Release
paperclipai/paperclip
Coordinate a full Paperclip release across engineering verification, npm, GitHub, smoke testing, and announcement follow-up.
Audit software releases with unforgiving standards. An agent skill from aiskillstore/marketplace.
$ npx skills add aiskillstore/marketplace --skill universal-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aiskillstore/marketplace universal-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/glenskii/universal-audit .claude/skills/universal-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "universal-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/universal-audit into .claude/skills/universal-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "universal-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/universal-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aiskillstore/marketplace --skill universal-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aiskillstore/marketplace universal-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/glenskii/universal-audit .agents/skills/universal-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "universal-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/universal-audit into .agents/skills/universal-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "universal-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aiskillstore/marketplace --skill universal-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aiskillstore/marketplace universal-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/glenskii/universal-audit .cursor/skills/universal-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "universal-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/universal-audit into .cursor/skills/universal-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "universal-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aiskillstore/marketplace.git --path skills/glenskii/universal-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aiskillstore/marketplace --skill universal-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aiskillstore/marketplace universal-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/glenskii/universal-audit .gemini/skills/universal-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "universal-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/universal-audit into .gemini/skills/universal-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "universal-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aiskillstore/marketplace universal-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aiskillstore/marketplace --skill universal-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/glenskii/universal-audit .github/skills/universal-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "universal-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/universal-audit into .github/skills/universal-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "universal-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aiskillstore/marketplace --skill universal-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aiskillstore/marketplace universal-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/glenskii/universal-audit .opencode/skills/universal-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "universal-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/universal-audit into .opencode/skills/universal-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "universal-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
universal-auditAudit software releases with unforgiving standards. An agent skill from aiskillstore/marketplace.
Universal Audit is an agent skill from aiskillstore/marketplace. Audit software releases with unforgiving standards. Use when soft approvals or incomplete scope could create deployment risk. Execute a full-lifecycle audit across fifteen core domains, including security, architecture, UX, and privacy. Apply deterministic scoring, evaluate hard evidence, and enforce release gates with hard-stop rules regardless of the overall score.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/audit-manifest-template.json` and `docs/evidence-ledger-guide.md`).
The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ad8daf7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Universal Audit loads about 1.9k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 930 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aiskillstore/marketplace at commit ad8daf7, republished under its MIT licence (© aiskillstore). 930 words, ~1,928 tokens.
.claude/skills/universal-audit/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.This skill executes the Universal Software Engineering Audit Specification v2.2 (bundled at spec/Universal_Software_Engineering_Audit_Specification.md). The spec is normative. This file is the execution procedure. When they conflict, the spec wins.
Core discipline, non-negotiable:
package.json / requirements.txt / wrangler.toml / equivalent before anything else.references/templates/intake-template.md. Ask the operator only for items you cannot establish yourself. Missing inputs go to Audit Limitations, never silently assumed.references/depth-and-profiles.md). If the operator did not specify depth, propose one with rationale and wait.AUD-[PRODUCT]-[YYYYMMDD]-[SEQ].GOV-SCOPE-001 and GOV-ROE-001 first. If either cannot PASS, the engagement is advisory only - say so now, not in the report.audits/<audit-id>/ in the project root (or an operator-specified location). Run scripts/init_audit_artifacts.py --audit-id <audit-id> --output audits/<audit-id> to create the initial manifest from assets/audit-manifest-template.json. It refuses to overwrite an existing directory.selected-controls.json (schema in references/schemas/). This freezes the coverage denominator before any evidence is gathered - selection cannot be trimmed later to inflate coverage.Work the spec Section 12 order. For each selected control, gather the minimum PASS evidence listed in the catalog or stronger. Practical guidance per family is in references/control-procedures.md. Read references/release-evidence-catalog.md when choosing evidence for a release gate. Read docs/evidence-ledger-guide.md before recording evidence for the first time.
evidence-ledger.json: ID, class, timestamp, location (file:line, endpoint, config key), method, sanitized excerpt, limitations.UNVERIFIED - Runtime inference only.findings.json. Severity is impact, likelihood is separate, confidence is separate. Low-confidence concerns normally stay UNVERIFIED.Run scripts/score.py:
python scripts/score.py audits/<audit-id>/selected-controls.json \
--profile P4 --tier standard --out audits/<audit-id>/score-sheet.jsonIt computes per-category provisional scores, applies the mandatory caps, computes tier-relative coverage (and the Standard-denominator figure for Rapid audits), validates category mapping, and evaluates the release gates. Do not hand-calculate scores; the script is the single source of arithmetic. 2. Select exactly one verdict - APPROVED / APPROVED WITH CONDITIONS / REQUIRES REWORK / DO NOT SHIP - from the script's gate evaluation plus the qualitative gates the script cannot check (critical-workflow verification, interim-control ownership). Justify the verdict against the gates line by line.
Standard tier: run a separate contradiction pass - a fresh subagent that did not author the findings attempts to refute every Critical/High finding, every release-significant Medium/WARN, and every C3 PASS supporting approval, and recalculates the score sheet. Deep tier: the challenge must be a genuinely independent agent or human review.
Record each challenge outcome: UPHELD / MODIFIED / REJECTED / NEEDS MORE EVIDENCE, with rationale, in verification-log.json. Resolve differences transparently.
report.md from references/templates/report-template.md. Executive summary is seven sentences maximum.audits/<audit-id>/: audit-manifest.json, selected-controls.json, evidence-ledger.json, findings.json, score-sheet.json, risk-register.json, verification-log.json, report.md.If the operator supplies a prior audit ID or report, run spec Section 16 instead of a fresh Phase 1–3: verify each prior FAIL/WARN against its original reproduction, classify (OPEN / PARTIALLY REMEDIATED / REMEDIATED / ACCEPTED / REGRESSED / NOT REPRODUCIBLE), re-run all applicable C3 controls, recalculate from current evidence, and produce the delta table. Never carry a PASS forward without confirming its evidence still holds.
© aiskillstore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 20 other files (scripts, references, assets) in skills/glenskii/universal-audit of aiskillstore/marketplace.
Open the folder on GitHubat commit ad8daf7
Universal Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Universal Audit this skillaiskillstore/marketplace | 430 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Releasepaperclipai/paperclip | 99k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Universal Project Release WorkflowJimLiu/baoyu-skills | 26k | — | ~4.9k | Automated safety check: Pass | MIT | |
| Openclaw Release Validationopenclaw/openclaw | 392k | — | ~987 | Automated safety check: Pass | MIT | |
| Release Generate Release Notesmountain-loop/yaak | 19k | — | ~548 | Automated safety check: Pass | MIT | |
| Verify Releaseopenclaw/openclaw | 392k | — | ~2.4k | Automated safety check: Pass | MIT |
paperclipai/paperclip
Coordinate a full Paperclip release across engineering verification, npm, GitHub, smoke testing, and announcement follow-up.
JimLiu/baoyu-skills
Detects a project's version file and changelog format, then runs a release: bumping the version, writing release notes and creating GitHub releases, including backfill.
openclaw/openclaw
Guide human release testing on an isolated OCM copy or approved in-place gateway, collect feedback, or refresh the release campaign.
mountain-loop/yaak
Generate Yaak release notes from git history and PR metadata, including feedback links and full changelog compare links.
openclaw/openclaw
Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…
codewhale-hq/Codewhale
Prepare a named version: preflight, version consistency, build/package, smoke test, checksums/notes, and release readiness.
aiskillstore/marketplace
Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).
aiskillstore/marketplace
Modern file and content search using fd, ripgrep (rg), and fzf.
aiskillstore/marketplace
Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.
aiskillstore/marketplace
Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.
aiskillstore/marketplace
Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.
aiskillstore/marketplace
Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…
Audit software releases with unforgiving standards. An agent skill from aiskillstore/marketplace. Universal Audit is an agent skill from aiskillstore/marketplace. Audit software releases with unforgiving standards.
Universal Audit fits situations like: incomplete scope could create deployment risk.
Run `npx skills add aiskillstore/marketplace --skill universal-audit -a claude-code`. Or copy the skill folder (skills/glenskii/universal-audit in aiskillstore/marketplace) into .claude/skills/universal-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aiskillstore/marketplace --skill universal-audit -a codex`. Or copy the skill folder (skills/glenskii/universal-audit in aiskillstore/marketplace) into .agents/skills/universal-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill universal-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/universal-audit, .gemini/skills/universal-audit, .github/skills/universal-audit and .opencode/skills/universal-audit in your project.
Going by SKILL.md and its folder, Universal Audit needs the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Universal Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Universal Audit: Release (paperclipai/paperclip, 99k stars), Universal Project Release Workflow (JimLiu/baoyu-skills, 26k stars), Openclaw Release Validation (openclaw/openclaw, 392k stars) and Release Generate Release Notes (mountain-loop/yaak, 19k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,108 skills in this directory. The repository was last updated on October 7, 2026.
Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.