ZCF Release Automation
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
$ npx skills add verdaccio/verdaccio --skill pull-requests -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install verdaccio/verdaccio pull-requests --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/pull-requests .claude/skills/pull-requests && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pull-requests" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pull-requests into .claude/skills/pull-requests/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pull-requests", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pull-requestsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add verdaccio/verdaccio --skill pull-requests -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install verdaccio/verdaccio pull-requests --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/pull-requests .agents/skills/pull-requests && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pull-requests" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pull-requests into .agents/skills/pull-requests/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pull-requests", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add verdaccio/verdaccio --skill pull-requests -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install verdaccio/verdaccio pull-requests --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/pull-requests .cursor/skills/pull-requests && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pull-requests" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pull-requests into .cursor/skills/pull-requests/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pull-requests", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/verdaccio/verdaccio.git --path .agents/skills/pull-requests--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add verdaccio/verdaccio --skill pull-requests -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install verdaccio/verdaccio pull-requests --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/pull-requests .gemini/skills/pull-requests && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pull-requests" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pull-requests into .gemini/skills/pull-requests/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pull-requests", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install verdaccio/verdaccio pull-requestsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add verdaccio/verdaccio --skill pull-requests -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/pull-requests .github/skills/pull-requests && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pull-requests" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pull-requests into .github/skills/pull-requests/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pull-requests", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add verdaccio/verdaccio --skill pull-requests -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install verdaccio/verdaccio pull-requests --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/verdaccio/verdaccio.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/pull-requests .opencode/skills/pull-requests && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pull-requests" agent skill from https://github.com/verdaccio/verdaccio/tree/master/.agents/skills/pull-requests into .opencode/skills/pull-requests/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pull-requests", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pull-requestsTakes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
The skill defines done as green checks, a review round with nothing left to act on, and every release line that needs the change having its own PR or an explicit note that the port is pending. Before opening, the agent branches from the current base (origin/master, or origin/6.x for a port), runs the checks that cover the change plus pnpm lint, pnpm format:check and a type check, adds one changeset naming each published package it touches, reviews its own diff and confirms the husky hooks are installed, never skipping them with --no-verify. CI does not run on draft PRs, so the local pass is the only gate until the PR is ready.
Commit messages and titles are lowercase Conventional Commits with no AI attribution trailers, and the PR title becomes the squash commit. Port PRs say which line they target, for example fix(6.x). The body is brief, a few sentences a reviewer needs. The PR is opened with gh pr create against verdaccio/verdaccio, as a draft if wanted, or from GitHub's compare page when gh is missing. The agent pushes only when you or the calling workflow authorized it, and the description adds the CI and review rounds that follow each push.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2d3bcca. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitpnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, git and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verdaccio Pull Request Workflow loads about 1.9k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 1,106 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from verdaccio/verdaccio at commit 2d3bcca, republished under its MIT licence (© verdaccio). 1,106 words, ~1,869 tokens.
.claude/skills/pull-requests/SKILL.md (or your agent's skills folder).Opening the PR is the middle of the task. It is done when the checks are green, the review round has nothing left to act on, and every release line that needs the change has its own PR or an explicit note that the port is pending.
Read the commit and label rules in AGENTS.md first; this skill is the workflow around them.
git fetch origin master then
git switch -c <type>/<short-name> origin/master (for a port, from origin/6.x).pnpm lint,
pnpm format:check, and the type check for touched packages. CI does not run on
draft PRs, so this local pass is the only gate until the PR is marked ready.pnpm changeset or a hand-written .changeset/<slug>.md), when a
published package changed. Otherwise say in the PR body why none is needed; the
skip changeset label is applied by a maintainer, never by an external author.git config core.hooksPath points at
.husky/_); commit normally so the pre-commit format, lint, and lockfile checks
run. Never --no-verify.Commit messages are lowercase Conventional Commits, no AI attribution trailers. Push only when the user or calling workflow authorised it.
gh pr create --repo verdaccio/verdaccio --base master --title "fix(store): <what changed>" --body-file <body.md> [--draft]Without gh, push the branch and open the PR from the compare page GitHub prints in
the push output (or https://github.com/verdaccio/verdaccio/compare); the title, body,
labels, and draft checkbox are all on that form. Checks, review threads, and
mergeability are on the PR page; labels are in its sidebar (see
pr-labels for the API form).
Title: lowercase, Conventional Commits, scope optional. It becomes the squash
commit, so write the history entry you want. Port PRs say which line they target:
fix(6.x): ... or the same title suffixed (6.x).
Body: brief. A few sentences a reviewer needs to understand the diff and nothing else:
<problem in one or two sentences, with the issue link when there is one: Closes verdaccio/verdaccio#NNNN>
<the approach in a sentence or two, and any decision a reviewer might question>No test plan, no validation log, no file-by-file walkthrough, no "not included" section; a pending port or follow-up is one sentence. No attribution footer. The changeset is where the change is explained in full for users (it is the changelog entry), so put the effort there and do not repeat it in the body. What you ran goes in your report to the person who asked, not in the PR.
Labels, immediately after creation (a PR without labels is not finished): exactly
one release-line label (7.x branch (next) for master, 6.x branch (latest) for
6.x) plus content labels (typically one to three). The pr-labels skill
has the taxonomy, the worked examples, the label you never apply (security) and the
one you apply only to your own PR when the author says so (AI assisted):
gh pr edit <n> --repo verdaccio/verdaccio --add-label "<release line>" --add-label "<content>"CI runs only on ready PRs, and an automated reviewer, when one is enabled on the
repository, re-reviews on every push to one. Open as a draft
while the change is still moving and the local checks are your only gate; mark it ready
(gh pr ready <n>) as soon as the diff is what you want reviewed. Do not leave a draft
behind silently: either mark it ready or say in the body what is left.
gh pr checks <n> --watch in the background, or poll.
Watch to the end: the next push cancels the in-progress run, so a second failure you
never saw costs another cycle.gh pr edit --title/--body); the title is what merges.gh pr view <n> --json mergeable,mergeStateStatus).
CONFLICTING means rebase (git rebase origin/<base>; a lockfile conflict is
resolved by pnpm install), then force-push with lease. Re-read the diff after a
rebase. Do not merge the base into the branch.A round is finished when the checks are green, every reviewer who took part has reported on the head commit, and none of it needs action. A quiet round is the stop signal, not a round count; if nobody has reviewed yet, the PR is simply waiting for a maintainer, and that wait is not yours to fill with pushes.
Never write a failure off as pre-existing, flaky, or unrelated without evidence.
gh run view <run-id> --log-failed, reproduce it locally with the testing-changes
selection, fix the cause. The e2e CLI matrix fails per client; a failure in one
client is a compatibility finding, not noise. The changeset-check job fails on a PR
without a changeset unless a maintainer has labelled it skip changeset.
A bug fix on master that also exists on 6.x (binary) or 8.x (internal modules
6.x consumes) is not finished until each affected line has its own PR. Cherry-pick
onto a branch from that line, adapt (6.x uses yarn and an older toolchain; code may
have diverged), run that line's tests there, open the PR against that branch with the
matching release-line label, and link the original PR in the body. If the port is
deferred, say so in one sentence in the original PR body.
Report which findings were real, which were not, what was declined and why, the CI
state, and which ports exist or are pending. Do not add AI attribution anywhere on the
PR; the AI assisted label is how AI involvement is disclosed. The author adds it to
their own PR (apply it when the author tells you to), and maintainers may add it too.
© verdaccio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/pull-requests of verdaccio/verdaccio.
Open the folder on GitHubat commit 2d3bcca
Verdaccio Pull Request Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verdaccio Pull Request Workflow this skillverdaccio/verdaccio | 18k | — | ~1.9k | Automated safety check: Pass | MIT | |
| ZCF Release AutomationUfoMiao/zcf | 6.1k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Release Clawpatchopenclaw/clawpatch | 813 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Prisma Release PRprisma/orm | 48k | — | ~4k | Automated safety check: Pass | Apache-2.0 | |
| Releasecyanfish-x/tellux | 207 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Nylas Nodejs Releasenylas/nylas-nodejs | 181 | — | ~1.6k | Automated safety check: Warn | MIT |
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
openclaw/clawpatch
clawpatch release: version/changelog, CI, npm publish, GitHub release, verify.
prisma/orm
Helps a Prisma 8 maintainer cut the next release by bumping the version across every workspace package, opening the release PR and preparing the docs PR.
cyanfish-x/tellux
Cut and publish a new tellux release — bump version, curate a changelog summary from recent commits, pause for the user to manually pnpm publish (browser 2FA), then push the tag and create the…
nylas/nylas-nodejs
Prepares nylas-nodejs SDK releases on a versioned release branch with CHANGELOG updates, version bump, git tag, and PR body.
emanuelcasco/pi-mono-extensions
Release a new version of pi-extensions: bump individual package versions (independent mode), update CHANGELOGs and READMEs, create per-package git tags, publish a GitHub release, and publish…
verdaccio/verdaccio
Reviews an existing verdaccio/verdaccio pull request end to end, verifies each finding and reports whether it is mergeable, optionally fixing it on the PR branch.
verdaccio/verdaccio
Triages an incoming verdaccio/verdaccio issue against the code, the affected release line and related issues, and picks labels from the repository's existing taxonomy.
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
verdaccio/verdaccio
Figures out which rebuild and test suites actually cover a change in the verdaccio monorepo, instead of a scoped run that passes untested.
verdaccio/verdaccio
A workflow for implementing a Verdaccio bug fix, feature or refactor: pick the release lines, check existing options, edit the owning layer, test and add a changeset.
verdaccio/verdaccio
Maintains Verdaccio's bundled plugins and the plugin contracts in @verdaccio/core, and diagnoses plugin loading problems.
Categories
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines. The skill defines done as green checks, a review round with nothing left to act on, and every release line that needs the change having its own PR or an explicit note that the port is pending.x for a port), runs the checks that cover the change plus pnpm lint, pnpm format:check and a type check, adds one changeset naming each published package it touches, reviews its own diff and confirms the husky hooks are installed, never skipping them with --no-verify.
Verdaccio Pull Request Workflow fits situations like: opening a pull request against verdaccio/verdaccio; responding to a failing check or review comments after a push; porting a fix to another release line with its own PR; deciding whether a change needs a changeset.
Run `npx skills add verdaccio/verdaccio --skill pull-requests -a claude-code`. Or copy the skill folder (.agents/skills/pull-requests in verdaccio/verdaccio) into .claude/skills/pull-requests in your project. Claude Code loads it when a task matches its description.
Run `npx skills add verdaccio/verdaccio --skill pull-requests -a codex`. Or copy the skill folder (.agents/skills/pull-requests in verdaccio/verdaccio) into .agents/skills/pull-requests in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add verdaccio/verdaccio --skill pull-requests -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pull-requests, .gemini/skills/pull-requests, .github/skills/pull-requests and .opencode/skills/pull-requests in your project.
Going by SKILL.md and its folder, Verdaccio Pull Request Workflow needs the command-line tools its instructions call (gh, git and pnpm). Our summary lists: Git, pnpm and the GitHub CLI (gh); A checkout of verdaccio/verdaccio with the husky hooks installed.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verdaccio Pull Request Workflow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verdaccio Pull Request Workflow: ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Release Clawpatch (openclaw/clawpatch, 813 stars), Prisma Release PR (prisma/orm, 48k stars) and Release (cyanfish-x/tellux, 207 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
verdaccio (a GitHub organization) maintains it in verdaccio/verdaccio, which has 17,913 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.
Source: verdaccio/verdaccio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.