Agent skill

Pre Release Sweep

by LanternOps in LanternOps/breeze

Use before cutting a Breeze release, or whenever asked to "test everything since the last release", "check what's changed on main in the browser", "boot the stack and verify the merged PRs", or…

AGPL-3.0Auto-check: notesTesting & QA

Install Pre Release Sweep

skills CLI
$ npx skills add LanternOps/breeze --skill pre-release-sweep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LanternOps/breeze pre-release-sweep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LanternOps/breeze.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pre-release-sweep .claude/skills/pre-release-sweep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pre-release-sweep
GitHub stars
132
Token cost
~2.6k tokens
SKILL.md length
1,372 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Use before cutting a Breeze release, or whenever asked to "test everything since the last release", "check what's changed on main in the browser", "boot the stack and verify the merged PRs", or…

  • Works in 6 steps: Gate on in-flight work → Stack at main (not the feature branch) → Change inventory (sonnet, no browser) → …
  • Tasks that involve UI design
  • SKILL.md covers Phase 0 — Gate on in-flight work, Phase 1 — Stack at main (not…, Phase 2 — Change inventory… and Phase 3 — Browser sweep (opus,…, plus 4 more sections
  • Calls pnpm, gh and docker

What it does

Pre Release Sweep is an agent skill from LanternOps/breeze. Use before cutting a Breeze release, or whenever asked to "test everything since the last release", "check what's changed on main in the browser", "boot the stack and verify the merged PRs", or "pre-release QA". Covers the gate on in-flight CI, standing up a stack at current main, walking every merged-since-tag change through Playwright, tracking results in a dated doc, logging UI/UX paper cuts, and fixing small defects on the way. For a whole-app sweep unrelated to a release window use ui-qa-sweep; for one…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering UI design and Browser testing. It works with Playwright. The repository describes itself as: The open-source IT platform that comes with the workers. RMM + PSA in one system, with a governed AI operator built in. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve UI design
  • Tasks that involve Browser testing

Example prompts

  • “test everything since the last release”
  • “check what”
  • “boot the stack and verify the merged PRs”
  • “/pre-release-sweep”

Requirements

  • Node.js
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Gate on in-flight work
  2. Stack at main (not the feature branch)
  3. Change inventory (sonnet, no browser)
  4. Browser sweep (opus, one group at a time)
  5. Fix small, file the rest
  6. Close

What it can do on your machine

Read from SKILL.md and the folder at commit 8329045. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • gh
    • docker
    • git
    • nvm
    • npx
    • tsc

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, gh, docker, git and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pre Release Sweep loads about 2.6k tokens when it runs. Until then it costs about 144 tokens; SKILL.md has 1,372 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:46
    DY_IP=.*|BREEZE_CADDY_IP=<same /24>.10|' .env
  • NoteMentions a .env fileSKILL.md:63
    `WEBAUTHN_RP_ID=localhost` in the sweep `.env` or every passkey ceremony throws `SecurityError` (`rp.id` comes back as t
  • NoteMentions a .env fileSKILL.md:65
    8.2→main sweep):** (1) a fresh worktree `.env` copied from `.env.example` has `FORCE_HTTPS=true`, `NODE_ENV=production`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LanternOps/breeze at commit 8329045, republished under its AGPL-3.0 licence (© LanternOps). 1,372 words, ~2,573 tokens.

Download SKILL.mdSave it as .claude/skills/pre-release-sweep/SKILL.md (or your agent's skills folder).
name
pre-release-sweep
description
Use before cutting a Breeze release, or whenever asked to "test everything since the last release", "check what's changed on main in the browser", "boot the stack and verify the merged PRs", or "pre-release QA". Covers the gate on in-flight CI, standing up a stack at current main, walking every merged-since-tag change through Playwright, tracking results in a dated doc, logging UI/UX paper cuts, and fixing small defects on the way. For a whole-app sweep unrelated to a release window use `ui-qa-sweep`; for one just-built feature use `feature-testing`.

Pre-Release Sweep

Verify every change merged since the last release tag actually works in the browser, on a stack built from current origin/main, and leave a tracking doc a release cut can cite. The tracking doc is the deliverable; the browser work exists to fill it.

Tracking doc: docs/testing/release-sweeps/<YYYY-MM-DD>-<from-tag>-to-<to>.md (copy TEMPLATE.md in that directory). Write to it as you go — a sweep outlives a context window.

Phase 0 — Gate on in-flight work

  1. gh pr list --state open — non-draft PRs against main with CI running are the "waiting" set. Draft/stacked PRs are not.
  2. gh pr checks <n> --watch in the background (never poll by hand).
  3. Merge only on head-SHA green (bare gh pr merge <N> enqueues; never --admin). Ignore only known-noise checks and say which: Trivy on CVE-2026-14456 (base-image openssl) is the current one — confirm the CVE id in the log before dismissing it.
  4. Record the final origin/main SHA in the doc header. That SHA is the base of the sweep; anything merged after it is a follow-up entry, not silently absorbed.

Phase 1 — Stack at main (not the feature branch)

pnpm wt-stack up builds from the worktree's checkout. A sweep on a feature branch verifies the wrong code (bit us 2026-08-24, 47 commits stale).

bash
git fetch --deepen=200 origin main            # herdr worktrees are shallow
git checkout -b qa/sweep-post-<from-tag> origin/main   # fixes land here
sed -i '' 's|^BREEZE_DOCKER_SUBNET=.*|BREEZE_DOCKER_SUBNET=<fresh /24>|; s|^BREEZE_CADDY_IP=.*|BREEZE_CADDY_IP=<same /24>.10|' .env
source ~/.nvm/nvm.sh && nvm use               # .nvmrc pin, not host node
pnpm install --frozen-lockfile                # code-mounted node_modules — stale tree = Astro NoMatchingRenderer
pnpm wt-stack up                              # read .breeze-stack.json for baseUrl + creds

Pick the /24 from docker network ls -q | xargs docker network inspect --format '{{.Name}} {{range .IPAM.Config}}{{.Subnet}}{{end}}' — an existing network with the same subnet fails compose with "Pool overlaps", running or not.

Boot with every feature flag the inventory (Phase 2) names, or the surface is invisible and the check reads as a false FAIL. If the API is unhealthy with a does not provide an export named … error, the dev image is stale — pnpm wt-stack up --rebuild. The seed has one org and a non-platform-admin; promote it for /admin/* rows (update users set is_platform_admin=true where email='admin@breeze.local') and let a sweep agent create sibling orgs. Then log in yourself once before dispatching any browser agent; a blocked sweep agent is 15 wasted minutes.

Stack traps seen 2026-09-08 (v0.110→main sweep): (1) the first wt-stack up on a fresh DB fails with "api is unhealthy" because the healthcheck window closes during the ~645-migration replay — wait for Applied N migration(s) in docker logs <api> then run up again, it is idempotent; (2) set WEBAUTHN_RP_ID=localhost in the sweep .env or every passkey ceremony throws SecurityError (rp.id comes back as the prod domain) — the CDP virtual authenticator does not help; (3) SMS has no local provider (POST /auth/phone/verify → 501), phone-MFA rows are BLOCKED by design, say so; (4) role-forced MFA (force_mfa on Partner Admin) can lock the seeded admin into /auth/mfa/setup?forced=1 — MFA_FORCE_FOR_PARTNER_ADMIN=false is the relief valve (default OFF since #5307); (5) the seed's Invite offers partner-scoped roles only, so an org/site-restricted reader must be created via SQL; (6) fixer first-passes regress: run one review round per fix even when the diff is small — two of nine fixes this sweep needed it.

Stack traps seen 2026-09-29 (v0.118.2→main sweep): (1) a fresh worktree .env copied from .env.example has FORCE_HTTPS=true, NODE_ENV=production and a placeholder PUBLIC_API_URL, and the dev override defaults PUBLIC_API_URL to the prod domain — every API POST returns 400 until you set FORCE_HTTPS=false, TRUST_PROXY_HEADERS=false, and PUBLIC_API_URL / PUBLIC_APP_URL / DASHBOARD_URL / CORS_ALLOWED_ORIGINS to the local base URL; (2) the dev override defaults BREEZE_WORKSPACE_ENABLED to true — set it false on a stack without pgvector; (3) when the Playwright MCP browser is held by another session, drive headless Playwright scripts instead: save storageState after every script (refresh tokens rotate, and a script that dies before saving leaves the next run logged out) and set localStorage['breeze-onboarding-complete']='true' to skip the onboarding overlay.

Phase 2 — Change inventory (sonnet, no browser)

Dispatch one Explore agent (model: sonnet) to produce the inventory table: merged PRs since the tag, surface (web / portal / api-only / agent-only / docs-chore), a concrete click-path read from source (real route from apps/web/src/pages, real button labels), the visible outcome that proves the change, and prereqs (flag, role, live agent) that make it BLOCKED locally. It must also list every BREEZE_*/*_ENABLED env var in the diffs and cluster the click-paths into 4–6 area groups.

Paste the table into the doc with a Status column = TODO. Every row ends the sweep as PASS | PARTIAL | FAIL | BLOCKED | N/A — never left TODO.

Show full SKILL.md (673 more words)Show less

Phase 3 — Browser sweep (opus, one group at a time)

One agent owns the Playwright MCP browser at a time; groups run sequentially. Each agent gets: the stack descriptor, its group's rows verbatim, the doc path, and the rules below. It appends its rows' results plus a "Paper cuts" sub-list before returning. Read ui-qa-sweep Phase 3/4 for the everyday-workflow checks to fold in when a group is thin.

Rules every sweep agent must follow (they are the recurring false-positive sources):

  • Toast host is custom: [data-testid="toast"], auto-dismiss 5 s. Click and poll for the toast inside one browser_evaluate, or install a MutationObserver recorder before clicking. A "no toast" reading is a measurement, not a finding, until grep -n runAction <component> shows no successMessage.
  • Scope element lookups to main or the drawer — tab labels collide with sidebar links by text.
  • Modals are fixed inset-0 divs with no role=dialog; assert on title text or data-testid, and on the outcome, not the container.
  • A 2xx with no visible confirmation is a FAIL, not a PASS.
  • Known noise, note once: 428 on the first POST /auth/login (session-binding handshake, the retry succeeds); non-platform-admin 403s on /admin/*.
  • The API limiter is 300 req / 60 s per client. A fast nav crawl trips it and every page then "fails" with 429 — pace the crawl; a burst of 429s is the agent's own doing, not a finding.
  • Fix agents run concurrently with the sweep on a code-mounted stack: a web edit hot-reloads one page; an apps/api/src edit restarts the API for ~40 s. Tell the sweep agent which files are being edited and to treat a Vite overlay / 502 burst there as "wait 20 s and reload"; run API-side fixes in an isolated worktree (isolation: "worktree") and cherry-pick after the sweep group finishes.

Phase 4 — Fix small, file the rest

"Small" = one file or one component, no tenancy/auth/migration/billing/agent surface, reproducible in a unit test. Fix on the qa/sweep-* branch, red test first, then npx vitest run <file> (no -- before the flag; never a trailing-slash path). Dispatch a sonnet agent per fix with the exact repro + file. Tell it: lint/typecheck in the foreground with timeout 240 (a backgrounded run stalls the agent with the fix uncommitted — SendMessage it to finish if that happens); --pool=threads --maxWorkers=2 if vitest can't start workers under the running stack; never an eslint-disable for a rule not in the package's eslint config (the comment itself is the lint error). Verify its commit exists, skim the diff, and run eslint on the changed files yourself before recording it. Run the heavy web tsc --noEmit once from the main session, not per agent. Anything larger → GitHub issue via github-issues, dedupe first, cite the doc.

Both go in the doc: Fixes applied (commit SHA) and Issues filed (#).

Phase 5 — Close

Summary table (group → PASS/PARTIAL/FAIL/BLOCKED counts), "Top findings" (systemic patterns beat single bugs), the oldest PR reached, and what a release cut still needs (flags to enable, BLOCKED rows needing a live agent). Open one PR: the fixes + the tracking doc. Then tear down: pnpm wt-stack down from this worktree, and docker compose ls -a to confirm nothing from the sweep is still up — sweep agents' pnpm test-stack copies included (worktree-stack skill → "Tear down when done"). Report anything you left running and why.

Model tiering

WorkAgent
Inventory, env-var grep, mechanical single-file fixessonnet
Browser sweep (judgement on paper cuts, false-positive traps)opus
Review of a fix that touched auth/tenancyopus, one round

Red flags

  • Sweeping on the branch you happened to be on → wrong base, re-do Phase 1.
  • A row marked FAIL with no API status+body captured → not a finding yet.
  • "Merged, didn't check head-SHA CI" → the sweep merged red (#4159).
  • Tracking doc written at the end → context loss ate the middle of the sweep.
  • A "no toast → silent failure" finding whose click and poll were in separate tool calls → re-measure in one browser_evaluate before filing.
  • A row marked PASS on a stack whose flags were off for that surface → the surface never rendered; check the flag list in the doc header.

© LanternOps, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/pre-release-sweep of LanternOps/breeze.

Open the folder on GitHubat commit 8329045

Compare with similar skills

Pre Release Sweep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pre Release Sweep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pre Release Sweep this skillLanternOps/breeze132—~2.6kAutomated safety check: NotesAGPL-3.0
UI Reviewjvm-skills/jvm-skills140—~545Automated safety check: PassApache-2.0
Liteyuki Webui FrontendLiteyukiStudio/LiteyukiBot157—~2.5kAutomated safety check: PassCustom licence
Igniteui Angular Figma To AppIgniteUI/igniteui-angular599—~6.4kAutomated safety check: PassMIT
Web Application Testinganthropics/skills180k51 repos~966Automated safety check: PassApache-2.0
Chrome Tracelayoutit/polycss761—~2kAutomated safety check: PassMIT

Similar skills

  • UI Review

    jvm-skills/jvm-skills

    Verify UI/UX by running Playwright tests and reviewing screenshots.

    140 GitHub stars~545 tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Liteyuki Webui Frontend

    LiteyukiStudio/LiteyukiBot

    Build, review, or test LiteyukiBot v7's React/Vite WebUI under webui/ and its packaged static delivery in packages/webui/.

    157 GitHub stars~2.5k tokensUpdated 1 mo ago
    Frontend & DesignAuto-check passed
  • Igniteui Angular Figma To App

    IgniteUI/igniteui-angular

    Builds Angular views from Figma designs with Ignite UI for Angular, supporting Indigo.Design kits, third-party kits, and plain frames.

    599 GitHub stars~6.4k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Web Application Testing

    anthropics/skills

    Official

    Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.

    180k GitHub starsUsed in 51 repos~966 tokens
    Testing & QAAuto-check passed
  • Chrome Trace

    layoutit/polycss

    Capture and analyze Chrome/Chromium performance traces with Playwright around a concrete browser interaction.

    761 GitHub stars~2k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Add Generation To Gallery

    SunkenInTime/which-ai

    Add a generated regular Next.js source app into the ui-design-bench static gallery as a model generation, including source placement, variant wrapper, manifest/registry/type updates, scoped CSS…

    129 GitHub stars~2k tokensUpdated yesterday
    Frontend & DesignAuto-check passed

More from LanternOps/breeze

All 14 skills in this repo
  • Agent Info

    LanternOps/breeze

    Quick reference for the Breeze RMM Go agent architecture, commands, configuration, build process, and data flows.

    132 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Agent Log Debugging

    LanternOps/breeze

    A skill your agent uses when debugging agent issues, investigating agent errors, checking agent connectivity, or reviewing agent diagnostic logs.

    132 GitHub stars~1.6k tokensUpdated today
    Auto-check: notes
  • AI Agent

    LanternOps/breeze

    Quick reference for the Breeze RMM AI Agent system architecture, MCP tools, streaming chat, cost tracking, guardrails, and MCP server.

    132 GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Breeze Helper

    LanternOps/breeze

    Quick reference for the Breeze Helper Tauri desktop app — architecture, Rust backend commands, React frontend, config files, IPC with the Go agent, helper chat API routes, tool approval flow, and…

    132 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • E2E Coverage

    LanternOps/breeze

    A skill your agent uses when running a broad manual/AI-driven end-to-end verification of Breeze RMM across many merged PRs or commits — "test everything since the last release", release-readiness…

    132 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Feature Delivery

    LanternOps/breeze

    A skill your agent uses when orchestrating Breeze implementation work from this seat — dispatching waves or issue fixes to background sessions, deciding whether an open PR gets merged, handling a…

    132 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Pre Release Sweep

What does Pre Release Sweep do?

Use before cutting a Breeze release, or whenever asked to "test everything since the last release", "check what's changed on main in the browser", "boot the stack and verify the merged PRs", or…. Pre Release Sweep is an agent skill from LanternOps/breeze. Use before cutting a Breeze release, or whenever asked to "test everything since the last release", "check what's changed on main in the browser", "boot the stack and verify the merged PRs", or "pre-release QA".

When should I use Pre Release Sweep?

Pre Release Sweep fits situations like: tasks that involve UI design; tasks that involve Browser testing.

How do I install Pre Release Sweep in Claude Code?

Run `npx skills add LanternOps/breeze --skill pre-release-sweep -a claude-code`. Or copy the skill folder (.claude/skills/pre-release-sweep in LanternOps/breeze) into .claude/skills/pre-release-sweep in your project. Claude Code loads it when a task matches its description.

How do I install Pre Release Sweep in Codex?

Run `npx skills add LanternOps/breeze --skill pre-release-sweep -a codex`. Or copy the skill folder (.claude/skills/pre-release-sweep in LanternOps/breeze) into .agents/skills/pre-release-sweep in your project. Codex loads it when a task matches its description.

Can I use Pre Release Sweep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LanternOps/breeze --skill pre-release-sweep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pre-release-sweep, .gemini/skills/pre-release-sweep, .github/skills/pre-release-sweep and .opencode/skills/pre-release-sweep in your project.

What does Pre Release Sweep need to run?

Going by SKILL.md and its folder, Pre Release Sweep needs the command-line tools its instructions call (pnpm, gh, docker, git, nvm and npx). Our summary lists: Node.js; Docker.

Does Pre Release Sweep access the network?

SKILL.md contains no URLs. Its commands use gh, docker, git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pre Release Sweep safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Pre Release Sweep use?

Pre Release Sweep is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pre Release Sweep use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pre Release Sweep?

Skills that share tags, products or a category with Pre Release Sweep: UI Review (jvm-skills/jvm-skills, 140 stars), Liteyuki Webui Frontend (LiteyukiStudio/LiteyukiBot, 157 stars), Igniteui Angular Figma To App (IgniteUI/igniteui-angular, 599 stars) and Web Application Testing (anthropics/skills, 180k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pre Release Sweep?

LanternOps (a GitHub organization) maintains it in LanternOps/breeze, which has 132 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 9, 2026.

Source: LanternOps/breeze on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.