Agent skill

Mac App Release

by steipete in steipete/agent-scripts

Release workflow for Sparkle-updated macOS apps, driven by a repo-owned manifest and a shared script covering appcast, signing, GitHub Release and Homebrew closeout.

MITAuto-check passedDevOps & Cloud

Install Mac App Release

skills CLI
$ npx skills add steipete/agent-scripts --skill release-mac-app -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install steipete/agent-scripts release-mac-app --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/release-mac-app .claude/skills/release-mac-app && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-mac-app
GitHub stars
7.3k
Token cost
~2.3k tokens
SKILL.md length
890 words
Files
9 (incl. scripts)
Skills in repo
45
Repo updated
First seen
Licence
MIT

At a glance

Release workflow for Sparkle-updated macOS apps, driven by a repo-owned manifest and a shared script covering appcast, signing, GitHub Release and Homebrew closeout.

  • Shipping a new version of a Sparkle-updated macOS app
  • SKILL.md covers Rules, Commands, Manifest and Done
  • Runs Shell scripts from its folder; calls bash; needs MAC_RELEASE_SUPUBLIC_ED_KEY and NPM_TOKEN
  • Generating release notes and changelog HTML for an appcast entry

What it does

The skill runs releases for macOS apps that update through Sparkle, such as BlackBar, RepoBar, CodexBar and Trimmy. Each app repository owns a .mac-release.env manifest, kept free of secrets, that names the app, repository, bundle ID, version file, appcast, feed URL, download URL prefix, app zip and package command, plus either an Info.plist or a Sparkle public key. A shared scripts/mac-release tool handles release notes, changelog HTML and the shared release, appcast and verify work.

The safety rules are explicit: never print private key material, upload app and dSYM assets to a draft before publishing, and after a failure keep the release, tags, appcast commit and local edits and resume the failed step instead of deleting or retagging. For headless signing it prefers a Sparkle key referenced in 1Password, then Keychain signing, with a key file only as a local override. App-specific build, package and sign steps stay in each repo's own scripts.

When your agent uses it

  • Shipping a new version of a Sparkle-updated macOS app
  • Generating release notes and changelog HTML for an appcast entry
  • Resuming a macOS release that failed partway through
  • Verifying the appcast and published assets after a release

Example prompts

  • “Check mac-release status for RepoBar and ship the next release.”
  • “Generate release notes and changelog HTML for the version we are about to publish.”
  • “The release upload failed after tagging. Inspect the current state and resume without retagging.”

Requirements

  • A .mac-release.env manifest in the app repository
  • A Sparkle signing key in Keychain or 1Password
  • macOS with Bash

What it can do on your machine

Read from SKILL.md and the folder at commit 79150cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • MAC_RELEASE_SUPUBLIC_ED_KEY
    • NPM_TOKEN
    • MAC_RELEASE_CODESIGN_KEYCHAIN_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mac App Release loads about 2.3k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 890 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from steipete/agent-scripts at commit 79150cf, republished under its MIT licence (© steipete). 890 words, ~2,252 tokens.

Download SKILL.mdSave it as .claude/skills/release-mac-app/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
release-mac-app
description
macOS app release: Sparkle, notarization, GitHub Release, Homebrew, closeout.

Mac App Release

Use for BlackBar, RepoBar, CodexBar, Trimmy, and similar Sparkle-updated macOS apps.

Rules

  • Work from the app repo.
  • Read .mac-release.env; it is the repo-owned release manifest.
  • Use scripts/mac-release from this skill for shared release/appcast/verify work.
  • Execute mac-release directly so its privileged Bash shebang ignores startup hooks; if an explicit interpreter is unavoidable, use /bin/bash -p, never plain bash mac-release.
  • Keep app-specific build/package/sign behavior in repo scripts unless it is already manifest-driven.
  • Never print private key material.
  • Upload app/dSYM assets to a draft before publication. After a failure, preserve the release, tags, appcast commit, and local edits; inspect existing state and resume the failed step instead of deleting or retagging a possibly published release.
  • Prefer MAC_RELEASE_SPARKLE_OP_REF for headless release signing when the key is in 1Password; otherwise prefer Keychain Sparkle signing. SPARKLE_PRIVATE_KEY_FILE is an explicit local override only.

Commands

bash
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release status
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release notes [version] [output.md]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release changelog-html <version> [CHANGELOG.md]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release make-appcast <zip> [feed-url]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release verify-appcast [version]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release check-assets [tag]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release release
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release codesign-run [--with-package-secrets] -- <command> [args...]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release package-run -- <command> [args...]

Manifest

Each repo owns .mac-release.env. It must contain no secrets.

Required:

  • MAC_RELEASE_APP_NAME
  • MAC_RELEASE_REPO
  • MAC_RELEASE_BUNDLE_ID
  • MAC_RELEASE_VERSION_FILE
  • MAC_RELEASE_APPCAST
  • MAC_RELEASE_FEED_URL
  • MAC_RELEASE_DOWNLOAD_URL_PREFIX
  • MAC_RELEASE_APP_ZIP
  • either MAC_RELEASE_INFO_PLIST or MAC_RELEASE_SUPUBLIC_ED_KEY
  • MAC_RELEASE_PACKAGE_CMD

Common optional:

  • MAC_RELEASE_PRECHECK
  • MAC_RELEASE_SOURCE_FILES (space-separated app helper files to source before expanding artifact names)
  • MAC_RELEASE_DSYM_ZIP
  • MAC_RELEASE_REQUIRE_DSYM=0 for app-only releases
  • MAC_RELEASE_ARTIFACT_PREFIX
  • MAC_RELEASE_TAG_SIGNED
  • MAC_RELEASE_TAG_FORCE
  • MAC_RELEASE_RELEASE_BRANCH
  • MAC_RELEASE_SPARKLE_ACCOUNT
  • MAC_RELEASE_SPARKLE_CHANNEL
  • MAC_RELEASE_GENERATE_APPCAST_ARGS
  • MAC_RELEASE_RUN_SPARKLE_UPDATE_TEST
  • MAC_RELEASE_SPARKLE_OP_REF — exact op://Vault/Item/field reference for the Sparkle EdDSA private key. The helper resolves it inside the shared op-work tmux session, writes only a mode-0600 temporary key file, validates its public key against SUPublicEDKey, and removes it on success or failure.
  • MAC_RELEASE_SPARKLE_OP_ACCOUNT and MAC_RELEASE_SPARKLE_OP_USE_SERVICE_ACCOUNT override the primary 1Password account/service-account mode for the Sparkle reference. Service-account-backed refs should set service-account mode to 1.
  • MAC_RELEASE_SIGNING_KEY_FILE (local fallback path only; Keychain is used when the file is absent)
  • MAC_RELEASE_EXTRA_ASSET_PATTERNS
  • MAC_RELEASE_EXTRA_ASSET_WAIT_SECONDS
  • MAC_RELEASE_EXTRA_ASSET_WAIT_INTERVAL
  • MAC_RELEASE_OP_ENV_REFS — ';'-separated NAME=op://Vault/Item/field entries resolved in the same credential pass and exported for the package command (item names may contain spaces, hence ';'). Already-exported names are preferred; refs only trigger an op read when missing. Example: NPM_TOKEN=op://Molty/npm Registry - steipete - Release Automation/registry_token.
  • MAC_RELEASE_OP_ITEM + MAC_RELEASE_OP_FIELDS for required packaging secrets. The release helper reads the known item once via op inside one persistent tmux session, then exports the requested fields for the package command.
  • MAC_RELEASE_OP_ACCOUNT defaults to my.1password.com; MAC_RELEASE_OP_VAULT, MAC_RELEASE_OP_TMUX_SESSION, MAC_RELEASE_OP_WAIT_SECONDS are optional. Without a vault, service-account token env is unset for that single op read so the personal desktop account handles it.
  • MAC_RELEASE_CODESIGN_IDENTITY + MAC_RELEASE_CODESIGN_OP_ITEM + MAC_RELEASE_CODESIGN_KEYCHAIN_MANAGED=1 enable non-interactive Developer ID signing. The keychain must be replaceable, dedicated to release automation, separate from the default keychain, not shared with interactive use, and contain exactly one signing private key. The helper owns and may permanently normalize that key's partition ACL to apple-tool:,apple:,codesign:. After precheck, the same tmux credential pass reads keychain_path and normally keychain_password, takes a per-user release lock, prepends the keychain without hiding existing keychains, verifies a Developer ID Application canary, scopes package signing through a temporary codesign --keychain shim, then restores transient state and releases the lock. Set MAC_RELEASE_CODESIGN_PASSWORDLESS=1 only for the canonical passwordless, never-locking release keychain; this omits the password field, preserves its unlocked state, and disables timeout/lock-on-sleep settings.
  • MAC_RELEASE_CODESIGN_OP_ACCOUNT, MAC_RELEASE_CODESIGN_OP_VAULT, MAC_RELEASE_CODESIGN_OP_USE_SERVICE_ACCOUNT, MAC_RELEASE_CODESIGN_OP_PATH_FIELD, and MAC_RELEASE_CODESIGN_OP_PASSWORD_FIELD override the codesign credential item defaults; account, vault, and service-account mode otherwise inherit the primary item settings. Set vault empty and service-account mode 0 for a personal desktop-account item. MAC_RELEASE_CODESIGN_KEYCHAIN + MAC_RELEASE_CODESIGN_KEYCHAIN_PASSWORD may be supplied directly instead.
  • MAC_RELEASE_RUN_LOGIN_SHELL=1 opts command hooks back into bash -lc; default hooks use env -u BASH_ENV bash -c so shell startup files cannot override exported release secrets.
Show full SKILL.md (339 more words)Show less

1Password rules:

  • Prefer already-exported env vars first; no op call if all MAC_RELEASE_OP_FIELDS are present.
  • If fields are missing, read configured package and codesign items in one tmux command for the whole release.
  • Provider stderr and parser exceptions are discarded; failed reads stop with fixed provider-read, JSON/schema, missing-field, or parser-failure diagnostics, without values or field labels.
  • Direct env-reference handoffs use Bash %q to preserve captured values safely on Bash 3.2; command substitution still strips terminal newlines from op read output.
  • Resolve MAC_RELEASE_SPARKLE_OP_REF without exposing the private key in the generated environment file or logs; only the temporary file path crosses the helper boundary.
  • Use service-account mode only with an explicit vault or MAC_RELEASE_OP_USE_SERVICE_ACCOUNT=1.
  • Do not retry op reads in a fresh shell; rerun only from the same tmux session after explicit user direction.
  • Never allow a release to reach app packaging with an unprepared Developer ID keychain. No SecurityAgent password windows during release; fail the signing canary first.
  • For non-app release scripts, use codesign-run instead of copying keychain setup into the repository. Supply the codesign manifest fields through .mac-release.env or explicit MAC_RELEASE_CODESIGN_* environment configuration. It loads only codesign credentials by default; pass --with-package-secrets when the wrapped release script also needs the configured package/notary fields in the same 1Password pass. It runs the bounded signing canary, scopes codesign through the managed-keychain shim, and restores/relocks before returning.
  • Use package-run for notarization/package credentials when no signing operation is required. It never resolves, prepares, or unlocks the Developer ID keychain and strips signing and Sparkle authority from the child.
  • Disable shell xtrace and verbose mode before loading release secrets. Arm cleanup before keychain/search-list mutations, restore the dedicated keychain's original lock policy and user search list, and relock it after packaging.

Done

  • appcast entry has URL, length, Sparkle signature.
  • downloaded enclosure verifies with Sparkle.
  • extracted app passes codesign, spctl, and stapler validate.
  • GitHub release has app zip, dSYM zip when configured, plus app-specific extra assets.
  • release notes match the changelog section.
  • after verified release, bump changelog to next patch Unreleased in the app repo.

© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts) in skills/release-mac-app of steipete/agent-scripts.

  • SKILL.md
  • scripts/lib/mac_release.sh
  • scripts/mac-release
  • scripts/mac-release-assets.test.sh
  • scripts/mac-release-canary.test.sh
  • scripts/mac-release-download.test.sh
  • scripts/mac-release-provider.test.sh
  • scripts/mac-release-publication.test.sh
  • scripts/mac-release.test.sh

Open the folder on GitHubat commit 79150cf

Compare with similar skills

Mac App Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mac App Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mac App Release this skillsteipete/agent-scripts7.3k—~2.3kAutomated safety check: PassMIT
ClickUp CLI Release Processkrodak/clickup-cli120—~906Automated safety check: WarnMIT
Mole CLI Release Flowtw93/Mole69k—~2.5kAutomated safety check: PassGPL-3.0
AnyDrag Release RoutineXueshiQiao/AnyDrag227—~2.6kAutomated safety check: PassGPL-3.0
Releaseeugene1g/agent-safehouse2.1k—~3.5kAutomated safety check: PassApache-2.0
Sake CI Releasekattouf/Sake116—~731Automated safety check: PassMIT

Similar skills

  • ClickUp CLI Release Process

    krodak/clickup-cli

    Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.

    120 GitHub stars~906 tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    69k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • AnyDrag Release Routine

    XueshiQiao/AnyDrag

    Runs the full AnyDrag release process end to end, from cumulative bilingual release notes through version bumping to watching CI and the Homebrew cask update.

    227 GitHub stars~2.6k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Release

    eugene1g/agent-safehouse

    Run the local Agent Safehouse release flow: inspect commits since the last published release, propose the next SemVer version and changelog, present a dry-run for confirmation, then update…

    2.1k GitHub stars~3.5k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Sake CI Release

    kattouf/Sake

    A skill your agent uses when working on CI workflows, GitHub Actions, release process, changelog generation (git-cliff), or dependabot configuration.

    116 GitHub stars~731 tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Release

    bmeares/Meerschaum

    Meerschaum release process — bump version, update changelog, stage dev→main PR, run CI, publish to PyPI, tag, GitHub release, build/push Docker images, rebuild docs on prod VPS.

    154 GitHub stars~1.1k tokensUpdated 28 days ago
    DevOps & CloudAuto-check: notes

More from steipete/agent-scripts

All 45 skills in this repo
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated 2 days ago
    Auto-check passed
  • Agent Transcript for PRs

    steipete/agent-scripts

    Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.

    7.3k GitHub starsUsed in 1 repo~698 tokens
    Auto-check passed
  • Parallels macOS VM Lab

    steipete/agent-scripts

    Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.

    7.3k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • ClawSweeper Status

    steipete/agent-scripts

    Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.

    7.3k GitHub stars~972 tokensUpdated 2 days ago
    Auto-check passed
  • GitHub Project Triage

    steipete/agent-scripts

    Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.

    7.3k GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed
  • Nano Banana Image Generation

    steipete/agent-scripts

    Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.

    7.3k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed

Questions about Mac App Release

What does Mac App Release do?

Release workflow for Sparkle-updated macOS apps, driven by a repo-owned manifest and a shared script covering appcast, signing, GitHub Release and Homebrew closeout. The skill runs releases for macOS apps that update through Sparkle, such as BlackBar, RepoBar, CodexBar and Trimmy.plist or a Sparkle public key.

When should I use Mac App Release?

Mac App Release fits situations like: shipping a new version of a Sparkle-updated macOS app; generating release notes and changelog HTML for an appcast entry; resuming a macOS release that failed partway through; verifying the appcast and published assets after a release.

How do I install Mac App Release in Claude Code?

Run `npx skills add steipete/agent-scripts --skill release-mac-app -a claude-code`. Or copy the skill folder (skills/release-mac-app in steipete/agent-scripts) into .claude/skills/release-mac-app in your project. Claude Code loads it when a task matches its description.

How do I install Mac App Release in Codex?

Run `npx skills add steipete/agent-scripts --skill release-mac-app -a codex`. Or copy the skill folder (skills/release-mac-app in steipete/agent-scripts) into .agents/skills/release-mac-app in your project. Codex loads it when a task matches its description.

Can I use Mac App Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill release-mac-app -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-mac-app, .gemini/skills/release-mac-app, .github/skills/release-mac-app and .opencode/skills/release-mac-app in your project.

What does Mac App Release need to run?

Going by SKILL.md and its folder, Mac App Release needs a shell for the scripts in its folder, the command-line tools its instructions call (bash) and credentials named MAC_RELEASE_SUPUBLIC_ED_KEY, NPM_TOKEN and MAC_RELEASE_CODESIGN_KEYCHAIN_PASSWORD. Our summary lists: A .mac-release.env manifest in the app repository; A Sparkle signing key in Keychain or 1Password; macOS with Bash.

Does Mac App Release access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mac App Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Mac App Release use?

Mac App Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mac App Release use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mac App Release?

Skills that share tags, products or a category with Mac App Release: ClickUp CLI Release Process (krodak/clickup-cli, 120 stars), Mole CLI Release Flow (tw93/Mole, 69k stars), AnyDrag Release Routine (XueshiQiao/AnyDrag, 227 stars) and Release (eugene1g/agent-safehouse, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mac App Release?

steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,259 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 4, 2026.

Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.