Agent skill

Release Review

by m4r1k in m4r1k/Eneru

Mandatory pre-release deep review for minor/major releases (X.Y.0 / X.0.0).

MITAuto-check passedDevOps & Cloud

Install Release Review

skills CLI
$ npx skills add m4r1k/Eneru --skill release-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install m4r1k/Eneru release-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/m4r1k/Eneru.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/release-review .claude/skills/release-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-review
GitHub stars
149
Token cost
~1.9k tokens
SKILL.md length
970 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Mandatory pre-release deep review for minor/major releases (X.Y.0 / X.0.0).

  • Works in 4 steps: Spawn three specialist subagents IN… → Orchestrator direct checks (main… → Merge, dedupe, and write the report at… → …
  • Asks for a full-repository audit/review
  • SKILL.md covers When, Round 1 — fan-out review…, Remediation PR and Round 2 — verification (after…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Release Review is an agent skill from m4r1k/Eneru. Mandatory pre-release deep review for minor/major releases (X.Y.0 / X.0.0). Runs a multi-agent adversarial audit of the ENTIRE repository, produces a stable-ID findings report with user triage, drives the remediation PR, then runs a post-implementation verification round with fresh lenses. Point releases (X.Y.Z, bug fixes only) are exempt. Invoke when preparing a new minor/major release, or whenever the user asks for a full-repository audit/review.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Monitoring and alerting and Debugging. It works with Docker, Prometheus, Linux and Grafana. The repository describes itself as: ⚡ UPS monitoring and shutdown orchestration for NUT: multi-UPS policy, VM/container/remote shutdown, TUI, API, Prometheus, MQTT, Grafana, and persistent notifications. The licence is MIT.

When your agent uses it

  • Asks for a full-repository audit/review
  • Tasks that involve Monitoring and alerting
  • Tasks that involve Debugging

Example prompts

  • “/release-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Spawn three specialist subagents IN PARALLEL (one message, three
  2. Orchestrator direct checks (main session, while agents run): docs
  3. Merge, dedupe, and write the report at the repo root
  4. User triage (required before any fix). Present an ELI5 table — one

What it can do on your machine

Read from SKILL.md and the folder at commit e2a4f30. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Review loads about 1.9k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 970 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from m4r1k/Eneru at commit e2a4f30, republished under its MIT licence (© m4r1k). 970 words, ~1,866 tokens.

Download SKILL.mdSave it as .claude/skills/release-review/SKILL.md (or your agent's skills folder).
name
release-review
description
Mandatory pre-release deep review for minor/major releases (X.Y.0 / X.0.0). Runs a multi-agent adversarial audit of the ENTIRE repository, produces a stable-ID findings report with user triage, drives the remediation PR, then runs a post-implementation verification round with fresh lenses. Point releases (X.Y.Z, bug fixes only) are exempt. Invoke when preparing a new minor/major release, or whenever the user asks for a full-repository audit/review.

Release review — full-repository adversarial audit

Automated tests prove the code does what a test author thought to ask. They do not prove that nobody overlooked a way the daemon can drop a healthy host or miss a real outage. Before every minor/major release, the whole repository at HEAD — not just the release diff — goes through this structured audit.

ELI5: every deep clean of a big house finds dirt; that never means the house is filthy. The point is not "zero findings" (unreachable) — it's that new findings stop being scary. Track the severity trend, not the count.

History (why this is mandatory): the v6.0.0 pass found ~100 issues, the v6.1.6 pass 64, the v6.1.7 pass 65 + 28 more in verification — each round's Criticals shrank in number and blast radius and migrated from the shutdown core toward the periphery. See "Pre-release code review" in docs/testing.md.

When

  • MANDATORY before tagging any X.Y.0 or X.0.0 release. Do not tag without a completed cycle (both rounds) for the release.
  • NOT required for patch releases (X.Y.Z) — those are bug-fix only and inherit the minor's review. (If a "patch" has grown feature-sized, that's a sign it should have been a minor — review it.)
  • Also usable on demand when the user asks for a full-repo audit.

Round 1 — fan-out review (before any fixes)

  1. Spawn three specialist subagents IN PARALLEL (one message, three Agent calls — sequential spawning defeats the purpose). These are task roles, not assumed installed agent types: use general-purpose agents for the security and test roles. For the first role, use agent-skills:code-reviewer when that skill is installed; otherwise give a general-purpose agent the same fresh-context review prompt. In Codex, use ordinary spawned agents with descriptive task names such as code_review, security_audit, and test_quality:
    • Code review — five-axis review (correctness, readability, architecture, security, performance) of the whole tree. Priority: production-readiness of the shutdown orchestration, state machine, signal handling, subprocess/SSH execution, config validation, error paths. Remind it of the uv-venv rule from AGENTS.md.
    • Security audit — threat model + vulnerability pass: OWASP for the dashboard/API, command/argument injection, secrets in logs, YAML safety, dependency CVEs, systemd/packaging hardening. Ask for an explicit list of surfaces examined and found clean.
    • Test quality — coverage AND quality: run the unit suite in a uv venv for ground truth; find behavioral gaps (simulated-but-never-exercised paths, races), not just uncovered lines.
  2. Orchestrator direct checks (main session, while agents run): docs freshness, CI/workflow health, dashboard accessibility signals.
  3. Merge, dedupe, and write the report at the repo root (SHIP_REVIEW.md pattern — a working artifact, do NOT commit it):
    • Ship decision (GO/NO-GO) + a rollback plan (trigger conditions, per-install-path procedure, RTO).
    • Master findings table — ID | Sev | Axis (source) | file:line | Finding | Suggested remediation | Effort. IDs are stable F-NNN, continuing the existing series across rounds and releases, never reused.
    • Implementation guidance: findings sharing a root cause become one fix group landed as one unit (the v6.1.7 config schema gate closed seven findings at once); a suggested landing order; per-fix verification.
    • The report must be self-contained for a fresh agent session: no references to the review conversation.
  4. User triage (required before any fix). Present an ELI5 table — one plain-language row per finding, concrete metaphor first, jargon second — so the user can drop or downgrade findings. Record drops in the report with the user's reason (strikethrough row + scope-rule entry). A dropped finding is never implemented; reviewers never return empty, so triage is part of the process, not an insult to it.
Show full SKILL.md (404 more words)Show less

Remediation PR

  • Track every in-scope finding with /goals until closed — do not declare done while any non-dropped finding is open (v6.1.7 shipped its PR with one of 62 silently unaddressed; the tracker exists to make that impossible).
  • One commit per category (fix group / silent-failures / security / perf / CI / tests / docs-tail), all on a single branch, delivered as one PR.
  • Then the standard AGENTS.md flow: CI green → both upstream AI reviews → address findings (max two rounds) → wait for the user's explicit greenlight. Never self-merge.

Round 2 — verification (after implementation, before merge/tag)

Spawn IN PARALLEL:

  1. Compliance audit — every in-scope finding vs the actual diff: fixed / fixed-differently (judge the deviation) / partial / missing. Verify substance by reading the changed code, not commit messages. Explicitly re-verify every user-mandated constraint from triage.
  2. Regression review of the diff itself — bugs the fixes introduced. Crucially: verify each fix works in the exact scenario its finding cites (three v6.1.7 fixes failed their own cited scenario).
  3. Fresh bug hunts with lenses earlier rounds did NOT use — rotate among: cross-module interactions, real-world data edges (malformed/ extreme NUT variables, odd SSH targets), time & ordering (DST, monotonic-vs-wall, rollover), resource lifecycle (leaks, unbounded growth over weeks of uptime), newest-code-meets-oldest-code.

Rules for round-2 agents: read the round-1 report first — re-reporting a known or user-dropped finding is a task failure; findings need a concrete, traceable failure path (no hardening wishlists); an honest "found little" beats padding.

Output: a separate round-2 report (SHIP_REVIEW_ROUND2.md pattern — never fold into the round-1 report), continuing the F-ID series, with a merge/tag gate section, already-fixed markers for anything closed in the meantime, and a "verified sound — do not re-litigate" list so later passes don't churn. New findings go through the same user triage, then loop back into the remediation PR; re-verify only what changed.

Principles (learned over v6.0.0 → v6.1.7)

  • Close bug classes, not instances. A declarative gate or a CI tripwire beats N spot fixes; ask "what invariant was missing?" for every cluster.
  • Finding count is not a health metric; the severity trend is. Expect a long Minor/Low tail forever; reserve alarm for Criticals recurring in previously-audited core code.
  • A fix is not done until verified against its own cited scenario.
  • New code carries new bugs at roughly constant density — a review after a feature wave harvests that wave; that's the process working.
  • Reports carry stable IDs and file:line anchors so any harness (Claude, Codex, a human) can execute them without the originating conversation.

© m4r1k, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/release-review of m4r1k/Eneru.

Open the folder on GitHubat commit e2a4f30

Compare with similar skills

Release Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Review this skillm4r1k/Eneru149—~1.9kAutomated safety check: PassMIT
Aqua Metricsoracle/accelerated-data-science125—~1.5kAutomated safety check: PassUPL-1.0
Live Debugmacro-inc/macro4.6k—~2.4kAutomated safety check: NotesAGPL-3.0
Alloygrafana/skills282—~1.3kAutomated safety check: PassApache-2.0
Beylagrafana/skills282—~1.1kAutomated safety check: PassApache-2.0
Grafanamagnus919/agent-skills115—~2.4kAutomated safety check: PassMIT

Similar skills

  • Aqua Metrics

    oracle/accelerated-data-science

    Official

    Set up Prometheus and Grafana monitoring for AQUA vLLM model deployments on OCI.

    125 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Live Debug

    macro-inc/macro

    Debug the running local stack with traces, logs, and a shared headless browser.

    4.6k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Alloy

    grafana/skills

    Official

    Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo /…

    282 GitHub stars~1.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Beyla

    grafana/skills

    Official

    Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart.

    282 GitHub stars~1.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Grafana

    magnus919/agent-skills

    Operate, configure, provision, secure, and troubleshoot Grafana OSS, Enterprise, and Cloud, including dashboards, folders, data sources, annotations, alert rules, contact points, notification…

    115 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Code Review

    aide-family/moon

    Reviews code for correctness and potential bugs, pinpoints bug locations by file and line, and suggests concrete fixes.

    253 GitHub stars~815 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed

More from m4r1k/Eneru

  • Visually verify Eneru browser-dashboard changes against a live daemon or audit an exact deployment.

    149 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Graft

    m4r1k/Eneru

    This repo is indexed by graft/. An agent skill from m4r1k/Eneru.

    149 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Questions about Release Review

What does Release Review do?

Mandatory pre-release deep review for minor/major releases (X.Y.0 / X.0.0). Release Review is an agent skill from m4r1k/Eneru.0).

When should I use Release Review?

Release Review fits situations like: asks for a full-repository audit/review; tasks that involve Monitoring and alerting; tasks that involve Debugging.

How do I install Release Review in Claude Code?

Run `npx skills add m4r1k/Eneru --skill release-review -a claude-code`. Or copy the skill folder (.claude/skills/release-review in m4r1k/Eneru) into .claude/skills/release-review in your project. Claude Code loads it when a task matches its description.

How do I install Release Review in Codex?

Run `npx skills add m4r1k/Eneru --skill release-review -a codex`. Or copy the skill folder (.claude/skills/release-review in m4r1k/Eneru) into .agents/skills/release-review in your project. Codex loads it when a task matches its description.

Can I use Release Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add m4r1k/Eneru --skill release-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-review, .gemini/skills/release-review, .github/skills/release-review and .opencode/skills/release-review in your project.

What does Release Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Release Review is instructions for the agent only.

Does Release Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Release Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Review use?

Release Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Review use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Review?

Skills that share tags, products or a category with Release Review: Aqua Metrics (oracle/accelerated-data-science, 125 stars), Live Debug (macro-inc/macro, 4.6k stars), Alloy (grafana/skills, 282 stars) and Beyla (grafana/skills, 282 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Review?

m4r1k (a GitHub user) maintains it in m4r1k/Eneru, which has 149 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.

Source: m4r1k/Eneru on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.