Publish UI Package Release
cline/cline
Validates and publishes the standalone @cline/ui npm package through its own release workflow, separate from the Cline SDK runtime packages.
Handles npm registry tasks such as whoami checks, package name availability, name reservation and publishing, with credentials pulled from 1Password.
$ npx skills add steipete/agent-scripts --skill npm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install steipete/agent-scripts npm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/npm .claude/skills/npm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "npm" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/npm into .claude/skills/npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/steipete/agent-scripts/tree/main/skills/npmType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add steipete/agent-scripts --skill npm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install steipete/agent-scripts npm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/npm .agents/skills/npm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "npm" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/npm into .agents/skills/npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add steipete/agent-scripts --skill npm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install steipete/agent-scripts npm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/npm .cursor/skills/npm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "npm" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/npm into .cursor/skills/npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/steipete/agent-scripts.git --path skills/npm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add steipete/agent-scripts --skill npm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install steipete/agent-scripts npm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/npm .gemini/skills/npm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "npm" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/npm into .gemini/skills/npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install steipete/agent-scripts npmInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add steipete/agent-scripts --skill npm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/npm .github/skills/npm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "npm" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/npm into .github/skills/npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add steipete/agent-scripts --skill npm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install steipete/agent-scripts npm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/npm .opencode/skills/npm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "npm" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/npm into .opencode/skills/npm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "npm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
npmHandles npm registry tasks such as whoami checks, package name availability, name reservation and publishing, with credentials pulled from 1Password.
The skill covers account and registry work: checking who is logged in, seeing whether a package name is free, reserving names, publishing, checking organizations and debugging authentication. It ships shell and Node helpers, including npm-auth.sh, npm-auth-login.mjs, npm-service.sh for ad-hoc authenticated npm commands, publish-package.sh for a local package and reserve-packages.sh.
Credentials come from 1Password, and the agent is told never to run op directly in the shell tool. A stored registry session is tried first, with a registry login using a fresh one-time code as the fallback, and successful fallback sessions are cached back to the same item. Work happens in a shared tmux window with a temporary npmrc that is deleted afterward. The agent stops and asks if the item is missing, the vault is ambiguous or npm denies access.
The excerpt names a specific 1Password item and vault belonging to the author, so you would point it at your own item. It also relies on a separate one-password skill for secret handling.
Read from SKILL.md and the folder at commit 79150cf. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 10 files in scripts/ (JavaScript and Shell), which the agent can run.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OP_SERVICE_ACCOUNT_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
npm Registry Operations loads about 1.1k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 532 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from steipete/agent-scripts at commit 79150cf, republished under its MIT licence (© steipete). 532 words, ~1,132 tokens.
.claude/skills/npm/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.Use for npm registry/account tasks: npm whoami, package availability, package reservation, publish, org checks, and auth debugging.
one-password first for secret rules.op directly in the shell tool.npm Registry - steipete - Release Automation in Molty.OP_SERVICE_ACCOUNT_TOKEN; no desktop unlock. The item carries the working registry session (registry_token) plus username/password/TOTP fallback.npmjs fallback is explicit only: pass --account my.1password.com when Molty is unavailable and the user wants the fallback. Explicit release/publish requests are consent for its unlock prompt.op-work tmux session (clawdbot-op.sock; see one-password). Reuse the window on failure; kill it when the npm task is done. Never mint an npm-specific socket or session.scripts/npm-auth.sh: stored registry_token session first, then scripts/npm-auth-login.mjs registry login with a fresh six-digit OTP; successful fallback sessions are cached back to the same item. Do not hand-roll field extraction, registry login, or cache writes.npm-auth.sh owns NPM_AUTH_SCRIPT_DIR without changing the caller's SCRIPT_DIR or working directory. Node helpers also support file symlinks, including --preserve-symlinks-main.id, then purpose, then a unique label; duplicate label-only matches are rejected (legacy npmjs may retain same-label fields).scripts/npm-service.sh -- <npm args...>; use publish-package.sh for a local package.printf ... | npm login --auth-type=legacy.expect for npm login unless necessary; logs can echo prompts and are easy to get wrong.npm-profile loginCouch) for automation.npm whoami fails, stop and ask for the exact field label / credential fix. Do not probe more 1Password items or open another tmux window/session.From the package root, inside the same auth tmux window:
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/publish-package.shThe helper verifies identity, refuses an existing package version, publishes with a fresh OTP, retries one expired OTP, verifies registry visibility, and cleans auth files.
Use scripts/reserve-packages.sh from inside the same tmux window:
/Users/steipete/Projects/agent-scripts/skills/npm/scripts/reserve-packages.sh package-one package-twoWhat it does:
op0.0.0 placeholder packages with a generic READMENotes:
npm login.npm view can lag/404 even when the package exists. Check npm access get status <pkg>; public or a publish failure saying previously published versions means the name is reserved.From the repo root; synthetic fixtures only, no real 1Password/npm auth. Always use an empty environment (the shell mock checks its environment for token leaks):
test_home="$(mktemp -d)"
(
set -e
trap 'rm -rf "$test_home"' EXIT
env -i HOME="$test_home" PATH="$PATH" node --test skills/npm/scripts/*.test.mjs </dev/null
env -i HOME="$test_home" PATH="$PATH" /bin/bash skills/npm/scripts/npm-auth.test.sh </dev/null
)© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (scripts) in skills/npm of steipete/agent-scripts.
Open the folder on GitHubat commit 79150cf
npm Registry Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| npm Registry Operations this skillsteipete/agent-scripts | 7.3k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Publish UI Package Releasecline/cline | 70k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Releasepaperclipai/paperclip | 99k | — | ~2.4k | Automated safety check: Pass | MIT | |
| ClickUp CLI Release Processkrodak/clickup-cli | 121 | — | ~906 | Automated safety check: Warn | MIT | |
| Azure Data FactoryMicrosoftDocs/Agent-Skills | 777 | 1 repos | ~16k | Automated safety check: Pass | CC-BY-4.0 | |
| Azure Data Science VmMicrosoftDocs/Agent-Skills | 777 | — | ~1.8k | Automated safety check: Pass | CC-BY-4.0 |
cline/cline
Validates and publishes the standalone @cline/ui npm package through its own release workflow, separate from the Cline SDK runtime packages.
paperclipai/paperclip
Coordinate a full Paperclip release across engineering verification, npm, GitHub, smoke testing, and announcement follow-up.
krodak/clickup-cli
Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure Data Factory development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations…
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure Data Science Virtual Machines development including troubleshooting, decision making, architecture & design patterns, security, configuration, integrations & coding…
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure DevTest Labs development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations…
steipete/agent-scripts
Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.
steipete/agent-scripts
Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.
steipete/agent-scripts
Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.
steipete/agent-scripts
Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.
steipete/agent-scripts
Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.
steipete/agent-scripts
Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.
Categories
Handles npm registry tasks such as whoami checks, package name availability, name reservation and publishing, with credentials pulled from 1Password. The skill covers account and registry work: checking who is logged in, seeing whether a package name is free, reserving names, publishing, checking organizations and debugging authentication.sh.
npm Registry Operations fits situations like: confirming which npm account the agent is logged in as; checking whether a package name is available, or reserving it; publishing a local package to the npm registry with stored credentials; debugging a failed npm login or denied package access.
Run `npx skills add steipete/agent-scripts --skill npm -a claude-code`. Or copy the skill folder (skills/npm in steipete/agent-scripts) into .claude/skills/npm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add steipete/agent-scripts --skill npm -a codex`. Or copy the skill folder (skills/npm in steipete/agent-scripts) into .agents/skills/npm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill npm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/npm, .gemini/skills/npm, .github/skills/npm and .opencode/skills/npm in your project.
Going by SKILL.md and its folder, npm Registry Operations needs JavaScript and a shell for the scripts in its folder, the command-line tools its instructions call (npm) and credentials named OP_SERVICE_ACCOUNT_TOKEN. Our summary lists: npm and Node.js; A 1Password service account token (OP_SERVICE_ACCOUNT_TOKEN); tmux; The one-password skill.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
npm Registry Operations is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with npm Registry Operations: Publish UI Package Release (cline/cline, 70k stars), Release (paperclipai/paperclip, 99k stars), ClickUp CLI Release Process (krodak/clickup-cli, 121 stars) and Azure Data Factory (MicrosoftDocs/Agent-Skills, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,273 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 4, 2026.
Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.