Cutting A Release
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
Cut a stable GitHub release or prerelease directly from a Tracecat release branch, including the version bump, tag, image verification, and categorized release notes.
$ npx skills add TracecatHQ/tracecat --skill gh-release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TracecatHQ/tracecat gh-release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TracecatHQ/tracecat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/gh-release .claude/skills/gh-release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gh-release" agent skill from https://github.com/TracecatHQ/tracecat/tree/main/.agents/skills/gh-release into .claude/skills/gh-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gh-release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TracecatHQ/tracecat/tree/main/.agents/skills/gh-releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TracecatHQ/tracecat --skill gh-release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TracecatHQ/tracecat gh-release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TracecatHQ/tracecat.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/gh-release .agents/skills/gh-release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gh-release" agent skill from https://github.com/TracecatHQ/tracecat/tree/main/.agents/skills/gh-release into .agents/skills/gh-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gh-release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TracecatHQ/tracecat --skill gh-release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TracecatHQ/tracecat gh-release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TracecatHQ/tracecat.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/gh-release .cursor/skills/gh-release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gh-release" agent skill from https://github.com/TracecatHQ/tracecat/tree/main/.agents/skills/gh-release into .cursor/skills/gh-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gh-release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TracecatHQ/tracecat.git --path .agents/skills/gh-release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TracecatHQ/tracecat --skill gh-release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TracecatHQ/tracecat gh-release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TracecatHQ/tracecat.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/gh-release .gemini/skills/gh-release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gh-release" agent skill from https://github.com/TracecatHQ/tracecat/tree/main/.agents/skills/gh-release into .gemini/skills/gh-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gh-release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TracecatHQ/tracecat gh-releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TracecatHQ/tracecat --skill gh-release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TracecatHQ/tracecat.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/gh-release .github/skills/gh-release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gh-release" agent skill from https://github.com/TracecatHQ/tracecat/tree/main/.agents/skills/gh-release into .github/skills/gh-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gh-release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TracecatHQ/tracecat --skill gh-release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TracecatHQ/tracecat gh-release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TracecatHQ/tracecat.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/gh-release .opencode/skills/gh-release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gh-release" agent skill from https://github.com/TracecatHQ/tracecat/tree/main/.agents/skills/gh-release into .opencode/skills/gh-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gh-release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gh-releaseCut a stable GitHub release or prerelease directly from a Tracecat release branch, including the version bump, tag, image verification, and categorized release notes.
Gh Release is an agent skill from TracecatHQ/tracecat. Cut a stable GitHub release or prerelease directly from a Tracecat release branch, including the version bump, tag, image verification, and categorized release notes.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Changelog and release notes. It works with GitHub. The repository describes itself as: Open-source security automation platform for teams and AI agents. The licence is AGPL-3.0.
Read from SKILL.md and the folder at commit a01d80b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgituvjustFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, git and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gh Release loads about 3.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 1,711 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from TracecatHQ/tracecat at commit a01d80b, republished under its AGPL-3.0 licence (© TracecatHQ). 1,711 words, ~3,090 tokens.
.claude/skills/gh-release/SKILL.md (or your agent's skills folder).Cut a release directly from a release branch. Do not open a release PR, merge the
release branch into main, or advance main to record a release. Follow the
version policy in CONTRIBUTING.md.
Parse $ARGUMENTS as <tag> [<commit>]. Tags are bare public versions without
v: 1.2.0-alpha.1, 1.2.0-alpha.1.1, 1.2.0-rc.1, 1.2.0, or 1.2.1.
Validate numeric components without leading zeros. Prereleases use alpha.N,
alpha.N.M (a hotfix of alpha N), or rc.N and only attach to a .0.
Stable patches increment the patch component. If no tag was given, inspect
published releases and ask which version to cut. Do not infer permission to
publish from a request to inspect or prepare a release.
X.Y.0-alpha.N starts from the chosen merged main
commit (default origin/main) on release/X.Y.0-alpha.N.X.Y.0-alpha.N.M reuses release/X.Y.0-alpha.N. Require the
existing branch and a published alpha on that line; no stable release is
required. Cherry-pick fixes onto it and add successive immutable tags. Never
create a branch per hotfix or start the hotfix from newer main code.
For example, 1.1.0-alpha.1.1 and 1.1.0-alpha.1.2 both use
release/1.1.0-alpha.1; 1.1.0-alpha.2 starts a new alpha line from main.release/<major>.<minor> from the chosen merged main
commit. RCs, stable minors, and subsequent patches use that train branch.main or create a patch
branch from newer trunk code.main
first and were cherry-picked onto the release branch. Verify the full diff
from the previous release: no migration changes, database-schema changes,
backfills, or new registry actions. If a fix depends on those changes,
exclude it rather than pulling its feature dependencies into the patch.Resolve the selected commit to an immutable COMMIT_SHA and the branch to
BRANCH. A new alpha line's base or a new train's base must be reachable from
origin/main; hotfix commits instead descend from their release branch and
retain the source commits' cherry-pick provenance. Do not release an unmerged
PR. Check the selected commit's CI and stop on missing or failing evidence
unless the user explicitly accepts it.
Verify the selected branch contains the stable-only image guard and the current
release workflow before cutting its tag; old train branches may need those
changes cherry-picked first.
Fetch branches and tags, inspect the working tree, and verify the public tag is absent locally, remotely, and from GitHub releases. Distinguish a missing release from an API/authentication error. If the tag exists, stop; never move it.
A new alpha line's branch must be absent remotely and locally. For an alpha hotfix or an existing frozen train, reuse the existing release branch; create a train branch only at its initial freeze. Preserve any prepared local cherry-picks and verify they fast-forward the remote tip before pushing. Use an isolated worktree if the branch is checked out elsewhere. Do not stash, reset, or overwrite unrelated working changes.
Every patch release, including alpha hotfixes (X.Y.0-alpha.N.M) and stable
patches (X.Y.Z, where Z > 0), must pass this gate before any version bump,
release commit, push, tag, image build/rebuild, or publication. Prerelease
status does not exempt a patch. Never deploy a patch that violates this
invariant; deployment remains outside this skill's scope.
Resolve and pin PREV_TAG using the published-release baseline rules in
Release notes below, before mutation. Require it to be an ancestor of
COMMIT_SHA. Compare the complete release trees, not just the latest commit
or the cherry-picked fixes:
git diff --name-status "$PREV_TAG" "$COMMIT_SHA" -- alembic/versions/
git diff "$PREV_TAG" "$COMMIT_SHA"Any added, modified, deleted, or renamed migration is a hard blocker, including edits to an already-published migration. Inspect the full diff for migrations outside that directory, database-schema changes, and data backfills; those also block the patch. Existing migrations unchanged from the baseline are allowed. If the baseline or inspection cannot be verified, stop.
On a blocker, refuse the patch release and report the baseline, candidate SHA, and offending files. Release approval, urgency, successful CI, or claims that a migration is safe do not waive this invariant. Exclude the change and its dependencies from the patch, or propose a separately approved non-patch release. Never silently change the requested version to bypass the gate.
Before mutation, show:
latest; prereleases leave latest unchanged.
This policy permits an older train's stable hotfix to become latest.Wait for explicit confirmation unless the user already approved this exact release plan. Approval to merge or fix a PR is not release authorization.
Create or switch to BRANCH at the verified commit. Run
just update-version <tag> and answer its overwrite prompt only for the
approved release. It writes the public tag to __version__ and its PEP 440
value to __pep440_version__ (for example, 1.2.0-alpha.1 becomes 1.2.0a1,
and 1.2.0-alpha.1.2 becomes 1.2.0a1.post2).
Verify both application and registry versions agree, and validate the Python
version with packaging.version.Version through uv run python.
Review the generated diff and, for a patch, repeat the migration gate against
the final release tree (including all version-bump edits) before committing or
pushing. Stage only the changed files individually, and
create a signed release: <tag> commit. Never bypass hooks or signing. Push
BRANCH. For a prerelease, record both current latest image digests before
pushing the tag. Create an annotated <tag> on the version-bump commit and push
it. No merge to main is involved. Leave the branch in place.
Tag push triggers .github/workflows/build-push-images.yml. Find the run whose
tag and headSha match the new release commit, then watch it to successful
completion. Inspect both multi-platform manifests and their version/revision
labels. For a prerelease, compare both latest digests before and after the
build; for a stable release, verify latest points to the new image manifests.
If image publication fails, stop before creating the GitHub release. Report the
existing branch/tag and failed run; never move the tag or automatically cut a
replacement. To rebuild, use a separate trusted, updated main checkout and run:
uv run python scripts/rebuild_release_images.py '<tag>'The helper requires the remote tag's workflow to exactly match the committed
publisher in that checkout before dispatching with the tag as both ref and
input. An older tag runs its own historical workflow, so guards on main
cannot protect a direct dispatch or rerun. On a mismatch or lookup failure,
stop; never bypass the helper or move the tag. A new release containing the
current publisher requires a separately approved release plan. For a retry,
verify the run ID, event, and release commit rather than accepting an older
successful run.
Resolve PREV_TAG from published releases, paginating the full list. For an
alpha hotfix, use the previous published hotfix on the same alpha.N line,
or its original alpha tag for the first hotfix. For 1.1.0-alpha.1.2, the
baseline is 1.1.0-alpha.1.1, even if 1.1.0-alpha.2 has already shipped.
Verify the baseline is an ancestor of the selected release commit.
For other releases, use the previous version on the same major/minor train,
ordered by semantic version (alpha before RC before stable, then patches).
For the first alpha of a new train, use the preceding stable version. If a
train skips alphas, its first
release also uses the preceding stable version. Never pick an unrelated train
merely because it was published most recently. If there is no unambiguous
baseline, ask before publication.
Pin the range to PREV_TAG..<tag>. The draft maintained on main is not a
release branch's changelog; do not publish or consume that draft.
Generate raw notes with explicit tag_name, previous_tag_name, and the
version-bump commit as target_commitish:
REPO=$(gh repo view --json nameWithOwner --jq .nameWithOwner)
RAW_NOTES=$(gh api "repos/$REPO/releases/generate-notes" \
--method POST \
-f tag_name='<tag>' \
-f previous_tag_name="$PREV_TAG" \
-f target_commitish='<release-commit>')Extract PR numbers from the returned body and retrieve their titles and labels. For cherry-picked fixes, verify that the notes include the original merged PRs represented in the commit range, even if GitHub omits their associations.
Read .github/release-drafter.yml and derive the buckets from it. Do not copy
the category list into this skill: the last copy drifted, and a stale copy
silently files changes under headings the real release notes do not have.
From that file you need:
exclude-labels: drop any PR carrying one of these.categories, in order: bucket each remaining PR into the first category
whose labels intersect the PR's labels. Use the category's title
verbatim.Anything left with no matching label goes under a trailing Other section. Do not silently drop PRs.
Format each entry as - <title> (#<number>), matching the config's
change-template, then apply every rule in the config's replacers: to the
assembled body, in order. Read them from the file the way you read
categories:; do not restate them here.
They are not cosmetic, and they are not only scope aliases. They rewrite the
type prefix too -- chore(deps) and fix(deps) become build(deps), a scope
that merely repeats its type is dropped, feat!(api) moves the bang to
feat(api)! -- and they capitalize the first letter of most descriptions.
Three shapes are spared, and the config lists them: a first word holding _ or
., a first word with a capital after its first letter, and an explicit list of
lowercase names that must not be Title-cased. Read the guard from the file
rather than reasoning about which of the three applies.
Skip the replacers and this skill's output disagrees with the stable release notes for the same commits.
Write the categorized Markdown and a PREV_TAG...<tag> comparison link to a
temporary notes file. Publish the existing tag using --verify-tag, so a typo
cannot create a tag on the default branch:
# Stable release:
gh release create '<tag>' --verify-tag --latest \
--title 'Tracecat <tag>' --notes-file "$BODY_FILE"
# Prerelease:
gh release create '<tag>' --verify-tag --prerelease --latest=false \
--title 'Tracecat <tag>' --notes-file "$BODY_FILE"Run only the command for the approved release type. If the range contains no
changes, state No changes since <PREV_TAG>. rather than reusing older notes.
Report the branch, immutable tag/commit, GitHub release URL, image-build run, and manifest verification. Never delete the alpha-line or train branch, force-push, amend existing release commits, or deploy as part of this skill. If signing or a publication step fails, stop and report the concrete state before attempting further external mutations.
© TracecatHQ, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/gh-release of TracecatHQ/tracecat.
Open the folder on GitHubat commit a01d80b
Gh Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gh Release this skillTracecatHQ/tracecat | 3.8k | — | ~3.1k | Automated safety check: Pass | AGPL-3.0 | |
| Cutting A ReleaseTriliumNext/Trilium | 38k | — | ~3.2k | Automated safety check: Pass | AGPL-3.0 | |
| Mole CLI Release Flowtw93/Mole | 69k | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | |
| Draft Release Notesjamiepine/voicebox | 57k | — | ~941 | Automated safety check: Pass | MIT | |
| Mole Release Notes Publishertw93/Mole | 69k | — | ~1.9k | Automated safety check: Pass | GPL-3.0 | |
| Release Bumpjamiepine/voicebox | 57k | — | ~1.1k | Automated safety check: Pass | MIT |
TriliumNext/Trilium
A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.
tw93/Mole
Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.
jamiepine/voicebox
Writes or refreshes the Unreleased section of CHANGELOG.md as a themed narrative built from the commits, PRs and diff since the last version tag.
tw93/Mole
Publishes curated, bilingual release notes for an existing Mole version tag with gh release edit, including contributor thanks and reactions, after the release workflow finishes.
jamiepine/voicebox
Ends a release cycle by moving the Unreleased changelog notes under a dated version heading, bumping version files with bumpversion and tagging the commit.
jfernandez/bpftop
Cut a new versioned release of bpftop — pick the version, open a version-bump PR, sign-tag the merge commit on main, and draft GitHub release notes in the project's established format.
TracecatHQ/tracecat
A skill your agent uses when adding or updating documentation pages in an existing docs site.
TracecatHQ/tracecat
Create, retitle, or label a pull request for the current branch.
TracecatHQ/tracecat
QA Tracecat product features in a real local cluster. An agent skill from TracecatHQ/tracecat.
Works with
Categories
Cut a stable GitHub release or prerelease directly from a Tracecat release branch, including the version bump, tag, image verification, and categorized release notes. Gh Release is an agent skill from TracecatHQ/tracecat. Cut a stable GitHub release or prerelease directly from a Tracecat release branch, including the version bump, tag, image verification, and categorized release notes.
Gh Release fits situations like: tasks that involve Changelog and release notes.
Run `npx skills add TracecatHQ/tracecat --skill gh-release -a claude-code`. Or copy the skill folder (.agents/skills/gh-release in TracecatHQ/tracecat) into .claude/skills/gh-release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TracecatHQ/tracecat --skill gh-release -a codex`. Or copy the skill folder (.agents/skills/gh-release in TracecatHQ/tracecat) into .agents/skills/gh-release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TracecatHQ/tracecat --skill gh-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gh-release, .gemini/skills/gh-release, .github/skills/gh-release and .opencode/skills/gh-release in your project.
Going by SKILL.md and its folder, Gh Release needs the command-line tools its instructions call (gh, git, uv and just). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use gh, git and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gh Release is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gh Release: Cutting A Release (TriliumNext/Trilium, 38k stars), Mole CLI Release Flow (tw93/Mole, 69k stars), Draft Release Notes (jamiepine/voicebox, 57k stars) and Mole Release Notes Publisher (tw93/Mole, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TracecatHQ (a GitHub organization) maintains it in TracecatHQ/tracecat, which has 3,824 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.
Source: TracecatHQ/tracecat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.