release
Publish a new release of the Feishu plugin. Use when the user asks to release, publish, or cut a new version.
How do I install this agent skill?
npx skills add https://github.com/m1heng/clawdbot-feishu --skill releaseIs this agent skill safe to install?
- Gen Agent Trust Hubfail
The skill automates the software release process by publishing to npm and GitHub. It is vulnerable to Indirect Prompt Injection because it reads untrusted data from git logs and diffs to generate release notes and perform deployment tasks. A malicious contributor could embed instructions in commit messages that an agent might execute or follow during the release workflow.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
- Runlayerwarn
1/1 file flagged
- ZeroLeakspass
Score: 93/100 · 2 sections analyzed
What does this agent skill do?
Release Workflow
Publish a new version of @m1heng-clawd/feishu to npm and create a GitHub release.
Prerequisites
- Working tree is clean (all changes committed to
main) npm loginsession is active with publish access to@m1heng-clawdscopeghCLI is authenticated
Steps
1. Determine version bump
Check what changed since the last release:
# Find latest release tag
gh release list --limit 1
# Review commits and diff stat
git log <last-tag>..HEAD --oneline
git diff <last-tag>..HEAD --stat
Choose bump type: patch (bug fixes), minor (new features), or major (breaking changes).
2. Type check
npx tsc --noEmit
Do NOT proceed if type check fails.
3. Draft release notes
Review the full diff to write release notes:
git diff <last-tag>..HEAD
Create a GitHub release draft first:
gh release create v<new-version> --draft --title "v<new-version>" --target main --notes "<release notes markdown>"
4. Bump version in package.json
Edit package.json to update the "version" field to <new-version>.
5. Commit, tag, and push
git add package.json
git commit -m "chore: bump version to <new-version>"
git tag v<new-version>
git push && git push --tags
6. Publish to npm
npm publish
If auth fails, ask the user to run npm login first, then retry.
7. Publish GitHub release
gh release edit v<new-version> --draft=false
Release Notes Format
Follow the established format (see previous releases for reference):
## Features
- **Feature title** — Description. (#PR)
## Bug Fixes
- **Fix title** — Description. (#PR)
## Internal
- Internal change description.
Troubleshooting
npm publish 404 / auth error
npm login # re-authenticate
npm whoami # verify logged in
npm publish # retry
Tag already exists
If the tag was created but publish failed, delete and recreate after fixing:
git tag -d v<version>
git push origin :refs/tags/v<version>
# fix issue, then re-tag and push
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/m1heng/clawdbot-feishu/release">View release on skillZs</a>