做)

bash
npm run check:release-risks
  • HARD 反模式 → exit 1,阻断发布(已纳入 check:ci 第 10 步):
    • cmd-c-start-url / cmd-c-start-argv:cmd /c start <url> 会把 URL 里的 & 当命令 分隔符截断,丢失 client_id/state(登录)或 oy_bridge_url/oy_bridge_token(bridge)。 → 改用 rundll32 url.dll,FileProtocolHandler,并复用 resolveBrowserLauncher。
    • open-n-url-new-tab:open -n <url> 在 macOS 不会开新窗口,只在默认浏览器开新标签页 (假装开窗口)。→ 要真开新窗口须指定浏览器 App 并传其 --new-window/-new-window; 检测不到默认浏览器时回退纯 open <url>。
  • SOFT 提示 → 不阻断:列出涉及浏览器/URL 拉起的文件,提醒补人工跨端验证。

扫描逻辑见 scripts/check-release-risks.js(纯静态扫描 lib/,会跳过注释,并正确识别字符串中的 // / /* 不是注释;命令字符串仍会保留扫描,确保能抓到 spawn('cmd', ...) 这类真实反模式); 契约由 tests/check-release-risks.test.js 锁定。

第二步:跨端人工验证清单

CI 通过只代表纯逻辑没问题,浏览器真实拉起必须在目标 OS 各自实测:

平台拉起方式默认浏览器标识必测
macOSopen(新标签页)/ open -b <bundle> -n --args --new-window(新窗口)LaunchServices bundle id(com.google.chrome)openyida login 弹出浏览器且回调页自动关闭;bridge 页面能唤起
Windowsrundll32 url.dll,FileProtocolHandler(默认)/ 浏览器 exe --new-window注册表 ProgId(ChromeHTML/MSEdgeHTM/FirefoxURL)登录 URL 的 client_id/state 不被 & 截断;bridge 参数不丢
Linuxxdg-open(默认)/ 浏览器 exe --new-window.desktop 文件名(google-chrome.desktop)openyida login 能拉起浏览器

要点:

  • 三端「默认浏览器标识」互不通用,各自独立分类;未知/不支持的默认浏览器一律回退到 系统默认浏览器新标签页 + 回调页自动关闭,绝不假装开新窗口。
  • URL 必须作为单个 argv 元素传递,任何经过 shell(cmd /c、sh -c)的路径都要确认 & 不被解释。

第三步:发布收尾

  1. 确认 package.json version 与 CHANGELOG 顶部版本一致(日期格式 vYYYY.MM.DD,同日多次 发布用 -1/-2 后缀)。
  2. npm run check:ci 全绿(含发布风险扫描)。
  3. CHANGELOG 记录本次改动,浏览器/登录/bridge 类改动务必写明受影响平台。

反哺

发现新的「只在某平台暴露」的拉起坑时,在 scripts/check-release-risks.js 的 HARD_RULES 增加一条规则 + 在 tests/check-release-risks.test.js 补对应用例,让守卫随坑增长。

© openyida, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/openyida-cross-platform-release-guard of openyida/openyida.

Open the folder on GitHubat commit 4932d0b

Compare with similar skills

Openyida Cross Platform Release Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openyida Cross Platform Release Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openyida Cross Platform Release Guard this skillopenyida/openyida221—~637Automated safety check: PassMIT
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Apple Container Test RunnerRustPython/RustPython22k—~467Automated safety check: PassMIT
Native Feel Cross Platform Desktopyetone/native-feel-skill1.9k1 repos~1.5kAutomated safety check: PassMIT
TreeSheets Agent Socketaardappel/treesheets3.2k—~5.7kAutomated safety check: NotesZlib

Similar skills

  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Apple Container Test Runner

    RustPython/RustPython

    Runs RustPython tests inside a Linux container built with Apple's container CLI, so macOS users can compare Linux results with their local ones.

    22k GitHub stars~467 tokensUpdated today
    Testing & QAAuto-check passed
  • Native Feel Cross Platform Desktop

    yetone/native-feel-skill

    A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a…

    1.9k GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • TreeSheets Agent Socket

    aardappel/treesheets

    Runs Lobster scripts against the document open in a running TreeSheets instance through its local agent socket, and returns the results or errors.

    3.2k GitHub stars~5.7k tokensUpdated yesterday
    Productivity & AutomationAuto-check: notes
  • Open Computer Use

    iFurySt/open-codex-computer-use

    Platform-neutral guidance for using Open Computer Use, the open-source Computer Use MCP server and CLI for macOS, Linux, and Windows.

    2.4k GitHub stars~1.5k tokensUpdated today
    Productivity & AutomationAuto-check passed

More from openyida/openyida

All 59 skills in this repo
  • Yida Canvas Custom Page

    openyida/openyida

    宜搭自定义页面开发规范,使用 YidaCodeCanvas 组件实现现代 React18 自定义页面。用于官网、看板、工作台、列表、详情、门户壳、可视化、hooks 交互、表单入口,以及需要门户组件、数据管理视图、成员、部门或上传组件的场景;发布层自动注入 yida/utils window 桥。

    221 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Openyida Release

    openyida/openyida

    快速发布 OpenYida npm 正式版或测试版。用户说“发布正式版”“发布测试版”“发 beta”或要求按当天日期生成版本 tag 时使用;不用于宜搭应用或自定义页面发布。

    221 GitHub stars~520 tokensUpdated today
    Auto-check passed
  • Yida Design Plan

    openyida/openyida

    Plan 模式的视觉设计分支。基于需求选择视觉方向,再结合业务页面规划维护 build-plan.json 的 visualStyle,供 CLI 派生 design.md。

    221 GitHub stars~756 tokensUpdated today
    Auto-check passed
  • Prevent stale local OpenYida custom page source from overwriting live designer edits.

    221 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Codemap

    openyida/openyida

    Generate, update, or drift-check agent-facing CodeMaps as progressive code terrain indexes for projects, features, capabilities, functions, modules, or bug chains.

    221 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Sdd Riper One Light

    openyida/openyida

    面向 GPT-5.5 等强模型和熟练用户的轻量 AI Agent Harness / checkpoint-driven coding skill。默认用户已经把任务切到基本可执行的最小混沌单元;模型自行分解、探索与推进,人类通过最终目标、最小 spec、复述、checkpoint、证据验证与回写来低干扰控盘。

    221 GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Openyida Cross Platform Release Guard

What does Openyida Cross Platform Release Guard do?

OpenYida 跨端发布风险守卫。当改动涉及浏览器/URL 拉起(openyida login、bridge 页面唤起、resolveBrowserLauncher、openBrowser、spawn 打开浏览器),或用户明确要求检查 Windows/Linux 发布风险时使用。用于静态扫描并拦截「cmd /c start 截断 URL」「open -n 假装开新窗口」等跨端问题;普通版本…. Openyida Cross Platform Release Guard is an agent skill from openyida/openyida.

How do I install Openyida Cross Platform Release Guard in Claude Code?

Run `npx skills add openyida/openyida --skill openyida-cross-platform-release-guard -a claude-code`. Or copy the skill folder (.agents/skills/openyida-cross-platform-release-guard in openyida/openyida) into .claude/skills/openyida-cross-platform-release-guard in your project. Claude Code loads it when a task matches its description.

How do I install Openyida Cross Platform Release Guard in Codex?

Run `npx skills add openyida/openyida --skill openyida-cross-platform-release-guard -a codex`. Or copy the skill folder (.agents/skills/openyida-cross-platform-release-guard in openyida/openyida) into .agents/skills/openyida-cross-platform-release-guard in your project. Codex loads it when a task matches its description.

Can I use Openyida Cross Platform Release Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openyida/openyida --skill openyida-cross-platform-release-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openyida-cross-platform-release-guard, .gemini/skills/openyida-cross-platform-release-guard, .github/skills/openyida-cross-platform-release-guard and .opencode/skills/openyida-cross-platform-release-guard in your project.

What does Openyida Cross Platform Release Guard need to run?

Going by SKILL.md and its folder, Openyida Cross Platform Release Guard needs the command-line tools its instructions call (npm and sh).

Does Openyida Cross Platform Release Guard access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Openyida Cross Platform Release Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openyida Cross Platform Release Guard use?

Openyida Cross Platform Release Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openyida Cross Platform Release Guard use?

About 637 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openyida Cross Platform Release Guard?

Skills that share tags, products or a category with Openyida Cross Platform Release Guard: Engine Whats New (flutter/flutter, 179k stars), Openclaw Live Updater (openclaw/openclaw, 392k stars), Apple Container Test Runner (RustPython/RustPython, 22k stars) and Native Feel Cross Platform Desktop (yetone/native-feel-skill, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openyida Cross Platform Release Guard?

openyida (a GitHub organization) maintains it in openyida/openyida, which has 221 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 10, 2026.

Source: openyida/openyida on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.