aikc-open-source-release

aikc-open-source-release is a skill for Claude Code, Codex from AHappyAtlas/ai-knowledge-center. It costs 0 tokens per session (495 once invoked), scanned A, original, MIT.

A release checklist and workflow for preparing AI Knowledge Center for a public GitHub or npm release. npm is a package registry used to distribute JavaScript software.

In plain words
What is it for?
Use it when preparing or reviewing a release after changes to the package, command-line tool, security, community files, or documentation.
Why use it?
It helps catch missing project policies, security checks, documentation, validation, and release details before publishing.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Needs its repository: it runs a file that does not travel with it, so clone the repository first. The line is node ai-knowledge/scripts/doctor.cjs --json.

Good fit Use it when preparing or reviewing a release after changes to the package, command-line tool, security, community files, or documentation.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/AHappyAtlas/ai-knowledge-center
agentmods
npx agentmods add skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for aikc-open-source-release

README.md
[![agentmods](https://agentmods.dev/badge/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release/github.svg)](https://agentmods.dev/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release)
Your own site
<a href="https://agentmods.dev/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release"><img src="https://agentmods.dev/badge/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for aikc-open-source-release

Your own site · 80×15
<a href="https://agentmods.dev/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release"><img src="https://agentmods.dev/badge/skills/ahappyatlas/ai-knowledge-center/aikc-open-source-release.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 0 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 495 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.00495
Opus 5 $0.00000 $0.00247
Sonnet 5 $0.00000 $0.00099
Haiku 4.5 $0.00000 $0.00049

Measured 9d ago against content hash 4262c1c3aac8, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

aikc-open-source-release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

ai-knowledge/skills/aikc-open-source-release/SKILL.md · 57 lines

How it starts

The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AIKC Open-Source Release Skill

Use this skill when preparing AI Knowledge Center for a public GitHub or npm release, or when validating release readiness after package, CLI, security, community, or documentation changes.

Release Contract

  • License, contribution guide, security policy, code of conduct, changelog, issue templates, and CI must be present before a first public release.
  • Preserve local-first defaults: 127.0.0.1, repository-scoped MCP, allowlisted commands, and telemetry opt-out with AIKC_TELEMETRY_EXPORTER=none.
  • Release notes must include user-visible changes, upgrade notes, rollback version, validation evidence, and supported platforms.
  • The published CLI must expose aikc doctor --json and aikc context-pack --project <path> --task <task> as direct verification and context-routing entrypoints.
  • Never print or commit npm tokens, .env.local, private project content, or user registry data.

Validation

Run from the package repository:

node ai-knowledge/scripts/doctor.cjs --json
node ai-knowledge/scripts/eval-workflow.cjs
node ai-knowledge/scripts/code-review.cjs
node ai-knowledge/scripts/knowledge-check.cjs
npm run typecheck
npm run lint
npm run build
npm pack --dry-run
npm run smoke:package

smoke:package packs the built package, installs it in a clean local temporary directory and a temporary npm global prefix, initializes projects through both install modes, and runs doctor plus context-pack. It must use an isolated AIKC_HOME and remove its temporary package and state after completion.

Platform Boundary

  • Local host: Windows, macOS, or Linux. The smoke script must handle the local npm launcher safely on each platform.
  • Remote target: GitHub Actions runners on Windows, macOS, and Linux. CI must run the same package smoke test across that matrix.
  • No remote shell, SSH, production deployment, or broadened network binding is part of release preparation.

Publish

Use docs/release-checklist.md for the human publish sequence. Publishing and creating a GitHub Release require explicit maintainer authority; do not attempt them merely because the checks pass.

Read the full file on GitHub · 57 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 57 lines · 0 tokens per session scan A 4262c1c3aac8

Subscribe to this mod's changes

aikc-open-source-release is a skill published in the GitHub repository AHappyAtlas/ai-knowledge-center (0 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 495 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

agentplane-release-and-packaging-operator

Use when preparing, validating, publishing, auditing, or recovering an Agentplane release, especially package build ordering, version parity, npm/GitHub/GHCR/external distribution publication, public install smoke tests, hosted publish evidence, or release CI failures.

basilisk-labs/agentplane · 60 tokens

checking-release-readiness

Records a ship, block, defer, or ship-with-risk decision that ties baseline, evidence status, residual risk, rollback, monitoring, and handoff together. Use when a packet, PR, release, dependency change, or agent-authority change approaches merge. Do not use early in development before evidence exists.

FlyFission/nuclear-grade-context-engineering · 67 tokens

brpr

(devtools plugin) Create a branch, commit changes, push, and open a PR — or just commit+push+PR if already on a feature branch. Links related issues from GitHub or Linear based on project tracker config.

feniix/pi-extensions · 49 tokens

release

Automate the release process. Use when user says "cut a release", "new version", "bump version", "publish release", or anything about versioning and publishing.

feniix/pi-extensions · 38 tokens

release-deploy

Prepare a public open-source project for release and deploy it to a detected target. Use at a release or submission boundary to verify setup, docs, secrets, tests, lint, build, and licenses, then follow the target-specific deployment path. Runs expensive checks sequentially. Never publishes, tags, commits, pushes, or…

olgaiv39/claude-oss-skills · 75 tokens

bump-version

Bump this repository's version across VERSION and the four plugin manifests, then commit it. Use when preparing a release or when a merge into main needs its version bump.

LenoSeibert/semver-plugin · 38 tokens