release

A release command that commits current changes, pushes them to GitHub, increases the patch version in package.json, updates CHANGELOG.md, and publishes the package to npm, the JavaScript package registry.

In plain words
What is it for?
Use it to prepare and publish a new npm package version, including its Git commit, version number, changelog entry, and registry upload.
Why use it?
It removes the need to repeat and remember the release steps manually. It also checks that the changes were pushed and the working tree is clean.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/davidsmorais/mcpocket/release
Clone the repo
git clone --depth 1 https://github.com/davidsmorais/mcpocket
Per session 20 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 306 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00020 $0.00306
Opus 5 $0.00010 $0.00153
Sonnet 5 $0.00004 $0.00061
Haiku 4.5 $0.00002 $0.00031

Measured 2d ago against content hash 43b7449a6dcd, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.opencode/commands/release.md · 32 lines

What it actually says

Commit all current changes, push to GitHub, bump the patch version in package.json, update CHANGELOG.md with the new version, and publish to the npm registry.

Follow these steps in order:

  1. Commit & Push:

    • Stage all modified files (exclude .claude/settings.local.json and other local/session files)
    • Use git add then git commit with a concise message describing the changes
    • Push to the remote with git push
  2. Bump Version:

    • Read the current version from package.json
    • Increment the patch version (e.g., 0.6.60.6.7)
    • Update package.json with the new version
  3. Update Changelog:

    • Read CHANGELOG.md
    • Insert a new version entry at the top (after the header) with today's date
    • Summarize the changes from the commit message
  4. Publish to npm:

    • Run npm publish (or pnpm publish if the project uses pnpm)
    • Verify the publish succeeded
  5. Verify:

    • Run git status to confirm working tree is clean
    • Run git log -3 --oneline to show the new commit
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 32 lines · 20 tokens per session scan A 43b7449a6dcd

Subscribe to this mod's changes

release is a command published in the GitHub repository davidsmorais/mcpocket (9 stars, last pushed 3mo ago), licensed MIT. It adds 20 tokens to every session and 306 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.