paperclip-surfers: Skill for Claude Code

.agents/skills/release/SKILL.md

release is a skill for Claude Code, Codex from IncomeStreamSurfer/paperclip-surfers. It costs 41 tokens per session (1,619 once invoked), scanned A, a copy of release, MIT.

A release workflow for the Paperclip project, covering engineering checks, npm publishing, Docker smoke tests, GitHub releases, and follow-up announcements. A canary release is a pre-stable version used for verification.

In plain words
What is it for?
Use it when shipping, promoting, or cutting a Paperclip release, including changelog work, canary checks, stable promotion, publishing, smoke testing, and GitHub release creation.
Why use it?
It coordinates the many steps needed to ship a Paperclip release and checks conditions such as a clean working tree and verified candidate changes.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: installed under .agents/ (shared by several agents).

This is IncomeStreamSurfer/paperclip-surfers's own configuration. It tells Claude Code and Codex how to work on paperclip-surfers itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything paperclip-surfers configures →

Needs its repository: it runs a file that does not travel with it, so clone the repository first. The line is PAPERCLIPAI_VERSION=canary ./scripts/docker-onboard-smoke.sh.

Reuse

Borrowing it

Nothing to install: this file belongs to IncomeStreamSurfer/paperclip-surfers. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/IncomeStreamSurfer/paperclip-surfers/master/.agents/skills/release/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/IncomeStreamSurfer/paperclip-surfers

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for release

README.md
[![agentmods](https://agentmods.dev/badge/skills/incomestreamsurfer/paperclip-surfers/release/github.svg)](https://agentmods.dev/skills/incomestreamsurfer/paperclip-surfers/release)
Your own site
<a href="https://agentmods.dev/skills/incomestreamsurfer/paperclip-surfers/release"><img src="https://agentmods.dev/badge/skills/incomestreamsurfer/paperclip-surfers/release/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for release

Your own site · 80×15
<a href="https://agentmods.dev/skills/incomestreamsurfer/paperclip-surfers/release"><img src="https://agentmods.dev/badge/skills/incomestreamsurfer/paperclip-surfers/release.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 41 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,619 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 86% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00041 $0.01619
Opus 5 $0.00020 $0.00809
Sonnet 5 $0.00008 $0.00324
Haiku 4.5 $0.00004 $0.00162

Measured 10d ago against content hash d9067c2218ef, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

86% identical to release — 76 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.agents/skills/release/SKILL.md · 248 lines

How it starts

The opening of the file, as written. The whole thing — 248 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Release Coordination Skill

Run the full Paperclip maintainer release workflow, not just an npm publish.

This skill coordinates:

  • stable changelog drafting via release-changelog
  • canary verification and publish status from master
  • Docker smoke testing via scripts/docker-onboard-smoke.sh
  • manual stable promotion from a chosen source ref
  • GitHub Release creation
  • website / announcement follow-up tasks

Trigger

Use this skill when leadership asks for:

  • "do a release"
  • "ship the release"
  • "promote this canary to stable"
  • "cut the stable release"

Preconditions

Before proceeding, verify all of the following:

  1. .agents/skills/release-changelog/SKILL.md exists and is usable.
  2. The repo working tree is clean, including untracked files.
  3. There is at least one canary or candidate commit since the last stable tag.
  4. The candidate SHA has passed the verification gate or is about to.
  5. If manifests changed, the CI-owned pnpm-lock.yaml refresh is already merged on master.
  6. npm publish rights are available through GitHub trusted publishing, or through local npm auth for emergency/manual use.
  7. If running through Paperclip, you have issue context for status updates and follow-up task creation.

If any precondition fails, stop and report the blocker.

Inputs

Collect these inputs up front:

  • whether the target is a canary check or a stable promotion
  • the candidate source_ref for stable
  • whether the stable run is dry-run or live
  • release issue / company context for website and announcement follow-up

Step 0 — Release Model

Paperclip now uses a commit-driven release model:

  1. every push to master publishes a canary automatically
  2. canaries use YYYY.MDD.P-canary.N
  3. stable releases use YYYY.MDD.P
  4. the middle slot is MDD, where M is the UTC month and DD is the zero-padded UTC day
  5. the stable patch slot increments when more than one stable ships on the same UTC date
  6. stable releases are manually promoted from a chosen tested commit or canary source commit
  7. only stable releases get releases/vYYYY.MDD.P.md, git tag vYYYY.MDD.P, and a GitHub Release

Read the full file on GitHub · 248 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 248 lines · 41 tokens per session scan A d9067c2218ef

Subscribe to this mod's changes

release is a skill published in the GitHub repository IncomeStreamSurfer/paperclip-surfers (74 stars, last pushed 5mo ago), licensed MIT. It adds 41 tokens to every session and 1,619 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 86% identical to release, differing in 76 lines, and is treated as a copy.