Agent skill

Point Latest At Rc

by yamcodes in yamcodes/arkenv

Point npm latest at the current @rc versions using local interactive npm auth (no GitHub NPMTOKEN).

MITAuto-check passed

Install Point Latest At Rc

skills CLI
$ npx skills add yamcodes/arkenv --skill point-latest-at-rc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yamcodes/arkenv point-latest-at-rc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yamcodes/arkenv.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/point-latest-at-rc .claude/skills/point-latest-at-rc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
point-latest-at-rc
GitHub stars
145
Token cost
~777 tokens
SKILL.md length
299 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Point npm latest at the current @rc versions using local interactive npm auth (no GitHub NPMTOKEN).

  • Works in 3 steps: Repo root on a branch with… → Packages already published under @rc… → npm user who can write dist-tags on…
  • Promoting RC to latest after publish
  • SKILL.md covers Preconditions, Steps, Verify and Smoke (after retag), plus 2 more sections
  • Calls npm, pnpm and npx; needs NPM_TOKEN

What it does

Point Latest At Rc is an agent skill from yamcodes/arkenv. Point npm latest at the current @rc versions using local interactive npm auth (no GitHub NPMTOKEN). Use when promoting RC to latest after publish, when CI promoterctolatest 403s, when package Publishing access disallows tokens, or when the user asks to retag latest / run point-latest-at-rc without a CI token.

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with npm and GitHub. The repository describes itself as: ⛯ Typesafe environment variables with ArkType, Zod, or Valibot. The licence is MIT.

When your agent uses it

  • Promoting RC to latest after publish
  • CI promoterctolatest 403s
  • Package Publishing access disallows tokens
  • The user asks to retag latest / run point-latest-at-rc without a CI token

Example prompts

  • “/point-latest-at-rc”

Requirements

  • Node.js
  • A credential in NPM_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Repo root on a branch with .changeset/pre.json →
  2. Packages already published under @rc (e.g. 1.0.0-rc.1).
  3. npm user who can write dist-tags on @arkenv/* and arkenv

What it can do on your machine

Read from SKILL.md and the folder at commit 50d0325. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pnpm
    • npx
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pnpm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NPM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Point Latest At Rc loads about 777 tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 299 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~777

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yamcodes/arkenv at commit 50d0325, republished under its MIT licence (© yamcodes). 299 words, ~777 tokens.

Download SKILL.mdSave it as .claude/skills/point-latest-at-rc/SKILL.md (or your agent's skills folder).
name
point-latest-at-rc
description
Point npm `latest` at the current `@rc` versions using local interactive npm auth (no GitHub `NPM_TOKEN`). Use when promoting RC to latest after publish, when CI promote_rc_to_latest 403s, when package Publishing access disallows tokens, or when the user asks to retag latest / run point-latest-at-rc without a CI token.
metadata.author
Yam Borodetsky
metadata.version
1.0.0
metadata.internal
true

Point npm latest at @rc (local / no CI token)

Maintainer break-glass alternative to the release workflow’s NPM_TOKEN path. The root script pnpm point-latest-at-rc runs scripts/point-latest-at-rc.js --from-rc --local so npm dist-tag uses your logged-in session. Write commands inherit stdin/stdout so npm can prompt for OTP when 2FA is on auth-and-writes (run from a real TTY). Prefer a single OTP for the whole run via --otp <code> or NPM_CONFIG_OTP — otherwise npm prompts once per package (~12 times). Trusted Publishing still covers publish; this skill only covers dist-tag.

Do not remove or disable the CI promote job. Prefer CI promote_rc_to_latest when secrets.NPM_TOKEN works; use this only when CI cannot (or as emergency retag).

Preconditions

  1. Repo root on a branch with .changeset/pre.json → "mode": "pre", "tag": "rc" (same gate as CI).
  2. Packages already published under @rc (e.g. 1.0.0-rc.1).
  3. npm user who can write dist-tags on @arkenv/* and arkenv (npm login if needed).

Steps

bash
# 1. Confirm auth
npm whoami

# 2. Optional dry-run (lists dist-tag commands; still resolves @rc)
pnpm point-latest-at-rc --dry-run

# 3. Retag (no NPM_TOKEN) — preferred: one OTP for all packages
pnpm point-latest-at-rc -- --otp <code-from-authenticator>
# or: NPM_CONFIG_OTP=<code> pnpm point-latest-at-rc

Without --otp / NPM_CONFIG_OTP, run from a real TTY and expect one interactive OTP prompt per package.

Verify

bash
npm view arkenv dist-tags
npm view @arkenv/core dist-tags
npm view @arkenv/agent-plugin dist-tags

Expect latest and rc both at the same 1.0.0-rc.n.

Smoke (after retag)

  • Bare npx arkenv init
  • @arkenv/core + arktype in a fresh Node app
  • One framework example if time allows

Failures

SymptomLikely cause
Soft-skip without --localMissing NPM_TOKEN — use pnpm point-latest-at-rc for this path
Local mode requires npm authNot logged in — npm login
EOTP / no OTP promptNot a TTY (piped/non-interactive) — pass --otp / NPM_CONFIG_OTP, or run from a real terminal
OTP prompt per packageExpected without --otp / NPM_CONFIG_OTP — pass one code for the whole run
E403 on dist-tagUser lacks write on that package
Gate skip (pre.json / not rc)Not in RC pre mode — do not force
  • Docs: docs/RC_CHECKLIST.md §C (CI primary; local break-glass)
  • CI: .github/workflows/release.yml → promote_rc_to_latest (needs NPM_TOKEN; leave in place — primary path)
  • Script help: node scripts/point-latest-at-rc.js --help

© yamcodes, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/point-latest-at-rc of yamcodes/arkenv.

Open the folder on GitHubat commit 50d0325

Compare with similar skills

Point Latest At Rc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Point Latest At Rc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Point Latest At Rc this skillyamcodes/arkenv145—~777Automated safety check: PassMIT
Proxychains Network Fallback2025Emma/vibe-coding-cn23k1 repos~1.1kAutomated safety check: NotesMIT
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Update .NET Supported OS Matrixdotnet/core22k—~4.1kAutomated safety check: PassMIT
Hunk Release Workflowmodem-dev/hunk9.6k—~3.8kAutomated safety check: PassMIT

Similar skills

  • Proxychains Network Fallback

    2025Emma/vibe-coding-cn

    Retries failed network commands through proxychains4 and a local proxy when it sees timeouts, DNS failures or blocked access.

    23k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Audits and updates the supported-os.json files for .NET releases, checking them against upstream lifecycle data and regenerating the markdown with the release-notes tool.

    22k GitHub stars~4.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.6k GitHub stars~3.8k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Version Release

    NG-ZORRO/ng-zorro-antd

    NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.

    9.2k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from yamcodes/arkenv

All 20 skills in this repo
  • Hallmark

    yamcodes/arkenv

    Anti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots.

    145 GitHub starsUsed in 4 repos~18k tokens
    Auto-check passed
  • Bulletproof React

    yamcodes/arkenv

    Bulletproof React architecture patterns for scalable, maintainable applications.

    145 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Arkenv

    yamcodes/arkenv

    Answer questions about ArkEnv and help implement environment variable validation.

    145 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Code Review

    yamcodes/arkenv

    Fetch, analyze, and address code reviews and comments on GitHub, or perform a code review on changes in the workspace.

    145 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Forward Port

    yamcodes/arkenv

    Manually forward-ports merged dev (v0) changes to the v1 branch, adapting code to v1's package layout and changeset names.

    145 GitHub stars~970 tokensUpdated today
    Auto-check passed
  • Groom Issue

    yamcodes/arkenv

    Groom a poorly written issue by grilling the user to clarify requirements, updating the issue on GitHub via the gh cli, and utilizing the triage skill to apply the correct label and add an agent…

    145 GitHub stars~1k tokensUpdated today
    Auto-check passed

Works with

Questions about Point Latest At Rc

What does Point Latest At Rc do?

Point npm latest at the current @rc versions using local interactive npm auth (no GitHub NPMTOKEN). Point Latest At Rc is an agent skill from yamcodes/arkenv. Point npm latest at the current @rc versions using local interactive npm auth (no GitHub NPMTOKEN).

When should I use Point Latest At Rc?

Point Latest At Rc fits situations like: promoting RC to latest after publish; CI promoterctolatest 403s; package Publishing access disallows tokens; the user asks to retag latest / run point-latest-at-rc without a CI token.

How do I install Point Latest At Rc in Claude Code?

Run `npx skills add yamcodes/arkenv --skill point-latest-at-rc -a claude-code`. Or copy the skill folder (skills/point-latest-at-rc in yamcodes/arkenv) into .claude/skills/point-latest-at-rc in your project. Claude Code loads it when a task matches its description.

How do I install Point Latest At Rc in Codex?

Run `npx skills add yamcodes/arkenv --skill point-latest-at-rc -a codex`. Or copy the skill folder (skills/point-latest-at-rc in yamcodes/arkenv) into .agents/skills/point-latest-at-rc in your project. Codex loads it when a task matches its description.

Can I use Point Latest At Rc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yamcodes/arkenv --skill point-latest-at-rc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/point-latest-at-rc, .gemini/skills/point-latest-at-rc, .github/skills/point-latest-at-rc and .opencode/skills/point-latest-at-rc in your project.

What does Point Latest At Rc need to run?

Going by SKILL.md and its folder, Point Latest At Rc needs the command-line tools its instructions call (npm, pnpm, npx and node) and credentials named NPM_TOKEN. Our summary lists: Node.js; A credential in NPM_TOKEN.

Does Point Latest At Rc access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Point Latest At Rc safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Point Latest At Rc use?

Point Latest At Rc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Point Latest At Rc use?

About 777 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Point Latest At Rc?

Skills that share tags, products or a category with Point Latest At Rc: Proxychains Network Fallback (2025Emma/vibe-coding-cn, 23k stars), Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars) and Update .NET Supported OS Matrix (dotnet/core, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Point Latest At Rc?

yamcodes (a GitHub user) maintains it in yamcodes/arkenv, which has 145 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 9, 2026.

Source: yamcodes/arkenv on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.