What does this skill do, and when should you use it?
cmux-release is a bundled skill in the cmux repository (skills/cmux-release/SKILL.md) that codifies how a cmux release is prepared and troubleshot. It prefers the /release command, which determines the new version (minor by default), gathers Changelog lines from every merged PR, updates CHANGELOG.md, runs the version-bump and pretag-guard scripts, then tags and pushes. This skill is aimed at cmux project maintainers, not at end users of the cmux terminal.
- Runs the /release flow: picks the new version (minor by default), fetches Changelog lines from all PRs merged since the last stable v* tag in one GraphQL query, updates CHANGELOG.md, commits, runs the pretag guard, then tags and pushes
- Executes ./scripts/bump-version.sh to increment MARKETING_VERSION and CURRENT_PROJECT_VERSION (minor/patch/major or explicit version)
- Classifies fetched PRs with references/changelog-lines.jq: valid lines become entries with author thanks, 'none' is skipped, in-range reverts are skipped, PRs missing a Changelog section are flagged for human review
- Runs ./scripts/release-pretag-guard.sh and, on failure, re-bumps the build number before retrying
- Verifies release asset expectations (cmux-macos.dmg attached to the tag) and the signing/notarization secrets
- A cmux maintainer preparing a release who wants changelog assembly, version bump, guard, and tagging done per the project's documented flow
- A maintainer whose release-pretag-guard failed and needs the correct remediation (re-bump the build number, commit, retry)
- A reviewer deciding how reverts and PRs without Changelog sections should be classified for the upcoming release
- A maintainer debugging missing release assets or CI signing/notarization failures for the DMG
- Only fits the cmux repository itself — other projects' release flows cannot use it without porting its scripts and conventions
- Not a cmux usage guide; end users of the terminal should consult the README and docs instead
- Depends on repo-private scripts (bump-version.sh, release-pretag-guard.sh) and the internal glaeda-gh wait tool, so it cannot run outside this repository
How do you install this skill?
- This is a purely static source review; no scripts or release flows were executed, and confidence is low.
- Key referenced scripts (bump-version.sh, release-pretag-guard.sh, notary-auth.sh) are not included in the evidence; verify their behavior before use.
- The skill only fits cmux repository maintainers; triggering it as a general user is meaningless, and the flow depends entirely on GitHub and Apple services.
- Repository license metadata is NOASSERTION while the actual licensing is dual GPL-3.0-or-later / BUSL-1.1; confirm license boundaries before redistributing related scripts.
- The release involves signing and notarization secrets; confirm secret scoping and cleanup of temporary key files when operating.
- Shell / CLI
- Network access
- Local filesystem
cmux repository checkoutscripts/bump-version.shscripts/release-pretag-guard.shGitHub GraphQL access for changelog gathering
The skill ships inside the cmux repository at skills/cmux-release/ and is available to any Agent Skills-compatible client once the repo is cloned. The source documents no standalone install command; do not assume an npm/pip-style installation.
tmp="$(mktemp -d)"
git clone --depth 1 https://github.com/manaflow-ai/cmux.git "$tmp"
mkdir -p ~/.claude/skills
cp -R "$tmp/skills/cmux-release" ~/.claude/skills/
rm -rf "$tmp"Generated from the source repository and skill path; it copies only this skill's folder. If the author's install steps above differ, follow those first. To scope it to one project, replace ~/.claude/skills with that project's .claude/skills.
How do you use this skill?
Once installed, send your agent any of these to trigger it:
- Prepare the next cmux release using the default minor version via the /release flow
- The pretag guard failed — re-bump the build number and retry tagging per the flow
- Which merged PRs since the last v tag are missing a Changelog section and need human review?
- Check that the cmux-macos.dmg signing and notarization secrets are in place for this release
Trigger the full release via the documented /release command; the skill applies whenever preparing or troubleshooting a cmux release. Core sequence: bump the version, commit the build-number change, run the guard, then tag and push:
./scripts/bump-version.sh # minor by default
./scripts/release-pretag-guard.sh
git tag vX.Y.Z
git push origin vX.Y.ZOptions: bump-version.sh accepts patch, major, or an explicit version (e.g. 1.0.0). The tag push creates a CI run observed by run ID rather than polling GitHub. Signing requires the APPLE_CERTIFICATE_* secrets; CI notarization uses the ASC_API_* App Store Connect key.
What are this skill's strengths and limitations?
- Encodes cmux's release conventions (changelog aggregated from PR descriptions, mandatory build-number increment, pretag guard) into an executable flow that reduces manual omissions
- Handles edge cases explicitly: reverts, PRs without Changelog sections, and human-review flags
- Well documented, with a release checklist reference and failure triage guidance
- Tightly bound to cmux's scripts, secrets, and internal tooling (glaeda-gh); not transferable to other projects as-is
- GPL-3.0-or-later license (server side BSL 1.1) adds compliance considerations if reused elsewhere
- Signing/notarization depends on GitHub secrets not verified within the skill itself, so failures require consulting the referenced checklist
How does this skill compare with similar options?
Side by side with related skills; every score comes from the same FSRS standard.
| Skill | FS score | Stars | Last updated | License |
|---|---|---|---|---|
| cmux Release Skill this page | 53 · Use with care | ★ 28k | 1d ago | NOASSERTION |
| Universal Release Flow | 51 · Use with care | ★ 4.3k | 18d ago | MIT |
| DeepChat Release Assistant | 46 · Use with care | ★ 6.4k | 3d ago | Apache-2.0 |
| ORCH — AI Agent Orchestrator | 49 · Use with care | ★ 170 | 2mo ago | MIT |
| Bump Version — Automated Release Workflow for AionUi | 38 · Not recommended | ★ 33k | 1mo ago | Apache-2.0 |
The source names no alternatives. Compared with generic semver/tag release actions, this skill's distinguishing behavior is assembling the changelog from PR descriptions rather than requiring edits to CHANGELOG.md — but it only covers cmux's own release path.
How did FollowSkills review this skill?
The skill documents the cmux maintainer release flow and explicitly discloses required GitHub secrets (APPLE_CERTIFICATE_*, ASC_API_*) plus mode-600 temp-file handling with deletion, giving good data-flow transparency; however bump-version.sh, release-pretag-guard.sh and other key scripts are absent from evidence, rollback is only partially described, publisher identity is unverified, and license metadata is NOASSERTION, so full marks are withheld. No malicious behavior or covert exfiltration observed.
Instructions are self-consistent with explicit command sequences, and release-checklist.md provides detailed failure triage (pretag guard failure, signing/notarization failure, nightly notarization recovery), showing good failure feedback; but this is a static review — the referenced scripts are not in evidence and reproducibility cannot be confirmed, so the static cap of 10 applies.
Trigger conditions are clear in the description (use when preparing or troubleshooting a cmux release) and the audience is well defined as cmux maintainers; however it targets an internal workflow, and its core dependencies (GitHub Actions, Apple notarization, glaeda-gh) limit reachability and applicability for FollowSkills' mainland-China users, hence 9.
Docs are well layered (SKILL.md main flow, references/checklist, openai.yaml metadata), with dependency and failure notes; the repo actually carries a dual GPL-3.0-or-later / BUSL-1.1 license with full text present; but the skill itself lacks versioning, changelog, and explicit maintenance ownership, and NOASSERTION license metadata mismatches the actual license, so 9.
The core task (version bump, changelog aggregation, pretag guard, tagging, asset expectations) is described completely with judgment rules and failure recovery, offering marginal value over manual recall; but static review cannot verify directly usable outputs and the scripts are not in evidence, so below the static cap at 6.
There are traceable references (release.md, changelog-lines.jq, release-checklist.md, CI workflow files, script paths) and the repo contains real CI workflows corroborating the execution environment; but static review cannot independently reproduce the release flow, the referenced scripts are outside the evidence, and coverage is thin, so 4.
Open a dimension to read why it scored that way
Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.
See the full review method →