Cutting A Release
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to…
$ npx skills add signageos/vscode-sops --skill release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install signageos/vscode-sops release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/signageos/vscode-sops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/release .claude/skills/release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release" agent skill from https://github.com/signageos/vscode-sops/tree/master/.github/skills/release into .claude/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/signageos/vscode-sops/tree/master/.github/skills/releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add signageos/vscode-sops --skill release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install signageos/vscode-sops release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/signageos/vscode-sops.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/release .agents/skills/release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release" agent skill from https://github.com/signageos/vscode-sops/tree/master/.github/skills/release into .agents/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add signageos/vscode-sops --skill release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install signageos/vscode-sops release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/signageos/vscode-sops.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/release .cursor/skills/release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release" agent skill from https://github.com/signageos/vscode-sops/tree/master/.github/skills/release into .cursor/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/signageos/vscode-sops.git --path .github/skills/release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add signageos/vscode-sops --skill release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install signageos/vscode-sops release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/signageos/vscode-sops.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/release .gemini/skills/release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/signageos/vscode-sops/tree/master/.github/skills/release into .gemini/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install signageos/vscode-sops releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add signageos/vscode-sops --skill release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/signageos/vscode-sops.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/release .github/skills/release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/signageos/vscode-sops/tree/master/.github/skills/release into .github/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add signageos/vscode-sops --skill release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install signageos/vscode-sops release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/signageos/vscode-sops.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/release .opencode/skills/release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/signageos/vscode-sops/tree/master/.github/skills/release into .opencode/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
releaseReleases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to…
Release is an agent skill from signageos/vscode-sops. Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to VS Code Marketplace (vsce) and Open VSX Registry (ovsx), tags and pushes the release commit, and creates a GitHub Release with a changelog. Handles token expiration with re-generation guidance and stops on any build or type error, showing issues and suggestions before asking to continue. Use when the user asks to…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Operations and SOPs and Changelog and release notes. It works with Visual Studio Code, npm and GitHub. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 36dda63. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmnpxghmakecurlnvmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
registry.npmjs.orgdev.azure.comopen-vsx.orggithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OVSX_TOKENGH_TOKENGITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Release loads about 2.2k tokens when it runs. Until then it costs about 145 tokens; SKILL.md has 713 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ps` CLI is available (needed to decrypt `.env` for OVSX token)GH_TOKEN` from `~/dev/signageos/projects/.env.secrets`)n available in `~/dev/signageos/projects/.env.secrets` as `GITHUB_TOKEN`pt (`tools/ovsx-publish.bash`) decrypts `.env` with `sops`, sources it, and runs `npx ovsx publish -p $OVSX_TOKEN`.sops -d .env > .decrypted~.enve the OVSX_TOKEN value in the encrypted `.env` file:- Decrypt: sops -d .env > .decrypted~.env- Re-encrypt: sops -e .decrypted~.env > .env- Commit the updated .env: git add .env && git commit -m "chore: rotate OVSX token"ep GITHUB_TOKEN ~/dev/signageos/projects/.env.secrets | cut -d= -f2)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from signageos/vscode-sops at commit 36dda63, republished under its MIT licence (© signageos). 713 words, ~2,159 tokens.
.claude/skills/release/SKILL.md (or your agent's skills folder).Bumps the version, builds, publishes to VS Code Marketplace and Open VSX, then creates a GitHub Release.
vscode-sops repository rootmaster branch is clean (no uncommitted changes)sops CLI is available (needed to decrypt .env for OVSX token)vsce CLI available (npx vsce from node_modules)npx ovsx availablenvm use 22 or latest LTS)npm install — use --registry https://registry.npmjs.org if the private CodeArtifact registry token is expired)gh CLI for creating GitHub Release (install locally if needed; authenticate with GH_TOKEN from ~/dev/signageos/projects/.env.secrets)~/dev/signageos/projects/.env.secrets as GITHUB_TOKENpackage.json (field "version").git --no-pager log --oneline --grep="^Bump" -100.9.1 → 0.9.2 → 0.9.3 — patch bump is the default.X.Y.Z → X.Y.(Z+1).CHANGELOG.md.## [Unreleased] section header to ## [X.Y.Z] (the new version).## [Unreleased] section above it.[Unreleased] is empty, stop and ask the user what to put in the release notes before continuing.Example before:
## [Unreleased]
### Fixed
- Support for files parsed as `null`
## [0.9.3]Example after:
## [Unreleased]
## [0.9.4]
### Fixed
- Support for files parsed as `null`
## [0.9.3]Update the "version" field in both files from the old version to the new version:
npm version X.Y.Z --no-git-tag-versionThis updates package.json and package-lock.json atomically without creating a git tag yet.
vscode:prepublishnpm run vscode:prepublishOn failure — STOP immediately. Show:
npm run lint to see all lint issues", or show the TS error with file/line).Do not proceed to publishing if the build fails.
vsce publishnpx vsce publishIf the command fails with an error like Failed to publish: 401 Unauthorized, The Personal Access Token used has expired, or similar auth error:
⚠️ VS Code Marketplace token has expired or is invalid.
To regenerate:
1. Go to: https://dev.azure.com/signageos/_usersSettings/tokens
(Make sure you are signed in under a user that has access to the signageos organization)
2. Create a new token with:
- Organization: All accessible organizations (or "signageos")
- Scopes: Click "Show all scopes", then enable Marketplace → Manage (not just Read)
- Expiration: up to 1 year
3. Copy the token.
4. Run: npx vsce login signageos
(Enter the new token when prompted — it is stored in ~/.vsce)
After completing the above, respond with "continue" or "done" to resume.npx vsce publish.ovsx:publishThe script (tools/ovsx-publish.bash) decrypts .env with sops, sources it, and runs npx ovsx publish -p $OVSX_TOKEN.
Note: If npm run ovsx:publish fails because npx ovsx tries to install from the private CodeArtifact registry and gets a 401, run the publish manually with the public registry:
sops -d .env > .decrypted~.env
source .decrypted~.env
npx --registry https://registry.npmjs.org ovsx publish -p $OVSX_TOKEN
rm -f .decrypted~.envIf the command fails with Unauthorized, invalid_token, 401, or similar:
⚠️ Open VSX token has expired or is invalid.
To regenerate:
1. Go to: https://open-vsx.org → Log in → User Settings → Access Tokens
2. Generate a new token and copy it.
3. Update the OVSX_TOKEN value in the encrypted `.env` file:
- Decrypt: sops -d .env > .decrypted~.env
- Edit .decrypted~.env and set OVSX_TOKEN=<new-token>
- Re-encrypt: sops -e .decrypted~.env > .env
- Remove plaintext: rm .decrypted~.env
- Commit the updated .env: git add .env && git commit -m "chore: rotate OVSX token"
After completing the above, respond with "continue" or "done" to resume.npm run ovsx:publish.git add package.json package-lock.json CHANGELOG.md
git commit -m "Bump X.Y.Z"
git tag -a "vX.Y.Z" -m "Release vX.Y.Z"
git push github master
git push github "vX.Y.Z"Note: The primary remote for GitHub is github (not origin, which points to GitLab). Check with git remote -v if unsure.
CHANGELOG.md (everything between ## [X.Y.Z] and the next ## [ heading).export GH_TOKEN=$(grep GITHUB_TOKEN ~/dev/signageos/projects/.env.secrets | cut -d= -f2)gh CLI:gh release create "vX.Y.Z" \
--repo signageos/vscode-sops \
--title "vX.Y.Z" \
--notes "<changelog content>"Note: If gh CLI is not installed, download it to /tmp:
curl -sL https://github.com/cli/cli/releases/latest/download/gh_*_linux_amd64.tar.gz -o /tmp/gh.tar.gz
tar xzf /tmp/gh.tar.gz -C /tmp
export PATH="/tmp/gh_*_linux_amd64/bin:$PATH"Release body format — mirror existing releases (e.g. v0.9.3):
### Fixed, ### Added, etc.).Example:
### Fixed
- Support for files parsed as `null`| Error | Action |
|---|---|
| TypeScript compile error | Stop, show error + file/line, suggest fix, wait |
| ESLint / lint error | Stop, show rule + file, suggest npm run lint, wait |
vsce publish 401 / token expired | Show Azure DevOps PAT regeneration steps, wait |
ovsx publish 401 / token expired | Show Open VSX token rotation steps (sops), wait |
git push rejected | Stop, show reason (e.g., non-fast-forward), suggest git pull --rebase, wait |
gh release create fails | Stop, show error, suggest verifying gh auth status, wait |
| Any other unexpected error | Stop, show full output, state likely cause and suggestion, wait for user |
After successful completion, report:
✅ Released vscode-sops vX.Y.Z
- CHANGELOG.md updated
- package.json / package-lock.json bumped
- Built with vscode:prepublish
- Published to VS Code Marketplace (signageos.signageos-vscode-sops)
- Published to Open VSX Registry
- Git tag: vX.Y.Z pushed
- GitHub Release: https://github.com/signageos/vscode-sops/releases/tag/vX.Y.Z© signageos, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/release of signageos/vscode-sops.
Open the folder on GitHubat commit 36dda63
Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Release this skillsignageos/vscode-sops | 122 | — | ~2.2k | Automated safety check: Notes | MIT | |
| Cutting A ReleaseTriliumNext/Trilium | 38k | — | ~3.2k | Automated safety check: Pass | AGPL-3.0 | |
| Verdaccio Pull Request Workflowverdaccio/verdaccio | 18k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Version ReleaseNG-ZORRO/ng-zorro-antd | 9.2k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Hunk Release Workflowmodem-dev/hunk | 9.5k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Release Roundethereumjs/ethereumjs-monorepo | 2.8k | — | ~2k | Automated safety check: Pass | None |
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
NG-ZORRO/ng-zorro-antd
NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.
modem-dev/hunk
Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.
ethereumjs/ethereumjs-monorepo
Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.
SeemSeam/claude_codex_bridge
Maintain this CCB project's GitHub-facing release and npm publication surface.
Works with
Categories
Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to…. Release is an agent skill from signageos/vscode-sops.json, builds via vscode:prepublish, publishes to VS Code Marketplace (vsce) and Open VSX Registry (ovsx), tags and pushes the release commit, and creates a GitHub Release with a changelog.
Release fits situations like: the user asks to release; bump and publish the extension.
Run `npx skills add signageos/vscode-sops --skill release -a claude-code`. Or copy the skill folder (.github/skills/release in signageos/vscode-sops) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add signageos/vscode-sops --skill release -a codex`. Or copy the skill folder (.github/skills/release in signageos/vscode-sops) into .agents/skills/release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add signageos/vscode-sops --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.
Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (git, npm, npx, gh, make and curl) and credentials named OVSX_TOKEN, GH_TOKEN and GITHUB_TOKEN. Our summary lists: Node.js; A credential in GITHUB_TOKEN; A credential in OVSX_TOKEN.
SKILL.md names 4 domains. In commands or code: registry.npmjs.org, dev.azure.com, open-vsx.org and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Release: Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Version Release (NG-ZORRO/ng-zorro-antd, 9.2k stars) and Hunk Release Workflow (modem-dev/hunk, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
signageos (a GitHub organization) maintains it in signageos/vscode-sops, which has 122 GitHub stars. The repository was last updated on April 6, 2026.
Source: signageos/vscode-sops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.