Agent skill

Audit Release

by devcodex-labs in devcodex-labs/devcodex

发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于…

AGPL-3.0Auto-check: warningsProduct & Project Management

Install Audit Release

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add devcodex-labs/devcodex --skill audit-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcodex-labs/devcodex audit-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/audit-release .claude/skills/audit-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-release
GitHub stars
439
Token cost
~1k tokens
SKILL.md length
200 words
Files
2
Skills in repo
70
Repo updated
First seen
Licence
AGPL-3.0

At a glance

发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于…

  • Works in 5 steps: 先执行 audit-common 的… → 冻结发布审查范围:目标版本、发布包、registry、关联… → 逐项执行 RL-1~RL-10;缺证据时标为 ⚠️待验证,不得写成通过。 → …
  • Tasks that involve Feature launches and release readiness
  • SKILL.md covers 职责边界, 输入范围, RL-1~RL-10 发布审查维度 and 执行步骤, plus 1 more section
  • Calls npm

What it does

Audit Release is an agent skill from devcodex-labs/devcodex. 发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于 release-verification,本 Skill 负责审查判断,不执行真实发布动作。

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).

It sits in Product & Project Management, covering Feature launches and release readiness. The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Feature launches and release readiness

Example prompts

  • “/audit-release”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 先执行 audit-common 的 G0~G5,确认审查范围、文件完整性、一致性与链接基础质量。
  2. 冻结发布审查范围:目标版本、发布包、registry、关联 changelog、关联需求/bug,并用 tag/registry/release note/public docs/实际消费者建立发布权威证据。
  3. 逐项执行 RL-1~RL-10;缺证据时标为 ⚠️待验证,不得写成通过。
  4. 对照 release-verification:执行链缺失写 RL-7;审查风险缺失写 RL-1~RL-6/RL-8~RL-10;RL-9 触发 PublisherCredentialTopologyGate 时,复制 workflow 或普通 dry-run 不能替代…
  5. 输出 findings-first 报告;无问题时仍列出通过证据和残余风险。

What it can do on your machine

Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Release loads about 1k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 200 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:38
    y 追加 `ScopedRegistryResolutionGate`,核对 `.npmrc` scope 路由、命令级 override、发布身份、secret scope/access/inheritance、workflow perm

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 200 words, ~1,030 tokens.

Download SKILL.mdSave it as .claude/skills/audit-release/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
audit-release
description
发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于 release-verification,本 Skill 负责审查判断,不执行真实发布动作。

Release Audit Skill

职责边界

audit-release 回答“当前变更是否适合进入正式发布,以及风险是否被充分披露”。release-verification 回答“版本、测试、pack、publish dry-run、tag 和发布后验收链是否执行通过”。

  • 审查型:发现风险、缺口、遗漏与建议,默认只读。
  • 不执行真实 tag / push / publish。
  • 可引用 release-verification 的 R0~R7 结果作为证据,但不能用执行通过替代审查结论。
  • package completeness gate 是 RL-4 的输入之一,不等于完整发布前审查。
  • 发布前复审、tag/publish 前风险清单或多轮 release readiness 收敛必须触发 review-checklist,冻结 RL-1~RL-10 及关联发布风险项,并逐项绑定证据。

输入范围

优先读取当前发布相关真相源:

  • package.json、package-lock.json、plugin.json
  • changelogs/unreleased.md、根 CHANGELOG.md、changelogs/releases/vX.Y.Z.md
  • README、安装说明、release guide、website 当前文档、Profile
  • 当前 git diff/status、已确认需求/bug 产物、发布报告或 ReleaseVerification 证据

RL-1~RL-10 发布审查维度

维度检查内容优先级
RL-1 版本身份目标版本、SemVer、tag、registry、发布范围是否唯一且一致🔴
RL-2 发布说明质量changelog/release notes 是否覆盖用户可见变化、修复、迁移提示与已知限制🔴
RL-3 兼容与迁移风险先执行 ReleaseAuthorityBeforeCompatibilityGate 核对 publishedState、consumerEvidence 和 authoritySources;已发布再审 breaking/迁移,未发布无稳定消费者默认直接收敛🔴
RL-4 元数据完整性description、keywords、repository、homepage、bugs、license、files/exports/bin、publishConfig、engines、plugin.json 是否完整准确🔴
RL-5 包边界与安装面pack 内容、安装路径、认证前提、二进制入口、禁发文件与部署副本边界是否清楚;是否执行 PublicSurfaceClosureGate,分类历史 pack 公开内容、README 隐藏链接、public types 兼容 API、examples/sidebar/nav 和搜索索引源文档;公开打包脚本是否执行 PackagedScriptDependencyClosureGate,递归核对本地 helper、spawn 目标脚本和运行时依赖进入 tarball🔴
RL-6 消费链同步README、website、Profile、release guide、模板、validate 与部署副本是否同步;用户可交互发布面命中时执行 InteractiveSemanticProbe🔴
RL-7 验证准备度npm test、test:audit、远端 CI 绿色、pack/publish dry-run、install smoke、ReleaseVerification R0~R7 的触发与证据是否充分;是否执行 CandidateDiffCompletenessGate、CandidateFreezeGate、ReleaseCriticalPathBudgetGate、ValidationEvidenceReuseGate、RemoteCIParityPushGate 与 NativeCommandExitCodeGate,不得用普通 working diff、未冻结候选、无基线预算或测试通过替代 staged candidate、coverage、audit、examples、website、pack、矩阵脚本或真实退出码🟡
RL-8 回滚与恢复失败恢复、版本回退、tag/registry 冲突、半发布状态处理是否可执行🟡
RL-9 凭据与 registry 安全token 不落盘、不输出;GitHub Packages / npm registry / access 策略与文档一致;首次发布或 publisher/repository/package/registry/auth topology 变化时执行 PublisherCredentialTopologyGate;scoped package / 双 registry 追加 ScopedRegistryResolutionGate,核对 .npmrc scope 路由、命令级 override、发布身份、secret scope/access/inheritance、workflow permission、package ownership 与最近成功 run,不读取 secret value🔴
RL-10 发布后验收registry/tag 验收、安装包边界复核、逃逸复盘与后续台账回写是否定义🟡

执行步骤

  1. 先执行 audit-common 的 G0~G5,确认审查范围、文件完整性、一致性与链接基础质量。
  2. 冻结发布审查范围:目标版本、发布包、registry、关联 changelog、关联需求/bug,并用 tag/registry/release note/public docs/实际消费者建立发布权威证据。
  3. 逐项执行 RL-1~RL-10;缺证据时标为 ⚠️待验证,不得写成通过。
  4. 对照 release-verification:执行链缺失写 RL-7;审查风险缺失写 RL-1RL-6/RL-8RL-10;RL-9 触发 PublisherCredentialTopologyGate 时,复制 workflow 或普通 dry-run 不能替代 topology evidence;双 registry scoped package 若未显式复核 scope registry precedence,不得把两次 dry-run 计作独立通道证据。
  5. 输出 findings-first 报告;无问题时仍列出通过证据和残余风险。

输出要求

markdown
## Release Audit

| 维度 | 状态 | 证据 | 结论/动作 |
|------|------|------|-----------|
| RL-1 | ✅/⚠️/❌/N/A | | |
| RL-2 | ✅/⚠️/❌/N/A | | |
| RL-3 | ✅/⚠️/❌/N/A | ReleaseAuthorityBeforeCompatibilityGate | |
| RL-4 | ✅/⚠️/❌/N/A | package completeness gate | |
| RL-5 | ✅/⚠️/❌/N/A | pack/install evidence | |
| RL-6 | ✅/⚠️/❌/N/A | README/website/Profile;InteractiveSemanticProbe 或 N/A | |
| RL-7 | ✅/⚠️/❌/N/A | R0~R7 + candidate freeze/generation + budget/reuse decision + staged candidate + command/shell/cwd/exitCode | |
| RL-8 | ✅/⚠️/❌/N/A | rollback plan | |
| RL-9 | ✅/⚠️/❌/N/A | registry/token boundary + PublisherCredentialTopologyGate(无 secret value) | |
| RL-10 | ✅/⚠️/❌/N/A | post-release acceptance | |

报告中的问题清单必须继续附合理性、可实施性、收益、验证状态和影响范围。涉及正式发版动作时,真实 tag / push / publish 仍必须等待用户明确确认。

© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in content/skills/audit-release of devcodex-labs/devcodex.

  • SKILL.md
  • intent.json

Open the folder on GitHubat commit 1dd4525

Compare with similar skills

Audit Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Release this skilldevcodex-labs/devcodex439—~1kAutomated safety check: WarnAGPL-3.0
Schematicblader/schematic240—~2.2kAutomated safety check: PassMIT
QA Releasejitpass/jit162—~1.1kAutomated safety check: PassCustom licence
Azsdk Common Prepare Release PlanAzure/azure-sdk-for-android121—~733Automated safety check: PassMIT
Release Checklistbactopia/bactopia522—~4.9kAutomated safety check: PassMIT
Release Managerfinos/morphir213—~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Schematic

    blader/schematic

    Reverse engineer a detailed product and technical specification document from a git branch's implementation.

    240 GitHub stars~2.2k tokensUpdated 7 mo ago
    Product & Project ManagementAuto-check passed
  • QA Release

    jitpass/jit

    Run jit's pre-release QA — a team of QA-engineer subagents (functionality, integrations, UX, bug-hunting, code review) that exercise a release candidate on this real Mac and hand back a consolidated…

    162 GitHub stars~1.1k tokensUpdated 3 days ago
    Product & Project ManagementAuto-check passed
  • Azsdk Common Prepare Release Plan

    Azure/azure-sdk-for-android

    Official

    Create and manage release plan work items for Azure SDK releases across languages.

    121 GitHub stars~733 tokensUpdated 4 mo ago
    Product & Project ManagementAuto-check passed
  • Release Checklist

    bactopia/bactopia

    Audit whether Bactopia is ready for a version release and produce a GO / NO-GO recommendation report.

    522 GitHub stars~4.9k tokensUpdated 2 mo ago
    Product & Project ManagementAuto-check passed
  • Release Manager

    finos/morphir

    Assists with Morphir CLI release management for finos/morphir, including pre-release verification, extension verification, version bumps, tagging, and release coordination.

    213 GitHub stars~3.2k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • Release Readiness Review

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses for GitHub release, Hangar, CurseForge/BukkitDev upload, Spigot release handoff, licence, asset naming, supported-version, and workflow readiness checks; do not use for…

    225 GitHub stars~1.5k tokensUpdated 4 days ago
    Product & Project ManagementAuto-check passed

More from devcodex-labs/devcodex

All 70 skills in this repo
  • Accessibility I18n

    devcodex-labs/devcodex

    无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。

    439 GitHub stars~718 tokensUpdated 21 days ago
    Auto-check passed
  • AI Agent System Architecture

    devcodex-labs/devcodex

    AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。

    439 GitHub stars~2.4k tokensUpdated 21 days ago
    Auto-check passed
  • API Contract Architecture

    devcodex-labs/devcodex

    API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。

    439 GitHub stars~865 tokensUpdated 21 days ago
    Auto-check passed
  • Architecture Design

    devcodex-labs/devcodex

    架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。

    439 GitHub stars~1.1k tokensUpdated 21 days ago
    Auto-check passed
  • Audit Common

    devcodex-labs/devcodex

    审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层

    439 GitHub stars~4.1k tokensUpdated 21 days ago
    Auto-check passed
  • Audit Session

    devcodex-labs/devcodex

    审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复

    439 GitHub stars~1.8k tokensUpdated 21 days ago
    Auto-check passed

Questions about Audit Release

What does Audit Release do?

发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于…. Audit Release is an agent skill from devcodex-labs/devcodex.

When should I use Audit Release?

Audit Release fits situations like: tasks that involve Feature launches and release readiness.

How do I install Audit Release in Claude Code?

Run `npx skills add devcodex-labs/devcodex --skill audit-release -a claude-code`. Or copy the skill folder (content/skills/audit-release in devcodex-labs/devcodex) into .claude/skills/audit-release in your project. Claude Code loads it when a task matches its description.

How do I install Audit Release in Codex?

Run `npx skills add devcodex-labs/devcodex --skill audit-release -a codex`. Or copy the skill folder (content/skills/audit-release in devcodex-labs/devcodex) into .agents/skills/audit-release in your project. Codex loads it when a task matches its description.

Can I use Audit Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill audit-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-release, .gemini/skills/audit-release, .github/skills/audit-release and .opencode/skills/audit-release in your project.

What does Audit Release need to run?

Going by SKILL.md and its folder, Audit Release needs the command-line tools its instructions call (npm).

Does Audit Release access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Release safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Audit Release use?

Audit Release is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Release use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Release?

Skills that share tags, products or a category with Audit Release: Schematic (blader/schematic, 240 stars), QA Release (jitpass/jit, 162 stars), Azsdk Common Prepare Release Plan (Azure/azure-sdk-for-android, 121 stars) and Release Checklist (bactopia/bactopia, 522 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Release?

devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.

Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.