Schematic
blader/schematic
Reverse engineer a detailed product and technical specification document from a git branch's implementation.
发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add devcodex-labs/devcodex --skill audit-release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install devcodex-labs/devcodex audit-release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/audit-release .claude/skills/audit-release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-release" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-release into .claude/skills/audit-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add devcodex-labs/devcodex --skill audit-release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install devcodex-labs/devcodex audit-release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/content/skills/audit-release .agents/skills/audit-release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-release" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-release into .agents/skills/audit-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill audit-release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install devcodex-labs/devcodex audit-release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/content/skills/audit-release .cursor/skills/audit-release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-release" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-release into .cursor/skills/audit-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/devcodex-labs/devcodex.git --path content/skills/audit-release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add devcodex-labs/devcodex --skill audit-release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install devcodex-labs/devcodex audit-release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/content/skills/audit-release .gemini/skills/audit-release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-release" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-release into .gemini/skills/audit-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install devcodex-labs/devcodex audit-releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add devcodex-labs/devcodex --skill audit-release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .github/skills && cp -r skills-src/content/skills/audit-release .github/skills/audit-release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-release" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-release into .github/skills/audit-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill audit-release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install devcodex-labs/devcodex audit-release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/content/skills/audit-release .opencode/skills/audit-release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-release" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/audit-release into .opencode/skills/audit-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-release发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于…
Audit Release is an agent skill from devcodex-labs/devcodex. 发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于 release-verification,本 Skill 负责审查判断,不执行真实发布动作。
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).
It sits in Product & Project Management, covering Feature launches and release readiness. The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Release loads about 1k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 200 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
y 追加 `ScopedRegistryResolutionGate`,核对 `.npmrc` scope 路由、命令级 override、发布身份、secret scope/access/inheritance、workflow permAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 200 words, ~1,030 tokens.
.claude/skills/audit-release/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.audit-release 回答“当前变更是否适合进入正式发布,以及风险是否被充分披露”。release-verification 回答“版本、测试、pack、publish dry-run、tag 和发布后验收链是否执行通过”。
tag / push / publish。release-verification 的 R0~R7 结果作为证据,但不能用执行通过替代审查结论。review-checklist,冻结 RL-1~RL-10 及关联发布风险项,并逐项绑定证据。优先读取当前发布相关真相源:
package.json、package-lock.json、plugin.jsonchangelogs/unreleased.md、根 CHANGELOG.md、changelogs/releases/vX.Y.Z.md| 维度 | 检查内容 | 优先级 |
|---|---|---|
| RL-1 版本身份 | 目标版本、SemVer、tag、registry、发布范围是否唯一且一致 | 🔴 |
| RL-2 发布说明质量 | changelog/release notes 是否覆盖用户可见变化、修复、迁移提示与已知限制 | 🔴 |
| RL-3 兼容与迁移风险 | 先执行 ReleaseAuthorityBeforeCompatibilityGate 核对 publishedState、consumerEvidence 和 authoritySources;已发布再审 breaking/迁移,未发布无稳定消费者默认直接收敛 | 🔴 |
| RL-4 元数据完整性 | description、keywords、repository、homepage、bugs、license、files/exports/bin、publishConfig、engines、plugin.json 是否完整准确 | 🔴 |
| RL-5 包边界与安装面 | pack 内容、安装路径、认证前提、二进制入口、禁发文件与部署副本边界是否清楚;是否执行 PublicSurfaceClosureGate,分类历史 pack 公开内容、README 隐藏链接、public types 兼容 API、examples/sidebar/nav 和搜索索引源文档;公开打包脚本是否执行 PackagedScriptDependencyClosureGate,递归核对本地 helper、spawn 目标脚本和运行时依赖进入 tarball | 🔴 |
| RL-6 消费链同步 | README、website、Profile、release guide、模板、validate 与部署副本是否同步;用户可交互发布面命中时执行 InteractiveSemanticProbe | 🔴 |
| RL-7 验证准备度 | npm test、test:audit、远端 CI 绿色、pack/publish dry-run、install smoke、ReleaseVerification R0~R7 的触发与证据是否充分;是否执行 CandidateDiffCompletenessGate、CandidateFreezeGate、ReleaseCriticalPathBudgetGate、ValidationEvidenceReuseGate、RemoteCIParityPushGate 与 NativeCommandExitCodeGate,不得用普通 working diff、未冻结候选、无基线预算或测试通过替代 staged candidate、coverage、audit、examples、website、pack、矩阵脚本或真实退出码 | 🟡 |
| RL-8 回滚与恢复 | 失败恢复、版本回退、tag/registry 冲突、半发布状态处理是否可执行 | 🟡 |
| RL-9 凭据与 registry 安全 | token 不落盘、不输出;GitHub Packages / npm registry / access 策略与文档一致;首次发布或 publisher/repository/package/registry/auth topology 变化时执行 PublisherCredentialTopologyGate;scoped package / 双 registry 追加 ScopedRegistryResolutionGate,核对 .npmrc scope 路由、命令级 override、发布身份、secret scope/access/inheritance、workflow permission、package ownership 与最近成功 run,不读取 secret value | 🔴 |
| RL-10 发布后验收 | registry/tag 验收、安装包边界复核、逃逸复盘与后续台账回写是否定义 | 🟡 |
audit-common 的 G0~G5,确认审查范围、文件完整性、一致性与链接基础质量。⚠️待验证,不得写成通过。release-verification:执行链缺失写 RL-7;审查风险缺失写 RL-1PublisherCredentialTopologyGate 时,复制 workflow 或普通 dry-run 不能替代 topology evidence;双 registry scoped package 若未显式复核 scope registry precedence,不得把两次 dry-run 计作独立通道证据。## Release Audit
| 维度 | 状态 | 证据 | 结论/动作 |
|------|------|------|-----------|
| RL-1 | ✅/⚠️/❌/N/A | | |
| RL-2 | ✅/⚠️/❌/N/A | | |
| RL-3 | ✅/⚠️/❌/N/A | ReleaseAuthorityBeforeCompatibilityGate | |
| RL-4 | ✅/⚠️/❌/N/A | package completeness gate | |
| RL-5 | ✅/⚠️/❌/N/A | pack/install evidence | |
| RL-6 | ✅/⚠️/❌/N/A | README/website/Profile;InteractiveSemanticProbe 或 N/A | |
| RL-7 | ✅/⚠️/❌/N/A | R0~R7 + candidate freeze/generation + budget/reuse decision + staged candidate + command/shell/cwd/exitCode | |
| RL-8 | ✅/⚠️/❌/N/A | rollback plan | |
| RL-9 | ✅/⚠️/❌/N/A | registry/token boundary + PublisherCredentialTopologyGate(无 secret value) | |
| RL-10 | ✅/⚠️/❌/N/A | post-release acceptance | |报告中的问题清单必须继续附合理性、可实施性、收益、验证状态和影响范围。涉及正式发版动作时,真实 tag / push / publish 仍必须等待用户明确确认。
© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in content/skills/audit-release of devcodex-labs/devcodex.
Open the folder on GitHubat commit 1dd4525
Audit Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Release this skilldevcodex-labs/devcodex | 439 | — | ~1k | Automated safety check: Warn | AGPL-3.0 | |
| Schematicblader/schematic | 240 | — | ~2.2k | Automated safety check: Pass | MIT | |
| QA Releasejitpass/jit | 162 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Azsdk Common Prepare Release PlanAzure/azure-sdk-for-android | 121 | — | ~733 | Automated safety check: Pass | MIT | |
| Release Checklistbactopia/bactopia | 522 | — | ~4.9k | Automated safety check: Pass | MIT | |
| Release Managerfinos/morphir | 213 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 |
blader/schematic
Reverse engineer a detailed product and technical specification document from a git branch's implementation.
jitpass/jit
Run jit's pre-release QA — a team of QA-engineer subagents (functionality, integrations, UX, bug-hunting, code review) that exercise a release candidate on this real Mac and hand back a consolidated…
Azure/azure-sdk-for-android
Create and manage release plan work items for Azure SDK releases across languages.
bactopia/bactopia
Audit whether Bactopia is ready for a version release and produce a GO / NO-GO recommendation report.
finos/morphir
Assists with Morphir CLI release management for finos/morphir, including pre-release verification, extension verification, version bumps, tagging, and release coordination.
kernitus/BukkitOldCombatMechanics
A skill your agent uses for GitHub release, Hangar, CurseForge/BukkitDev upload, Spigot release handoff, licence, asset naming, supported-version, and workflow readiness checks; do not use for…
devcodex-labs/devcodex
无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。
devcodex-labs/devcodex
AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。
devcodex-labs/devcodex
API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。
devcodex-labs/devcodex
架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。
devcodex-labs/devcodex
审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层
devcodex-labs/devcodex
审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复
Categories
发布前审查维度 — 审查 release readiness、发布说明质量、兼容性/迁移风险、package/plugin 元数据、文档/Profile/website 同步、回滚策略、registry/tag 风险和发布后验收;用于用户要求发版前 review、release pre-review、publish/tag 前风险审查或 audit 工作流识别为发布准备审查时。不同于…. Audit Release is an agent skill from devcodex-labs/devcodex.
Audit Release fits situations like: tasks that involve Feature launches and release readiness.
Run `npx skills add devcodex-labs/devcodex --skill audit-release -a claude-code`. Or copy the skill folder (content/skills/audit-release in devcodex-labs/devcodex) into .claude/skills/audit-release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add devcodex-labs/devcodex --skill audit-release -a codex`. Or copy the skill folder (content/skills/audit-release in devcodex-labs/devcodex) into .agents/skills/audit-release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill audit-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-release, .gemini/skills/audit-release, .github/skills/audit-release and .opencode/skills/audit-release in your project.
Going by SKILL.md and its folder, Audit Release needs the command-line tools its instructions call (npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Audit Release is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Release: Schematic (blader/schematic, 240 stars), QA Release (jitpass/jit, 162 stars), Azsdk Common Prepare Release Plan (Azure/azure-sdk-for-android, 121 stars) and Release Checklist (bactopia/bactopia, 522 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.
Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.