Helmor Bump Vendors
dohooo/helmor
Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…
Trace a commit to its published npm versions, including transitive SDK resolution with time-aware accuracy
$ npx skills add tetherto/qvac --skill commit-trace -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tetherto/qvac commit-trace --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/ocr-ggml/.agent/skills/commit-trace .claude/skills/commit-trace && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "commit-trace" agent skill from https://github.com/tetherto/qvac/tree/main/packages/ocr-ggml/.agent/skills/commit-trace into .claude/skills/commit-trace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "commit-trace", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tetherto/qvac/tree/main/packages/ocr-ggml/.agent/skills/commit-traceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tetherto/qvac --skill commit-trace -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tetherto/qvac commit-trace --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/ocr-ggml/.agent/skills/commit-trace .agents/skills/commit-trace && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "commit-trace" agent skill from https://github.com/tetherto/qvac/tree/main/packages/ocr-ggml/.agent/skills/commit-trace into .agents/skills/commit-trace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "commit-trace", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill commit-trace -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tetherto/qvac commit-trace --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/ocr-ggml/.agent/skills/commit-trace .cursor/skills/commit-trace && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "commit-trace" agent skill from https://github.com/tetherto/qvac/tree/main/packages/ocr-ggml/.agent/skills/commit-trace into .cursor/skills/commit-trace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "commit-trace", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tetherto/qvac.git --path packages/ocr-ggml/.agent/skills/commit-trace--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tetherto/qvac --skill commit-trace -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tetherto/qvac commit-trace --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/ocr-ggml/.agent/skills/commit-trace .gemini/skills/commit-trace && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "commit-trace" agent skill from https://github.com/tetherto/qvac/tree/main/packages/ocr-ggml/.agent/skills/commit-trace into .gemini/skills/commit-trace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "commit-trace", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tetherto/qvac commit-traceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tetherto/qvac --skill commit-trace -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/ocr-ggml/.agent/skills/commit-trace .github/skills/commit-trace && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "commit-trace" agent skill from https://github.com/tetherto/qvac/tree/main/packages/ocr-ggml/.agent/skills/commit-trace into .github/skills/commit-trace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "commit-trace", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill commit-trace -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tetherto/qvac commit-trace --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/ocr-ggml/.agent/skills/commit-trace .opencode/skills/commit-trace && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "commit-trace" agent skill from https://github.com/tetherto/qvac/tree/main/packages/ocr-ggml/.agent/skills/commit-trace into .opencode/skills/commit-trace/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "commit-trace", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
commit-traceTrace a commit to its published npm versions, including transitive SDK resolution with time-aware accuracy
Commit Trace is an agent skill from tetherto/qvac. Trace a commit to its published npm versions, including transitive SDK resolution with time-aware accuracy
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in AI & LLM Engineering. It works with npm and llama.cpp. The repository describes itself as: Open-source local AI SDK - run AI on-device with no cloud, no API keys. Supports GGUF, RAG, image, music, and video generation, speech-to-text, P2P inference, and more… The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d92f697. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Commit Trace loads about 1.7k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 722 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tetherto/qvac at commit d92f697, republished under its Apache-2.0 licence (© tetherto). 722 words, ~1,711 tokens.
.claude/skills/commit-trace/SKILL.md (or your agent's skills folder).Given a commit SHA, determines exactly which npm package versions contain it — both directly and transitively via the SDK. Accounts for publish timestamps to give time-accurate resolution answers.
/commit-trace <commit-sha>
/commit-trace a1b2c3d
/commit-trace a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0Verify the commit exists:
git cat-file -t <sha>If invalid, report and stop.
Show the commit summary for context:
git log --oneline -1 <sha>Get the list of files changed by this commit:
git diff-tree --no-commit-id --name-only -r <sha>Map each changed file path to its package by matching packages/<dir>/ prefixes.
For each affected directory, read packages/<dir>/package.json to get:
@qvac/llm-llamacpp)Build a list of (directory, npm-name) pairs. If no packages/ files were touched, report "this commit does not affect any publishable package" and stop.
For each affected package, find which release tags contain the commit:
git tag --contains <sha>Filter to tags relevant to this package. Tag naming conventions in this repo:
llamacpp-llm-v0.12.1 for @qvac/llm-llamacpp (package llm-llamacpp)ocr-ggml-v0.11.0 for @qvac/ocr-ggmlwhispercpp-v0.5.0 for @qvac/transcription-whispercppAlso check release branches that contain the commit:
git branch -r --contains <sha>Filter to origin/release-* branches relevant to this package.
From the tags and branches, determine the earliest version that contains this commit.
For each affected package, query npm for all published versions with their timestamps:
npm view <npm-name> time --jsonThis returns a JSON object like {"0.12.0": "2026-03-01T...", "0.12.1": "2026-03-10T...", ...}.
Cross-reference: for the version(s) found in Step 3, get their exact publish dates.
If the commit is NOT in any released version yet, report it as unreleased — only on main (dev builds) or a feature branch.
This is the critical step. The SDK (@qvac/sdk) depends on addon packages with caret ranges (e.g., "@qvac/llm-llamacpp": "^0.12.1").
For each affected package that the SDK depends on:
Read packages/sdk/package.json and find the dependency entry for this package. Note the semver range (e.g., ^0.12.1).
npm view @qvac/sdk time --jsonFor each published SDK version:
Does the SDK's semver range allow the addon version containing the commit?
package.json at that SDK's release tag/branch to get the pinned range^) locks to the minor version, NOT the major. For example:^0.1.5 → >=0.1.5 <0.2.0 (will NOT pick up 0.2.0, 0.3.0, etc.)^0.12.1 → >=0.12.1 <0.13.0 (will NOT pick up 0.13.0)^1.2.3 → >=1.2.3 <2.0.0 (normal behavior for major >= 1)Was the addon version published before this SDK version?
Would a fresh install TODAY resolve to the addon version?
For the SDK's release branch, check if a lock file exists that pins the exact addon version:
git show origin/release-sdk-<version>:packages/sdk/package-lock.jsonor
git show origin/release-sdk-<version>:packages/sdk/npm-shrinkwrap.jsonIf a lock file exists, it tells us exactly what shipped. This is the ground truth.
Present findings in this format:
Commit: <sha> "<commit message>"
Date: <commit date>
━━━ Direct Packages ━━━
@qvac/llm-llamacpp
✅ Released in: v0.12.2 (published 2026-03-15)
⏳ Also in dev: 0.13.0-dev.4 (from main)
@qvac/sdk (files touched directly)
❌ Not yet released (latest: v0.7.0, commit is after)
━━━ Transitive via @qvac/sdk ━━━
@qvac/llm-llamacpp v0.12.2 → consumed by SDK:
@qvac/sdk@0.7.0 (published 2026-03-10, pins "^0.12.1")
Range allows 0.12.2? ✅ Yes
0.12.2 existed at SDK publish time? ❌ No (published 5 days later)
Fresh install today resolves to? 0.12.2 ✅
Lock file shipped with? 0.12.1 ❌
Verdict: ❌ NOT included at release, ✅ included on fresh install today
@qvac/sdk@0.8.0 (published 2026-03-20, pins "^0.12.1")
Range allows 0.12.2? ✅ Yes
0.12.2 existed at SDK publish time? ✅ Yes
Fresh install today resolves to? 0.12.2 ✅
Lock file shipped with? 0.12.2 ✅
Verdict: ✅ included at release AND on fresh install
━━━ Summary ━━━
To guarantee this commit:
• Direct: install @qvac/llm-llamacpp@>=0.12.2
• Via SDK: install @qvac/sdk@>=0.8.0 (or sdk@0.7.0 with fresh npm install today)If the argument looks like a package@version instead of a SHA (contains @):
/commit-trace @qvac/sdk@0.7.0Reverse the flow:
© tetherto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in packages/ocr-ggml/.agent/skills/commit-trace of tetherto/qvac.
Open the folder on GitHubat commit d92f697
Commit Trace next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Commit Trace this skilltetherto/qvac | 674 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Helmor Bump Vendorsdohooo/helmor | 1.3k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Aider DelegateamElnagdy/delegate-skills | 2.3k | 2 repos | ~3k | Automated safety check: Pass | MIT | |
| Hugging Face LLM Trainerhuggingface/skills | 11k | 3 repos | ~7.2k | Automated safety check: Pass | Apache-2.0 | |
| Compromise NLP for JavaScriptspencermountain/compromise | 12k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Tavily Search API Integrationandrewyng/context-hub | 14k | — | ~1.1k | Automated safety check: Pass | MIT |
dohooo/helmor
Bump or upgrade the pinned versions of Helmor's bundled agent CLIs, SDKs, and supporting binaries — Claude Code + claude-agent-sdk (lockstep), Codex, Cursor SDK, OpenCode, Kimi, Pi, and gh / glab /…
amElnagdy/delegate-skills
Delegate a coding task to Aider (aider) as a background implementer, then review its diff and land it yourself.
huggingface/skills
Trains or fine-tunes language and vision models with TRL or Unsloth on Hugging Face Jobs cloud GPUs, then converts the results to GGUF.
spencermountain/compromise
Guide for writing correct code with the compromise rule-based NLP library: tagging, match syntax, in-place transforms and common tasks like tense changes and redaction.
andrewyng/context-hub
Guides building Tavily integrations for web search, URL extraction, site crawling and AI-assisted research in Python or JavaScript agent and RAG projects.
R6410418/Jackrong-llm-finetuning-guide
Complete agent-ready workflow for Qwen-family MTP or nextn GGUF conversion and release.
tetherto/qvac
Creates a Solutions page in the QVAC documentation website from a real use case, generalizing the case into reusable guidance and registering the page in the site navigation.
tetherto/qvac
Updates the docs website after a change to the SDK or CLI. An agent skill from tetherto/qvac.
tetherto/qvac
Plan and prepare the QVAC agent-stack release cascade across @qvac/inference, @qvac/sdk, @qvac/cli, @qvac/ai-sdk-provider, @qvac/opencode-plugin, and @qvac/openclaw-plugin.
tetherto/qvac
Run the deterministic code-quality audit, turn related findings into contextual remediation groups, prepare approval-gated Asana proposals, reconcile recurring runs, or configure twice-monthly…
tetherto/qvac
Review C++ changes for string parameter and call-site efficiency conventions (std::stringview, std::string&&, const std::string&, const char, and TransparentStringMap lookup).
tetherto/qvac
Generate changelog entries for a target add-on package. An agent skill from tetherto/qvac.
Categories
Trace a commit to its published npm versions, including transitive SDK resolution with time-aware accuracy. Commit Trace is an agent skill from tetherto/qvac.
Commit Trace fits situations like: AI & LLM Engineering work in your project.
Run `npx skills add tetherto/qvac --skill commit-trace -a claude-code`. Or copy the skill folder (packages/ocr-ggml/.agent/skills/commit-trace in tetherto/qvac) into .claude/skills/commit-trace in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tetherto/qvac --skill commit-trace -a codex`. Or copy the skill folder (packages/ocr-ggml/.agent/skills/commit-trace in tetherto/qvac) into .agents/skills/commit-trace in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tetherto/qvac --skill commit-trace -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/commit-trace, .gemini/skills/commit-trace, .github/skills/commit-trace and .opencode/skills/commit-trace in your project.
Going by SKILL.md and its folder, Commit Trace needs the command-line tools its instructions call (git and npm). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Commit Trace is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Commit Trace: Helmor Bump Vendors (dohooo/helmor, 1.3k stars), Aider Delegate (amElnagdy/delegate-skills, 2.3k stars), Hugging Face LLM Trainer (huggingface/skills, 11k stars) and Compromise NLP for JavaScript (spencermountain/compromise, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tetherto (a GitHub organization) maintains it in tetherto/qvac, which has 674 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 7, 2026.
Source: tetherto/qvac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.