Agent skill

Publish npm Release

by user-w-ui in user-w-ui/search-before-build

Publish a completed npm package from the current repository.

MITAuto-check passed

Install Publish npm Release

skills CLI
$ npx skills add user-w-ui/search-before-build --skill publish-npm-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install user-w-ui/search-before-build publish-npm-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/user-w-ui/search-before-build.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/publish-npm-release .claude/skills/publish-npm-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
publish-npm-release
GitHub stars
129
Token cost
~912 tokens
SKILL.md length
476 words
Files
2
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Publish a completed npm package from the current repository.

  • Works in 4 steps: Read package.json to obtain the package… → Run npm whoami, then query the registry… → Select the target version from registry… → …
  • Code changes are finished and npm authentication is ready
  • SKILL.md covers Version policy, Validate and commit, Tag and publish and Stop conditions
  • Calls npm and git

What it does

Publish npm Release is an agent skill from user-w-ui/search-before-build. Publish a completed npm package from the current repository. Use when code changes are finished and npm authentication is ready, and Codex should inspect the registry, synchronize release versions, validate, commit, tag, push, and publish a new stable npm version.

Its SKILL.md is about 910 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It works with npm. The repository describes itself as: 一个面向 Coding Agents 的轻量插件:帮你说清问题、冷静判断开发必要性,并认真寻找已经存在的产品、开源项目和可复用组件。 The licence is MIT.

When your agent uses it

  • Code changes are finished and npm authentication is ready
  • Codex should inspect the registry
  • Synchronize release versions
  • Publish a new stable npm version

Example prompts

  • “/publish-npm-release”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read package.json to obtain the package name and local version. Read AGENTS.md, package scripts, and existing release scripts before…
  2. Run npm whoami, then query the registry for the package's latest version and complete published-version list. Handle a 404 as a first…
  3. Select the target version from registry evidence, never by incrementing an arbitrary local value
  4. Update package.json and every current release-metadata surface that repository validation requires to equal the target version. Prefer a…

What it can do on your machine

Read from SKILL.md and the folder at commit bf22907. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Publish npm Release loads about 912 tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 476 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~912

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from user-w-ui/search-before-build at commit bf22907, republished under its MIT licence (© user-w-ui). 476 words, ~912 tokens.

Download SKILL.mdSave it as .claude/skills/publish-npm-release/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
publish-npm-release
description
Publish a completed npm package from the current repository. Use when code changes are finished and npm authentication is ready, and Codex should inspect the registry, synchronize release versions, validate, commit, tag, push, and publish a new stable npm version.

Publish an npm release

Treat invocation as authority to perform the complete stable release workflow, including a Git commit, annotated tag, remote push, and npm publish. The caller has already completed product changes and updated npm authentication.

Version policy

  1. Read package.json to obtain the package name and local version. Read AGENTS.md, package scripts, and existing release scripts before changing anything.
  2. Run npm whoami, then query the registry for the package's latest version and complete published-version list. Handle a 404 as a first release.
  3. Select the target version from registry evidence, never by incrementing an arbitrary local value:
    • Keep the local version when it is valid SemVer, unpublished, and greater than npm latest.
    • Otherwise use the next patch version after npm latest.
    • If the caller explicitly requests minor or major, increment that component from npm latest instead.
    • Stop for prereleases unless the caller explicitly supplies the intended npm dist-tag. Do not publish a prerelease as latest by default.
  4. Update package.json and every current release-metadata surface that repository validation requires to equal the target version. Prefer a repository-provided version-sync command. Otherwise inspect exact-version references and update only manifests or runtime client metadata, never historical documentation, fixtures, or changelogs.

Validate and commit

  1. Run all release-relevant checks documented by AGENTS.md, package scripts, and existing release scripts. Include repository tests, syntax checks, plugin validation when present, npm pack --dry-run, and git diff --check.
  2. Stop before committing if any validation fails. Diagnose and fix only release/version issues; do not alter completed product behavior without asking.
  3. Review git status --short. Stage only the caller's completed changes plus the release-version updates. Stop if unrelated or ambiguous changes cannot be separated safely.
  4. Commit with Release v<target-version> if the target-version changes are not already committed. Push the current branch and require its push to succeed before tagging.
Show full SKILL.md (171 more words)Show less

Tag and publish

  1. Require a clean working tree and confirm the current branch is not detached.
  2. Refuse to reuse, move, delete, or force-push an existing v<target-version> tag.
  3. Create git tag -a v<target-version> -m "Release v<target-version>" at current HEAD.
  4. Run any repository release verifier after tagging. It must confirm that version metadata matches and that the tag resolves to HEAD.
  5. Push the tag, then use git ls-remote --tags origin to confirm the remote contains it before publishing.
  6. Run npm publish without an npm dist-tag for a stable release. Never confuse npm dist-tags with Git tags.
  7. Verify npm view <package>@<target-version> version and inspect npm dist-tags. Report the package name, published version, commit, Git tag, validations, and npm verification result.

Stop conditions

Stop without publishing if npm authentication fails, the target npm version already exists, version metadata cannot be synchronized, validation fails, branch/tag push fails, or remote tag verification fails. Do not use npm version, git tag -f, git push --force, or npm unpublish as a fallback.

© user-w-ui, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/publish-npm-release of user-w-ui/search-before-build.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit bf22907

Compare with similar skills

Publish npm Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Publish npm Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Publish npm Release this skilluser-w-ui/search-before-build129—~912Automated safety check: PassMIT
Defuddlekepano/obsidian-skills49k11 repos~208Automated safety check: PassMIT
Vercel Deploybytedance/deer-flow84k10 repos~797Automated safety check: PassMIT
Knap Markdown Templateskepano/obsidian-skills49k2 repos~986Automated safety check: PassMIT
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
Nx Run Tasksnomcopter/react-mosaic4.8k8 repos~613Automated safety check: PassCustom licence

Similar skills

  • Defuddle

    kepano/obsidian-skills

    Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.

    49k GitHub starsUsed in 11 repos~208 tokens
    Knowledge ManagementAuto-check passed
  • Vercel Deploy

    bytedance/deer-flow

    Deploys a project to Vercel with one script and no login, then returns a live preview URL and a claim link for moving the deployment into your own Vercel account.

    84k GitHub starsUsed in 10 repos~797 tokens
    DevOps & CloudAuto-check passed
  • Knap Markdown Templates

    kepano/obsidian-skills

    Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.

    49k GitHub starsUsed in 2 repos~986 tokens
    Documents & OfficeAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 8 repos~613 tokens
    DevelopmentAuto-check passed
  • Validates OpenHarness features by running real multi-turn agent loops with live LLM calls against an unfamiliar codebase, checking actual tool execution.

    16k GitHub starsUsed in 1 repo~2.1k tokens
    Testing & QAAuto-check: notes

More from user-w-ui/search-before-build

  • Search Before Build Assess

    user-w-ui/search-before-build

    Calmly decide whether a digital product or coding idea is worth building by clarifying the real problem, checking necessity, researching existing solutions, and recommending Build, Adapt, Use…

    129 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Search Before Build Compare

    user-w-ui/search-before-build

    Compare an existing plan, prototype, repository, or half-built digital product with current alternatives, identify reusable work, and recommend Build, Adapt, Use existing, or Stop.

    129 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Publish npm Release

What does Publish npm Release do?

Publish a completed npm package from the current repository. Publish npm Release is an agent skill from user-w-ui/search-before-build. Publish a completed npm package from the current repository.

When should I use Publish npm Release?

Publish npm Release fits situations like: code changes are finished and npm authentication is ready; Codex should inspect the registry; synchronize release versions; publish a new stable npm version.

How do I install Publish npm Release in Claude Code?

Run `npx skills add user-w-ui/search-before-build --skill publish-npm-release -a claude-code`. Or copy the skill folder (.agents/skills/publish-npm-release in user-w-ui/search-before-build) into .claude/skills/publish-npm-release in your project. Claude Code loads it when a task matches its description.

How do I install Publish npm Release in Codex?

Run `npx skills add user-w-ui/search-before-build --skill publish-npm-release -a codex`. Or copy the skill folder (.agents/skills/publish-npm-release in user-w-ui/search-before-build) into .agents/skills/publish-npm-release in your project. Codex loads it when a task matches its description.

Can I use Publish npm Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add user-w-ui/search-before-build --skill publish-npm-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/publish-npm-release, .gemini/skills/publish-npm-release, .github/skills/publish-npm-release and .opencode/skills/publish-npm-release in your project.

What does Publish npm Release need to run?

Going by SKILL.md and its folder, Publish npm Release needs the command-line tools its instructions call (npm and git).

Does Publish npm Release access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Publish npm Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Publish npm Release use?

Publish npm Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Publish npm Release use?

About 912 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Publish npm Release?

Skills that share tags, products or a category with Publish npm Release: Defuddle (kepano/obsidian-skills, 49k stars), Vercel Deploy (bytedance/deer-flow, 84k stars), Knap Markdown Templates (kepano/obsidian-skills, 49k stars) and MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Publish npm Release?

user-w-ui (a GitHub user) maintains it in user-w-ui/search-before-build, which has 129 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 5, 2026.

Source: user-w-ui/search-before-build on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.