Agent skill

Plugin Version Bump and Release

by thedotmack in thedotmack/claude-mem

Runs a semantic-versioning release workflow for a Claude Code plugin: bumps every manifest, builds, tags, creates a GitHub release, generates a changelog and publishes to npm.

Apache-2.0Auto-check: warningsDevelopment

Install Plugin Version Bump and Release

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add thedotmack/claude-mem --skill version-bump -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install thedotmack/claude-mem version-bump --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/thedotmack/claude-mem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugin/skills/version-bump .claude/skills/version-bump && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
version-bump
GitHub stars
98k
Token cost
~1.7k tokens
SKILL.md length
766 words
Files
2 (incl. scripts)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs a semantic-versioning release workflow for a Claude Code plugin: bumps every manifest, builds, tags, creates a GitHub release, generates a changelog and publishes to npm.

  • Works in 3 steps: Analyze: Determine if the change is… → Environment: Identify repository… → Paths — every file that carries the…
  • Releasing a new version of a Claude Code plugin
  • SKILL.md covers Preparation, Workflow and Checklist
  • Runs JavaScript scripts from its folder; calls git, npm and npx; reaches registry.npmjs.org; needs NPM_TOKEN

What it does

The skill starts by classifying the change as patch, minor or major and reading the repository owner from the git remote. It then lists every file that carries the version string: the root and plugin package.json files, manifests for Claude, Codex, OpenClaw, Grok and Cursor plugins, another bundled package, and the README version badge. A git grep check before and after editing confirms that all twelve JSON files and the badge match, and CHANGELOG.md is left alone because it is regenerated. The file list is written for the claude-mem repository.

The workflow then runs npm run build-and-sync, commits everything including build artifacts, and tags the release, while scripts/generate_changelog.js produces the changelog. The skill insists that nothing stays uncommitted or unpushed and that git status is checked at the end. It finishes with the agent running npm publish itself using the maintainer's npm token, so it needs publish credentials and affects a public package.

When your agent uses it

  • Releasing a new version of a Claude Code plugin
  • Bumping the version across every plugin manifest and the README badge
  • Generating a changelog and GitHub release for a tagged version

Example prompts

  • “Do a minor release of this plugin and write the release notes first.”
  • “Bump the version everywhere, tag it and generate the changelog, but stop before npm publish.”
  • “Check that every manifest carries the new version string.”

Requirements

  • Git with a GitHub remote
  • Node.js and npm, plus the maintainer's npm token for publishing

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Analyze: Determine if the change is PATCH (bug fixes), MINOR (features), or MAJOR (breaking).
  2. Environment: Identify repository owner/name from git remote -v.
  3. Paths — every file that carries the version string

What it can do on your machine

Read from SKILL.md and the folder at commit 71ddd11. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • npm
    • npx
    • gh
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • registry.npmjs.org

    Also links to:

    • npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plugin Version Bump and Release loads about 1.7k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 766 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:56
    in the maintainer's Mac `~/.npmrc`; he issues a new one every month. It is
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:68
    <url>`), replace the token value in `~/.npmrc` with
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:69
    `PASTE_NEW_TOKEN_HERE`, and `open -e ~/.npmrc` so he can paste the new token
  • NoteMentions a .env fileSKILL.md:83
    from `~/Scripts/claude-mem/`, where the `.env` with
  • NoteMentions a .env fileSKILL.md:89
    not have a local `.env`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from thedotmack/claude-mem at commit 71ddd11, republished under its Apache-2.0 licence (© thedotmack). 766 words, ~1,664 tokens.

Download SKILL.mdSave it as .claude/skills/version-bump/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
version-bump
description
Automated semantic versioning and release workflow for Claude Code plugins. Handles version increments across package.json, marketplace.json, plugin.json manifests, build verification, git tagging, GitHub releases, and changelog generation. Ends with the agent running npm publish itself using the maintainer's npm token.

Version Bump & Release Workflow

IMPORTANT: Plan and write detailed release notes before starting.

CRITICAL: Commit EVERYTHING (including build artifacts). At the end of this workflow, NOTHING should be left uncommitted or unpushed. Run git status at the end to verify.

Preparation

  1. Analyze: Determine if the change is PATCH (bug fixes), MINOR (features), or MAJOR (breaking).

  2. Environment: Identify repository owner/name from git remote -v.

  3. Paths — every file that carries the version string:

    • package.json — the npm/npx-published version (npx claude-mem@X.Y.Z resolves from this)
    • plugin/package.json — bundled plugin runtime deps
    • .claude-plugin/marketplace.json — version inside plugins[0].version
    • .claude-plugin/plugin.json — top-level Claude-plugin manifest
    • plugin/.claude-plugin/plugin.json — bundled Claude-plugin manifest
    • .codex-plugin/plugin.json — Codex-plugin manifest
    • plugin/.codex-plugin/plugin.json — bundled Codex-plugin manifest
    • openclaw/openclaw.plugin.json — OpenClaw plugin manifest
    • .grok-plugin/plugin.json — Grok plugin manifest
    • claude-mem-cursor/.cursor-plugin/plugin.json — Cursor plugin manifest
    • claude-mem-grok-bot/.cursor-plugin/plugin.json — Grok Bot Cursor plugin manifest
    • dsh/package.json — bundled DSH plugin package
    • README.md — the version badge (version-X.Y.Z-green), not a "version" key

    Verify coverage before editing: git grep -l "\"version\": \"<OLD>\"" should list the twelve JSON files above, and git grep -n "version-<OLD>-green" the README badge. If a new manifest has been added since this doc was last updated, update this list.

Workflow

  1. Update: Increment the version string in every path above. Do NOT touch CHANGELOG.md — it's regenerated.
  2. Verify: git grep -n "\"version\": \"<NEW>\"" — confirm all twelve JSON files match, and the README badge reads version-<NEW>-green. git grep -n "\"version\": \"<OLD>\"" — should return zero hits.
  3. Build and sync: npm run build-and-sync to regenerate artifacts, sync the local marketplace copy, restart the worker, and clear the queue. Do not use plain npm run build for release validation because it can leave the local marketplace/worker out of sync.
  4. Commit: git add -A && git commit -m "chore: bump version to X.Y.Z".
  5. Tag: git tag -a vX.Y.Z -m "Version X.Y.Z".
  6. Push: git push origin main && git push origin vX.Y.Z.
  7. GitHub release: gh release create vX.Y.Z --title "vX.Y.Z" --notes "RELEASE_NOTES".
  8. Changelog: Regenerate via the project's changelog script:
    bash
    npm run changelog:generate
    (Runs node scripts/generate-changelog.js, which pulls releases from the GitHub API and rewrites CHANGELOG.md.)
  9. Sync changelog: Commit and push the updated CHANGELOG.md.
  10. Pre-publish audit: Verify the release commit, tag, GitHub release, and changelog are pushed; confirm the release worktree has no pending tracked changes; and ensure its build dependencies are present because prepublishOnly rebuilds the package. If npm view claude-mem@X.Y.Z version already resolves, skip the publish and continue with post-publish checks.
  11. Publish to npm — the agent runs it. The old "human handoff" rule is obsolete: the maintainer allows agents to publish. The token is a 30-day granular npm token (read/write on claude-mem only, bypass 2FA) in the maintainer's Mac ~/.npmrc; he issues a new one every month. It is deliberately NOT in any backup (grok-bot-backups excludes secrets), so do not go looking for it elsewhere. Publish from a clean worktree of the tag (inside the project's .scratch/) so uncommitted edits never ship:
    bash
    git worktree add --detach .scratch/release-X.Y.Z vX.Y.Z
    cd .scratch/release-X.Y.Z && npm install --ignore-scripts
    npm whoami                    # must print thedotmack; 401 = token expired
    npm publish --access public   # prepublishOnly rebuilds the package
    If npm whoami fails, the monthly token has expired. Finish every other step, then: open https://www.npmjs.com/settings/thedotmack/tokens/granular-access-tokens/new for the maintainer (open <url>), replace the token value in ~/.npmrc with PASTE_NEW_TOKEN_HERE, and open -e ~/.npmrc so he can paste the new token there. Never ask for the token in chat. Re-run npm whoami, then publish. Do not wait on .github/workflows/npm-publish.yml — its NPM_TOKEN secret has failed every tag since v13.26.1 (E404 ... PUT https://registry.npmjs.org/claude-mem). The publish rebuild rewrites plugin/scripts/*.cjs with minifier-name churn only; discard it with the worktree (git worktree remove --force).
  12. Post-publish verification and notification: After publishing, verify both the exact version and the latest dist-tag:
    bash
    npm view claude-mem@X.Y.Z version
    npm view claude-mem version
    If the publish build touched tracked artifacts, run npm run build-and-sync, review the result, and commit/push any legitimate changes. Then run the Discord notification from ~/Scripts/claude-mem/, where the .env with webhook details lives:
    bash
    cd ~/Scripts/claude-mem/ && npm run discord:notify vX.Y.Z
    Do this only after npm verification, and even when the release worktree does not have a local .env.
  13. Finalize: git status — working tree must be clean and everything must be pushed.
Show full SKILL.md (78 more words)Show less

Checklist

  • All thirteen version files (twelve JSON manifests and the README badge) have matching versions
  • git grep for old version returns zero hits
  • npm run build-and-sync succeeded
  • Git tag created and pushed
  • GitHub release created with notes
  • CHANGELOG.md updated and pushed
  • Pre-publish audit passed
  • npm whoami succeeded and the agent ran npm publish --access public
  • Exact npm version and latest both verified after publishing
  • Discord notification run from ~/Scripts/claude-mem/ only after npm verification
  • git status shows clean tree

© thedotmack, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in plugin/skills/version-bump of thedotmack/claude-mem.

  • SKILL.md
  • scripts/generate_changelog.js

Open the folder on GitHubat commit 71ddd11

Compare with similar skills

Plugin Version Bump and Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Version Bump and Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Version Bump and Release this skillthedotmack/claude-mem98k—~1.7kAutomated safety check: WarnApache-2.0
Hunk Release Workflowmodem-dev/hunk9.5k—~3.8kAutomated safety check: PassMIT
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
ClawRouter Release ChecklistBlockRunAI/ClawRouter6.6k—~1.4kAutomated safety check: PassMIT
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Release Clawpatchopenclaw/clawpatch813—~1.1kAutomated safety check: PassMIT

Similar skills

  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.5k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • ClawRouter Release Checklist

    BlockRunAI/ClawRouter

    Walks the agent through every ClawRouter release step in order, from the version bump and changelog entry to build, tests, npm publish, git tag and GitHub release.

    6.6k GitHub stars~1.4k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release Clawpatch

    openclaw/clawpatch

    clawpatch release: version/changelog, CI, npm publish, GitHub release, verify.

    813 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Release

    OvenMediaLabs/OvenPlayer

    Release ovenplayer to npm — confirm the version, verify the committed dist/ bundle is current, write the release notes, and open a draft GitHub Release for the user to publish.

    592 GitHub stars~1.3k tokensUpdated 25 days ago
    DevelopmentAuto-check passed

More from thedotmack/claude-mem

All 26 skills in this repo
  • Walks you through creating, installing and verifying a custom claude-mem mode, including note types, tags and optional Telegram alerts for chosen memories.

    98k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Claude-Mem Cloud Sync

    thedotmack/claude-mem

    Checks claude-mem cloud sync status and guides you through connecting a cmem.ai Pro account without the sync token ever passing through the chat.

    98k GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Claude-Mem Search

    thedotmack/claude-mem

    Searches the user's persistent cross-session memory for timestamped observations synthesized from past agent sessions on cmem.ai.

    98k GitHub starsUsed in 1 repo~511 tokens
    Auto-check passed
  • Claude-Mem Cowork Pairing

    thedotmack/claude-mem

    Pairs the claude-mem Cowork plugin with a cmem.ai account by writing the sync token, user id and SyncHub URL into the plugin config without exposing the secret.

    98k GitHub starsUsed in 1 repo~659 tokens
    Auto-check passed
  • Project Timeline Report

    thedotmack/claude-mem

    Writes a narrative Journey Into report on a project's whole development history, built from the timeline that claude-mem has recorded.

    98k GitHub starsUsed in 1 repo~3.1k tokens
    Auto-check passed
  • Pull Request Babysitter

    thedotmack/claude-mem

    Keeps watching a pull request, fixing real review and CI problems and resolving stale threads, until it is clean and ready to merge.

    98k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Plugin Version Bump and Release

What does Plugin Version Bump and Release do?

Runs a semantic-versioning release workflow for a Claude Code plugin: bumps every manifest, builds, tags, creates a GitHub release, generates a changelog and publishes to npm. The skill starts by classifying the change as patch, minor or major and reading the repository owner from the git remote.json files, manifests for Claude, Codex, OpenClaw, Grok and Cursor plugins, another bundled package, and the README version badge.

When should I use Plugin Version Bump and Release?

Plugin Version Bump and Release fits situations like: releasing a new version of a Claude Code plugin; bumping the version across every plugin manifest and the README badge; generating a changelog and GitHub release for a tagged version.

How do I install Plugin Version Bump and Release in Claude Code?

Run `npx skills add thedotmack/claude-mem --skill version-bump -a claude-code`. Or copy the skill folder (plugin/skills/version-bump in thedotmack/claude-mem) into .claude/skills/version-bump in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Version Bump and Release in Codex?

Run `npx skills add thedotmack/claude-mem --skill version-bump -a codex`. Or copy the skill folder (plugin/skills/version-bump in thedotmack/claude-mem) into .agents/skills/version-bump in your project. Codex loads it when a task matches its description.

Can I use Plugin Version Bump and Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thedotmack/claude-mem --skill version-bump -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/version-bump, .gemini/skills/version-bump, .github/skills/version-bump and .opencode/skills/version-bump in your project.

What does Plugin Version Bump and Release need to run?

Going by SKILL.md and its folder, Plugin Version Bump and Release needs JavaScript for the scripts in its folder, the command-line tools its instructions call (git, npm, npx, gh and node) and credentials named NPM_TOKEN. Our summary lists: Git with a GitHub remote; Node.js and npm, plus the maintainer's npm token for publishing.

Does Plugin Version Bump and Release access the network?

SKILL.md names 2 domains. In commands or code: registry.npmjs.org; the agent is likely to contact it when it follows the instructions. As links in the text: npmjs.com. This is read from the text; nothing was executed.

Is Plugin Version Bump and Release safe to install?

Our automated static check of SKILL.md flagged 3 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Plugin Version Bump and Release use?

Plugin Version Bump and Release is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Version Bump and Release use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Plugin Version Bump and Release?

Skills that share tags, products or a category with Plugin Version Bump and Release: Hunk Release Workflow (modem-dev/hunk, 9.5k stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars), ClawRouter Release Checklist (BlockRunAI/ClawRouter, 6.6k stars) and Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Version Bump and Release?

thedotmack (a GitHub user) maintains it in thedotmack/claude-mem, which has 97,851 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: thedotmack/claude-mem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.