Cutting A Release
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
Generate NOTICE files with third-party attributions for all packages in the monorepo.
$ npx skills add tetherto/qvac --skill qv-notice-generate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tetherto/qvac qv-notice-generate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/qv-notice-generate .claude/skills/qv-notice-generate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "qv-notice-generate" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-notice-generate into .claude/skills/qv-notice-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-notice-generate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-notice-generateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tetherto/qvac --skill qv-notice-generate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tetherto/qvac qv-notice-generate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/qv-notice-generate .agents/skills/qv-notice-generate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "qv-notice-generate" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-notice-generate into .agents/skills/qv-notice-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-notice-generate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill qv-notice-generate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tetherto/qvac qv-notice-generate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/qv-notice-generate .cursor/skills/qv-notice-generate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "qv-notice-generate" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-notice-generate into .cursor/skills/qv-notice-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-notice-generate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tetherto/qvac.git --path .agents/skills/qv-notice-generate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tetherto/qvac --skill qv-notice-generate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tetherto/qvac qv-notice-generate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/qv-notice-generate .gemini/skills/qv-notice-generate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "qv-notice-generate" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-notice-generate into .gemini/skills/qv-notice-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-notice-generate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tetherto/qvac qv-notice-generateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tetherto/qvac --skill qv-notice-generate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/qv-notice-generate .github/skills/qv-notice-generate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "qv-notice-generate" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-notice-generate into .github/skills/qv-notice-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-notice-generate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tetherto/qvac --skill qv-notice-generate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tetherto/qvac qv-notice-generate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/qv-notice-generate .opencode/skills/qv-notice-generate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "qv-notice-generate" agent skill from https://github.com/tetherto/qvac/tree/main/.agents/skills/qv-notice-generate into .opencode/skills/qv-notice-generate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qv-notice-generate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
qv-notice-generateGenerate NOTICE files with third-party attributions for all packages in the monorepo.
Qv Notice Generate is an agent skill from tetherto/qvac. Generate NOTICE files with third-party attributions for all packages in the monorepo.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts (for example `scripts/check-forbidden-licenses.js`, `scripts/constants.js` and `scripts/generate-notice.js`).
It sits in Development, covering Monorepo tooling. It works with GitHub. The repository describes itself as: Open-source local AI SDK - run AI on-device with no cloud, no API keys. Supports GGUF, RAG, image, music, and video generation, speech-to-text, P2P inference, and more… The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 673ea94. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 12 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GH_TOKENHF_TOKENNPM_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Qv Notice Generate loads about 2k tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 839 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Before running, ensure `.env` is sourced and contains:2. Source `.env` in the shellsource .envsource .envsource .envsource .envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from tetherto/qvac at commit 673ea94, republished under its Apache-2.0 licence (© tetherto). 839 words, ~2,004 tokens.
.claude/skills/qv-notice-generate/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.Generate deterministic, sorted NOTICE files for individual packages or all packages at once, covering model, JS, Python, and C++ dependency attributions.
As of QVAC-21554, license/compliance enforcement on Tier-1 PRs is primarily a CI gate — .github/workflows/license-compliance.yml, delegating to the org reusable workflow public-reusable-license.yml (design: tetherto/qvac-actions/docs/license-compliance-ci.md). The gate deterministically classifies newly added PR dependencies against the org policy (allow/deny/review), honours .github/license-allowlist.yml, and posts a PR comment.
This SKILL is now the human fallback for the long tail the gate cannot decide:
check-forbidden-licenses.js to investigate, then record the decision in .github/license-allowlist.yml (CODEOWNERS-reviewed) or remove/replace the dependency. The gate is deterministic from then on.check-forbidden-licenses.js does a real npm install + license-checker (plus Python/C++/model scans) and is the tool for a complete audit — e.g. before a release, or when the gate's coverage is insufficient.generate-notice.js job.Use when:
/qv-notice-generateBefore running, ensure .env is sourced and contains:
GH_TOKEN -- GitHub token (access to private repos and GitHub API)HF_TOKEN -- HuggingFace token (model license verification)NPM_TOKEN -- npm registry token (private package resolution)System requirements for Python scanning:
python3 and pip available in PATH (for pip-licenses)--all for all packages).env in the shellFound 0 JS dependencies while HEAD's NOTICE still has a
JS section, restore that JS block from HEAD. (npm install failed is
written to gitignored NOTICE_LOG.txt, not stdout.) Keep successful
model-scan additions. Do not commit a wiped JS section.--dry-run if the user explicitly asks for itDo NOT commit changes. The user will review and commit manually.
source .env
node .agents/skills/qv-notice-generate/scripts/generate-notice.js <package-dir-name>Example: node .agents/skills/qv-notice-generate/scripts/generate-notice.js sdk
For registry sub-packages use the full path:
registry-server/clientregistry-server/sharedsource .env
node .agents/skills/qv-notice-generate/scripts/generate-notice.js --allsource .env
node .agents/skills/qv-notice-generate/scripts/generate-notice.js --all --dry-run
node .agents/skills/qv-notice-generate/scripts/generate-notice.js sdk --dry-runIn dry-run mode:
source .env
node .agents/skills/qv-notice-generate/scripts/check-forbidden-licenses.js --all --dry-run
node .agents/skills/qv-notice-generate/scripts/check-forbidden-licenses.js --allUses an allowlist approach. The ALLOWED_LICENSES array in config.js controls which licenses pass:
License strings from all sources (npm, PyPI, GitHub, models) are normalized to canonical SPDX ids before comparison, so adding apache-2.0 to the list automatically covers Apache 2.0, Apache Software License, Apache License 2.0, etc.
If violations are found, writes FORBIDDEN_LICENSES.txt to the repo root and exits with code 1.
Important: The agent should NOT edit ALLOWED_LICENSES directly. Present the scan results to the user and let them decide which licenses to allow. The allowlist and normalization map live in .agents/skills/qv-notice-generate/scripts/constants.js.
node .agents/skills/qv-notice-generate/scripts/generate-report.jsReads existing NOTICE files across all packages (no scanning, no tokens needed) and produces NOTICE_FULL_REPORT.txt with:
NOTICE file inside each scanned package directory (from generate-notice.js)NOTICE_FULL_REPORT.txt license overview report (from generate-report.js, gitignored)NOTICE_LOG.txt at the repo root with errors/warnings (gitignored)| Type | What | Tool |
|---|---|---|
| Models | Model attributions from models.prod.json | Direct JSON parsing |
| JS | Production npm dependencies (no peers / extraneous) | npm install --omit=dev --omit=peer + license-checker, intersected with npm ls |
| Python | Benchmark/script Python deps | pip-licenses (auto-installed in temp virtualenv) |
| C++ | vcpkg native dependencies | GitHub API + local portfile parsing |
sdk, inference, registry-server/clientpackage.jsonrequirements.txt or pyproject.toml in benchmarks/scriptsvcpkg.json| Package directory | Engine |
|---|---|
embed-llamacpp | @qvac/embed-llamacpp |
llm-llamacpp | @qvac/llm-llamacpp |
translation-nmtcpp | @qvac/translation-nmtcpp |
tts-onnx | @qvac/tts-onnx |
asr-ggml | @qvac/transcription-whispercpp, @qvac/asr-ggml |
diffusion-cpp | @qvac/diffusion-cpp |
asr-ggml carries two engine keys because the whisper + parakeet packages were
unified: models.prod.json still names the retired
@qvac/transcription-whispercpp engine until the SDK/registry repoint lands.
All entries within every NOTICE file section are sorted deterministically using locale-independent collation. Re-runs on identical input always produce identical output, resulting in clean git diffs.
npm run verify:licenses in packages/registry-server -- verifies model licenses in models.prod.json against HuggingFace/GitHub APIs (dry-run only, console output, fails on unverifiable)..agents/skills/qv-notice-generate/scripts/constants.js.agents/skills/qv-notice-generate/scripts/lib/config.js.github/teams/sdk.json© tetherto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 12 other files (scripts) in .agents/skills/qv-notice-generate of tetherto/qvac.
Open the folder on GitHubat commit 673ea94
Qv Notice Generate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Qv Notice Generate this skilltetherto/qvac | 685 | — | ~2k | Automated safety check: Notes | Apache-2.0 | |
| Cutting A ReleaseTriliumNext/Trilium | 38k | — | ~3.2k | Automated safety check: Pass | AGPL-3.0 | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| Create Vechain Dappvechain/x-app-template | 450 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Dependabot Alerts Updatelivesession/xyd | 114 | — | ~2k | Automated safety check: Pass | MIT | |
| Investigate Issueanalogjs/analog | 3.2k | — | ~2k | Automated safety check: Pass | MIT |
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
vechain/x-app-template
Scaffold a VeChain dApp with Next.js, VeChain Kit, Chakra UI v3, and GitHub Pages deployment.
livesession/xyd
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
analogjs/analog
Investigate a GitHub issue end to end — reproduce the reporter's repo or code snippet in an isolated sandbox outside the monorepo, trace the root cause in the source, and draft a reply back to the…
jd-solanki/slidev-theme-dracula
Automate npm package publishing via GitHub Actions for single-package repos and independent monorepo packages, including bumpp version tags, GitHub release notes, trusted publishing, provenance, and…
tetherto/qvac
Creates a Solutions page in the QVAC documentation website from a real use case, generalizing the case into reusable guidance and registering the page in the site navigation.
tetherto/qvac
Updates the docs website after a change to the SDK or CLI. An agent skill from tetherto/qvac.
tetherto/qvac
Plan and prepare the QVAC agent-stack release cascade across @qvac/inference, @qvac/sdk, @qvac/cli, @qvac/ai-sdk-provider, @qvac/opencode-plugin, and @qvac/openclaw-plugin.
tetherto/qvac
Run the deterministic code-quality audit, turn related findings into contextual remediation groups, prepare approval-gated Asana proposals, reconcile recurring runs, or configure twice-monthly…
tetherto/qvac
Review C++ changes for string parameter and call-site efficiency conventions (std::stringview, std::string&&, const std::string&, const char, and TransparentStringMap lookup).
tetherto/qvac
Generate changelog entries for a target add-on package. An agent skill from tetherto/qvac.
Works with
Categories
Generate NOTICE files with third-party attributions for all packages in the monorepo. Qv Notice Generate is an agent skill from tetherto/qvac. Generate NOTICE files with third-party attributions for all packages in the monorepo.
Qv Notice Generate fits situations like: tasks that involve Monorepo tooling.
Run `npx skills add tetherto/qvac --skill qv-notice-generate -a claude-code`. Or copy the skill folder (.agents/skills/qv-notice-generate in tetherto/qvac) into .claude/skills/qv-notice-generate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tetherto/qvac --skill qv-notice-generate -a codex`. Or copy the skill folder (.agents/skills/qv-notice-generate in tetherto/qvac) into .agents/skills/qv-notice-generate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tetherto/qvac --skill qv-notice-generate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qv-notice-generate, .gemini/skills/qv-notice-generate, .github/skills/qv-notice-generate and .opencode/skills/qv-notice-generate in your project.
Going by SKILL.md and its folder, Qv Notice Generate needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and npm) and credentials named GH_TOKEN, HF_TOKEN and NPM_TOKEN. Our summary lists: Python 3; Node.js; A credential in NPM_TOKEN.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Qv Notice Generate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Qv Notice Generate: Cutting A Release (TriliumNext/Trilium, 38k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Create Vechain Dapp (vechain/x-app-template, 450 stars) and Dependabot Alerts Update (livesession/xyd, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tetherto (a GitHub organization) maintains it in tetherto/qvac, which has 685 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 10, 2026.
Source: tetherto/qvac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.