The Airclerk Marketplace Publisher is a GitHub App. It publishes skills built in Airclerk into a GitHub repository you own, as a pull request. It writes Claude plugin marketplaces and OpenAI plugin marketplaces, and can keep both in the same repository.
Airclerk never becomes the owner of your marketplace. The repository is yours, the catalogue lists you as its owner, and every change arrives as a pull request. Unless you turn on automatic merging, nothing reaches your default branch until someone merges it.
Which marketplaces it writes
Your account's AI agents setting decides which formats a publish writes. Each format has its own manifest and catalogue, and both share one folder of skill files.
| File | Anthropic (Claude) | OpenAI |
|---|---|---|
| Catalogue | .claude-plugin/marketplace.json | .agents/plugins/marketplace.json |
| Plugin manifest | plugins/<plugin>/.claude-plugin/plugin.json | plugins/<plugin>/plugin.json |
| Skills | plugins/<plugin>/skills/<skill>/, shared by both | |
With both turned on, one publish writes both formats in the same pull request. Turning a format off later leaves its existing files in your repository as they are. Microsoft 365 Copilot agent packages are download only and are never published to a repository.
What happens when someone publishes
- The App reads the current file tree of your repository's default branch.
- It writes the skill's files under
plugins/<plugin>/skills/<skill>/. - It creates or updates the plugin manifest for each format you use and bumps its version, the same version in both. Without a version bump, installed clients see no change and never pull the update.
- It adds or updates the plugin's entry in each catalogue, preserving every other entry and any fields Airclerk does not own.
- It opens a pull request from a new branch named
airclerk-publish/<plugin>/<date>-<suffix>, orairclerk-publish/multi/…when the publish spans several plugins. - If your account has automatic merging turned on, it then asks GitHub to merge the pull request. See Merging below.
One publish is one commit and one pull request, however many skills, plugins or formats it spans.
Merging
By default the App opens the pull request and stops there. You read the diff and merge it yourself.
An account can turn on Merge into the default branch automatically when checks pass in its Automation settings. It is off by default, only people who can manage the account's settings can change it, and every change is recorded. With it on:
- The App turns on GitHub's auto-merge for the pull request, and GitHub merges it once the repository's required checks pass.
- If the repository has no required checks, there is nothing to wait for, so the App merges the pull request straight away.
- It uses a merge method your repository allows, preferring a merge commit, then squash, then rebase.
- If Allow auto-merge is off in the repository's GitHub settings, the pull request stays open and Airclerk tells you to turn that setting on or merge it yourself.
- If branch protection requires a review, the pull request waits for a person to approve it. The App never approves a pull request, including its own.
- The pull request description notes that the account's Automation settings requested the merge.
If auto-merge can't be set up, the publish still succeeds and the pull request stays open for you to merge.
With automatic merging on, your required checks are the only thing between a publish and everyone who has installed the plugin. If the repository has none, a publish goes live without anyone reading the diff.
A separate setting, Open the pull request after publishing, only affects the Airclerk portal: when it is on, the portal opens the new pull request in a browser tab. It is off by default and does not change what happens on GitHub.
What it never does
- It never commits to your default branch. There is no direct-push mode. Every change goes through a pull request.
- It never merges a pull request unless the account has turned on automatic merging.
- It never approves or closes a pull request.
- It never touches another plugin. Deletions are limited to the published skill's own folder.
- It never reads issues, Actions, secrets, packages, deployments or your organisation's membership. It does not request those permissions.
- It never stores a GitHub credential. See Tokens and storage below.
What a republish removes
Republishing a skill deletes files under plugins/<plugin>/skills/<skill>/ that the new bundle no longer contains, so a removed file does not linger. If a skill has been renamed or moved to another plugin, its old folder is removed. It leaves alone:
- other skills in the same plugin
- hand-authored files in the plugin, such as
.mcp.json - every other plugin in the repository
- the files of a format you have turned off
- anything outside
plugins/apart from the catalogues, which are updated in place and never deleted
Removals reach everyone who has installed the plugin. Read the diff before merging, or before turning on automatic merging.
Permissions
| Permission | Why it is needed |
|---|---|
| Contents, read & write | Read the current tree to know what to replace. Write the skill files, the plugin manifests and the catalogues. Merge the pull request when automatic merging is on. |
| Pull requests, write | Open the publish pull request and turn on auto-merge for it. |
| Metadata, read | GitHub requires it for every GitHub App. |
Nothing else is requested.
Repository access
Grant access to one repository: your marketplace repo. Each Airclerk account connects a single repository, and the connection is refused if the installation cannot reach one. If you grant more than one, Airclerk uses only the first, so grant just the one you want published to.
Tokens and storage
Each publish gets its own access token, scoped to your one repository, and it expires within the hour. When you first connect, a short-lived token is used once to list the repositories you granted. Tokens are never written to disk or to a database.
Airclerk stores the installation ID and the details it needs to publish: the repository's owner, name and ID, its default branch, the GitHub login that connected it, your marketplace's name and owner details, and the connection's status. None of these grants access to your repository without Airclerk's own App private key.
Why you are asked to authorize as well as install
GitHub's install flow hands us an installation ID. That proves the installation exists, but not that it is yours. So the flow also asks you to authorize the App as a user. We use that once, when you connect, to confirm with GitHub that the installation is one your GitHub account has access to.
Without that step, someone else could claim your installation and publish into your repository. The authorization is not stored, and we do not use it to read your profile, your email or any repository.
If you uninstall, suspend or remove the repository
GitHub notifies us. If you uninstall the App or remove the repository from it, the connection is marked revoked immediately and publishing stops. Reconnecting later starts with a fresh authorization. If you suspend the App, publishing pauses and resumes when you unsuspend it. Either way, the Airclerk operator is told why publishing has stopped instead of seeing a confusing failure.
Privacy
See the Airclerk privacy policy. Questions about the App can go to support@airclerk.ai.