Agent skill

Deploy To Maven Central

by spotify in spotify/android-auth

Deploys the library to OSSRH staging and creates a pre-release, but publishing must be done manually via the Sonatype web UI.

Apache-2.0Auto-check: notesFrontend & Design

Install Deploy To Maven Central

skills CLI
$ npx skills add spotify/android-auth --skill deploy-to-maven-central -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spotify/android-auth deploy-to-maven-central --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spotify/android-auth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/deploy-to-maven-central .claude/skills/deploy-to-maven-central && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploy-to-maven-central
GitHub stars
151
Token cost
~717 tokens
SKILL.md length
271 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys the library to OSSRH staging and creates a pre-release, but publishing must be done manually via the Sonatype web UI.

  • Works in 8 steps: Validate local.properties → Publish the auth flavour → Publish the store flavour → …
  • Tasks that involve Frontend development
  • Calls curl; reaches ossrh-staging-api.central.sonatype.com; needs REPO_KEY

What it does

Deploy To Maven Central is an agent skill from spotify/android-auth. Deploys the library to OSSRH staging and creates a pre-release, but publishing must be done manually via the Sonatype web UI.

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Frontend & Design, covering Frontend development. It works with Spotify and Android. The repository describes itself as: Spotify authentication and authorization for Android. Part of the Spotify Android SDK. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Frontend development

Example prompts

  • “Use the deploy-to-maven-central skill to deploy the library to OSSRH staging and creates a pre-release, but publishing must be done manually via the…”
  • “/deploy-to-maven-central”

Requirements

  • A credential in REPO_KEY
  • Pre-approved tools (allowed-tools): Bash(*)

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Validate local.properties
  2. Publish the auth flavour
  3. Publish the store flavour
  4. Generate a base64 auth token
  5. Fetch the staging repository list
  6. Extract the repository key
  7. Upload the repository
  8. Report result

What it can do on your machine

Read from SKILL.md and the folder at commit eef9af9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ossrh-staging-api.central.sonatype.com

    Also links to:

    • central.sonatype.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • REPO_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploy To Maven Central loads about 717 tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 271 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~717

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash(*)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spotify/android-auth at commit eef9af9, republished under its Apache-2.0 licence (© spotify). 271 words, ~717 tokens.

Download SKILL.mdSave it as .claude/skills/deploy-to-maven-central/SKILL.md (or your agent's skills folder).
name
deploy-to-maven-central
description
Deploys the library to OSSRH staging and creates a pre-release, but publishing must be done manually via the Sonatype web UI.
allowed-tools
Bash(*)
disable-model-invocation
true

Deploy to Maven Central (OSSRH Staging)

Deploy both auth and store flavours of the Android auth library to the OSSRH staging repository, then upload the staged deployment for publishing.

Steps

1. Validate local.properties

Check that the file local.properties in the project root exists and contains all of the following keys:

  • signing.keyId
  • signing.password
  • signing.secretKeyRingFile
  • ossrhUsername
  • ossrhPassword

If the file is missing or any key is absent, stop and tell the user:

local.properties must contain the following properties:

signing.keyId=<gpg signing key>
signing.password=<gpg signing password>
signing.secretKeyRingFile=<gpg keyring>
ossrhUsername=<ossrhUsername>
ossrhPassword=<ossrhPassword>

Extract the values of ossrhUsername and ossrhPassword from local.properties for use in later steps. Store them in shell variables OSSRH_USER and OSSRH_PASS.

2. Publish the auth flavour

Run Gradle to assemble and publish the auth (regular) flavour:

bash
./gradlew :auth-lib:assembleRelease :auth-lib:publishAuthReleasePublicationToOssrh-staging-apiRepository

Wait for this to succeed before continuing.

3. Publish the store flavour

Run Gradle to assemble and publish the store flavour:

bash
./gradlew :auth-lib:assembleRelease :auth-lib:publishStoreReleasePublicationToOssrh-staging-apiRepository

Wait for this to succeed before continuing.

4. Generate a base64 auth token

Compute a base64-encoded token from the credentials for the OSSRH staging API:

bash
TOKEN=$(printf "$OSSRH_USER:$OSSRH_PASS" | base64)
5. Fetch the staging repository list

Call the OSSRH staging API to get the list of repositories:

bash
curl -s --fail \
  -H "Authorization: Bearer $TOKEN" \
  https://ossrh-staging-api.central.sonatype.com/manual/search/repositories
6. Extract the repository key

Parse the JSON response to extract the repository key. It is the key field of the first (or only) entry in the repositories array. Save this as REPO_KEY.

7. Upload the repository

POST to the upload endpoint to promote the staged repository:

bash
curl -s --fail -X POST \
  -H "Authorization: Bearer $TOKEN" \
  "https://ossrh-staging-api.central.sonatype.com/manual/upload/repository/$REPO_KEY"
8. Report result

If all steps succeeded, tell the user:

Deployment uploaded successfully. To complete publishing, log in to the Sonatype OSSRH portal and manually release the staged repository.

If any step failed, report the error and stop.

© spotify, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/deploy-to-maven-central of spotify/android-auth.

Open the folder on GitHubat commit eef9af9

Compare with similar skills

Deploy To Maven Central next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploy To Maven Central compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploy To Maven Central this skillspotify/android-auth151—~717Automated safety check: NotesApache-2.0
Android UI AutomationOpenMinis/MinisSkills444—~1.6kAutomated safety check: PassMIT
AndroidCodename-11/hermes-relay318—~4.9kAutomated safety check: PassMIT
React Router Developmentremix-run/react-router57k1 repos~1.5kAutomated safety check: PassMIT
React UI State PatternsChrisWiles/claude-code-showcase6.1k8 repos~1.6kAutomated safety check: PassNone
GSAP in Vue, Nuxt and Sveltegreensock/gsap-skills16k4 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Android UI Automation

    OpenMinis/MinisSkills

    Automate Android apps that have no public API or web version by driving the UI layer through the Accessibility Service.

    444 GitHub stars~1.6k tokensUpdated yesterday
    MobileAuto-check passed
  • Android

    Codename-11/hermes-relay

    Control an Android phone via Hermes-Relay — navigate apps, tap, type, swipe, and drive Uber, WhatsApp, Spotify, Maps, Settings, and more

    318 GitHub stars~4.9k tokensUpdated today
    MobileAuto-check passed
  • React Router Development

    remix-run/react-router

    Guides work on React Router apps by first identifying whether the app uses Framework, Data or Declarative mode, then loading the matching reference and the installed package docs.

    57k GitHub starsUsed in 1 repo~1.5k tokens
    Frontend & DesignAuto-check passed
  • React UI State Patterns

    ChrisWiles/claude-code-showcase

    Sets patterns for React interfaces: when to show loading spinners or skeletons, how to surface errors, how to disable buttons during async work and how to handle empty lists.

    6.1k GitHub starsUsed in 8 repos~1.6k tokens
    Frontend & DesignAuto-check passed
  • GSAP in Vue, Nuxt and Svelte

    greensock/gsap-skills

    Shows how to use GSAP in Vue, Nuxt, Svelte and other lifecycle-based frameworks: create after mount, scope selectors to the component, and revert on unmount.

    16k GitHub starsUsed in 4 repos~2.6k tokens
    Frontend & DesignAuto-check passed
  • Rules for writing idiomatic Svelte 5 code: when to reach for runes like state, derived and effect, and how to handle props, attachments and bindings.

    2.9k GitHub starsUsed in 4 repos~1.8k tokens
    Frontend & DesignAuto-check passed

Works with

Questions about Deploy To Maven Central

What does Deploy To Maven Central do?

Deploys the library to OSSRH staging and creates a pre-release, but publishing must be done manually via the Sonatype web UI. Deploy To Maven Central is an agent skill from spotify/android-auth. Deploys the library to OSSRH staging and creates a pre-release, but publishing must be done manually via the Sonatype web UI.

When should I use Deploy To Maven Central?

Deploy To Maven Central fits situations like: tasks that involve Frontend development.

How do I install Deploy To Maven Central in Claude Code?

Run `npx skills add spotify/android-auth --skill deploy-to-maven-central -a claude-code`. Or copy the skill folder (.claude/skills/deploy-to-maven-central in spotify/android-auth) into .claude/skills/deploy-to-maven-central in your project. Claude Code loads it when a task matches its description.

How do I install Deploy To Maven Central in Codex?

Run `npx skills add spotify/android-auth --skill deploy-to-maven-central -a codex`. Or copy the skill folder (.claude/skills/deploy-to-maven-central in spotify/android-auth) into .agents/skills/deploy-to-maven-central in your project. Codex loads it when a task matches its description.

Can I use Deploy To Maven Central in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spotify/android-auth --skill deploy-to-maven-central -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploy-to-maven-central, .gemini/skills/deploy-to-maven-central, .github/skills/deploy-to-maven-central and .opencode/skills/deploy-to-maven-central in your project.

What does Deploy To Maven Central need to run?

Going by SKILL.md and its folder, Deploy To Maven Central needs the command-line tools its instructions call (curl) and credentials named REPO_KEY. Our summary lists: A credential in REPO_KEY. Its frontmatter pre-approves these tools: Bash(*).

Does Deploy To Maven Central access the network?

SKILL.md names 2 domains. In commands or code: ossrh-staging-api.central.sonatype.com; the agent is likely to contact it when it follows the instructions. As links in the text: central.sonatype.com. This is read from the text; nothing was executed.

Is Deploy To Maven Central safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Deploy To Maven Central use?

Deploy To Maven Central is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploy To Maven Central use?

About 717 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deploy To Maven Central?

Skills that share tags, products or a category with Deploy To Maven Central: Android UI Automation (OpenMinis/MinisSkills, 444 stars), Android (Codename-11/hermes-relay, 318 stars), React Router Development (remix-run/react-router, 57k stars) and React UI State Patterns (ChrisWiles/claude-code-showcase, 6.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploy To Maven Central?

spotify (a GitHub organization) maintains it in spotify/android-auth, which has 151 GitHub stars. The repository was last updated on July 10, 2026.

Source: spotify/android-auth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.