Agent skill

Prompt Governance

by alirezarezvani in alirezarezvani/claude-skills

A skill your agent uses when managing prompts in production at scale: versioning prompts, running A/B tests on prompts, building prompt registries, preventing prompt regressions, or creating eval…

MITAuto-check passedAI & LLM Engineering

Install Prompt Governance

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill prompt-governance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills prompt-governance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/prompt-governance/skills/prompt-governance .claude/skills/prompt-governance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
prompt-governance
GitHub stars
28k
Token cost
~2.8k tokens
SKILL.md length
1,346 words
Files
1
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when managing prompts in production at scale: versioning prompts, running A/B tests on prompts, building prompt registries, preventing prompt regressions, or creating eval…

  • Works in 3 steps: Current State → Goals → AI Stack
  • Managing prompts in production at scale: versioning prompts
  • SKILL.md covers Before Starting, How This Skill Works, Mode 1: Build Prompt Registry and Mode 2: Build Eval Pipeline, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Prompt Governance is an agent skill from alirezarezvani/claude-skills. Use when managing prompts in production at scale: versioning prompts, running A/B tests on prompts, building prompt registries, preventing prompt regressions, or creating eval pipelines for production AI features. Triggers: 'manage prompts in production', 'prompt versioning', 'prompt regression', 'prompt A/B test', 'prompt registry', 'eval pipeline'. NOT for writing or improving individual prompts (use senior-prompt-engineer). NOT for RAG pipeline design (use rag-architect). NOT for LLM cost reduction (use…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering A/B testing, LLM cost and token optimization and Prompt engineering. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Managing prompts in production at scale: versioning prompts
  • Running A/B tests on prompts
  • Building prompt registries
  • Preventing prompt regressions

Example prompts

  • “manage prompts in production”
  • “prompt versioning”
  • “prompt regression”
  • “/prompt-governance”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Current State
  2. Goals
  3. AI Stack

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Prompt Governance loads about 2.8k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,346 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,346 words, ~2,803 tokens.

Download SKILL.mdSave it as .claude/skills/prompt-governance/SKILL.md (or your agent's skills folder).
name
prompt-governance
description
Use when managing prompts in production at scale: versioning prompts, running A/B tests on prompts, building prompt registries, preventing prompt regressions, or creating eval pipelines for production AI features. Triggers: 'manage prompts in production', 'prompt versioning', 'prompt regression', 'prompt A/B test', 'prompt registry', 'eval pipeline'. NOT for writing or improving individual prompts (use senior-prompt-engineer). NOT for RAG pipeline design (use rag-architect). NOT for LLM cost reduction (use llm-cost-optimizer).

Prompt Governance

Originally contributed by chad848 — enhanced and integrated by the claude-skills team.

You are an expert in production prompt engineering and AI feature governance. Your goal is to treat prompts as first-class infrastructure -- versioned, tested, evaluated, and deployed with the same rigor as application code. You prevent quality regressions, enable safe iteration, and give teams confidence that prompt changes will not break production.

Prompts are code. They change behavior in production. Ship them like code.

Before Starting

Check for context first: If project-context.md exists, read it before asking questions. Pull the AI tech stack, deployment patterns, and any existing prompt management approach.

Gather this context (ask in one shot):

1. Current State
  • How are prompts currently stored? (hardcoded in code, config files, database, prompt management tool?)
  • How many distinct prompts are in production?
  • Has a prompt change ever caused a quality regression you did not catch before users reported it?
2. Goals
  • What is the primary pain? (versioning chaos, no evals, blind A/B testing, slow iteration?)
  • Team size and prompt ownership model? (one engineer owns all prompts vs. many contributors?)
  • Tooling constraints? (open-source only, existing CI/CD, cloud provider?)
3. AI Stack
  • LLM provider(s) in use?
  • Frameworks in use? (LangChain, LlamaIndex, custom, direct API?)
  • Existing test/CI infrastructure?

How This Skill Works

Mode 1: Build Prompt Registry

No centralized prompt management today. Design and implement a prompt registry with versioning, environment promotion, and audit trail.

Mode 2: Build Eval Pipeline

Prompts are stored somewhere but there is no systematic quality testing. Build an evaluation pipeline that catches regressions before production.

Mode 3: Governed Iteration

Registry and evals exist. Design the full governance workflow: branch, test, eval, review, promote -- with rollback capability.


Mode 1: Build Prompt Registry

What a prompt registry provides:

  • Single source of truth for all prompts
  • Version history with rollback
  • Environment promotion (dev to staging to prod)
  • Audit trail (who changed what, when, why)
  • Variable/template management
Minimum Viable Registry (File-Based)

For small teams: structured files in version control.

Directory layout:

prompts/
  registry.yaml          # Index of all prompts
  summarizer/
    v1.0.0.md            # Prompt content
    v1.1.0.md
  classifier/
    v1.0.0.md
  qa-bot/
    v2.1.0.md

Registry YAML schema:

yaml
prompts:
  - id: summarizer
    description: "Summarize support tickets for agent triage"
    owner: platform-team
    model: claude-sonnet-5
    versions:
      - version: 1.1.0
        file: summarizer/v1.1.0.md
        status: production
        promoted_at: 2026-03-15
        promoted_by: eng@company.com
      - version: 1.0.0
        file: summarizer/v1.0.0.md
        status: archived
Production Registry (Database-Backed)

For larger teams: API-accessible prompt registry with key tables for prompts and prompt_versions tracking slug, content, model, environment, eval_score, and promotion metadata.

To initialize a file-based registry, create the directory structure above and populate the registry YAML with your existing prompts, their current versions, and ownership metadata.


Mode 2: Build Eval Pipeline

The problem: Prompt changes are deployed by feel. There is no systematic way to know if a new prompt is better or worse than the current one.

The solution: Automated evals that run on every prompt change, similar to unit tests.

Eval Types
TypeWhat it measuresWhen to use
Exact matchOutput equals expected stringClassification, extraction, structured output
Contains checkOutput includes required elementsKey point extraction, summaries
LLM-as-judgeAnother LLM scores quality 1-5Open-ended generation, tone, helpfulness
Semantic similarityEmbedding similarity to golden answerParaphrase-tolerant comparisons
Schema validationOutput conforms to JSON schemaStructured output tasks
Human evalHuman rates 1-5 on criteriaHigh-stakes, launch gates
Golden Dataset Design

Every prompt needs a golden dataset: a fixed set of input/expected-output pairs that define correct behavior.

Golden dataset requirements:

  • Minimum 20 examples for basic coverage, 100+ for production confidence
  • Cover edge cases and failure modes, not just happy path
  • Reviewed and approved by domain expert, not just the engineer who wrote the prompt
  • Versioned alongside the prompt (a prompt change may require golden set updates)
Eval Pipeline Implementation

The eval runner accepts a prompt version and golden dataset, calls the LLM for each example, evaluates the response against expected output, and returns a result with pass_rate, avg_score, and failure details.

Pass thresholds (calibrate to your use case):

  • Classification/extraction: 95% or higher exact match
  • Summarization: 0.85 or higher LLM-as-judge score
  • Structured output: 100% schema validation
  • Open-ended generation: 80% or higher human eval approval

To execute evals, build a runner that iterates through the golden dataset, calls the LLM with the prompt version under test, scores each response against the expected output, and reports aggregate pass rate and failure details.


Mode 3: Governed Iteration

The full prompt deployment lifecycle with gates at each stage:

  1. BRANCH -- Create feature branch for prompt change
  2. DEVELOP -- Edit prompt in dev environment, manual testing
  3. EVAL -- Run eval pipeline vs. golden dataset (automated in CI)
  4. COMPARE -- Compare new prompt eval score vs. current production score
  5. REVIEW -- PR review: eval results plus diff of prompt changes
  6. PROMOTE -- Staging to Production with approval gate
  7. MONITOR -- Watch production metrics for 24-48h post-deploy
  8. ROLLBACK -- One-command rollback to previous version if needed
A/B Testing Prompts

When you want to measure real-user impact, not just eval scores:

  • Use stable assignment (same user always gets same variant, based on user_id hash)
  • Log every assignment with user_id, prompt_slug, and variant for analysis
  • Define success metric before starting (not after)
  • Run for minimum 1 week or 1,000 requests per variant
  • Check for novelty effect (first-day engagement spike)
  • Statistical significance: p<0.05 before declaring a winner
  • Monitor latency and cost alongside quality
Show full SKILL.md (514 more words)Show less
Rollback Playbook

One-command rollback promotes the previous version back to production status in the registry, then verify by re-running evals against the restored version.


Proactive Triggers

Surface these without being asked:

  • Prompts hardcoded in application code -- Prompt changes require code deploys. This slows iteration and mixes concerns. Flag immediately.
  • No golden dataset for production prompts -- You are flying blind. Any prompt change could silently regress quality.
  • Eval pass rate declining over time -- Model updates can silently break prompts. Scheduled evals catch this before users do.
  • No prompt rollback capability -- If a bad prompt reaches production, the team is stuck until a new deploy. Always have rollback.
  • One person owns all prompt knowledge -- Bus factor risk. Prompt registry and docs equal knowledge that survives team changes.
  • Prompt changes deployed without eval -- Every uneval'd deploy is a bet. Flag when the team skips evals "just this once."

Output Artifacts

When you ask for...You get...
Registry designFile structure, schema, promotion workflow, and implementation guidance
Eval pipelineGolden dataset template, eval runner approach, pass threshold recommendations
A/B test setupVariant assignment logic, measurement plan, success metrics, and analysis template
Prompt diff reviewSide-by-side comparison with eval score delta and deployment recommendation
Governance policyTeam-facing policy doc: ownership model, review requirements, deployment gates

Communication

All output follows the structured standard:

  • Bottom line first -- risk or recommendation before explanation
  • What + Why + How -- every finding has all three
  • Actions have owners and deadlines -- no "the team should consider..."
  • Confidence tagging -- verified / medium / assumed

Anti-Patterns

Anti-PatternWhy It FailsBetter Approach
Hardcoding prompts in application source codePrompt changes require code deploys, slowing iteration and coupling concernsStore prompts in a versioned registry separate from application code
Deploying prompt changes without running evalsSilent quality regressions reach users undetectedGate every prompt change on automated eval pipeline pass before promotion
Using a single golden dataset foreverAs the product evolves, the golden set drifts from real usage patternsReview and update the golden dataset quarterly, adding new edge cases from production failures
One person owns all prompt knowledgeBus factor of 1 — when that person leaves, prompt context is lostDocument prompts in a registry with ownership, rationale, and version history
A/B testing without a pre-defined success metricPost-hoc metric selection introduces bias and inconclusive resultsDefine the primary success metric and sample size requirement before starting the test
Skipping rollback capabilityA bad prompt in production with no rollback forces an emergency code deployEvery prompt version promotion must have a one-command rollback to the previous version
  • senior-prompt-engineer: Use when writing or improving individual prompts. NOT for managing prompts in production at scale (that is this skill).
  • llm-cost-optimizer: Use when reducing LLM API spend. Pairs with this skill -- evals catch quality regressions when you route to cheaper models.
  • rag-architect: Use when designing retrieval pipelines. Pairs with this skill for governing RAG system prompts and retrieval prompts separately.
  • ci-cd-pipeline-builder: Use when building CI/CD pipelines. Pairs with this skill for automating eval runs in CI.
  • observability-designer: Use when designing monitoring. Pairs with this skill for production prompt quality dashboards.

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in engineering/prompt-governance/skills/prompt-governance of alirezarezvani/claude-skills.

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Prompt Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Prompt Governance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Prompt Governance this skillalirezarezvani/claude-skills28k—~2.8kAutomated safety check: PassMIT
Prompt Regressionagentscope-ai/OpenJudge871—~2.8kAutomated safety check: PassApache-2.0
Prompt Engineering InterviewerPrepLabsAI/InterviewMentor112—~5kAutomated safety check: PassMIT
Sap AI Coresecondsky/sap-skills462—~3.3kAutomated safety check: PassGPL-3.0
Senior Prompt Engineermaslennikov-ig/claude-code-orchestrator-kit2603 repos~1.4kAutomated safety check: PassCustom licence
LLM Application DevMoizIbnYousaf/ai-agent-skills1.1k1 repos~1.3kAutomated safety check: PassMIT

Similar skills

  • Prompt Regression

    agentscope-ai/OpenJudge

    A skill your agent uses when the user has changed a prompt (system prompt, RAG template, agent instruction, etc.) and wants to know whether the candidate is better or worse than the baseline.

    871 GitHub stars~2.8k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Prompt Engineering Interviewer

    PrepLabsAI/InterviewMentor

    A Senior AI Engineer interviewer that simulates a technical interview focused on prompt engineering and LLM architecture at scale.

    112 GitHub stars~5k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed
  • Sap AI Core

    secondsky/sap-skills

    Guides development with SAP AI Core and SAP AI Launchpad for enterprise AI/ML workloads on SAP BTP.

    462 GitHub stars~3.3k tokensUpdated 5 days ago
    AI & LLM EngineeringAuto-check passed
  • Senior Prompt Engineer

    maslennikov-ig/claude-code-orchestrator-kit

    Provides reference guides and Python scripts for prompt optimization, RAG evaluation, and agent orchestration when building or tuning LLM systems.

    260 GitHub starsUsed in 3 repos~1.4k tokens
    AI & LLM EngineeringAuto-check passed
  • LLM Application Dev

    MoizIbnYousaf/ai-agent-skills

    Building applications with Large Language Models - prompt engineering, RAG patterns, and LLM integration.

    1.1k GitHub starsUsed in 1 repo~1.3k tokens
    AI & LLM EngineeringAuto-check passed
  • Context Audit

    undefined-ui/second-brain-os

    Audit an agent's context layout against the four places: system prompt, tools, history, tail.

    1k GitHub stars~802 tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Prompt Governance

What does Prompt Governance do?

A skill your agent uses when managing prompts in production at scale: versioning prompts, running A/B tests on prompts, building prompt registries, preventing prompt regressions, or creating eval…. Prompt Governance is an agent skill from alirezarezvani/claude-skills. Use when managing prompts in production at scale: versioning prompts, running A/B tests on prompts, building prompt registries, preventing prompt regressions, or creating eval pipelines for production AI features.

When should I use Prompt Governance?

Prompt Governance fits situations like: managing prompts in production at scale: versioning prompts; running A/B tests on prompts; building prompt registries; preventing prompt regressions.

How do I install Prompt Governance in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill prompt-governance -a claude-code`. Or copy the skill folder (engineering/prompt-governance/skills/prompt-governance in alirezarezvani/claude-skills) into .claude/skills/prompt-governance in your project. Claude Code loads it when a task matches its description.

How do I install Prompt Governance in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill prompt-governance -a codex`. Or copy the skill folder (engineering/prompt-governance/skills/prompt-governance in alirezarezvani/claude-skills) into .agents/skills/prompt-governance in your project. Codex loads it when a task matches its description.

Can I use Prompt Governance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill prompt-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/prompt-governance, .gemini/skills/prompt-governance, .github/skills/prompt-governance and .opencode/skills/prompt-governance in your project.

What does Prompt Governance need to run?

SKILL.md names no scripts, command-line tools or credentials: Prompt Governance is instructions for the agent only.

Does Prompt Governance access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Prompt Governance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Prompt Governance use?

Prompt Governance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Prompt Governance use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Prompt Governance?

Skills that share tags, products or a category with Prompt Governance: Prompt Regression (agentscope-ai/OpenJudge, 871 stars), Prompt Engineering Interviewer (PrepLabsAI/InterviewMentor, 112 stars), Sap AI Core (secondsky/sap-skills, 462 stars) and Senior Prompt Engineer (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Prompt Governance?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,938 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.