Agent skill

Release Evidence Workflow

by Ali-Marandi in Ali-Marandi/ClimateDataAnalyzer

Build an auditable release-evidence workflow for a desktop or packaged application.

MITAuto-check passedData & Analytics

Install Release Evidence Workflow

skills CLI
$ npx skills add Ali-Marandi/ClimateDataAnalyzer --skill release-evidence-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Ali-Marandi/ClimateDataAnalyzer release-evidence-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Ali-Marandi/ClimateDataAnalyzer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/release-evidence-workflow .claude/skills/release-evidence-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-evidence-workflow
GitHub stars
107
Token cost
~1.6k tokens
SKILL.md length
753 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Build an auditable release-evidence workflow for a desktop or packaged application.

  • Works in 7 steps: Establish the release boundary → Define data and geography semantics → Generate evidence, not assertions → …
  • Reviewing authoritative-data features
  • SKILL.md covers Guardrails, Workflow and Definition of Done
  • Calls git and pytest; needs CODESIGN_PFX_PASSWORD

What it does

Release Evidence Workflow is an agent skill from Ali-Marandi/ClimateDataAnalyzer. Build an auditable release-evidence workflow for a desktop or packaged application. Use when implementing or reviewing authoritative-data features, local and live smoke validation, guarded GitHub Actions Windows packaging/signing, controlled commit/push, release-readiness reporting, or technical/executive presentation materials.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering CI/CD, Feature launches and release readiness and Data visualization. It works with GitHub Actions, Jupyter, Python and Matplotlib. The repository describes itself as: A professional Python-based tool for analyzing and visualizing historical global temperature trends and climate anomalies. The licence is MIT.

When your agent uses it

  • Reviewing authoritative-data features
  • Local and live smoke validation
  • Guarded GitHub Actions Windows packaging/signing
  • Controlled commit/push

Example prompts

  • “/release-evidence-workflow”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Establish the release boundary
  2. Define data and geography semantics
  3. Generate evidence, not assertions
  4. Design GitHub Actions with a signed-release gate
  5. Commit and push in controlled stages
  6. Write a decision-ready evidence summary
  7. Prepare presentations without changing evidence

What it can do on your machine

Read from SKILL.md and the folder at commit a6a87f6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • pytest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CODESIGN_PFX_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Evidence Workflow loads about 1.6k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 753 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Ali-Marandi/ClimateDataAnalyzer at commit a6a87f6, republished under its MIT licence (© Ali-Marandi). 753 words, ~1,596 tokens.

Download SKILL.mdSave it as .claude/skills/release-evidence-workflow/SKILL.md (or your agent's skills folder).
name
release-evidence-workflow
description
Build an auditable release-evidence workflow for a desktop or packaged application. Use when implementing or reviewing authoritative-data features, local and live smoke validation, guarded GitHub Actions Windows packaging/signing, controlled commit/push, release-readiness reporting, or technical/executive presentation materials.

Release Evidence Workflow

Use this workflow to turn an implemented desktop product into evidence that is reviewable without overstating scientific, security, or release claims.

Guardrails

  • Separate branch CI artifacts from signed public releases. Never call an unsigned branch installer a stable signed release.
  • Require fresh, explicit approval before a remote push, tag, public release, secret mutation, payment, or installer execution.
  • Never request, print, stage, commit, or pass a PFX password, PAT, signing certificate, or Base64 certificate in a command argument.
  • Treat external-source responses as time-bounded evidence. Record the exact input, source label, timestamp, result, and failure collection; do not claim availability, accuracy, or latency guarantees from one smoke run.
  • Preserve the product’s scientific boundary. Published scenario summaries are not a new physical model, deterministic forecast, local-impact conclusion, or operational recommendation.

Workflow

1. Establish the release boundary

Inspect repository state before modifying it:

bash
git status -sb
git log --oneline -5
git remote -v
git config user.name && git config user.email

Record the current version in package metadata and runtime metadata. State whether the target operation is only a branch push, a version tag, or a public release. If the user has not explicitly authorized the relevant external action, stop after local preparation.

2. Define data and geography semantics

When the product consumes authoritative external data, document the source, parameter contract, uncertainty fields, and known scope. For country-level scenario summaries, label spatial exports as country summaries. Do not invent a high-resolution raster from a country aggregate. Preserve CRS, transform, data type, source and limitation metadata in GIS outputs.

3. Generate evidence, not assertions

Run the full local suite in a reproducible headless mode where appropriate. Persist a verbose log with test names and slowest durations:

bash
mkdir -p docs/validation_logs
set -o pipefail
QT_QPA_PLATFORM=offscreen pytest -vv --durations=10 2>&1 \
  | tee docs/validation_logs/local_pytest_YYYY-MM-DD.log

Run at most a bounded, user-relevant live smoke request. Save the output and elapsed observation. Clearly distinguish a test failure from a missing local measurement utility or other environment failure.

Report total collected/passed/failed/skipped/xfailed, duration, major test families, slowest tests, live request inputs, source label, returned fields, failure collection, and measurement limitations.

4. Design GitHub Actions with a signed-release gate

Use two distinct paths.

PathTriggerMinimum evidencePublication rule
Branch CIpush / pull requesttests, package build, installer build, silent install-uninstall test, unsigned artifactNever publish stable release
Stable releaseprotected vX.Y.Z tagenvironment approval, PFX secret checks, Authenticode signing and verification, signed installer silent testPublish only signed artifacts

Audit each invoked JavaScript action before publishing workflow changes. Inspect its tagged action.yml and upgrade to a Node.js 24-compatible major for checkout, language setup, artifact upload/download, and third-party release actions. Add a static contract test that rejects known Node.js 20 majors, then use the next CI run to prove the warning is gone.

Use a protected environment such as production for signing. Require expected secret names but never create fake secret values. A PFX pattern normally needs CODESIGN_PFX_BASE64, CODESIGN_PFX_PASSWORD, and a trusted timestamp URL configured as a variable or controlled input. Decode certificates only into the runner temp directory, use SHA-256 plus an RFC 3161 timestamp, run signtool verify /pa /all on both EXE and installer, and delete the temporary PFX afterward.

Do not claim code signing until a CI run has actually signed and verified artifacts with the real certificate.

Show full SKILL.md (236 more words)Show less
5. Commit and push in controlled stages

Use explicit paths rather than git add .. Before committing, inspect staged content:

bash
git diff --check
git add <explicit-paths>
git diff --cached --check
git diff --cached --stat
git diff --cached

Scan staged material for accidental credentials. The scan supplements, but does not replace, human review. Commit only after reviewing the staged diff. Before push, fetch and compare refs. Push only with fresh user authorization:

bash
git fetch --prune origin
git log --oneline origin/<branch>..HEAD
git push origin <branch>

After push, verify branch alignment and inspect the CI run. Do not create a tag or release unless it was separately authorized.

6. Write a decision-ready evidence summary

Create a concise technical report with: current commit/ref, exact test result, performance caveat, live-source result, CI state, signing state, release state, and next gates. Use status words precisely:

  • Passed: a named command or CI job completed successfully.
  • In progress: a remote job has started but has no final conclusion.
  • Not executed: a gated step, such as signing, was intentionally not run.
  • Not created: no tag, release, or secret exists.
7. Prepare presentations without changing evidence

Create separate content and speaker-script files before creating slides. Use a concise executive deck and, when requested, an internal technical deck. Include the scientific boundary, uncertainty, evidence artifacts, validation outcome, release state, and decisions required. Preserve current status rather than projecting future success.

Definition of Done

Deliver a readable evidence package with validation log(s), local/live metrics summary, CI link or status, signing/release state, and presentation materials. Attach this SKILL.md when delivering the skill so it can be installed or downloaded.

© Ali-Marandi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/release-evidence-workflow of Ali-Marandi/ClimateDataAnalyzer.

Open the folder on GitHubat commit a6a87f6

Compare with similar skills

Release Evidence Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Evidence Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Evidence Workflow this skillAli-Marandi/ClimateDataAnalyzer107—~1.6kAutomated safety check: PassMIT
Analytics Data AnalysisMindrally/skills269—~1.6kAutomated safety check: PassApache-2.0
SeabornK-Dense-AI/scientific-agent-skills48k1 repos~3.4kAutomated safety check: NotesBSD-3-Clause
Python Visualsdata-goblin/power-bi-agentic-development1k—~2.1kAutomated safety check: PassGPL-3.0
Plot ML Figureprobabl-ai/skills138—~785Automated safety check: PassBSD-3-Clause
SeabornzLanqing/codex-claude-academic-skills4.7k15 repos~4.9kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Analytics Data Analysis

    Mindrally/skills

    Best practices for analytics, data analysis, and visualization using Python, pandas, matplotlib, seaborn, and Jupyter notebooks.

    269 GitHub stars~1.6k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Seaborn

    K-Dense-AI/scientific-agent-skills

    Creates Seaborn statistical visualizations with pandas integration for distributions, relationships, categorical comparisons, regression displays, pair plots, and heatmaps.

    48k GitHub starsUsed in 1 repo~3.4k tokens
    Data & AnalyticsAuto-check: notes
  • Python Visuals

    data-goblin/power-bi-agentic-development

    Python visual creation and matplotlib/seaborn patterns for PBIR reports.

    1k GitHub stars~2.1k tokensUpdated 2 days ago
    Data & AnalyticsAuto-check passed
  • Plot ML Figure

    probabl-ai/skills

    Pick how to write a figure before custom plot code. An agent skill from probabl-ai/skills.

    138 GitHub stars~785 tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Seaborn

    zLanqing/codex-claude-academic-skills

    Statistical visualization with pandas integration. An agent skill from zLanqing/codex-claude-academic-skills.

    4.7k GitHub starsUsed in 15 repos~4.9k tokens
    Data & AnalyticsAuto-check passed
  • Python Executor

    cortega26/chile-hub

    Execute Python code in a safe sandboxed environment via [inference.sh](https://inference.sh).

    113 GitHub starsUsed in 2 repos~1.5k tokens
    Data & AnalyticsAuto-check passed

Questions about Release Evidence Workflow

What does Release Evidence Workflow do?

Build an auditable release-evidence workflow for a desktop or packaged application. Release Evidence Workflow is an agent skill from Ali-Marandi/ClimateDataAnalyzer. Build an auditable release-evidence workflow for a desktop or packaged application.

When should I use Release Evidence Workflow?

Release Evidence Workflow fits situations like: reviewing authoritative-data features; local and live smoke validation; guarded GitHub Actions Windows packaging/signing; controlled commit/push.

How do I install Release Evidence Workflow in Claude Code?

Run `npx skills add Ali-Marandi/ClimateDataAnalyzer --skill release-evidence-workflow -a claude-code`. Or copy the skill folder (skills/release-evidence-workflow in Ali-Marandi/ClimateDataAnalyzer) into .claude/skills/release-evidence-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Release Evidence Workflow in Codex?

Run `npx skills add Ali-Marandi/ClimateDataAnalyzer --skill release-evidence-workflow -a codex`. Or copy the skill folder (skills/release-evidence-workflow in Ali-Marandi/ClimateDataAnalyzer) into .agents/skills/release-evidence-workflow in your project. Codex loads it when a task matches its description.

Can I use Release Evidence Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Ali-Marandi/ClimateDataAnalyzer --skill release-evidence-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-evidence-workflow, .gemini/skills/release-evidence-workflow, .github/skills/release-evidence-workflow and .opencode/skills/release-evidence-workflow in your project.

What does Release Evidence Workflow need to run?

Going by SKILL.md and its folder, Release Evidence Workflow needs the command-line tools its instructions call (git and pytest) and credentials named CODESIGN_PFX_PASSWORD. Our summary lists: Node.js.

Does Release Evidence Workflow access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release Evidence Workflow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Evidence Workflow use?

Release Evidence Workflow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Evidence Workflow use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Evidence Workflow?

Skills that share tags, products or a category with Release Evidence Workflow: Analytics Data Analysis (Mindrally/skills, 269 stars), Seaborn (K-Dense-AI/scientific-agent-skills, 48k stars), Python Visuals (data-goblin/power-bi-agentic-development, 1k stars) and Plot ML Figure (probabl-ai/skills, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Evidence Workflow?

Ali-Marandi (a GitHub user) maintains it in Ali-Marandi/ClimateDataAnalyzer, which has 107 GitHub stars. The repository was last updated on August 27, 2026.

Source: Ali-Marandi/ClimateDataAnalyzer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.