Agent skill

Release

by tetherto in tetherto/qvac

Release a package to NPM. An agent skill from tetherto/qvac.

Apache-2.0Auto-check: warningsDevelopment

Install Release

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add tetherto/qvac --skill release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tetherto/qvac release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/ocr-ggml/.agent/skills/release .claude/skills/release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release
GitHub stars
674
Token cost
~1.6k tokens
SKILL.md length
559 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
Apache-2.0

At a glance

Release a package to NPM. An agent skill from tetherto/qvac.

  • Works in 7 steps: Validate prerequisites → Confirm with user → Create release branch → …
  • Tasks that involve Changelog and release notes
  • SKILL.md covers Usage, Workflow, Error handling and Important notes
  • Calls npm, git and gh; reaches registry.npmjs.org; needs NPM_TOKEN

What it does

Release is an agent skill from tetherto/qvac. Release a package to NPM. Validates version bump, changelog, creates release branch, monitors CI, verifies publish.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes. It works with npm. The repository describes itself as: Open-source local AI SDK - run AI on-device with no cloud, no API keys. Supports GGUF, RAG, image, music, and video generation, speech-to-text, P2P inference, and more… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Changelog and release notes

Example prompts

  • “/release”

Requirements

  • Node.js
  • A credential in NPM_TOKEN

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Validate prerequisites
  2. Confirm with user
  3. Create release branch
  4. Monitor CI pipeline
  5. Verify npm publish
  6. Verify public access
  7. Switch back to main

What it can do on your machine

Read from SKILL.md and the folder at commit d92f697. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git
    • gh
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release loads about 1.6k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 559 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:129
    registry=https://registry.npmjs.org/" > .npmrc

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tetherto/qvac at commit d92f697, republished under its Apache-2.0 licence (© tetherto). 559 words, ~1,614 tokens.

Download SKILL.mdSave it as .claude/skills/release/SKILL.md (or your agent's skills folder).
name
release
description
Release a package to NPM. Validates version bump, changelog, creates release branch, monitors CI, verifies publish.
argument-hint
<package-name> [base-branch]
disable-model-invocation
true

Release Package

Release a package to NPM. Ensures version bump, changelog, release branch, CI pipeline, and npm publish.

The package is identified by the <package-name> argument, which is the directory name under packages/ (e.g., ocr-ggml, sdk, tts-ggml). The skill reads packages/<package-name>/package.json to determine the package type and npm scope.

Usage

/release <package-name> [base-branch]

Where:

  • <package-name> is the directory name under packages/ (e.g., ocr-ggml, tts-onnx)
  • [base-branch] is optional — the branch to create the release from. Defaults to main. Use this for patches, e.g., /release ocr-ggml release-ocr-ggml-0.11.0

Workflow

Step 1: Validate prerequisites
  1. Read packages/$ARGUMENTS/package.json to get the current version and npm package name.

  2. Compare version against the latest version published on npm:

    bash
    npm view <npm-package-name> version
  3. If the local version is not higher than the npm version, stop and ask the user to bump the version first.

  4. Verify the CHANGELOG heading format exactly matches what the publish-release workflow extracts. The workflow uses this awk regex: ^## \[<version>\] — heading must be bracketed (Keep-a-Changelog style). Soft phrasing like "section for 0.1.0" is not enough; the heading line must literally be ## [0.1.0].

    Run this exact check (mirrors the regex in .github/workflows/create-github-release.yml):

    bash
    version=$(node -p "require('./packages/<package>/package.json').version")
    if ! grep -qE "^## \[${version}\]" "packages/<package>/CHANGELOG.md"; then
      echo "FAIL: packages/<package>/CHANGELOG.md is missing a '## [${version}]' heading."
      echo "      A heading like '## ${version}' (no brackets) will NOT match — publish-release will fail."
      exit 1
    fi

    If the check fails, fix the heading or generate the section first:

    • For addon packages (native C++): run /qv-addon-changelog
    • For SDK pod packages (TypeScript): run /qv-sdk-changelog
Step 2: Confirm with user

Display a summary and ask for confirmation before proceeding:

Release summary:
  Package: <package>
  Version: <version>
  Branch:  release-<package>-<version>
  Target:  NPM (latest tag)

Proceed? (y/n)
Step 3: Create release branch
  1. Ensure we're on the base branch and up to date:
    bash
    git checkout <base-branch>
    git pull origin <base-branch>
    Where <base-branch> is determined in Step 1 (main for new releases, release-<package>-<base-version> for patches).
  2. Create the release branch:
    bash
    git checkout -b release-<package>-<version>
  3. Push the release branch to remote (required for workflow dispatch to find the ref):
    bash
    git push origin release-<package>-<version>
  4. Trigger the release workflow manually:
    bash
    gh workflow run "on-merge-<package>.yml" --repo tetherto/qvac --ref release-<package>-<version>

This workflow:

  • Runs release-merge-guard (validates version bump + changelog)
  • Builds prebuilds across platforms
  • Publishes to NPM with latest tag
  • Creates a GitHub release with tag <package>-v<version>
Step 4: Monitor CI pipeline

Use /loop to poll the pipeline status every 2 minutes:

/loop 2m Check the CI pipeline status for the release branch release-<package>-<version>. Run: gh run list --branch release-<package>-<version> --limit 5. If all runs completed successfully, report SUCCESS and stop. If any run failed, report the failure details. If still running, report progress.
Show full SKILL.md (259 more words)Show less
Step 5: Verify npm publish

Once CI completes successfully:

  1. Check that the package was published to npm:

    bash
    npm view @qvac/<package>@<version> version

    (Note: some packages may not have the @qvac/ scope — check package.json for the actual package name)

  2. Check that the GitHub release was created:

    bash
    gh release view <package>-v<version>
  3. Report final status to user:

    Release complete:
      Package: <npm-package-name>@<version>
      NPM: published
      GitHub Release: <package>-v<version>
      Branch: release-<package>-<version>
Step 6: Verify public access

Verify the published package is publicly accessible without authentication by installing it in a clean temp directory with no npm token:

bash
# Create a temp directory and install without any auth
TMPDIR=$(mktemp -d)
cd $TMPDIR
echo "registry=https://registry.npmjs.org/" > .npmrc
npm install <npm-package-name>@<version> --ignore-scripts --no-package-lock

If the install succeeds, the package is publicly accessible. If it fails with a 401/403, the package may still be private — flag this to the user.

Sanity checks on the installed package:

bash
# Verify the tarball contents look correct
npm pack <npm-package-name>@<version> --pack-destination $TMPDIR
tar tf $TMPDIR/<tarball-filename> | head -20

# Check that key files are present in the installed package:
ls $TMPDIR/node_modules/<npm-package-name>/
# Expected: package.json, README.md, index.js (or similar entry point), prebuilds/ (for addons)

# Verify package.json version matches
node -e "console.log(require('$TMPDIR/node_modules/<npm-package-name>/package.json').version)"

Clean up:

bash
rm -rf $TMPDIR

If any check fails, report the issue to the user before proceeding.

Step 7: Switch back to main
bash
git checkout main

Error handling

  • If release-merge-guard fails: the version or changelog is missing/incorrect. Fix and re-trigger the workflow.
  • If prebuild jobs fail: check the failing platform logs with gh run view <run-id> --log-failed.
  • If npm publish fails: check if the version already exists (npm view), or if NPM_TOKEN is valid.
  • If the release branch already exists: ask the user whether to use the existing branch or abort.

Important notes

  • This skill creates a local release branch, pushes it to remote, and triggers CI manually.
  • The on-merge workflow handles building and publishing — do not manually publish.
  • Release branches are never merged back to main automatically. If main needs the changes, a separate PR is required.

© tetherto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/ocr-ggml/.agent/skills/release of tetherto/qvac.

Open the folder on GitHubat commit d92f697

Compare with similar skills

Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release this skilltetherto/qvac674—~1.6kAutomated safety check: WarnApache-2.0
Phoenix Release NotesArize-ai/phoenix12k—~6.7kAutomated safety check: PassCustom licence
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Hunk Release Workflowmodem-dev/hunk9.5k—~3.8kAutomated safety check: PassMIT
Version ReleaseNG-ZORRO/ng-zorro-antd9.2k—~3.1kAutomated safety check: PassMIT

Similar skills

  • Phoenix Release Notes

    Arize-ai/phoenix

    Create Phoenix release documentation grounded in actual code changes.

    12k GitHub stars~6.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.5k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Version Release

    NG-ZORRO/ng-zorro-antd

    NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.

    9.2k GitHub stars~3.1k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • AionUi Version Bump

    iOfficeAI/AionUi

    Automates an AionUi release: checks the latest AionCore release and its artifacts, updates package.json, writes the changelog, opens a PR and tags the release.

    33k GitHub stars~2.1k tokensUpdated 28 days ago
    DevelopmentAuto-check passed

More from tetherto/qvac

All 50 skills in this repo
  • Creates a Solutions page in the QVAC documentation website from a real use case, generalizing the case into reusable guidance and registering the page in the site navigation.

    674 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Qv Docs Update

    tetherto/qvac

    Updates the docs website after a change to the SDK or CLI. An agent skill from tetherto/qvac.

    674 GitHub stars~11k tokensUpdated today
    Auto-check passed
  • Qv Agent Stack Sync

    tetherto/qvac

    Plan and prepare the QVAC agent-stack release cascade across @qvac/inference, @qvac/sdk, @qvac/cli, @qvac/ai-sdk-provider, @qvac/opencode-plugin, and @qvac/openclaw-plugin.

    674 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Run the deterministic code-quality audit, turn related findings into contextual remediation groups, prepare approval-gated Asana proposals, reconcile recurring runs, or configure twice-monthly…

    674 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Review C++ changes for string parameter and call-site efficiency conventions (std::stringview, std::string&&, const std::string&, const char, and TransparentStringMap lookup).

    674 GitHub stars~702 tokensUpdated today
    Auto-check passed
  • Qv Addon Changelog

    tetherto/qvac

    Generate changelog entries for a target add-on package. An agent skill from tetherto/qvac.

    674 GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Works with

Questions about Release

What does Release do?

Release a package to NPM. An agent skill from tetherto/qvac. Release is an agent skill from tetherto/qvac. Release a package to NPM.

When should I use Release?

Release fits situations like: tasks that involve Changelog and release notes.

How do I install Release in Claude Code?

Run `npx skills add tetherto/qvac --skill release -a claude-code`. Or copy the skill folder (packages/ocr-ggml/.agent/skills/release in tetherto/qvac) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.

How do I install Release in Codex?

Run `npx skills add tetherto/qvac --skill release -a codex`. Or copy the skill folder (packages/ocr-ggml/.agent/skills/release in tetherto/qvac) into .agents/skills/release in your project. Codex loads it when a task matches its description.

Can I use Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tetherto/qvac --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.

What does Release need to run?

Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (npm, git, gh and node) and credentials named NPM_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN.

Does Release access the network?

SKILL.md names 1 domain. In commands or code: registry.npmjs.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Release safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Release use?

Release is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release?

Skills that share tags, products or a category with Release: Phoenix Release Notes (Arize-ai/phoenix, 12k stars), Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars) and Hunk Release Workflow (modem-dev/hunk, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release?

tetherto (a GitHub organization) maintains it in tetherto/qvac, which has 674 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 7, 2026.

Source: tetherto/qvac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.