Use case · By risk
Give a package release an owner and a record
For maintainers adding dependencies or publishing packages.
An installation, dependency review and package publication are different decisions. A single chat request can hide that distinction. Create separate Work tasks for the dependency review and publication. Give each an owner and link the package, changelog and verification results.
Installs and publishes
Review the shared package publication
- 1
Next action
Check the version and release evidence
- 2
Context
Package name and intended version
- 3
Evidence
Dependency review and verification results
What to put in the task
- Assign the task to the person responsible for the next action.
- Add evidence links and explain what they show in a comment.
- Update the task when the work changes so the next reader has the current state.
Before you rely on it
Command interception depends on your client's hooks or proxy; see the setup guide for Claude Code, Codex, Cursor and other MCP clients.
- Specify does not make a dependency safe by recording its version. Registry permissions, package review and publication controls remain necessary.
- Work must be enabled for the selected account, and you need permission to read or change the task. Security access and device setup are separate.
Related use cases and clients
By riskNetwork off the allowlistThe access decision stays attached to the work that required it.By riskProduction changesThe person reviewing the release can read the proposed change and its supporting evidence in the same task.By clientCursorSetup requirements for Cursor.
All use cases →