contrib-publishing

contrib-publishing is a skill for Claude Code from abderrahimghazali/drupal-boost. It costs 41 tokens per session (750 once invoked), scanned A, original, MIT.

A publishing checklist for contributed Drupal modules, meaning modules shared with the wider Drupal community through drupal.org.

In plain words
What is it for?
Use it to prepare a module for drupal.org by checking coding standards, static analysis, documentation, tests, permissions, input handling, and project structure.
Why use it?
It gathers code-quality, documentation, testing, security, and review requirements in one place before submission.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter.

Part of the drupal-boost plugin — 13 skills, 8 commands, 6 agents, 3 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/abderrahimghazali/drupal-boost/contrib-publishing
Any agent
npx skills add abderrahimghazali/drupal-boost --skill contrib-publishing
Clone the repo
git clone --depth 1 https://github.com/abderrahimghazali/drupal-boost

Made for: Claude Code.

Or install drupal-boost, the plugin that ships this one along with the rest of its 13 skills, 8 commands, 6 agents, 3 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for contrib-publishing

README.md
[![agentmods](https://agentmods.dev/badge/skills/abderrahimghazali/drupal-boost/contrib-publishing.svg)](https://agentmods.dev/skills/abderrahimghazali/drupal-boost/contrib-publishing)
Your own site
<a href="https://agentmods.dev/skills/abderrahimghazali/drupal-boost/contrib-publishing"><img src="https://agentmods.dev/badge/skills/abderrahimghazali/drupal-boost/contrib-publishing.svg" alt="Measured on agentmods" height="20"></a>
Per session 41 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 750 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00041 $0.00750
Opus 5 $0.00020 $0.00375
Sonnet 5 $0.00008 $0.00150
Haiku 4.5 $0.00004 $0.00075

Measured 6d ago against content hash 6c4d785d7872, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

contrib-publishing scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/contrib-publishing/SKILL.md · 102 lines

How it starts

The opening of the file, as written. The whole thing — 102 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Publishing to drupal.org

Module Checklist

Before submitting a module to drupal.org:

Code Quality

  • Follows Drupal coding standards (run PHPCS with Drupal/DrupalPractice)
  • Passes PHPStan at level 6+
  • No deprecated API usage (run Drupal Check)
  • All classes follow PSR-4 autoloading
  • No hardcoded strings — all user-facing text uses t()
  • Config schema defined for all configuration

Documentation

  • README.md with:
    • Module name and description
    • Requirements (Drupal version, PHP version, dependencies)
    • Installation instructions
    • Configuration guide
    • Usage examples
    • Troubleshooting
    • Maintainer info
  • INSTALL.md if installation is complex
  • Inline code documentation (PHPDoc on all public methods)
  • Help hook or help page for in-Drupal documentation

Testing

  • PHPUnit tests (at minimum Unit tests, ideally Kernel too)
  • Tests pass on all supported Drupal versions
  • Test coverage for critical functionality

Security

  • Security review passed (no XSS, SQL injection, access bypass)
  • Permissions defined with proper restrict access where needed
  • All entity queries use accessCheck(TRUE)
  • File uploads validated

Structure

  • Clean .info.yml with proper metadata
  • composer.json with proper package name (drupal/MODULE_NAME)
  • .gitignore excludes vendor, node_modules
  • No generated files committed (compiled CSS/JS, vendor/)

GitLab CI for drupal.org

Add .gitlab-ci.yml to your module:

include:
  - project: $_GITLAB_TEMPLATES_REPO
    ref: $_GITLAB_TEMPLATES_REF
    file:
      - '/includes/include.drupalci.main.yml'

This runs the Drupal Association's standard CI pipeline.

composer.json for Contrib

{
  "name": "drupal/MODULE_NAME",
  "type": "drupal-module",
  "description": "Brief description.",
  "license": "GPL-2.0-or-later",
  "homepage": "https://www.drupal.org/project/MODULE_NAME",
  "require": {
    "drupal/core": "^10 || ^11"
  },
  "extra": {
    "drupal": {
      "version": "VERSION",
      "datestamp": "DATESTAMP"
    }
  }
}

Read the full file on GitHub · 102 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 102 lines · 41 tokens per session scan A 6c4d785d7872

Subscribe to this mod's changes

contrib-publishing is a skill published in the GitHub repository abderrahimghazali/drupal-boost (1 stars, last pushed 5mo ago), licensed MIT. It adds 41 tokens to every session and 750 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

update-pr

Update an existing pull request with new changes. Use when the user wants to update a PR, push follow-up changes to a PR, refresh a PR description, or sync a PR with latest commits. Triggers on: update pr, update-pr, update the pr, push to pr, refresh pr, sync pr, update pull request.

ReflexioAI/claude-smart · 71 tokens

codex-setup

Initialize sd0x-dev-flow infrastructure for Codex CLI and other non-Claude agents. Generates AGENTS.md, installs the commit-msg hook, copies runner scripts. The pre-push gate is opt-in via --with-push-gate. Use when setting up a new project or after updating skills.

sd0xdev/sd0x-harness · 65 tokens

smart-rebase

Smart partial rebase for squash-merge repositories. Auto-detect which commits to keep/drop when base branch was squash-merged into target. Use when: user says 'rebase', 'partial rebase', 'base already merged', 'smart rebase', or /smart-rebase. Not for: simple git rebase (the developer runs it — Claude never executes…

sd0xdev/sd0x-harness · 131 tokens

next-step

Change-aware next step advisor. Use when: user asks what to do next, workflow progression is unclear, session just started with dirty worktree. Not for: executing the suggested command (user decides), auto-loop decisions (hooks handle that). Output: findings-based suggestions or session summary with commit seed.

sd0xdev/sd0x-harness · 63 tokens

merge-prep

Pre-merge analysis and preparation. Analyzes source branch vs target branch: commit stats, conflict detection, file impact. Analysis-only v1 — outputs report + suggested commands, does not auto-merge. Use when: user says 'merge prep', 'pre-merge', 'merge analysis', or /merge-prep.

sd0xdev/sd0x-harness · 69 tokens

pr-comment

Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review. Use when: posting code review comments, giving PR feedback, sending inline suggestions. Not for: reading existing reviews (use load-pr-review), creating PRs (use create-pr), PR status (use pr-summary).

sd0xdev/sd0x-harness · 67 tokens