versioning-policy

versioning-policy is a skill for Claude Code, Codex from bradygaster/squad. It costs 20 tokens per session (1,153 once invoked), scanned A, original, MIT.

A set of release rules for the Squad SDK and command-line tool, which are two npm packages in the same code repository. It defines how their version numbers must be formatted and kept in sync.

In plain words
What is it for?
Use it when reviewing version changes, building packages locally, preparing releases, or checking pull requests for invalid prerelease versions.
Why use it?
It prevents development-only version labels or mismatched package versions from breaking workspace dependencies or reaching shared branches.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/bradygaster/squad/versioning-policy
Any agent
npx skills add bradygaster/squad --skill versioning-policy
Clone the repo
git clone --depth 1 https://github.com/bradygaster/squad

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for versioning-policy

README.md
[![agentmods](https://agentmods.dev/badge/skills/bradygaster/squad/versioning-policy.svg)](https://agentmods.dev/skills/bradygaster/squad/versioning-policy)
Your own site
<a href="https://agentmods.dev/skills/bradygaster/squad/versioning-policy"><img src="https://agentmods.dev/badge/skills/bradygaster/squad/versioning-policy.svg" alt="Measured on agentmods" height="20"></a>
Per session 20 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,153 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00020 $0.01153
Opus 5 $0.00010 $0.00576
Sonnet 5 $0.00004 $0.00231
Haiku 4.5 $0.00002 $0.00115

Measured 2d ago against content hash db8c898c8fb1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

versioning-policy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

3 near-identical copies found in the catalogue:

.squad/skills/versioning-policy/SKILL.md · 124 lines

How it starts

The opening of the file, as written. The whole thing — 124 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Context

Squad publishes @bradygaster/squad-sdk and @bradygaster/squad-cli from one npm workspace. Their versions and the root version move together. A mismatched prerelease dependency can make npm silently resolve an older registry SDK instead of the local workspace.

1. Supported versions

Use Version Committed branch
Stable release MAJOR.MINOR.PATCH main, and briefly dev during promotion
Preview release MAJOR.MINOR.PATCH-preview.N dev
Insider snapshot MAJOR.MINOR.PATCH-insider.N Generated by the insider workflow
Local build MAJOR.MINOR.PATCH-build.N Never committed

preview is a release channel, not a branch. Stable promotion merges a sanitized release tree directly from dev to main.

2. Package versions stay in lockstep

These versions must always be identical:

  • package.json
  • packages/squad-sdk/package.json
  • packages/squad-cli/package.json
  • the corresponding workspace entries in package-lock.json

Use the workspace-aware version command:

npm version "$VERSION" --workspaces --include-workspace-root --no-git-tag-version

Never edit only one package version.

3. Prerelease workspace dependency rule

The CLI depends on the SDK through a SemVer range. SemVer deliberately excludes prereleases unless the comparator names a prerelease with the same base version. For example, >=0.13.0 does not match 0.14.0-preview.1.

For every committed preview version, set both the CLI manifest and lockfile dependency floor to that exact preview:

npm pkg set "dependencies.@bradygaster/squad-sdk=>=$VERSION" \
  --workspace @bradygaster/squad-cli
npm install --package-lock-only

For VERSION=0.14.0-preview.1, the required range is >=0.14.0-preview.1. Before stable promotion, change the version and floor to 0.14.0 / >=0.14.0; never leave a prerelease floor in a stable release.

This rule prevents the PR #640 failure mode, where the build succeeded against a stale published SDK rather than the workspace SDK.

Read the full file on GitHub · 124 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago Changed · +4 lines db8c898c8fb1
  2. 4d ago First seen · 120 lines · 20 tokens per session scan A 8688e0afb261

Subscribe to this mod's changes

versioning-policy is a skill published in the GitHub repository bradygaster/squad (3,154 stars, last pushed today), licensed MIT. It adds 20 tokens to every session and 1,153 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.