medusa: Skill for Claude Code

.claude/skills/medusa-commits-and-releases/SKILL.md

medusa-commits-and-releases is a skill for Claude Code from Skowt/medusa. It costs 69 tokens per session (1,376 once invoked), scanned C, original, MIT.

A guide for writing commits and preparing Medusa software releases. Commits are saved changes, while a release is a published version of the software.

In plain words
What is it for?
Use it when committing changes, creating a Medusa version, pushing a release tag, or creating a GitHub release.
Why use it?
It keeps commit messages consistent so the release tool can create focused release notes and follows the repository's release procedure.

Skill for Claude Code

Written for Claude Code: installed under .claude/.

This is Skowt/medusa's own configuration. It tells Claude Code how to work on medusa itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything medusa configures →

View source ↗ Skowt/medusa
Reuse

Borrowing it

Nothing to install: this file belongs to Skowt/medusa. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/Skowt/medusa/main/.claude/skills/medusa-commits-and-releases/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/Skowt/medusa

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for medusa-commits-and-releases

README.md
[![agentmods](https://agentmods.dev/badge/skills/skowt/medusa/medusa-commits-and-releases/github.svg)](https://agentmods.dev/skills/skowt/medusa/medusa-commits-and-releases)
Your own site
<a href="https://agentmods.dev/skills/skowt/medusa/medusa-commits-and-releases"><img src="https://agentmods.dev/badge/skills/skowt/medusa/medusa-commits-and-releases/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for medusa-commits-and-releases

Your own site · 80×15
<a href="https://agentmods.dev/skills/skowt/medusa/medusa-commits-and-releases"><img src="https://agentmods.dev/badge/skills/skowt/medusa/medusa-commits-and-releases.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 69 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,376 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00069 $0.01376
Opus 5 $0.00034 $0.00688
Sonnet 5 $0.00014 $0.00275
Haiku 4.5 $0.00007 $0.00138

Measured 12d ago against content hash c805f826b326, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade C, and why

medusa-commits-and-releases scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Downloads and executes remote codehighSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

sh -c 'curl -fsSL https://raw.githubusercontent.com/Skowt/medusa/main/install.sh | sh'

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

sh -c 'curl -fsSL https://raw.githubusercontent.com/Skowt/medusa/main/install.sh | sh'
.claude/skills/medusa-commits-and-releases/SKILL.md · 125 lines

How it starts

The opening of the file, as written. The whole thing — 125 lines — stays where its author put it; the contents beside it link to each section on GitHub.

medusa commits and releases

Commit format

Commit subjects follow a conventional-commit-lite convention. The .goreleaser.yml changelog filters depend on these prefixes to keep release notes focused on user-facing changes.

Subject line: <prefix>: <imperative summary> — ≤72 chars, lowercase after the prefix.

Allowed prefixes:

Prefix Meaning Surfaces in release notes?
feat: New user-facing feature Yes
fix: Bug fix Yes
refactor: Code restructuring, no behavior change Yes
perf: Performance improvement Yes
docs: Documentation only No
test: Tests only No
ci: CI/workflow/tooling No
chore: Routine maintenance, deps, housekeeping No

Optional PR reference at end of subject: (#123). GoReleaser carries it through to release notes; useful for linking context.

Body is optional. Include one when the why isn't obvious from the diff (hidden constraint, subtle invariant, reason for an unusual approach). Don't restate the what — the diff shows that.

Examples

fix: correct typo in copy gitignored files checkbox label
feat: add restart option to close tab dialog (#42)
refactor: extract PTY catch-up flush into dedicated helper
chore: bump tmux minimum version note

Anti-examples

Update stuff                              # no prefix, vague subject
feat: Added A Thing.                      # capitalized, period, past tense
Fix: bug in thing                         # wrong case, no detail
feat: massive overhaul of the state
machine plus some drive-by cleanups       # multi-purpose commit, unclear scope

Read the full file on GitHub · 125 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 125 lines · 69 tokens per session scan C c805f826b326

Subscribe to this mod's changes

medusa-commits-and-releases is a skill published in the GitHub repository Skowt/medusa (5 stars, last pushed 2d ago), licensed MIT. It adds 69 tokens to every session and 1,376 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

github-automation

GitHub workflow automation, PR management, issue tracking, and code review coordination. Integrates with GitHub Actions and repository management. Use when: PR creation, code review, issue management, release automation, workflow setup. Skip when: local-only changes, non-GitHub repositories.

ruvnet/ruflo · 61 tokens

comet-safe-delivery

A Chinese-language procedure for safely delivering specified Comet changes through Git. It covers checking worktrees and unrelated edits, staging exact files, validating hooks, and authorized commits or pushes.

rpamis/comet · 78 tokens

close-task-commit-push-pr

Close the active backlog task (detected from branch name), commit all changes, push to remote, and open a pull request. Use when the user says "close task and ship it", "close task commit push pr", or invokes /close-task-commit-push-pr.

devoxx/DevoxxGenieIDEAPlugin · 64 tokens

changelog

Auto-generates a changelog from git commits, sprint data, and design documents. Produces both internal and player-facing versions.

Donchitos/Claude-Code-Game-Studios · 29 tokens

git-workflow

Guides you through Git workflows — branching strategies, commit conventions, merge conflict resolution, and release management. Use when working with Git repositories or when the user asks about version control best practices.

ownpilot/OwnPilot · 42 tokens

development-workflow

Detailed development workflow with modular patterns for git, review, testing, and deployment.

athola/claude-night-market · 20 tokens