release-peekaboo

Installation
SKILL.md

Peekaboo Release

Release ~/Projects/Peekaboo as the npm package @steipete/peekaboo plus signed/notarized macOS app assets.

Use $one-password, $browser-use, $npm, $autoreview, and repo AGENTS.md rules. Load $release-private if it exists before resolving Peter-owned credential locators. Read $npm before any npm auth, token, or publish recovery work. Keep all op secret work inside one persistent tmux session. Never print .p8, npm tokens, passwords, or OTPs.

Current Secrets

  • Peter-owned credential item names, key ids, issuer ids, keychain paths, and npm token locators live in $release-private.
  • Required ASC fields: key_id, issuer_id, private_key_p8.
  • Stale/revoked key symptom: xcrun notarytool submit fails with HTTP status code: 401. Unauthenticated.
  • All ASC fields must come from the same current item; do not mix profile values with 1Password refs.

Sparkle key:

  • Resolve the exact MAC_RELEASE_SPARKLE_OP_REF from $release-private into the private release environment or tmux session; never add the locator to this public repo, status output, or logs.
  • The shared release helper uses the prompt-free service account, verifies the public key, and owns its mode-0600 temporary file cleanup. Do not set SPARKLE_PRIVATE_KEY_FILE for normal releases.
Installs
9
GitHub Stars
5.1K
First Seen
May 26, 2026
release-peekaboo — openclaw/peekaboo