ClickUp CLI Release Process
krodak/clickup-cli
Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.
Release workflow for Sparkle-updated macOS apps, driven by a repo-owned manifest and a shared script covering appcast, signing, GitHub Release and Homebrew closeout.
$ npx skills add steipete/agent-scripts --skill release-mac-app -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install steipete/agent-scripts release-mac-app --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/release-mac-app .claude/skills/release-mac-app && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release-mac-app" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/release-mac-app into .claude/skills/release-mac-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-mac-app", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/steipete/agent-scripts/tree/main/skills/release-mac-appType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add steipete/agent-scripts --skill release-mac-app -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install steipete/agent-scripts release-mac-app --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/release-mac-app .agents/skills/release-mac-app && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release-mac-app" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/release-mac-app into .agents/skills/release-mac-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-mac-app", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add steipete/agent-scripts --skill release-mac-app -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install steipete/agent-scripts release-mac-app --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/release-mac-app .cursor/skills/release-mac-app && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release-mac-app" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/release-mac-app into .cursor/skills/release-mac-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-mac-app", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/steipete/agent-scripts.git --path skills/release-mac-app--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add steipete/agent-scripts --skill release-mac-app -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install steipete/agent-scripts release-mac-app --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/release-mac-app .gemini/skills/release-mac-app && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release-mac-app" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/release-mac-app into .gemini/skills/release-mac-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-mac-app", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install steipete/agent-scripts release-mac-appInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add steipete/agent-scripts --skill release-mac-app -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/release-mac-app .github/skills/release-mac-app && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release-mac-app" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/release-mac-app into .github/skills/release-mac-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-mac-app", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add steipete/agent-scripts --skill release-mac-app -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install steipete/agent-scripts release-mac-app --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/release-mac-app .opencode/skills/release-mac-app && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release-mac-app" agent skill from https://github.com/steipete/agent-scripts/tree/main/skills/release-mac-app into .opencode/skills/release-mac-app/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-mac-app", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
release-mac-appRelease workflow for Sparkle-updated macOS apps, driven by a repo-owned manifest and a shared script covering appcast, signing, GitHub Release and Homebrew closeout.
The skill runs releases for macOS apps that update through Sparkle, such as BlackBar, RepoBar, CodexBar and Trimmy. Each app repository owns a .mac-release.env manifest, kept free of secrets, that names the app, repository, bundle ID, version file, appcast, feed URL, download URL prefix, app zip and package command, plus either an Info.plist or a Sparkle public key. A shared scripts/mac-release tool handles release notes, changelog HTML and the shared release, appcast and verify work.
The safety rules are explicit: never print private key material, upload app and dSYM assets to a draft before publishing, and after a failure keep the release, tags, appcast commit and local edits and resume the failed step instead of deleting or retagging. For headless signing it prefers a Sparkle key referenced in 1Password, then Keychain signing, with a key file only as a local override. App-specific build, package and sign steps stay in each repo's own scripts.
Read from SKILL.md and the folder at commit 79150cf. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 8 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
bashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
MAC_RELEASE_SUPUBLIC_ED_KEYNPM_TOKENMAC_RELEASE_CODESIGN_KEYCHAIN_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mac App Release loads about 2.3k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 890 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from steipete/agent-scripts at commit 79150cf, republished under its MIT licence (© steipete). 890 words, ~2,252 tokens.
.claude/skills/release-mac-app/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Use for BlackBar, RepoBar, CodexBar, Trimmy, and similar Sparkle-updated macOS apps.
.mac-release.env; it is the repo-owned release manifest.scripts/mac-release from this skill for shared release/appcast/verify work.mac-release directly so its privileged Bash shebang ignores startup hooks; if an explicit interpreter is
unavoidable, use /bin/bash -p, never plain bash mac-release.MAC_RELEASE_SPARKLE_OP_REF for headless release signing when the key is in 1Password; otherwise prefer
Keychain Sparkle signing. SPARKLE_PRIVATE_KEY_FILE is an explicit local override only./Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release status
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release notes [version] [output.md]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release changelog-html <version> [CHANGELOG.md]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release make-appcast <zip> [feed-url]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release verify-appcast [version]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release check-assets [tag]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release release
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release codesign-run [--with-package-secrets] -- <command> [args...]
/Users/steipete/Projects/agent-scripts/skills/release-mac-app/scripts/mac-release package-run -- <command> [args...]Each repo owns .mac-release.env. It must contain no secrets.
Required:
MAC_RELEASE_APP_NAMEMAC_RELEASE_REPOMAC_RELEASE_BUNDLE_IDMAC_RELEASE_VERSION_FILEMAC_RELEASE_APPCASTMAC_RELEASE_FEED_URLMAC_RELEASE_DOWNLOAD_URL_PREFIXMAC_RELEASE_APP_ZIPMAC_RELEASE_INFO_PLIST or MAC_RELEASE_SUPUBLIC_ED_KEYMAC_RELEASE_PACKAGE_CMDCommon optional:
MAC_RELEASE_PRECHECKMAC_RELEASE_SOURCE_FILES (space-separated app helper files to source before expanding artifact names)MAC_RELEASE_DSYM_ZIPMAC_RELEASE_REQUIRE_DSYM=0 for app-only releasesMAC_RELEASE_ARTIFACT_PREFIXMAC_RELEASE_TAG_SIGNEDMAC_RELEASE_TAG_FORCEMAC_RELEASE_RELEASE_BRANCHMAC_RELEASE_SPARKLE_ACCOUNTMAC_RELEASE_SPARKLE_CHANNELMAC_RELEASE_GENERATE_APPCAST_ARGSMAC_RELEASE_RUN_SPARKLE_UPDATE_TESTMAC_RELEASE_SPARKLE_OP_REF — exact op://Vault/Item/field reference for the Sparkle EdDSA private key. The
helper resolves it inside the shared op-work tmux session, writes only a mode-0600 temporary key file, validates
its public key against SUPublicEDKey, and removes it on success or failure.MAC_RELEASE_SPARKLE_OP_ACCOUNT and MAC_RELEASE_SPARKLE_OP_USE_SERVICE_ACCOUNT override the primary 1Password
account/service-account mode for the Sparkle reference. Service-account-backed refs should set service-account mode
to 1.MAC_RELEASE_SIGNING_KEY_FILE (local fallback path only; Keychain is used when the file is absent)MAC_RELEASE_EXTRA_ASSET_PATTERNSMAC_RELEASE_EXTRA_ASSET_WAIT_SECONDSMAC_RELEASE_EXTRA_ASSET_WAIT_INTERVALMAC_RELEASE_OP_ENV_REFS — ';'-separated NAME=op://Vault/Item/field entries resolved in the same credential pass and exported for the package command (item names may contain spaces, hence ';'). Already-exported names are preferred; refs only trigger an op read when missing. Example: NPM_TOKEN=op://Molty/npm Registry - steipete - Release Automation/registry_token.MAC_RELEASE_OP_ITEM + MAC_RELEASE_OP_FIELDS for required packaging secrets. The release helper reads the known item once via op inside one persistent tmux session, then exports the requested fields for the package command.MAC_RELEASE_OP_ACCOUNT defaults to my.1password.com; MAC_RELEASE_OP_VAULT, MAC_RELEASE_OP_TMUX_SESSION, MAC_RELEASE_OP_WAIT_SECONDS are optional. Without a vault, service-account token env is unset for that single op read so the personal desktop account handles it.MAC_RELEASE_CODESIGN_IDENTITY + MAC_RELEASE_CODESIGN_OP_ITEM + MAC_RELEASE_CODESIGN_KEYCHAIN_MANAGED=1 enable non-interactive Developer ID signing. The keychain must be replaceable, dedicated to release automation, separate from the default keychain, not shared with interactive use, and contain exactly one signing private key. The helper owns and may permanently normalize that key's partition ACL to apple-tool:,apple:,codesign:. After precheck, the same tmux credential pass reads keychain_path and normally keychain_password, takes a per-user release lock, prepends the keychain without hiding existing keychains, verifies a Developer ID Application canary, scopes package signing through a temporary codesign --keychain shim, then restores transient state and releases the lock. Set MAC_RELEASE_CODESIGN_PASSWORDLESS=1 only for the canonical passwordless, never-locking release keychain; this omits the password field, preserves its unlocked state, and disables timeout/lock-on-sleep settings.MAC_RELEASE_CODESIGN_OP_ACCOUNT, MAC_RELEASE_CODESIGN_OP_VAULT, MAC_RELEASE_CODESIGN_OP_USE_SERVICE_ACCOUNT, MAC_RELEASE_CODESIGN_OP_PATH_FIELD, and MAC_RELEASE_CODESIGN_OP_PASSWORD_FIELD override the codesign credential item defaults; account, vault, and service-account mode otherwise inherit the primary item settings. Set vault empty and service-account mode 0 for a personal desktop-account item. MAC_RELEASE_CODESIGN_KEYCHAIN + MAC_RELEASE_CODESIGN_KEYCHAIN_PASSWORD may be supplied directly instead.MAC_RELEASE_RUN_LOGIN_SHELL=1 opts command hooks back into bash -lc; default hooks use env -u BASH_ENV bash -c so shell startup files cannot override exported release secrets.1Password rules:
op call if all MAC_RELEASE_OP_FIELDS are present.%q to preserve captured values safely on Bash 3.2; command substitution still strips terminal newlines from op read output.MAC_RELEASE_SPARKLE_OP_REF without exposing the private key in the generated environment file or logs;
only the temporary file path crosses the helper boundary.MAC_RELEASE_OP_USE_SERVICE_ACCOUNT=1.op reads in a fresh shell; rerun only from the same tmux session after explicit user direction.codesign-run instead of copying keychain setup into the repository. Supply the codesign manifest fields through .mac-release.env or explicit MAC_RELEASE_CODESIGN_* environment configuration. It loads only codesign credentials by default; pass --with-package-secrets when the wrapped release script also needs the configured package/notary fields in the same 1Password pass. It runs the bounded signing canary, scopes codesign through the managed-keychain shim, and restores/relocks before returning.package-run for notarization/package credentials when no signing operation is required. It never resolves, prepares, or unlocks the Developer ID keychain and strips signing and Sparkle authority from the child.codesign, spctl, and stapler validate.Unreleased in the app repo.© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (scripts) in skills/release-mac-app of steipete/agent-scripts.
Open the folder on GitHubat commit 79150cf
Mac App Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mac App Release this skillsteipete/agent-scripts | 7.3k | — | ~2.3k | Automated safety check: Pass | MIT | |
| ClickUp CLI Release Processkrodak/clickup-cli | 120 | — | ~906 | Automated safety check: Warn | MIT | |
| Mole CLI Release Flowtw93/Mole | 69k | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | |
| AnyDrag Release RoutineXueshiQiao/AnyDrag | 227 | — | ~2.6k | Automated safety check: Pass | GPL-3.0 | |
| Releaseeugene1g/agent-safehouse | 2.1k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Sake CI Releasekattouf/Sake | 116 | — | ~731 | Automated safety check: Pass | MIT |
krodak/clickup-cli
Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.
tw93/Mole
Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.
XueshiQiao/AnyDrag
Runs the full AnyDrag release process end to end, from cumulative bilingual release notes through version bumping to watching CI and the Homebrew cask update.
eugene1g/agent-safehouse
Run the local Agent Safehouse release flow: inspect commits since the last published release, propose the next SemVer version and changelog, present a dry-run for confirmation, then update…
kattouf/Sake
A skill your agent uses when working on CI workflows, GitHub Actions, release process, changelog generation (git-cliff), or dependabot configuration.
bmeares/Meerschaum
Meerschaum release process — bump version, update changelog, stage dev→main PR, run CI, publish to PyPI, tag, GitHub release, build/push Docker images, rebuild docs on prod VPS.
steipete/agent-scripts
Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.
steipete/agent-scripts
Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.
steipete/agent-scripts
Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.
steipete/agent-scripts
Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.
steipete/agent-scripts
Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.
steipete/agent-scripts
Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.
Categories
Release workflow for Sparkle-updated macOS apps, driven by a repo-owned manifest and a shared script covering appcast, signing, GitHub Release and Homebrew closeout. The skill runs releases for macOS apps that update through Sparkle, such as BlackBar, RepoBar, CodexBar and Trimmy.plist or a Sparkle public key.
Mac App Release fits situations like: shipping a new version of a Sparkle-updated macOS app; generating release notes and changelog HTML for an appcast entry; resuming a macOS release that failed partway through; verifying the appcast and published assets after a release.
Run `npx skills add steipete/agent-scripts --skill release-mac-app -a claude-code`. Or copy the skill folder (skills/release-mac-app in steipete/agent-scripts) into .claude/skills/release-mac-app in your project. Claude Code loads it when a task matches its description.
Run `npx skills add steipete/agent-scripts --skill release-mac-app -a codex`. Or copy the skill folder (skills/release-mac-app in steipete/agent-scripts) into .agents/skills/release-mac-app in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill release-mac-app -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-mac-app, .gemini/skills/release-mac-app, .github/skills/release-mac-app and .opencode/skills/release-mac-app in your project.
Going by SKILL.md and its folder, Mac App Release needs a shell for the scripts in its folder, the command-line tools its instructions call (bash) and credentials named MAC_RELEASE_SUPUBLIC_ED_KEY, NPM_TOKEN and MAC_RELEASE_CODESIGN_KEYCHAIN_PASSWORD. Our summary lists: A .mac-release.env manifest in the app repository; A Sparkle signing key in Keychain or 1Password; macOS with Bash.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Mac App Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Mac App Release: ClickUp CLI Release Process (krodak/clickup-cli, 120 stars), Mole CLI Release Flow (tw93/Mole, 69k stars), AnyDrag Release Routine (XueshiQiao/AnyDrag, 227 stars) and Release (eugene1g/agent-safehouse, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,259 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 4, 2026.
Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.