Agent skill

Release

by WebMCP-org in WebMCP-org/npm-packages

Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

MITAuto-check: notesDevelopment

Install Release

skills CLI
$ npx skills add WebMCP-org/npm-packages --skill release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WebMCP-org/npm-packages release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WebMCP-org/npm-packages.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release .claude/skills/release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release
GitHub stars
103
Token cost
~1.6k tokens
SKILL.md length
769 words
Files
2 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

  • Works in 5 steps: Validate the changes → Run pnpm changeset. Select only packages… → Commit the changeset with the… → …
  • Tasks that involve Monorepo tooling
  • SKILL.md covers Stable releases, npm trusted publishing, Snapshots and Accumulating prereleases, plus 1 more section
  • Calls pnpm, npm and gh; needs NPM_TOKEN and GITHUB_TOKEN

What it does

Release is an agent skill from WebMCP-org/npm-packages. Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions. Covers stable releases, snapshots, prerelease trains, metadata checks, and MCPB artifacts.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/publishing.md`).

It sits in Development, covering Monorepo tooling, CI/CD and MCP servers. It works with npm, pnpm, Model Context Protocol and GitHub Actions. The repository describes itself as: NPM packages for MCP-B: Transport layers, React hooks, and browser tools for the Model Context Protocol. The licence is MIT.

When your agent uses it

  • Tasks that involve Monorepo tooling
  • Tasks that involve CI/CD
  • Tasks that involve MCP servers

Example prompts

  • “/release”

Requirements

  • A credential in NPM_TOKEN
  • A credential in GITHUB_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Validate the changes
  2. Run pnpm changeset. Select only packages with actual changes and describe the
  3. Commit the changeset with the implementation and submit the PR.
  4. After merge, CI creates or updates chore(release): version packages.
  5. Review that PR's versions, changelogs, relay manifest and global CDN test pin.

What it can do on your machine

Read from SKILL.md and the folder at commit 5f32a72. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm
    • gh
    • changeset
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.github.com
    • docs.npmjs.com
    • pnpm.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release loads about 1.6k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 50 tokens; SKILL.md has 769 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:103
    ; do not read, print, or shell-evaluate `.env` files.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WebMCP-org/npm-packages at commit 5f32a72, republished under its MIT licence (© WebMCP-org). 769 words, ~1,583 tokens.

Download SKILL.mdSave it as .claude/skills/release/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
release
description
Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions. Covers stable releases, snapshots, prerelease trains, metadata checks, and MCPB artifacts.

Release @mcp-b packages

Use the existing Release workflow. CI publishes from main using npm OIDC, not an NPM_TOKEN secret. Do not publish, dispatch, push, or change remote settings without authorization.

Stable releases

  1. Validate the changes:

    bash
    pnpm build && pnpm typecheck && vp check && pnpm test:unit && pnpm release:check
  2. Run pnpm changeset. Select only packages with actual changes and describe the consumer-facing effect. Separate summaries when packages need different release notes.

  3. Commit the changeset with the implementation and submit the PR.

  4. After merge, CI creates or updates chore(release): version packages.

  5. Review that PR's versions, changelogs, relay manifest and global CDN test pin. Merging it lets CI publish the release.

The version PR uses GITHUB_TOKEN. GitHub can hold workflows from bot-created or updated PRs for approval: a maintainer with write access selects Approve workflows to run in the PR merge box, then waits for all required checks. Do not bypass checks or add a PAT to work around an approval prompt. See GitHub's workflow trigger rules.

Never hand-edit package versions or use pnpm version: this bypasses changelogs and fixed-group coordination. All 12 published packages belong to one Changesets fixed group; private workspace apps and examples are not released.

pnpm changeset:version applies versions and synchronizes checked-in metadata through scripts/release-metadata.mjs --write. Normally the workflow runs it. Use it locally only when preparing an explicitly requested version commit.

ci:publish validates metadata, publishes unpublished package versions in dependency order, then runs changeset tag. The pinned Changesets action reads those new-tag messages to create GitHub releases and trigger SBOM, MCPB and signing steps. Keep the tag command after a successful publish; plain pnpm publish does not emit Changesets release events.

npm trusted publishing

Each public package must configure the same trusted publisher on npm:

  • Organization: WebMCP-org
  • Repository: npm-packages
  • Workflow filename: changesets.yml
  • Environment: npm-publish
  • Allowed action: npm publish

The workflow uses GitHub-hosted runners and job-level id-token: write. Node 24 and the pinned npm CLI meet npm's OIDC requirements. pnpm packs the workspace, resolving workspace: and catalog: protocols, then delegates publication to npm. Keep the npm CLI setup. Provenance is enabled; no long-lived npm publish token is needed.

Configure npm-publish environment reviewers and restrict deployment branches to main in GitHub settings. Naming an environment in YAML does not configure these protections. Verify OIDC publishing works before disabling legacy token access in npm settings. The workflow's canonical-repository and branch checks are additional safeguards.

See npm trusted publishing and pnpm publish.

Snapshots

For one temporary build from main, dispatch only when requested:

bash
gh workflow run "Release" --ref main -f tag=beta

This publishes <next>-beta.<datetime> under beta, without committing temporary versions or consuming the changesets on main. Dispatch before merging the version PR: snapshots need pending changesets. The workflow rejects an empty release, latest, unsafe tag text, and existing pre-mode state. It publishes only snapshot packages and signs the registry artifact in each prerelease GitHub release.

A snapshot is independent of the accumulating prerelease flow below. Never restore an entire working tree with git checkout . to discard snapshot versions. Prefer the workflow; if a local snapshot is explicitly needed, prepare it in a disposable clean checkout.

Show full SKILL.md (272 more words)Show less

Accumulating prereleases

bash
pnpm changeset pre enter beta

Commit .changeset/pre.json. Normal version PRs now produce X.Y.Z-beta.0, then beta.1, and so on. scripts/npm-dist-tag.mjs selects the active prerelease tag for ci:publish and publish:all; invalid state must stop publication rather than defaulting to latest.

To graduate, run pnpm changeset pre exit and commit the change. The next version PR removes the prerelease suffix and publishes to latest.

Local publishing and recovery

Use local publishing only when explicitly requested. Authenticate with npm login through the user's approved interactive flow; do not read, print, or shell-evaluate .env files. Then use pnpm publish:all, which builds, checks release metadata, and selects the dist-tag. Do not publish a source directory with npm: it cannot resolve pnpm dependency protocols.

Publication is not atomic across packages. pnpm skips versions already on npm, so rerun the same release after fixing the cause of a partial publish. Never overwrite or silently bump an already published version. If npm publishing succeeded but a later GitHub artifact step failed, recover those missing artifacts explicitly: existing tags can make Changesets report no new publication on a rerun. A rerun of snapshot versioning creates a new timestamp.

If only signing failed after stable GitHub releases were created, recover signatures with:

bash
gh workflow run "Release" --ref main -f recover_signatures_version=5.0.3

Use the affected stable version. This checks out its usewebmcp@<version> tag, validates every public package's version, tag commit and existing release, then signs source archives with Sigstore bundles. It never publishes npm packages or replaces SBOM/MCPB/R2 artifacts.

Verify exact versions (npm view <name>@<version> version) and dist-tags, including unscoped usewebmcp and nested @mcp-b/smart-dom-reader-server. Do not use the default npm view version as a prerelease check: it reads latest.

See publishing references for MCPB artifact recovery.

© WebMCP-org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/release of WebMCP-org/npm-packages.

  • SKILL.md
  • references/publishing.md

Open the folder on GitHubat commit 5f32a72

Compare with similar skills

Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release this skillWebMCP-org/npm-packages103—~1.6kAutomated safety check: NotesMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Publishingadeze/raindrop-mcp188—~398Automated safety check: PassMIT
Dsh Web UI Releaseningbainb/deepseek-harness-desktop776—~1.4kAutomated safety check: WarnBSD-3-Clause
Automate npm Releasejd-solanki/slidev-theme-dracula161—~626Automated safety check: PassNone
Code Reviewoaslananka/kicad-mcp-pro119—~3.9kAutomated safety check: PassMIT

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Publishing

    adeze/raindrop-mcp

    Publishing and release workflow with semantic-release and GitHub Actions

    188 GitHub stars~398 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Dsh Web UI Release

    ningbainb/deepseek-harness-desktop

    Release and publish the dsh-web-ui monorepo (DSH Web GUI plugin family + skin collection) — bump all packages to one unified version, commit and tag, push the vX.Y.Z tag that triggers the GitHub…

    776 GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check: warnings
  • Automate npm Release

    jd-solanki/slidev-theme-dracula

    Automate npm package publishing via GitHub Actions for single-package repos and independent monorepo packages, including bumpp version tags, GitHub release notes, trusted publishing, provenance, and…

    161 GitHub stars~626 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Code Review

    oaslananka/kicad-mcp-pro

    A skill your agent uses for GitHub Copilot pull request and code reviews in oaslananka/kicad-mcp-pro.

    119 GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Agent WorkflowsAuto-check: notes

More from WebMCP-org/npm-packages

  • Docs Authoring

    WebMCP-org/npm-packages

    Author and review the WebMCP documentation site using its Diataxis structure, Mintlify conventions, writing rules, design system, and source-of-truth boundaries.

    103 GitHub stars~6.1k tokensUpdated 3 days ago
    Auto-check passed
  • Diataxis

    WebMCP-org/npm-packages

    Write technical documentation following the Diataxis framework by Daniele Procida.

    103 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed

Questions about Release

What does Release do?

Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions. Release is an agent skill from WebMCP-org/npm-packages. Release the @mcp-b monorepo with Changesets and pnpm, using npm trusted publishing in GitHub Actions.

When should I use Release?

Release fits situations like: tasks that involve Monorepo tooling; tasks that involve CI/CD; tasks that involve MCP servers.

How do I install Release in Claude Code?

Run `npx skills add WebMCP-org/npm-packages --skill release -a claude-code`. Or copy the skill folder (.agents/skills/release in WebMCP-org/npm-packages) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.

How do I install Release in Codex?

Run `npx skills add WebMCP-org/npm-packages --skill release -a codex`. Or copy the skill folder (.agents/skills/release in WebMCP-org/npm-packages) into .agents/skills/release in your project. Codex loads it when a task matches its description.

Can I use Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WebMCP-org/npm-packages --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.

What does Release need to run?

Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (pnpm, npm, gh, changeset and git) and credentials named NPM_TOKEN and GITHUB_TOKEN. Our summary lists: A credential in NPM_TOKEN; A credential in GITHUB_TOKEN.

Does Release access the network?

SKILL.md names 3 domains. As links in the text: docs.github.com, docs.npmjs.com and pnpm.io. This is read from the text; nothing was executed.

Is Release safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Release use?

Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 605 tokens, read only when the agent opens those files.

What are the alternatives to Release?

Skills that share tags, products or a category with Release: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Publishing (adeze/raindrop-mcp, 188 stars), Dsh Web UI Release (ningbainb/deepseek-harness-desktop, 776 stars) and Automate npm Release (jd-solanki/slidev-theme-dracula, 161 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release?

WebMCP-org (a GitHub organization) maintains it in WebMCP-org/npm-packages, which has 103 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 4, 2026.

Source: WebMCP-org/npm-packages on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.