Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/frostney/pascal-mcp-sdk/create-releasenpx skills add frostney/pascal-mcp-sdk --skill create-releasegit clone --depth 1 https://github.com/frostney/pascal-mcp-sdkWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/frostney/pascal-mcp-sdk/create-release)<a href="https://agentmods.dev/skills/frostney/pascal-mcp-sdk/create-release"><img src="https://agentmods.dev/badge/skills/frostney/pascal-mcp-sdk/create-release.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00054 | $0.00749 |
| Opus 5 | $0.00027 | $0.00375 |
| Sonnet 5 | $0.00011 | $0.00150 |
| Haiku 4.5 | $0.00005 | $0.00075 |
Grade A, and why
create-release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
88% identical to create-release — 14 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Create release
Prepare a release whose tag contains its changelog, then publish through exactly one evidence-backed path when publication is authorized.
Authorization
- Prepare: determine the version, update changelog/version declarations, validate, and open the release PR. Requests to prepare, bump, or generate notes authorize only this stage.
- Publish: after the PR merges, create or trigger the tag/release through the
repository's established publisher. Requests to cut, tag, publish, or run
/create-releaseauthorize this stage too. - When ambiguous, perform Prepare only.
Invariants
- The changelog and version bump land before the tag, through a squash-merged PR.
- Use the repository's configured tools and current documentation. Regenerate generated changelogs rather than hand-editing them.
- Use an explicit version or recommend one from unreleased conventional commits and wait for the user's decision.
- Run the declared release-relevant gate and report only observed results.
- Never amend, force-push, force-update a tag, skip hooks, or publish through more than one path.
Prepare
- Resolve the authorization stage, remote default branch, clean working tree, changelog/version tooling, last release, remote tags, workflows, and release documentation.
- Stop if there are no releasable commits.
- Validate a supplied version, or recommend and confirm the next version from unreleased commits.
- Create a release branch from the fresh remote base.
- Generate the changelog section and update every authoritative version declaration using project tooling. Do not invent a manifest bump when the project derives its version from tags.
- Run the release-relevant project gate, commit
chore(release): <version>, and open a draft release PR through/create-pr. Include the changelog section and observed validation. Stop here for Prepare-only requests.
Publish
- Wait for and verify the squash merge; never tag the open PR branch.
- Refresh the merged base, then re-read the actual workflow YAML and release documentation. Identify separate owners for tag creation, GitHub release creation, artifact signing, and registry publishing.
- Select exactly one route:
- workflow owns tag and release: trigger or monitor it only;
- agent owns tag, workflow owns release: push the verified tag once, then monitor;
- workflow owns tag, agent owns release: verify its tag, then create one GitHub release;
- agent owns both: only when no workflow owns either action, push the verified tag once and create one release.
- Stop when ownership is ambiguous or documentation and workflow disagree.
- Execute only the selected route and verify the final tag target, release, workflow result, artifacts, and registry state that the route owns.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 77 lines · 54 tokens per session scan A dc1ece431982
create-release is a skill published in the GitHub repository frostney/pascal-mcp-sdk (2 stars, last pushed 7d ago), licensed MIT. It adds 54 tokens to every session and 749 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 88% identical to create-release, differing in 14 lines, and is treated as a copy.
Other skills, from other repositories
git-wrapup
Land working-tree changes as logical commits — the work grouped by concern, topped by a release commit (version bump, changelog, regenerated artifacts) and an annotated tag. Verify, commit, tag. Stops at "committed and tagged locally" — no push, no publish. The release-and-publish skill picks up from here. Distilled…
release-and-publish
Ship a release end-to-end across every registry the project targets (npm, MCP Registry, GitHub Releases for .mcpb bundles, GHCR). Runs the final verification gate, pushes commits and tags, then publishes to each applicable destination. Assumes git wrapup (version bumps, changelog, commit, annotated tag) is already…
polish-docs-meta
Finalize documentation and project metadata for a ship-ready release. Use after implementation is complete, tests pass, and devcheck is clean. Safe to run at any stage — each step checks current state and only acts on what still needs work.
release-and-publish
Ship a release end-to-end across every registry this project targets (npm, MCP Registry). Runs the final verification gate, pushes commits and tags, then publishes to each applicable destination. Assumes git wrapup (version bumps, changelog, commit, annotated tag) is already complete — this skill is the post-wrapup…
codexless-release-supervisor
Prepare, validate, and publish Codexless preview/hotfix releases from the canonical household source, including acceptance anti-omission gates, candidate provenance/parity, manifest/build identity, native Windows/macOS fresh-install acceptance from clean public source, safe Git integration, GitHub prerelease…
bob-export
Create a Hacker Bob post-release improvement bundle for the currently installed Bob version.