Agent skill

Release

by signageos in signageos/vscode-sops

Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to…

MITAuto-check: notesDevelopment

Install Release

skills CLI
$ npx skills add signageos/vscode-sops --skill release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install signageos/vscode-sops release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/signageos/vscode-sops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/release .claude/skills/release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release
GitHub stars
122
Token cost
~2.2k tokens
SKILL.md length
713 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to…

  • Works in 8 steps: Determine Next Version → Update CHANGELOG.md → Bump Version in package.json and… → …
  • The user asks to release
  • SKILL.md covers When to Apply, Prerequisites, Workflow and Error Handling Reference, plus 1 more section
  • Calls git, npm and npx; reaches registry.npmjs.org and dev.azure.com; needs OVSX_TOKEN and GH_TOKEN

What it does

Release is an agent skill from signageos/vscode-sops. Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to VS Code Marketplace (vsce) and Open VSX Registry (ovsx), tags and pushes the release commit, and creates a GitHub Release with a changelog. Handles token expiration with re-generation guidance and stops on any build or type error, showing issues and suggestions before asking to continue. Use when the user asks to…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Operations and SOPs and Changelog and release notes. It works with Visual Studio Code, npm and GitHub. The licence is MIT.

When your agent uses it

  • The user asks to release
  • Bump and publish the extension

Example prompts

  • “release”
  • “publish”
  • “bump and publish”
  • “/release”

Requirements

  • Node.js
  • A credential in GITHUB_TOKEN
  • A credential in OVSX_TOKEN

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Determine Next Version
  2. Update CHANGELOG.md
  3. Bump Version in package.json and package-lock.json
  4. Build — vscode:prepublish
  5. Publish to VS Code Marketplace — vsce publish
  6. Publish to Open VSX Registry — ovsx:publish
  7. Commit, Tag, and Push
  8. Create GitHub Release

What it can do on your machine

Read from SKILL.md and the folder at commit 36dda63. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • npx
    • gh
    • make
    • curl
    • nvm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org
    • dev.azure.com
    • open-vsx.org
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OVSX_TOKEN
    • GH_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release loads about 2.2k tokens when it runs. Until then it costs about 145 tokens; SKILL.md has 713 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~145
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:25
    ps` CLI is available (needed to decrypt `.env` for OVSX token)
  • NoteMentions a .env fileSKILL.md:30
    GH_TOKEN` from `~/dev/signageos/projects/.env.secrets`)
  • NoteMentions a .env fileSKILL.md:31
    n available in `~/dev/signageos/projects/.env.secrets` as `GITHUB_TOKEN`
  • NoteMentions a .env fileSKILL.md:151
    pt (`tools/ovsx-publish.bash`) decrypts `.env` with `sops`, sources it, and runs `npx ovsx publish -p $OVSX_TOKEN`.
  • NoteMentions a .env fileSKILL.md:156
    sops -d .env > .decrypted~.env
  • NoteMentions a .env fileSKILL.md:174
    e the OVSX_TOKEN value in the encrypted `.env` file:
  • NoteMentions a .env fileSKILL.md:175
    - Decrypt: sops -d .env > .decrypted~.env
  • NoteMentions a .env fileSKILL.md:177
    - Re-encrypt: sops -e .decrypted~.env > .env
  • NoteMentions a .env fileSKILL.md:179
    - Commit the updated .env: git add .env && git commit -m "chore: rotate OVSX token"
  • NoteMentions a .env fileSKILL.md:208
    ep GITHUB_TOKEN ~/dev/signageos/projects/.env.secrets | cut -d= -f2)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from signageos/vscode-sops at commit 36dda63, republished under its MIT licence (© signageos). 713 words, ~2,159 tokens.

Download SKILL.mdSave it as .claude/skills/release/SKILL.md (or your agent's skills folder).
name
release
description
Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via `vscode:prepublish`, publishes to VS Code Marketplace (vsce) and Open VSX Registry (ovsx), tags and pushes the release commit, and creates a GitHub Release with a changelog. Handles token expiration with re-generation guidance and stops on any build or type error, showing issues and suggestions before asking to continue. Use when the user asks to "release", "publish", or "bump and publish" the extension.

Skill: Release vscode-sops Extension

Bumps the version, builds, publishes to VS Code Marketplace and Open VSX, then creates a GitHub Release.

When to Apply

  • "release", "publish", "bump and publish", "ship the extension"
  • NOT applicable for pre-release/beta builds or individual CI steps

Prerequisites

  • Working directory is the vscode-sops repository root
  • master branch is clean (no uncommitted changes)
  • sops CLI is available (needed to decrypt .env for OVSX token)
  • vsce CLI available (npx vsce from node_modules)
  • npx ovsx available
  • Node.js available via nvm (use nvm use 22 or latest LTS)
  • Node.js dependencies installed (npm install — use --registry https://registry.npmjs.org if the private CodeArtifact registry token is expired)
  • gh CLI for creating GitHub Release (install locally if needed; authenticate with GH_TOKEN from ~/dev/signageos/projects/.env.secrets)
  • GitHub token available in ~/dev/signageos/projects/.env.secrets as GITHUB_TOKEN

Workflow

Step 1: Determine Next Version
  1. Read current version from package.json (field "version").
  2. Check recent bump commits to understand the versioning pattern:
    bash
    git --no-pager log --oneline --grep="^Bump" -10
    Historical pattern: 0.9.1 → 0.9.2 → 0.9.3 — patch bump is the default.
  3. Compute next patch version: X.Y.Z → X.Y.(Z+1).
  4. Confirm with the user before proceeding:
    • Show current version and proposed next version.
    • Ask whether to use patch / minor / major if context suggests otherwise.

Step 2: Update CHANGELOG.md
  1. Open CHANGELOG.md.
  2. Rename the ## [Unreleased] section header to ## [X.Y.Z] (the new version).
  3. Insert a fresh empty ## [Unreleased] section above it.
  4. If [Unreleased] is empty, stop and ask the user what to put in the release notes before continuing.

Example before:

markdown
## [Unreleased]
### Fixed
- Support for files parsed as `null`

## [0.9.3]

Example after:

markdown
## [Unreleased]

## [0.9.4]
### Fixed
- Support for files parsed as `null`

## [0.9.3]

Step 3: Bump Version in package.json and package-lock.json

Update the "version" field in both files from the old version to the new version:

bash
npm version X.Y.Z --no-git-tag-version

This updates package.json and package-lock.json atomically without creating a git tag yet.


Step 4: Build — vscode:prepublish
bash
npm run vscode:prepublish

On failure — STOP immediately. Show:

  • The full compiler/linter output.
  • Likely cause (TypeScript error, import error, lint rule).
  • Suggestion to fix (e.g., "Run npm run lint to see all lint issues", or show the TS error with file/line).
  • Ask the user to fix the issue and then re-run this skill (or confirm to retry after they fix it).

Do not proceed to publishing if the build fails.


Step 5: Publish to VS Code Marketplace — vsce publish
bash
npx vsce publish
Token expiration handling

If the command fails with an error like Failed to publish: 401 Unauthorized, The Personal Access Token used has expired, or similar auth error:

  1. Stop and display this guidance:
⚠️  VS Code Marketplace token has expired or is invalid.

To regenerate:
1. Go to: https://dev.azure.com/signageos/_usersSettings/tokens
   (Make sure you are signed in under a user that has access to the signageos organization)
2. Create a new token with:
   - Organization: All accessible organizations (or "signageos")
   - Scopes: Click "Show all scopes", then enable Marketplace → Manage (not just Read)
   - Expiration: up to 1 year
3. Copy the token.
4. Run: npx vsce login signageos
   (Enter the new token when prompted — it is stored in ~/.vsce)

After completing the above, respond with "continue" or "done" to resume.
  1. Wait for the user to confirm they have re-authenticated.
  2. Retry npx vsce publish.
Other publish failures
  • Show full output.
  • Suggest fix based on error message (missing README, invalid manifest, etc.).
  • Stop and wait for confirmation before retrying.

Show full SKILL.md (293 more words)Show less
Step 6: Publish to Open VSX Registry — ovsx:publish

The script (tools/ovsx-publish.bash) decrypts .env with sops, sources it, and runs npx ovsx publish -p $OVSX_TOKEN.

Note: If npm run ovsx:publish fails because npx ovsx tries to install from the private CodeArtifact registry and gets a 401, run the publish manually with the public registry:

bash
sops -d .env > .decrypted~.env
source .decrypted~.env
npx --registry https://registry.npmjs.org ovsx publish -p $OVSX_TOKEN
rm -f .decrypted~.env
Token expiration handling

If the command fails with Unauthorized, invalid_token, 401, or similar:

  1. Stop and display this guidance:
⚠️  Open VSX token has expired or is invalid.

To regenerate:
1. Go to: https://open-vsx.org → Log in → User Settings → Access Tokens
2. Generate a new token and copy it.
3. Update the OVSX_TOKEN value in the encrypted `.env` file:
   - Decrypt: sops -d .env > .decrypted~.env
   - Edit .decrypted~.env and set OVSX_TOKEN=<new-token>
   - Re-encrypt: sops -e .decrypted~.env > .env
   - Remove plaintext: rm .decrypted~.env
   - Commit the updated .env: git add .env && git commit -m "chore: rotate OVSX token"

After completing the above, respond with "continue" or "done" to resume.
  1. Wait for the user to confirm they have updated the token.
  2. Retry npm run ovsx:publish.

Step 7: Commit, Tag, and Push
bash
git add package.json package-lock.json CHANGELOG.md
git commit -m "Bump X.Y.Z"
git tag -a "vX.Y.Z" -m "Release vX.Y.Z"
git push github master
git push github "vX.Y.Z"

Note: The primary remote for GitHub is github (not origin, which points to GitLab). Check with git remote -v if unsure.


Step 8: Create GitHub Release
  1. Extract the new version's changelog section from CHANGELOG.md (everything between ## [X.Y.Z] and the next ## [ heading).
  2. Load the GitHub token:
    bash
    export GH_TOKEN=$(grep GITHUB_TOKEN ~/dev/signageos/projects/.env.secrets | cut -d= -f2)
  3. Create the release via gh CLI:
bash
gh release create "vX.Y.Z" \
  --repo signageos/vscode-sops \
  --title "vX.Y.Z" \
  --notes "<changelog content>"

Note: If gh CLI is not installed, download it to /tmp:

bash
curl -sL https://github.com/cli/cli/releases/latest/download/gh_*_linux_amd64.tar.gz -o /tmp/gh.tar.gz
tar xzf /tmp/gh.tar.gz -C /tmp
export PATH="/tmp/gh_*_linux_amd64/bin:$PATH"

Release body format — mirror existing releases (e.g. v0.9.3):

  • Use the changelog section as-is (Markdown headings like ### Fixed, ### Added, etc.).
  • Keep it concise and readable.

Example:

markdown
### Fixed
- Support for files parsed as `null`

Error Handling Reference

ErrorAction
TypeScript compile errorStop, show error + file/line, suggest fix, wait
ESLint / lint errorStop, show rule + file, suggest npm run lint, wait
vsce publish 401 / token expiredShow Azure DevOps PAT regeneration steps, wait
ovsx publish 401 / token expiredShow Open VSX token rotation steps (sops), wait
git push rejectedStop, show reason (e.g., non-fast-forward), suggest git pull --rebase, wait
gh release create failsStop, show error, suggest verifying gh auth status, wait
Any other unexpected errorStop, show full output, state likely cause and suggestion, wait for user

Output Summary

After successful completion, report:

✅ Released vscode-sops vX.Y.Z

- CHANGELOG.md updated
- package.json / package-lock.json bumped
- Built with vscode:prepublish
- Published to VS Code Marketplace (signageos.signageos-vscode-sops)
- Published to Open VSX Registry
- Git tag: vX.Y.Z pushed
- GitHub Release: https://github.com/signageos/vscode-sops/releases/tag/vX.Y.Z

© signageos, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/release of signageos/vscode-sops.

Open the folder on GitHubat commit 36dda63

Compare with similar skills

Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release this skillsignageos/vscode-sops122—~2.2kAutomated safety check: NotesMIT
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Version ReleaseNG-ZORRO/ng-zorro-antd9.2k—~3.1kAutomated safety check: PassMIT
Hunk Release Workflowmodem-dev/hunk9.5k—~3.8kAutomated safety check: PassMIT
Release Roundethereumjs/ethereumjs-monorepo2.8k—~2kAutomated safety check: PassNone

Similar skills

  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Version Release

    NG-ZORRO/ng-zorro-antd

    NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.

    9.2k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.5k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release Round

    ethereumjs/ethereumjs-monorepo

    Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.

    2.8k GitHub stars~2k tokensUpdated 20 days ago
    DevelopmentAuto-check passed
  • Ccb GitHub

    SeemSeam/claude_codex_bridge

    Maintain this CCB project's GitHub-facing release and npm publication surface.

    3.6k GitHub stars~4.9k tokensUpdated today
    DevelopmentAuto-check passed

Questions about Release

What does Release do?

Releases the vscode-sops extension end-to-end: determines the next version from the bump history, updates CHANGELOG.md and package.json/package-lock.json, builds via vscode:prepublish, publishes to…. Release is an agent skill from signageos/vscode-sops.json, builds via vscode:prepublish, publishes to VS Code Marketplace (vsce) and Open VSX Registry (ovsx), tags and pushes the release commit, and creates a GitHub Release with a changelog.

When should I use Release?

Release fits situations like: the user asks to release; bump and publish the extension.

How do I install Release in Claude Code?

Run `npx skills add signageos/vscode-sops --skill release -a claude-code`. Or copy the skill folder (.github/skills/release in signageos/vscode-sops) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.

How do I install Release in Codex?

Run `npx skills add signageos/vscode-sops --skill release -a codex`. Or copy the skill folder (.github/skills/release in signageos/vscode-sops) into .agents/skills/release in your project. Codex loads it when a task matches its description.

Can I use Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add signageos/vscode-sops --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.

What does Release need to run?

Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (git, npm, npx, gh, make and curl) and credentials named OVSX_TOKEN, GH_TOKEN and GITHUB_TOKEN. Our summary lists: Node.js; A credential in GITHUB_TOKEN; A credential in OVSX_TOKEN.

Does Release access the network?

SKILL.md names 4 domains. In commands or code: registry.npmjs.org, dev.azure.com, open-vsx.org and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Release safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Release use?

Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release?

Skills that share tags, products or a category with Release: Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Version Release (NG-ZORRO/ng-zorro-antd, 9.2k stars) and Hunk Release Workflow (modem-dev/hunk, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release?

signageos (a GitHub organization) maintains it in signageos/vscode-sops, which has 122 GitHub stars. The repository was last updated on April 6, 2026.

Source: signageos/vscode-sops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.