Agent skill

ASC Ad Hoc Distribution

by rorkai in rorkai/app-store-connect-cli-skills

Prepares, publishes, resumes and verifies private iOS test installs for registered devices with `asc distribute`, using storage you own that speaks the S3 protocol.

MITAuto-check passedMobile

Install ASC Ad Hoc Distribution

skills CLI
$ npx skills add rorkai/app-store-connect-cli-skills --skill asc-ad-hoc-distribution -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rorkai/app-store-connect-cli-skills asc-ad-hoc-distribution --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rorkai/app-store-connect-cli-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/asc-ad-hoc-distribution .claude/skills/asc-ad-hoc-distribution && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
asc-ad-hoc-distribution
GitHub stars
1.1k
Used in
1 other repo
Token cost
~1.8k tokens
SKILL.md length
640 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Prepares, publishes, resumes and verifies private iOS test installs for registered devices with `asc distribute`, using storage you own that speaks the S3 protocol.

  • Works in 4 steps: Create the private distribution spec → Plan without mutation → Apply the exact authorized plan → …
  • Distributing an IPA to registered devices outside TestFlight
  • SKILL.md covers Choose the workflow, Guardrails, Preconditions and 1. Create the private…, plus 4 more sections
  • Calls jq; needs ASC_S3_ACCESS_KEY_ID and ASC_S3_SECRET_ACCESS_KEY

What it does

The skill turns an existing iOS archive into a private, verified install link through the experimental `asc distribute` workflow, and points to the TestFlight or App Store skills when a build should use Apple-hosted distribution. The end-to-end path runs plan, apply, resume or status, then verify, with each run authorized by a plan hash. A lower-level path of inspect, prepare and publish exists for callers who already hold an ad hoc IPA. The agent first confirms the installed command contract with the `--help` output.

Guardrails are strict. The distribution spec, devices file, PKCS#12 identity, password file, run state and the install link are private and kept out of Git with owner-only permissions, and S3 credentials come from `ASC_S3_*` variables or the AWS SDK credential chain, never from the spec, logs or chat. The `plan` step is read-only. The `apply` step can register devices, create App IDs and ad hoc profiles and publish objects, so it runs only after you approve the exact plan. It does not create buckets, delete builds or install the app, and any drift or expired material needs a fresh plan.

When your agent uses it

  • Distributing an IPA to registered devices outside TestFlight
  • Resuming or diagnosing an interrupted private distribution run
  • Reconciling ad hoc provisioning profiles with a devices file
  • Publishing a test build to your own S3-compatible bucket

Example prompts

  • “Plan a private ad hoc distribution of build/MyApp.xcarchive to the devices in devices.json.”
  • “The last distribution run stopped halfway. Check its status and resume it.”
  • “Verify that the install link from the last run still works on our registered iPhones.”

Requirements

  • The `asc` CLI with the `distribute` command
  • An iOS `.xcarchive` with one main app target
  • A PKCS#12 distribution identity and a protected devices file
  • App Store Connect authentication
  • An existing S3-compatible bucket and its credentials

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Create the private distribution spec
  2. Plan without mutation
  3. Apply the exact authorized plan
  4. Inspect, resume, and verify

What it can do on your machine

Read from SKILL.md and the folder at commit 9c7e769. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ASC_S3_ACCESS_KEY_ID
    • ASC_S3_SECRET_ACCESS_KEY
    • ASC_S3_SESSION_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

ASC Ad Hoc Distribution loads about 1.8k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 640 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rorkai/app-store-connect-cli-skills at commit 9c7e769, republished under its MIT licence (© rorkai). 640 words, ~1,838 tokens.

Download SKILL.mdSave it as .claude/skills/asc-ad-hoc-distribution/SKILL.md (or your agent's skills folder).
name
asc-ad-hoc-distribution
description
Prepare, publish, resume, and verify private iOS release-testing installs with asc distribute. Use when distributing an IPA to registered devices outside TestFlight, reconciling ad hoc profiles, publishing through caller-owned S3-compatible storage, or diagnosing a resumable private distribution run.

ASC ad hoc distribution

Use the experimental asc distribute workflow to turn an existing iOS archive into a private, verified install link for registered devices. Use TestFlight or the App Store release skills instead when the build should go through Apple-hosted distribution.

Confirm the installed contract before acting:

bash
asc distribute --help
asc distribute plan --help
asc distribute apply --help
asc distribute resume --help
asc distribute status --help
asc distribute verify --help

Choose the workflow

  • Use plan -> apply -> resume/status -> verify for an end-to-end, hash-authorized run starting from an .xcarchive.
  • Use inspect -> prepare -> publish only when the caller already owns the ad hoc IPA and wants to operate the lower-level boundaries separately.

Guardrails

  • Treat the distribution spec, devices file, PKCS#12 identity, password file, run state, and exact install-link artifact as private. Keep them out of Git and require owner-only permissions.
  • Never put S3 credentials or presigned URLs in the distribution spec, command output, logs, issues, or chat. Use ASC_S3_ACCESS_KEY_ID, ASC_S3_SECRET_ACCESS_KEY, and optional ASC_S3_SESSION_TOKEN, or the standard AWS SDK credential chain.
  • plan is read-only and may exit successfully with ready: false. Inspect the typed blockers and effects before continuing.
  • apply can register missing devices, create safe App IDs and successor ad hoc profiles, write local artifacts, and publish immutable objects. Run it only after the user authorizes the exact plan hash and effect inventory.
  • The orchestrated workflow supports private access to an existing S3-compatible bucket. It does not create buckets, change policies, delete old builds, install the app, or launch it.
  • Input drift, an immutable-object conflict, expired signing material, or an expired private link requires a new plan. Do not force the old run forward.

Preconditions

  • An existing iOS .xcarchive with one main app target. Embedded apps, extensions, Watch apps, and App Clips make the v1 plan not ready.
  • A local iOS distribution PKCS#12 identity and optional protected password file.
  • A protected strict-v1 devices file. For example:
json
{"schemaVersion":1,"devices":[{"name":"Test iPhone","udid":"DEVICE_UDID","platform":"IOS"}]}
  • App Store Connect authentication with access to devices, Bundle IDs, certificates, and profiles.
  • An existing S3-compatible bucket and valid credentials.

1. Create the private distribution spec

Relative paths resolve from the spec directory. The spec does not interpolate environment variables or accept credentials. A representative private config is:

json
{
  "schemaVersion": 1,
  "devicesFile": "devices.json",
  "signing": {
    "identity": {
      "format": "pkcs12",
      "path": "../signing/distribution.p12",
      "passwordFile": "../secrets/distribution-p12-password"
    },
    "minimumValidityDays": 7,
    "maxMutations": 32
  },
  "publication": {
    "endpoint": "https://objects.example.com",
    "downloadEndpoint": "https://downloads.example.com",
    "region": "auto",
    "bucket": "ios-builds",
    "prefix": "team/app",
    "addressingStyle": "path",
    "urlTtl": "24h",
    "downloadGrace": "1h",
    "verifyTimeout": "30s"
  },
  "metadata": {
    "title": "App",
    "channel": "pull-request-42",
    "sourceRevision": "abc123",
    "sourceUrl": "https://example.com/team/app/commit/abc123"
  }
}

passwordFile, certificateSha256, downloadEndpoint, and every metadata field are optional. An omitted password file means the PKCS#12 must use an empty password. Protect the config and secret inputs before planning:

bash
chmod 600 ".asc/distribution/config.json" ".asc/distribution/devices.json"
chmod 600 ".asc/signing/distribution.p12" ".asc/secrets/distribution-p12-password"
Show full SKILL.md (272 more words)Show less

2. Plan without mutation

bash
asc distribute plan \
  --archive-path ".asc/artifacts/App.xcarchive" \
  --config ".asc/distribution/config.json" \
  --plan ".asc/distribution/plan.json" \
  --state-dir ".asc/distribution/runs" \
  --output json

Inspect ready, planHash, signing validity, destination, and the complete ordered effects inventory. Resolve blockers and create a new plan when ready is false. Do not infer readiness from exit code alone.

3. Apply the exact authorized plan

After approval of the exact effects, pass the full 64-character hash:

bash
PLAN_HASH="$(jq -er '.planHash' ".asc/distribution/plan.json")"
asc distribute apply \
  --plan ".asc/distribution/plan.json" \
  --confirm "$PLAN_HASH" \
  --output json

Missing, malformed, or unequal confirmation is rejected before side effects. Success means publication and live fetch verification completed; it does not mean a device installed or launched the app.

4. Inspect, resume, and verify

Use the returned runId:

bash
asc distribute status --run "RUN_ID" --state-dir ".asc/distribution/runs" --output json
asc distribute resume --run "RUN_ID" --state-dir ".asc/distribution/runs" --output json
asc distribute verify --run "RUN_ID" --state-dir ".asc/distribution/runs" --timeout 30s --output json

status is local-only and succeeds for running, recoverable, and blocked runs; branch on typed fields rather than prose. resume revalidates durable evidence before retrying and never blindly repeats a remote write. verify is read-only but performs live fetches. Add --device "DEVICE_SELECTOR" only when the user asks to observe the matching installed bundle, version, and build on a connected device; this observation does not prove IPA byte identity.

The exact private install URL is a bearer credential stored only in the owner-private link artifact reported by the completed run. Share it only with the intended tester through an approved private channel.

Lower-level IPA workflow

Use this lane when signing and export are already complete. Pass the exact bundleDir returned by prepare to publish:

bash
asc distribute inspect --ipa ".asc/artifacts/App.ipa" --output json
asc distribute prepare --ipa ".asc/artifacts/App.ipa" --channel "pull-request-42" --output json
asc distribute publish \
  --bundle-dir ".asc/distribution/com.example.app/1.2-42-IPA_SHA_PREFIX" \
  --endpoint "https://objects.example.com" \
  --region "auto" \
  --bucket "ios-builds" \
  --prefix "team/app" \
  --receipt ".asc/publishes/app-1.2-42.json" \
  --link-path ".asc/publishes/app-1.2-42-link.json" \
  --output json

inspect omits raw device UDIDs unless --include-devices is explicitly needed. prepare never overwrites a bundle and reuses only an exact equivalent. Private publish is the default and writes exact presigned links only to the mode-0600 link artifact. Public publication is a separate explicit lane using --access public --public-base-url; it assumes anonymous reads are already configured and never changes storage policy.

© rorkai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/asc-ad-hoc-distribution of rorkai/app-store-connect-cli-skills.

Open the folder on GitHubat commit 9c7e769

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in rorkai/app-store-connect-cli-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

ASC Ad Hoc Distribution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

ASC Ad Hoc Distribution compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
ASC Ad Hoc Distribution this skillrorkai/app-store-connect-cli-skills1.1k1 repos~1.8kAutomated safety check: PassMIT
Expo Deploymentkingstinct/react-native-healthkit7164 repos~930Automated safety check: PassMIT
Releasemovieclaw/MovieClaw160—~2.7kAutomated safety check: PassCustom licence
OdevioOdevio/Odevio-CLI423—~7.6kAutomated safety check: PassMIT
iOS App Store SubmitZestfulPulse/ios-app-store-submit142—~4.7kAutomated safety check: PassMIT
Remote Installericodesign/remote-installer107—~4kAutomated safety check: PassMIT

Similar skills

  • Expo Deployment

    kingstinct/react-native-healthkit

    Deploying Expo apps to iOS App Store, Android Play Store, web hosting, and API routes

    716 GitHub starsUsed in 4 repos~930 tokens
    MobileAuto-check passed
  • Release

    movieclaw/MovieClaw

    发布 movieclaw 新版本。当用户要求发版、发布新版本、打 tag、发布 NER 模型、发布 Docker 镜像,或打包上传 iOS App 到 TestFlight / App Store、补传发版附件(IPA、Mac 转码器、Mac 版 App)时使用。涵盖版本号三处同步、应用/模型/镜像/iOS 的完整流程、可选附件失败补救与检查清单。

    160 GitHub stars~2.7k tokensUpdated today
    MobileAuto-check passed
  • Odevio

    Odevio/Odevio-CLI

    Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.

    423 GitHub stars~7.6k tokensUpdated 16 days ago
    MobileAuto-check passed
  • iOS App Store Submit

    ZestfulPulse/ios-app-store-submit

    Build, sign, and submit a Flutter/iOS app to the App Store Connect — covers Xcode archive/export, code signing (including headless-Mac keychain workarounds), the asc CLI for App Store Connect…

    142 GitHub stars~4.7k tokensUpdated 10 days ago
    MobileAuto-check passed
  • Remote Installer

    icodesign/remote-installer

    Put an iOS or Android build on a real phone or tablet over the air with the remote-installer CLI — it validates the build, opens a temporary HTTPS tunnel, and prints one or more install URLs plus QR…

    107 GitHub stars~4k tokensUpdated 11 days ago
    MobileAuto-check passed
  • Release

    vaayne/mori

    Release workflow for Mori macOS workspace terminal and MoriRemote iOS app.

    303 GitHub stars~1.2k tokensUpdated 2 mo ago
    MobileAuto-check passed

More from rorkai/app-store-connect-cli-skills

All 12 skills in this repo
  • App Store Release Flow

    rorkai/app-store-connect-cli-skills

    Orchestrates App Store releases with the asc CLI: staging a version, uploading or building, publishing and submitting for review, with dry-run and confirmation gates.

    1.1k GitHub starsUsed in 2 repos~2k tokens
    Auto-check passed
  • App Store Submission Health

    rorkai/app-store-connect-cli-skills

    Diagnoses why an App Store version cannot be submitted or is stuck in review, using the asc CLI for validation, repair routing, status checks and retry decisions.

    1.1k GitHub starsUsed in 2 repos~2.2k tokens
    Auto-check passed
  • App Store Connect App Creator

    rorkai/app-store-connect-cli-skills

    Creates a new App Store Connect app record by driving the New App form through browser automation, for cases where no public API covers app creation.

    1.1k GitHub starsUsed in 3 repos~1.5k tokens
    Auto-check passed
  • Asc Ppp Pricing

    rorkai/app-store-connect-cli-skills

    Set territory-specific pricing for subscriptions and in-app purchases using current asc setup, pricing summary, price import, and price schedule commands.

    1.1k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check passed
  • Asc Revenuecat Catalog Sync

    rorkai/app-store-connect-cli-skills

    Reconcile App Store Connect subscriptions and in-app purchases with RevenueCat products, entitlements, offerings, and packages using asc and RevenueCat MCP.

    1.1k GitHub starsUsed in 3 repos~3.8k tokens
    Auto-check passed
  • Asc Subscription Localization

    rorkai/app-store-connect-cli-skills

    Bulk-localize subscription, subscription-group, and in-app purchase display names across App Store locales using asc, including API 4.4.1 version-scoped v2 resources.

    1.1k GitHub starsUsed in 2 repos~2.7k tokens
    Auto-check passed

Questions about ASC Ad Hoc Distribution

What does ASC Ad Hoc Distribution do?

Prepares, publishes, resumes and verifies private iOS test installs for registered devices with `asc distribute`, using storage you own that speaks the S3 protocol. The skill turns an existing iOS archive into a private, verified install link through the experimental `asc distribute` workflow, and points to the TestFlight or App Store skills when a build should use Apple-hosted distribution. The end-to-end path runs plan, apply, resume or status, then verify, with each run authorized by a plan hash.

When should I use ASC Ad Hoc Distribution?

ASC Ad Hoc Distribution fits situations like: distributing an IPA to registered devices outside TestFlight; resuming or diagnosing an interrupted private distribution run; reconciling ad hoc provisioning profiles with a devices file; publishing a test build to your own S3-compatible bucket.

How do I install ASC Ad Hoc Distribution in Claude Code?

Run `npx skills add rorkai/app-store-connect-cli-skills --skill asc-ad-hoc-distribution -a claude-code`. Or copy the skill folder (skills/asc-ad-hoc-distribution in rorkai/app-store-connect-cli-skills) into .claude/skills/asc-ad-hoc-distribution in your project. Claude Code loads it when a task matches its description.

How do I install ASC Ad Hoc Distribution in Codex?

Run `npx skills add rorkai/app-store-connect-cli-skills --skill asc-ad-hoc-distribution -a codex`. Or copy the skill folder (skills/asc-ad-hoc-distribution in rorkai/app-store-connect-cli-skills) into .agents/skills/asc-ad-hoc-distribution in your project. Codex loads it when a task matches its description.

Can I use ASC Ad Hoc Distribution in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rorkai/app-store-connect-cli-skills --skill asc-ad-hoc-distribution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/asc-ad-hoc-distribution, .gemini/skills/asc-ad-hoc-distribution, .github/skills/asc-ad-hoc-distribution and .opencode/skills/asc-ad-hoc-distribution in your project.

What does ASC Ad Hoc Distribution need to run?

Going by SKILL.md and its folder, ASC Ad Hoc Distribution needs the command-line tools its instructions call (jq) and credentials named ASC_S3_ACCESS_KEY_ID, ASC_S3_SECRET_ACCESS_KEY and ASC_S3_SESSION_TOKEN. Our summary lists: The `asc` CLI with the `distribute` command; An iOS `.xcarchive` with one main app target; A PKCS#12 distribution identity and a protected devices file; App Store Connect authentication; An existing S3-compatible bucket and its credentials.

Does ASC Ad Hoc Distribution access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is ASC Ad Hoc Distribution safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does ASC Ad Hoc Distribution use?

ASC Ad Hoc Distribution is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does ASC Ad Hoc Distribution use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to ASC Ad Hoc Distribution?

Skills that share tags, products or a category with ASC Ad Hoc Distribution: Expo Deployment (kingstinct/react-native-healthkit, 716 stars), Release (movieclaw/MovieClaw, 160 stars), Odevio (Odevio/Odevio-CLI, 423 stars) and iOS App Store Submit (ZestfulPulse/ios-app-store-submit, 142 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains ASC Ad Hoc Distribution?

rorkai (a GitHub organization) maintains it in rorkai/app-store-connect-cli-skills, which has 1,064 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 5, 2026.

Source: rorkai/app-store-connect-cli-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.