Agent skill

Project Release

by swimmwatch in swimmwatch/cloakbrowser-mcp

Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

MITAuto-check passedAgent Workflows

Install Project Release

skills CLI
$ npx skills add swimmwatch/cloakbrowser-mcp --skill project-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install swimmwatch/cloakbrowser-mcp project-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/swimmwatch/cloakbrowser-mcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/project-release .claude/skills/project-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
project-release
GitHub stars
161
Token cost
~1.9k tokens
SKILL.md length
842 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

  • Explicitly requests release work
  • SKILL.md covers Authorization And Interview, Choosing The Target Version, Preconditions and Version Preparation, plus 4 more sections
  • Calls npm, docker and git; reaches semver.org and keepachangelog.com; needs DOCKERHUB_TOKEN
  • Tasks that involve MCP servers

What it does

Project Release is an agent skill from swimmwatch/cloakbrowser-mcp. Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work. Require a Prompt MCP-confirmed target version and stability, follow the repository's version, changelog, PR, GitHub Release, npm, Docker, MCP Registry, and docs process, and never tag, publish, create/update a release PR, or mutate external release state without separate explicit authorization.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers, Browser automation and Containers. It works with Model Context Protocol, Docker, npm and GitHub. The repository describes itself as: ⚡ CloakBrowser MCP server for AI agents: Playwright-powered browsing, clean tool forwarding, Docker support, and multi-session HTTP transport. The licence is MIT.

When your agent uses it

  • Explicitly requests release work
  • Tasks that involve MCP servers
  • Tasks that involve Browser automation

Example prompts

  • “/project-release”

Requirements

  • Python 3
  • Docker
  • A credential in DOCKERHUB_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 7e5ddd0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • docker
    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • semver.org
    • keepachangelog.com
    • conventionalcommits.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DOCKERHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Project Release loads about 1.9k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 842 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from swimmwatch/cloakbrowser-mcp at commit 7e5ddd0, republished under its MIT licence (© swimmwatch). 842 words, ~1,946 tokens.

Download SKILL.mdSave it as .claude/skills/project-release/SKILL.md (or your agent's skills folder).
name
project-release
description
Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work. Require a Prompt MCP-confirmed target version and stability, follow the repository's version, changelog, PR, GitHub Release, npm, Docker, MCP Registry, and docs process, and never tag, publish, create/update a release PR, or mutate external release state without separate explicit authorization.

Project Release

Use this skill only for cloakbrowser-mcp release work. Require a confirmed target version such as v1.2.8, and decide whether it is stable or prerelease before preparing, publishing, or recovering a release. If the user has not provided a target version, propose one from the unreleased changes and ask the user through Prompt MCP to confirm it or choose a different tag before release execution.

Release tags use Semantic Versioning 2.0.0 with the repository's v prefix, for example v1.2.8 or v1.2.8-rc.1. The pinned specification URL is https://semver.org/spec/v2.0.0.html.

Authorization And Interview

  • Start or reopen a persistent workspace Prompt MCP interview with a stable ID such as release:vX.Y.Z after inspecting the callable schemas.
  • Record target tag and stable/prerelease selection as separate material decisions. Treat only committed answers as confirmation.
  • Release preparation, commit, push, release PR creation/update, merge, tag or GitHub Release creation, npm publication, Docker publication, MCP Registry publication, workflow rerun, and recovery mutations are separate authorization gates.
  • Never infer publish authorization from version confirmation, preparation approval, merged code, or passing checks.

Choosing The Target Version

  • If the user provides a target tag, validate it before changing files.
  • If no target tag is provided, fetch tags and inspect changes since the previous release tag:
bash
git fetch origin --tags --prune
git describe --tags --abbrev=0
git log --oneline <previous-tag>..HEAD
  • Also inspect [Unreleased] in CHANGELOG.md, merged PR titles, and Conventional Commit subjects when available.
  • Propose the next tag using Semantic Versioning 2.0.0:
    • MAJOR for backward-incompatible public API, CLI, MCP protocol, config, or artifact contract changes;
    • MINOR for backward-compatible user-facing features;
    • PATCH for backward-compatible fixes, dependency updates, docs, CI, or packaging-only changes.
  • Present the proposed tag and short rationale, then ask the user to confirm it or choose another tag through Prompt MCP. Do not run npm run version:apply until the tag is confirmed and release preparation is explicitly authorized.

Preconditions

  • Start from a clean worktree; do not overwrite unrelated user changes.
  • Fetch latest refs and branch from current main unless the user explicitly gives another base.
  • Confirm no existing Git tag or GitHub Release already uses the target version.
  • Before confirming the release tag, open and scan https://semver.org/spec/v2.0.0.html, then validate that the requested tag is the v-prefixed form of a SemVer 2.0.0 version.
  • Exclude known failing or unrelated dependency PRs unless the user explicitly includes them.
  • Before editing CHANGELOG.md, open and scan https://keepachangelog.com/en/1.1.0/.
  • Before committing, open and scan https://www.conventionalcommits.org/en/v1.0.0/.

Version Preparation

Run the release version script with the exact tag:

bash
npm run version:apply -- vX.Y.Z

The script updates:

  • package.json
  • package-lock.json
  • server.json

Documentation release tags and pinned install examples are rendered at MkDocs build time from package.json through docs_macros.py; do not manually rewrite those values in Markdown sources.

Manual release updates still required:

  • add one new row to docs/data/version-compatibility.json;
  • run npm run docs:compatibility;
  • verify README.md, docs/index.md, and docs/version-compatibility.md changed as expected;
  • verify the new compatibility row records the actual @playwright/mcp, Playwright MCP Docker base, CloakBrowser dependency, supported transport, and platform;
  • run npm run docs:compatibility:check;
  • move current [Unreleased] entries in CHANGELOG.md into ## [X.Y.Z] - YYYY-MM-DD;
  • add or update the empty [Unreleased] section above the new release;
  • update changelog compare links so [Unreleased] compares vX.Y.Z...HEAD and [X.Y.Z] compares the previous tag to vX.Y.Z;
  • update release docs examples only if they are intended to show the current release instead of a generic example.

Do not bump the package version outside release preparation.

Show full SKILL.md (307 more words)Show less

Validation

Before opening or merging the release PR, run:

bash
npm run check:ci
npm run package:verify
npm run docker:build
npm run docker:smoke
npm run bridge:compare -- cloakbrowser-mcp:dev --report bridge-parity-report.json
docker run --rm -v "$PWD:/repo" --workdir /repo docker.io/rhysd/actionlint:1.7.12@sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667 -color
python3 -m pipx run zizmor --min-severity high .
npm run docs:build
npm run docs:seo:validate

Remove bridge-parity-report.json after inspecting it. If a check fails, fix the smallest release-relevant cause and rerun the relevant command.

PR And Release Flow

  • After explicit commit authorization, commit release preparation as chore(release): prepare vX.Y.Z.
  • For release PR creation or updates, also read and follow .agents/skills/project-pull-request/SKILL.md.
  • After separate PR authorization, open a PR to main with a concise release summary and validation list.
  • Call out security-sensitive release workflow changes, especially registry credentials, public image publishing, OIDC, or token behavior.
  • Wait for required PR checks to pass before merging.
  • After separate publication authorization, create a published GitHub Release for stable releases with:
    • tag vX.Y.Z;
    • target main;
    • title vX.Y.Z;
    • notes from the CHANGELOG.md section.
  • Mark prerelease versions as GitHub prereleases. Stable releases publish npm latest and Docker latest; prereleases publish npm next and prerelease Docker tags only.

Post-Release Verification

Watch the unified Release workflow until metadata, npm, docker, mcp-registry, docs-build, and docs-deploy complete. docs-deploy must run only after npm, Docker, and MCP Registry publishing have succeeded.

Then verify:

bash
npm view cloakbrowser-mcp@X.Y.Z version
docker pull swimmwatch/cloakbrowser-mcp:X.Y.Z
docker run --rm --init swimmwatch/cloakbrowser-mcp:X.Y.Z --help
docker pull ghcr.io/swimmwatch/cloakbrowser-mcp:X.Y.Z
npm run registry:check -- --version X.Y.Z

Confirm Docker Hub overview, short description, npm, GHCR, Docker Hub, docs, and the official MCP Registry are current. GitHub /mcp visibility is curated separately and may lag; treat it as a warning unless the user makes it a gate.

Recovery

  • If Docker Hub overview update fails with Forbidden, the DOCKERHUB_TOKEN secret needs a Docker Hub personal access token with read/write/delete permissions for swimmwatch/cloakbrowser-mcp; rerun failed release jobs after the secret is updated.
  • If npm, GHCR, Docker Hub, or MCP Registry already published artifacts, do not delete and retag the same release for code defects. Prepare a follow-up patch release instead.
  • Rerun failed jobs only after confirming the failure is transient or caused by a fixed external configuration.
  • Keep release recovery notes in the final status report, including published artifact state and any warnings.

© swimmwatch, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/project-release of swimmwatch/cloakbrowser-mcp.

Open the folder on GitHubat commit 7e5ddd0

Compare with similar skills

Project Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Project Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Project Release this skillswimmwatch/cloakbrowser-mcp161—~1.9kAutomated safety check: PassMIT
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
Skillz Integrationgithub/gh-aw5.4k—~905Automated safety check: PassMIT
Frontend Build Timing Auditopenops-cloud/openops1.1k—~2.3kAutomated safety check: PassCustom licence
Scraper Builderjwynia/agent-skills166—~4kAutomated safety check: PassMIT
Skillredf0x1/camofox-mcp117—~3.1kAutomated safety check: PassMIT

Similar skills

  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Skillz Integration

    github/gh-aw

    Official

    Run and integrate Skillz MCP server with Docker for skill execution.

    5.4k GitHub stars~905 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Frontend Build Timing Audit

    openops-cloud/openops

    Detects and diagnoses chunk-evaluation timing bugs in the Vite/rolldown production build of react-ui (works-in-dev / broken-in-build i18n regressions, missing UI labels, module-scope t()…

    1.1k GitHub stars~2.3k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Scraper Builder

    jwynia/agent-skills

    Guide AI agents to generate complete PageObject pattern web scraper projects using Playwright and TypeScript with Docker deployment.

    166 GitHub stars~4k tokensUpdated 7 mo ago
    Data & AnalyticsAuto-check passed
  • Skill

    redf0x1/camofox-mcp

    Anti-detection browser automation MCP skill for OpenClaw agents with 47 tools for navigation, interaction, observation, extraction, downloads, profiles, sessions, and stealth web search.

    117 GitHub stars~3.1k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Setup Xhs MCP

    autoclaw-cc/xiaohongshu-mcp-skills

    安装部署 xiaohongshu-mcp 服务并配置 MCP 连接,引导用户完成从零到可用的全流程. An agent skill from autoclaw-cc/xiaohongshu-mcp-skills.

    269 GitHub stars~678 tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed

More from swimmwatch/cloakbrowser-mcp

  • Project Pull Request

    swimmwatch/cloakbrowser-mcp

    Create, update, prepare, or review a cloakbrowser-mcp GitHub Pull Request only when the user explicitly requests PR work.

    161 GitHub stars~1k tokensUpdated 6 days ago
    Auto-check passed
  • Project Docs Maintainer

    swimmwatch/cloakbrowser-mcp

    Maintain, organize, consolidate, or audit the cloakbrowser-mcp documentation set only when the user explicitly requests project documentation maintenance or an authorized public change requires it.

    161 GitHub stars~569 tokensUpdated 6 days ago
    Auto-check passed

Questions about Project Release

What does Project Release do?

Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work. Project Release is an agent skill from swimmwatch/cloakbrowser-mcp. Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

When should I use Project Release?

Project Release fits situations like: explicitly requests release work; tasks that involve MCP servers; tasks that involve Browser automation.

How do I install Project Release in Claude Code?

Run `npx skills add swimmwatch/cloakbrowser-mcp --skill project-release -a claude-code`. Or copy the skill folder (.agents/skills/project-release in swimmwatch/cloakbrowser-mcp) into .claude/skills/project-release in your project. Claude Code loads it when a task matches its description.

How do I install Project Release in Codex?

Run `npx skills add swimmwatch/cloakbrowser-mcp --skill project-release -a codex`. Or copy the skill folder (.agents/skills/project-release in swimmwatch/cloakbrowser-mcp) into .agents/skills/project-release in your project. Codex loads it when a task matches its description.

Can I use Project Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add swimmwatch/cloakbrowser-mcp --skill project-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-release, .gemini/skills/project-release, .github/skills/project-release and .opencode/skills/project-release in your project.

What does Project Release need to run?

Going by SKILL.md and its folder, Project Release needs the command-line tools its instructions call (npm, docker, git and python3) and credentials named DOCKERHUB_TOKEN. Our summary lists: Python 3; Docker; A credential in DOCKERHUB_TOKEN.

Does Project Release access the network?

SKILL.md names 3 domains. In commands or code: semver.org, keepachangelog.com and conventionalcommits.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Project Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Project Release use?

Project Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Project Release use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Project Release?

Skills that share tags, products or a category with Project Release: Devcontainer Dev (stacklok/toolhive-studio, 170 stars), Skillz Integration (github/gh-aw, 5.4k stars), Frontend Build Timing Audit (openops-cloud/openops, 1.1k stars) and Scraper Builder (jwynia/agent-skills, 166 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Project Release?

swimmwatch (a GitHub user) maintains it in swimmwatch/cloakbrowser-mcp, which has 161 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 1, 2026.

Source: swimmwatch/cloakbrowser-mcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.