Draft Release Notes
jamiepine/voicebox
Writes or refreshes the Unreleased section of CHANGELOG.md as a themed narrative built from the commits, PRs and diff since the last version tag.
Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release.
$ npx skills add kenryu42/cc-safety-net --skill release-notes -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kenryu42/cc-safety-net release-notes --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/release-notes .claude/skills/release-notes && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release-notes" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/.claude/skills/release-notes into .claude/skills/release-notes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-notes", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kenryu42/cc-safety-net/tree/main/.claude/skills/release-notesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kenryu42/cc-safety-net --skill release-notes -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kenryu42/cc-safety-net release-notes --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/release-notes .agents/skills/release-notes && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release-notes" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/.claude/skills/release-notes into .agents/skills/release-notes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-notes", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kenryu42/cc-safety-net --skill release-notes -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kenryu42/cc-safety-net release-notes --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/release-notes .cursor/skills/release-notes && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release-notes" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/.claude/skills/release-notes into .cursor/skills/release-notes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-notes", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kenryu42/cc-safety-net.git --path .claude/skills/release-notes--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kenryu42/cc-safety-net --skill release-notes -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kenryu42/cc-safety-net release-notes --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/release-notes .gemini/skills/release-notes && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release-notes" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/.claude/skills/release-notes into .gemini/skills/release-notes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-notes", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kenryu42/cc-safety-net release-notesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kenryu42/cc-safety-net --skill release-notes -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/release-notes .github/skills/release-notes && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release-notes" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/.claude/skills/release-notes into .github/skills/release-notes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-notes", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kenryu42/cc-safety-net --skill release-notes -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kenryu42/cc-safety-net release-notes --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/release-notes .opencode/skills/release-notes && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release-notes" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/.claude/skills/release-notes into .opencode/skills/release-notes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release-notes", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
release-notesGenerate and publish concise, evidence-based notes in the body of the latest existing GitHub Release.
Release Notes is an agent skill from kenryu42/cc-safety-net. Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release. Use only when the user explicitly invokes $release-notes or explicitly asks to update the latest existing GitHub Release body. Do not invoke for general release planning, changelog, tag, or version tasks.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Development, covering Changelog and release notes. It works with GitHub and Git. The repository describes itself as: A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 2615848. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Release Notes loads about 3.2k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 1,529 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kenryu42/cc-safety-net at commit 2615848, republished under its MIT licence (© kenryu42). 1,529 words, ~3,223 tokens.
.claude/skills/release-notes/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Update only the body of the latest existing GitHub Release. Treat the repository diff as the source of truth. Use pull requests and commits only as supporting evidence.
gh for all GitHub Release, pull request, issue, and API operations. Use git fetch only when required tag objects or history are missing.Run all checks from the repository that the user wants to release:
Confirm that the current directory is in a Git worktree:
git rev-parse --is-inside-work-treeConfirm that gh is available:
command -v ghConfirm that gh can resolve and access the current GitHub repository. Save its URL and get the GitHub host from it:
REPO_URL="$(gh repo view --json url --jq '.url')"
GH_HOSTNAME="${REPO_URL#*://}"
GH_HOSTNAME="${GH_HOSTNAME%%/*}"Use the repository URL to get its GitHub host. Confirm the active account for that host:
gh auth status --active --hostname "$GH_HOSTNAME"Stop with a clear error if a check fails. Do not initialize a Git repository, change authentication, or select another repository as a fallback.
Use GitHub's descending release-list order as the release sequence. Include drafts and prereleases because they are existing releases:
gh release list --limit 2 --order desc \
--json tagName,name,createdAt,publishedAt,isDraft,isPrerelease,isImmutable,isLatestpublishedAt value.Set LATEST_TAG and, when present, PREVIOUS_TAG from this result. Quote both values in every command. Then load and record the latest release before any edit:
gh release view \
--json tagName,name,body,isDraft,isPrerelease,isImmutable,publishedAt,targetCommitish,url \
-- "$LATEST_TAG"Confirm that the returned tagName is LATEST_TAG. Record tagName, name, isDraft, isPrerelease, isImmutable, and targetCommitish from this result. Also record isLatest, createdAt, and publishedAt from the release-list result. Use these values for the final safety check. If isImmutable is true, stop and report that GitHub does not permit the body update.
Set full Git refs so that a tag that starts with - cannot become a command option:
LATEST_REF="refs/tags/$LATEST_TAG"
PREVIOUS_REF="refs/tags/$PREVIOUS_TAG"Set PREVIOUS_REF only when PREVIOUS_TAG exists. Confirm that each selected release tag resolves to a local commit:
git rev-parse --verify "$LATEST_REF^{commit}"
git rev-parse --verify "$PREVIOUS_REF^{commit}"Run the second command only when PREVIOUS_TAG exists. If a tag is missing, inspect the Git remotes, identify the remote for the same GitHub repository, and use git fetch to get the required tags. Do not assume that the remote is named origin. Stop if the remote is ambiguous or a release tag still does not resolve. Do not guess a replacement range.
Check for a shallow repository:
git rev-parse --is-shallow-repositoryIf the result is true, use the identified GitHub remote to fetch complete history and tags:
git fetch --unshallow --tags "$GITHUB_REMOTE"Then run the shallow-repository check again. Continue only when the result is false and both required tag commits resolve. If the full history cannot be fetched, stop. Do not generate notes from an incomplete history.
When PREVIOUS_TAG exists, check whether it is an ancestor of LATEST_TAG:
git merge-base --is-ancestor "$PREVIOUS_REF^{commit}" "$LATEST_REF^{commit}"A non-ancestor result is not an automatic failure. State it in the working notes, use the tree diff to identify the shipped-state change, and inspect both sides of the history so that the commit list does not cause a false claim.
When a previous release exists, start with:
git log --date=short --format='%H%x09%ad%x09%s' "$PREVIOUS_REF..$LATEST_REF"
git diff --stat "$PREVIOUS_REF" "$LATEST_REF"
git diff --name-status "$PREVIOUS_REF" "$LATEST_REF"
git diff "$PREVIOUS_REF" "$LATEST_REF"For non-linear history, also inspect:
git log --left-right --graph --oneline "$PREVIOUS_REF...$LATEST_REF"For the first release, inspect all history reachable from the latest tag and compare its shipped tree with an empty tree:
git log --reverse --date=short --format='%H%x09%ad%x09%s' "$LATEST_REF"
EMPTY_TREE="$(git hash-object -t tree /dev/null)"
git diff --stat "$EMPTY_TREE" "$LATEST_REF"
git diff --name-status "$EMPTY_TREE" "$LATEST_REF"
git diff "$EMPTY_TREE" "$LATEST_REF"Account for every changed path. Inspect the relevant diff hunks, not only the statistics or file names. For generated or binary files, inspect the source, manifest, configuration, or other evidence that explains their user impact. Do not include working-tree changes or commits after LATEST_TAG.
Use this evidence order:
Use PR data when it resolves an unclear purpose, user impact, migration step, or reference. Find associated PRs for a commit when needed:
gh api -H 'Accept: application/vnd.github+json' \
"repos/{owner}/{repo}/commits/$COMMIT_SHA/pulls"
gh pr view "$PR_NUMBER" \
--json number,state,mergedAt,title,body,files,commits,closingIssuesReferences,urlUse PR context only when state is MERGED and mergedAt is present. Verify every PR or issue association before adding its number. A commit prefix, PR label, or PR title does not prove user impact.
For each changed behavior, identify what a user can observe and the evidence that supports it. Include a change only when it materially affects one or more of these areas:
Normally exclude refactoring, formatting, lint changes, tests, CI changes, build maintenance, merge commits, routine dependency updates, internal cleanup, and documentation-only changes. Include one only when the diff proves material user impact.
Investigate an ambiguous change before classification. If the available evidence cannot support a useful claim, describe only the supported fact or omit the change. Never invent behavior, fixes, performance results, security effects, breaking effects, migration steps, or PR and issue links.
If no change has material user impact, write only a short, factual summary that says the release contains maintenance changes with no material change to user-visible behavior. Do not create empty sections.
Create an isolated temporary directory and Markdown file:
RELEASE_NOTES_DIR="$(mktemp -d)"
RELEASE_NOTES_FILE="$RELEASE_NOTES_DIR/release-notes.md"Arrange the body in this exact order, and omit all empty sections:
### Highlights### Added### Changed### Fixed### Breaking Changes### Deprecated### Removed### SecurityStart with a concise one-sentence or two-sentence summary. Do not add a version heading and do not repeat the release title. Use this shape only for sections that contain entries:
A concise summary of the release and its most important user impact.
### Highlights
- Major user-facing improvement.
### Added
- Added support for ... (#123)
### Changed
- Improved ...
### Fixed
- Fixed an issue where ...
### Breaking Changes
- Replaced `--old-flag` with `--new-flag` for users of the command-line interface.
- **Migration:** Replace `--old-flag` with `--new-flag` in scripts and configuration.Apply these writing rules:
Added, Improved, Changed, Fixed, Deprecated, or Removed.Highlights only for approximately one to three important items. Omit it for a small release.Highlights entry gives useful emphasis.Full Changelog link.For each breaking change, explain what changed and who is affected. Add a nested **Migration:** instruction when the evidence supports one. Mention an important breaking change in the opening summary. Do not use the breaking label without evidence.
Use ### Security only for material public security impact. State the improvement at a safe public level. Do not include sensitive vulnerability details or exploitation instructions.
Read the complete temporary Markdown file. Correct all problems before the edit. Confirm that:
Full Changelog linkImmediately before the edit, run the release-list query from step 2 again. Confirm that its first tag is still LATEST_TAG and that the recorded list metadata for this release did not change. Then run gh release view -- "$LATEST_TAG" again and confirm that the recorded release metadata still identifies the intended release. Stop if CI or another actor created a newer release or changed the selected release.
Run exactly this release edit command. Do not add any other gh release edit option:
gh release edit --notes-file "$RELEASE_NOTES_FILE" -- "$LATEST_TAG"If the command fails, report the error. Do not create a replacement release and do not change release settings to make the edit pass.
Read the release again after success. Confirm that its body matches RELEASE_NOTES_FILE and that tagName, name, isDraft, isPrerelease, and isImmutable match the values recorded before the edit:
gh release view \
--json tagName,name,body,isDraft,isPrerelease,isImmutable,publishedAt,targetCommitish,url \
-- "$LATEST_TAG"
gh release list --limit 2 --order desc \
--json tagName,name,createdAt,publishedAt,isDraft,isPrerelease,isImmutable,isLatestAlso confirm that targetCommitish, createdAt, publishedAt, and isLatest did not change. Confirm that LATEST_TAG is still the first item. If a new release appeared during the edit, report the race and do not claim that the edited release is still the latest.
Report the updated tag and URL, the sections that were published, and any omitted ambiguous change. Do not claim success if the readback does not match.
Remove the temporary file and directory after success or failure. Delete the file first, then remove the empty directory. Do not use a recursive removal command.
© kenryu42, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/release-notes of kenryu42/cc-safety-net.
Open the folder on GitHubat commit 2615848
Release Notes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Release Notes this skillkenryu42/cc-safety-net | 1.6k | — | ~3.2k | Automated safety check: Pass | MIT | |
| Draft Release Notesjamiepine/voicebox | 57k | — | ~941 | Automated safety check: Pass | MIT | |
| Mole Release Notes Publishertw93/Mole | 70k | — | ~1.9k | Automated safety check: Pass | GPL-3.0 | |
| Release Bumpjamiepine/voicebox | 57k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Verdaccio Pull Request Workflowverdaccio/verdaccio | 18k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Go-Redis Release Preparationredis/go-redis | 22k | — | ~1.1k | Automated safety check: Pass | BSD-2-Clause |
jamiepine/voicebox
Writes or refreshes the Unreleased section of CHANGELOG.md as a themed narrative built from the commits, PRs and diff since the last version tag.
tw93/Mole
Publishes curated, bilingual release notes for an existing Mole version tag with gh release edit, including contributor thanks and reactions, after the release workflow finishes.
jamiepine/voicebox
Ends a release cycle by moving the Unreleased changelog notes under a dated version heading, bumping version files with bumpversion and tagging the commit.
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
redis/go-redis
Prepares a go-redis release locally: picks the next semver, gathers merged PRs, writes the RELEASE-NOTES entry and bumps versions, without publishing.
modem-dev/hunk
Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.
kenryu42/cc-safety-net
Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.
kenryu42/cc-safety-net
Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.
kenryu42/cc-safety-net
A skill your agent uses when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell…
kenryu42/cc-safety-net
Use in the cc-safety-net repo when bun run lint:comments or bun run check reports a comment, a stale comment-allowlist entry, or a file it cannot parse, and before writing a code comment there.
Categories
Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release. Release Notes is an agent skill from kenryu42/cc-safety-net. Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release.
Release Notes fits situations like: explicitly invokes $release-notes; explicitly asks to update the latest existing GitHub Release body.
Run `npx skills add kenryu42/cc-safety-net --skill release-notes -a claude-code`. Or copy the skill folder (.claude/skills/release-notes in kenryu42/cc-safety-net) into .claude/skills/release-notes in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kenryu42/cc-safety-net --skill release-notes -a codex`. Or copy the skill folder (.claude/skills/release-notes in kenryu42/cc-safety-net) into .agents/skills/release-notes in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kenryu42/cc-safety-net --skill release-notes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-notes, .gemini/skills/release-notes, .github/skills/release-notes and .opencode/skills/release-notes in your project.
Going by SKILL.md and its folder, Release Notes needs the command-line tools its instructions call (git and gh).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Release Notes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Release Notes: Draft Release Notes (jamiepine/voicebox, 57k stars), Mole Release Notes Publisher (tw93/Mole, 70k stars), Release Bump (jamiepine/voicebox, 57k stars) and Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kenryu42 (a GitHub user) maintains it in kenryu42/cc-safety-net, which has 1,582 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.
Source: kenryu42/cc-safety-net on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.