release

A release workflow for the vscode-deck extension. It checks that the working tree is clean, the project is on the main branch, and tests pass before updating the version, creating a release commit and tag, and building a VSIX package.

In plain words
What is it for?
Use it to prepare a specific extension version for release and build its installable VSIX file; publishing to Git or the VS Code Marketplace is outside its scope.
Why use it?
It keeps release steps and commit naming consistent while stopping when important preconditions are not met.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/a9a4k/vscode-deck/release
Any agent
npx skills add a9a4k/vscode-deck --skill release
Clone the repo
git clone --depth 1 https://github.com/a9a4k/vscode-deck

Made for: Claude Code, Codex.

Per session 82 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 795 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00082 $0.00795
Opus 5 $0.00041 $0.00398
Sonnet 5 $0.00016 $0.00159
Haiku 4.5 $0.00008 $0.00080

Measured 2d ago against content hash 3f87d4cec841, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

release scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

Note: `npm version` may strip linux-only optional peer entries from `package-lock.json` on darwin. That's the accepted status quo — sandcastle's next merger detects the drift and auto-commits `fix: synchronize npm lockfi
.agents/skills/release/SKILL.md · 74 lines

How it starts

The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Release

Cut a new release of the vscode-deck extension.

Preconditions to check first (fail loudly if any miss):

  • Working tree is clean (git status --short prints nothing).
  • On main branch.
  • npm test passes.

Steps

  1. Read current version and pick target. Read package.json for the current version. Ask the user for the explicit target X.Y.Z (this skill does not compute bumps — you pick the exact version). Show recent releases for context:

    git log --oneline --grep='chore(release)' -5
    
  2. Ask for the summary line. The commit title format is:

    chore(release): X.Y.Z — <summary>
    

    Summary is one line, often ends with issue refs like (#151, #152, #153). Look at recent releases for tone. If the release has more nuance than one line can hold, ask if they want a longer commit body — otherwise the message is just the title + Co-Authored-By trailer.

  3. Bump.

    npm version <target> --no-git-tag-version
    

    Updates package.json and package-lock.json version fields. Does not create a tag (we make one manually in step 5 so the commit format stays clean).

    Note: npm version may strip linux-only optional peer entries from package-lock.json on darwin. That's the accepted status quo — sandcastle's next merger detects the drift and auto-commits fix: synchronize npm lockfile. Don't try to regen the lockfile here (a fresh rm -rf node_modules && npm install can pull newer transitive deps, drifting the release from what was tested).

  4. Commit. Use a HEREDOC to preserve formatting:

    git add package.json package-lock.json
    git commit -m "$(cat <<'EOF'
    chore(release): X.Y.Z — <summary>
    
    Co-Authored-By: <your model attribution> <[email protected]>
    EOF
    )"
    

    Attribution: use the current session's model name (e.g. Claude Opus 4.7, Claude Fable 5). Do not hardcode.

  5. Tag.

    git tag vX.Y.Z
    

    Lightweight tag (matches existing tag style).

Read the full file on GitHub · 74 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 74 lines · 82 tokens per session scan C 3f87d4cec841

Subscribe to this mod's changes

release is a skill published in the GitHub repository a9a4k/vscode-deck (10 stars, last pushed 19d ago), licensed MIT. It adds 82 tokens to every session and 795 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

git-workflow-and-versioning

Structures git workflow practices. Use when making any code change. Use when committing, branching, resolving conflicts, opening or reviewing a pull request (PR), pushing to a remote, or when you need to organize work across multiple parallel streams. Use when cutting a release, choosing a semantic version bump…

addyosmani/agent-skills · 74 tokens

release

Cut a Symphony release by bumping the committed version, landing it, tagging the merged commit, and verifying the Burrito release workflow. Use when asked to release, tag, or retag Symphony.

openai/symphony · 42 tokens

release-notes

Draft concise release notes.

ollama/ollama · 9 tokens

greptimedb-release

Runbook for publishing a new GreptimeDB version (tag + GitHub release + docs release-note PR) on the upstream GreptimeTeam/greptimedb repo. Use when asked to "release" / "publish" a GreptimeDB version (e.g. v1.1.0, v1.0.3).

GreptimeTeam/greptimedb · 75 tokens

refresh-arm-sdk-release

WORKFLOW SKILL — Prepares Azure.ResourceManager SDK refresh pull requests in azure-sdk-for-net. WHEN: "prepare sdk refresh", "refresh Azure.ResourceManager package", "update ARM SDK from autorest tag", "refresh changelog dependencies". INVOKES: git and GitHub pull request tools for branch, commit, push, and PR…

Azure/azure-sdk-for-net · 91 tokens

store-update

在 CCX Desktop 发布后下载 Store MSIX 并生成发布公告。用户提到 Store 上架、MSIX、从 GitHub Release 下载 store.msix、发布后同步 Windows Store、从 release 填写商店更新内容时必须使用此技能。该技能会下载最新 GitHub Release 的 amd64/arm64 MSIX,校验 sha256,从 Release body 生成 Store listing releaseNotes 预览,并输出手动上传指引。.

BenedictKing/ccx · 100 tokens