Agent skill

Publish Placeholder Package

by remix-run in remix-run/remix

Publish a placeholder npm package at version 0.0.0 so package names are reserved and npm OIDC permissions can be configured before CI publishing.

MITAuto-check passedBackend & APIs

Install Publish Placeholder Package

skills CLI
$ npx skills add remix-run/remix --skill publish-placeholder-package -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install remix-run/remix publish-placeholder-package --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/remix-run/remix.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/publish-placeholder-package .claude/skills/publish-placeholder-package && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
publish-placeholder-package
GitHub stars
33k
Token cost
~921 tokens
SKILL.md length
310 words
Files
2
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Publish a placeholder npm package at version 0.0.0 so package names are reserved and npm OIDC permissions can be configured before CI publishing.

  • Creating a brand-new package that is not ready for full release
  • SKILL.md covers Overview, Workflow and Notes
  • Calls npm
  • Tasks that involve OAuth and OpenID Connect

What it does

Publish Placeholder Package is an agent skill from remix-run/remix. Publish a placeholder npm package at version 0.0.0 so package names are reserved and npm OIDC permissions can be configured before CI publishing. Use when creating a brand-new package that is not ready for full release.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with npm and Remix. The repository describes itself as: The fully-stacked web framework. The licence is MIT.

When your agent uses it

  • Creating a brand-new package that is not ready for full release
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/publish-placeholder-package”

What it can do on your machine

Read from SKILL.md and the folder at commit 3c25f7a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Publish Placeholder Package loads about 921 tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 310 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~921

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from remix-run/remix at commit 3c25f7a, republished under its MIT licence (© remix-run). 310 words, ~921 tokens.

Download SKILL.mdSave it as .claude/skills/publish-placeholder-package/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
publish-placeholder-package
description
Publish a placeholder npm package at version 0.0.0 so package names are reserved and npm OIDC permissions can be configured before CI publishing. Use when creating a brand-new package that is not ready for full release.

Publish Placeholder Package

Overview

Use this skill to publish a minimal placeholder package to npm at 0.0.0. This is used to reserve the package name and unblock npm-side OIDC configuration for CI publishing.

Workflow

  1. Confirm publish target.
  • Collect:
    • npm package name (for example, @remix-run/my-package)
    • package directory in repo (for example, packages/my-package)
  • Validate the package does not already exist at 0.0.0:
sh
npm view <package-name>@0.0.0 version
  • If it already exists, stop and report that no placeholder publish is needed.
  1. Build a temporary placeholder package outside the repo.
  • Always publish from a temp directory to avoid shipping real package files by mistake.
  • Create the temp directory and write a minimal package.json:
sh
tmp_dir="$(mktemp -d)"
cd "$tmp_dir"

cat > package.json <<'JSON'
{
  "name": "<package-name>",
  "version": "0.0.0",
  "description": "Placeholder package for Remix CI/OIDC setup",
  "license": "MIT",
  "repository": {
    "type": "git",
    "url": "git+https://github.com/remix-run/remix.git",
    "directory": "<repo-package-dir>"
  },
  "publishConfig": {
    "access": "public"
  }
}
JSON
  • Add a short README:
sh
cat > README.md <<'MD'
# Placeholder Package

This package is a placeholder published at `0.0.0` to reserve the npm name and configure CI publish permissions.
MD
  1. Ensure npm auth is valid (expect re-auth/OTP).
  • Check session:
sh
npm whoami
  • If not authenticated, run:
sh
npm login
  • Expect npm to require a fresh login and/or one-time password. If prompted for OTP, request it from the user and continue.
  1. Publish the placeholder.
  • Publish with public access:
sh
npm publish --access public
  • If the account enforces 2FA for writes, publish with OTP:
sh
npm publish --access public --otp <code>
  1. Wait for the placeholder to appear on npm, then configure trusted publishing.
  • New package names may take a short time to become visible in the registry after npm publish.
  • Poll until 0.0.0 resolves before running npm trust:
sh
for attempt in $(seq 1 18); do
  version=$(npm view <package-name>@0.0.0 version --silent 2>/dev/null || true)
  if [ "$version" = "0.0.0" ]; then
    break
  fi

  echo "Waiting for <package-name>@0.0.0 to appear on npm..."
  sleep 10
done

if [ "$version" != "0.0.0" ]; then
  echo "Package did not appear on npm in time"
  exit 1
fi
  • As soon as it resolves, configure the GitHub Actions trusted publisher from the same local machine where you published the placeholder:
sh
npm trust github <package-name> --repo remix-run/remix --file publish.yaml --yes
  • This follow-up should be done immediately after placeholder publish while local npm auth is already available.
  1. Verify and report.
  • Verify the published version:
sh
npm view <package-name>@0.0.0 version
  • Report:
    • package name
    • published version (0.0.0)
    • confirmation that npm trust github succeeded for .github/workflows/publish.yaml
  1. Clean up temp files.
sh
rm -rf "$tmp_dir"

Notes

  • Keep placeholder publish minimal. Do not publish full source code for this step.
  • This is a one-time bootstrap step. Normal releases should continue through CI.
  • Do not stop after npm publish; the placeholder is only fully ready once npm trust github has been configured.

© remix-run, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/publish-placeholder-package of remix-run/remix.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 3c25f7a

Compare with similar skills

Publish Placeholder Package next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Publish Placeholder Package compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Publish Placeholder Package this skillremix-run/remix33k—~921Automated safety check: PassMIT
Openclone CLIteam-attention/openclone130—~712Automated safety check: PassCustom licence
Nopal Setupfivetaku/gptaku-plugins-codex128—~1.1kAutomated safety check: NotesMIT
Intercom Install Authjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: NotesMIT
Releaseseasonedcc/remix-forms514—~1.3kAutomated safety check: PassMIT
Automate npm Releasejd-solanki/slidev-theme-dracula161—~626Automated safety check: PassNone

Similar skills

  • Openclone CLI

    team-attention/openclone

    A skill your agent uses when the user wants to consult an AI persona "clone" for advice, strategy, analysis, or domain expertise—especially in startup, VC, tech, growth, HR, or business contexts.

    130 GitHub stars~712 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Nopal Setup

    fivetaku/gptaku-plugins-codex

    Codex용 Google Workspace 설정 가이드 스킬. An agent skill from fivetaku/gptaku-plugins-codex.

    128 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Intercom Install Auth

    jeremylongshore/tons-of-skills-marketplace

    Install and configure Intercom API authentication with access tokens or OAuth.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Release

    seasonedcc/remix-forms

    Release a new version of the remix-forms npm package. An agent skill from seasonedcc/remix-forms.

    514 GitHub stars~1.3k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Automate npm Release

    jd-solanki/slidev-theme-dracula

    Automate npm package publishing via GitHub Actions for single-package repos and independent monorepo packages, including bumpp version tags, GitHub release notes, trusted publishing, provenance, and…

    161 GitHub stars~626 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Release

    nubjs/nub

    Cut a Nub patch release end-to-end in one invocation. An agent skill from nubjs/nub.

    4.4k GitHub stars~7.6k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from remix-run/remix

All 19 skills in this repo
  • Supersede PR

    remix-run/remix

    Safely replace one GitHub pull request with another. An agent skill from remix-run/remix.

    33k GitHub stars~456 tokensUpdated yesterday
    Auto-check passed
  • Add Package

    remix-run/remix

    Create or align a package in the Remix monorepo to match existing package conventions.

    33k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Author UI Primitives

    remix-run/remix

    Build idiomatic headless primitives in packages/ui for Remix.

    33k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Fix Issue

    remix-run/remix

    Fix a reported issue in Remix from a GitHub issue. An agent skill from remix-run/remix.

    33k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Make Demo

    remix-run/remix

    Create or revise demos in the Remix repository. An agent skill from remix-run/remix.

    33k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Make PR

    remix-run/remix

    Create GitHub pull requests with clear, reviewer-friendly descriptions.

    33k GitHub stars~847 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Publish Placeholder Package

What does Publish Placeholder Package do?

Publish a placeholder npm package at version 0.0.0 so package names are reserved and npm OIDC permissions can be configured before CI publishing. Publish Placeholder Package is an agent skill from remix-run/remix.0 so package names are reserved and npm OIDC permissions can be configured before CI publishing.

When should I use Publish Placeholder Package?

Publish Placeholder Package fits situations like: creating a brand-new package that is not ready for full release; tasks that involve OAuth and OpenID Connect.

How do I install Publish Placeholder Package in Claude Code?

Run `npx skills add remix-run/remix --skill publish-placeholder-package -a claude-code`. Or copy the skill folder (.agents/skills/publish-placeholder-package in remix-run/remix) into .claude/skills/publish-placeholder-package in your project. Claude Code loads it when a task matches its description.

How do I install Publish Placeholder Package in Codex?

Run `npx skills add remix-run/remix --skill publish-placeholder-package -a codex`. Or copy the skill folder (.agents/skills/publish-placeholder-package in remix-run/remix) into .agents/skills/publish-placeholder-package in your project. Codex loads it when a task matches its description.

Can I use Publish Placeholder Package in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add remix-run/remix --skill publish-placeholder-package -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/publish-placeholder-package, .gemini/skills/publish-placeholder-package, .github/skills/publish-placeholder-package and .opencode/skills/publish-placeholder-package in your project.

What does Publish Placeholder Package need to run?

Going by SKILL.md and its folder, Publish Placeholder Package needs the command-line tools its instructions call (npm).

Does Publish Placeholder Package access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Publish Placeholder Package safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Publish Placeholder Package use?

Publish Placeholder Package is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Publish Placeholder Package use?

About 921 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Publish Placeholder Package?

Skills that share tags, products or a category with Publish Placeholder Package: Openclone CLI (team-attention/openclone, 130 stars), Nopal Setup (fivetaku/gptaku-plugins-codex, 128 stars), Intercom Install Auth (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Release (seasonedcc/remix-forms, 514 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Publish Placeholder Package?

remix-run (a GitHub organization) maintains it in remix-run/remix, which has 33,404 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: remix-run/remix on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.