Contributor-First PR Merge
HKUDS/OpenHarness
Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.
Chooses the release-line label and one to three content labels for a verdaccio/verdaccio pull request and applies them with the gh CLI.
$ npx skills add verdaccio/verdaccio --skill pr-labels -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install verdaccio/verdaccio pr-labels --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pr-labels .claude/skills/pr-labels && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pr-labels" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pr-labels into .claude/skills/pr-labels/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-labels", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pr-labelsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add verdaccio/verdaccio --skill pr-labels -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install verdaccio/verdaccio pr-labels --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/pr-labels .agents/skills/pr-labels && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pr-labels" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pr-labels into .agents/skills/pr-labels/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-labels", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add verdaccio/verdaccio --skill pr-labels -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install verdaccio/verdaccio pr-labels --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/pr-labels .cursor/skills/pr-labels && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pr-labels" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pr-labels into .cursor/skills/pr-labels/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-labels", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/verdaccio/verdaccio.git --path .agents/skills/pr-labels--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add verdaccio/verdaccio --skill pr-labels -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install verdaccio/verdaccio pr-labels --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/pr-labels .gemini/skills/pr-labels && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pr-labels" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pr-labels into .gemini/skills/pr-labels/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-labels", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install verdaccio/verdaccio pr-labelsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add verdaccio/verdaccio --skill pr-labels -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/pr-labels .github/skills/pr-labels && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pr-labels" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pr-labels into .github/skills/pr-labels/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-labels", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add verdaccio/verdaccio --skill pr-labels -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install verdaccio/verdaccio pr-labels --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/pr-labels .opencode/skills/pr-labels && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pr-labels" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pr-labels into .opencode/skills/pr-labels/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pr-labels", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pr-labelsChooses the release-line label and one to three content labels for a verdaccio/verdaccio pull request and applies them with the gh CLI.
Written for contributors to the verdaccio/verdaccio repository, this skill sets out how every pull request is labeled right after it is opened. Each PR gets exactly one release-line label, picked from its base branch (master or 6.x), plus content labels such as bug, performance, refactor, CI or docs that describe what the change is about.
Labels come only from the repository's existing list, which the agent reads with gh label list, and new ones are never created. They are applied with gh pr edit, with the GitHub web sidebar or the REST API as fallbacks, and if nothing works the agent reports the exact labels so the author can add them. The skill also rules out a security label and limits the AI assisted label to the author's own PR.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 726dd15. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghcurlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verdaccio PR Labels loads about 1.6k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 753 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from verdaccio/verdaccio at commit 726dd15, republished under its MIT licence (© verdaccio). 753 words, ~1,562 tokens.
.claude/skills/pr-labels/SKILL.md (or your agent's skills folder).No PR without labels. Every pull request carries exactly one release-line label and at least one content label (typically one to three; see §2 for when more is right), applied right after it is created:
gh pr edit <n> --repo verdaccio/verdaccio --add-label "<release line>" --add-label "<content>"Labels come from the existing list only (gh label list --repo verdaccio/verdaccio --limit 300, or https://github.com/verdaccio/verdaccio/labels); never create one.
Without gh, use the Labels sidebar on the PR page, or the REST API:
curl -s -X POST -H "Authorization: Bearer $GITHUB_TOKEN" \
https://api.github.com/repos/verdaccio/verdaccio/issues/<n>/labels \
-d '{"labels":["<release line>","<content>"]}'If you cannot apply labels at all, list the exact labels in your report so the author can add them.
| Base branch of the PR | Label |
|---|---|
master (9.x) | 7.x branch (next) |
6.x | 6.x branch (latest) |
7.x branch (next) is the label in use for master; it predates 9.x and was kept so
the history stays searchable. A port PR to another branch takes that branch's label,
not the original's. 4.x and 5.x are deprecated with no further development: no PR
targets them and their labels (4.x deprecated, 5.x branch (legacy)) are not used.
The content label answers "which mental folder does this PR open?". A focused PR takes two or three labels; a large multi-topic PR may take more, but every label must describe something central to the change, never something tangential.
By nature of the change:
issue: bug — fixes a reported defect (pair it with the area).performance — measurable optimisation; the numbers go in the PR body.feat: breaking-change — breaks configuration, plugin interfaces, or the HTTP contract.dev: refactor — no behaviour change.dev: experiment — new behaviour behind a flag or an experimental package.dev: ci-build — workflows and CI only. dev: tooling — repo tooling, scripts, lint.dev: migration — toolchain or dependency-major migrations.docs, topic: readme, topic: testing, topic: e2e — documentation and test-only work.bot: dependencies — automated bumps (Renovate, Dependabot).By area (topic: *): topic: proxy/uplinks, topic: web, topic: api, topic: search,
topic: config, topic: token, topic: logging, topic: core, topic: middleware,
topic: typescript, topic: devops, topic: offline-mode, topic: signature,
topic: env-variables, topic: npm, topic: pnpm, topic: yarn-modern,
topic: yarn-classic, topic: kubernetes, helm, Docker, topic: docker-compose,
topic: nginx, topic: apache, topic: windows, React (UI components).
By subsystem: feat: auth, feat: storage, feat: notifications,
plugin: local-storage, plugin: htpasswd, plugin: package-filter,
plugin: verdaccio-memory, cmd: publish, cmd: unpublish, cmd: owner,
cmd: npm team, cmd: npm deprecate.
Process labels: skip changeset (docs, tests, CI, tooling: nothing published changes,
disables the changeset check; maintainers only, never on an external contributor's
PR, see §3), WIP, dev: do-not-merge, dev: blocked.
skip changeset — maintainers only. It bypasses a CI gate, so it is applied by a
maintainer after confirming the PR changes nothing published. An external contributor
states in the PR body why no changeset is needed and leaves the label to the
maintainer.security — never. It publicly marks a PR as a security fix before a release
carries it and hints at the vector. A security fix is labelled by area only
(topic: *, feat: *); maintainers add security afterwards if they choose.AI assisted — the author's (or a maintainer's) call, not a reviewer's. It marks
PRs containing AI-generated content. The author adds it to their own PR, and an agent
working for the author applies it when the author says so; maintainers may add it as
well. If you notice AI-generated content in a PR you did not author, mention it in
your report; do not label it.perf(6.x): stop re-compressing tarballs… → performance + 6.x branch (latest).feat: staged publishing and 2FA → dev: experiment + 7.x branch (next).fix(search): include license in local results → topic: search + 7.x branch (next).fix(logger): honor JSON sync… → issue: bug + topic: logging + 7.x branch (next).fix: emit tarball content-length before data flows → issue: bug + feat: storage +
plugin: local-storage + 7.x branch (next).fix: tarball download reliability — uplink selection… (large, multi-topic) →
issue: bug + feat: storage + topic: proxy/uplinks + performance +
7.x branch (next).chore: migrate pnpm to v12 → dev: migration + 7.x branch (next) (+ skip changeset,
added by a maintainer).dev: ci-build + the release line.Rule of thumb: a perf(...) title takes performance; anything touching uplinks,
remote tarballs, or the proxy takes topic: proxy/uplinks; a storage-layer change takes
feat: storage and the plugin label when a bundled plugin changed; UI work takes
topic: web and React when components changed.
Missing or wrong labels are a review finding, reported like any other. Fix them yourself only when the task asked you to maintain the PR; otherwise name the labels it should carry.
© verdaccio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/pr-labels of verdaccio/verdaccio.
Open the folder on GitHubat commit 726dd15
Verdaccio PR Labels next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verdaccio PR Labels this skillverdaccio/verdaccio | 18k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Contributor-First PR MergeHKUDS/OpenHarness | 16k | 1 repos | ~847 | Automated safety check: Pass | MIT | |
| Pre-Release PR Triagejamiepine/voicebox | 57k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Ansible Backport Creatoransible/ansible | 71k | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | |
| Codewhale Landing Workflowcodewhale-hq/Codewhale | 41k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Ouroboros Maintainer TriageQ00/ouroboros | 6.2k | — | ~1.7k | Automated safety check: Pass | MIT |
HKUDS/OpenHarness
Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.
jamiepine/voicebox
Sorts a backlog of open pull requests into must-merge, candidate, superseded and deferred, writes a triage doc and works the merge loop before a release.
ansible/ansible
Creates backports of a merged Ansible devel pull request onto the right stable branches by cherry-picking its merge commit onto new backport branches.
codewhale-hq/Codewhale
Decides how verified work should reach main, directly, in a worktree or on an integration branch, while keeping contributor credit and respecting merge gates.
Q00/ouroboros
Triages and works through GitHub issues and pull requests in the Q00/ouroboros repo as a maintainer, within a stated review boundary and clear limits on what it may change.
QwenLM/qwen-code
Gatekeeps GitHub issues and pull requests for Qwen Code maintainers through staged static reviews that post a comment after each stage, under strict safety rules.
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
verdaccio/verdaccio
Reviews an existing verdaccio/verdaccio pull request end to end, verifies each finding and reports whether it is mergeable, optionally fixing it on the PR branch.
verdaccio/verdaccio
Triages an incoming verdaccio/verdaccio issue against the code, the affected release line and related issues, and picks labels from the repository's existing taxonomy.
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
verdaccio/verdaccio
Figures out which rebuild and test suites actually cover a change in the verdaccio monorepo, instead of a scoped run that passes untested.
verdaccio/verdaccio
A workflow for implementing a Verdaccio bug fix, feature or refactor: pick the release lines, check existing options, edit the owning layer, test and add a changeset.
Works with
Categories
Chooses the release-line label and one to three content labels for a verdaccio/verdaccio pull request and applies them with the gh CLI. Written for contributors to the verdaccio/verdaccio repository, this skill sets out how every pull request is labeled right after it is opened.x), plus content labels such as bug, performance, refactor, CI or docs that describe what the change is about.
Verdaccio PR Labels fits situations like: right after opening a pull request against verdaccio/verdaccio; reviewing a PR whose labels are missing or look wrong; deciding which labels a change should carry before it is merged.
Run `npx skills add verdaccio/verdaccio --skill pr-labels -a claude-code`. Or copy the skill folder (.agents/skills/pr-labels in verdaccio/verdaccio) into .claude/skills/pr-labels in your project. Claude Code loads it when a task matches its description.
Run `npx skills add verdaccio/verdaccio --skill pr-labels -a codex`. Or copy the skill folder (.agents/skills/pr-labels in verdaccio/verdaccio) into .agents/skills/pr-labels in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add verdaccio/verdaccio --skill pr-labels -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-labels, .gemini/skills/pr-labels, .github/skills/pr-labels and .opencode/skills/pr-labels in your project.
Going by SKILL.md and its folder, Verdaccio PR Labels needs the command-line tools its instructions call (gh and curl) and credentials named GITHUB_TOKEN. Our summary lists: GitHub CLI (gh) signed in with access to verdaccio/verdaccio, or a GITHUB_TOKEN for the REST API.
SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verdaccio PR Labels is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verdaccio PR Labels: Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Pre-Release PR Triage (jamiepine/voicebox, 57k stars), Ansible Backport Creator (ansible/ansible, 71k stars) and Codewhale Landing Workflow (codewhale-hq/Codewhale, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
verdaccio (a GitHub organization) maintains it in verdaccio/verdaccio, which has 17,912 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 8, 2026.
Source: verdaccio/verdaccio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.