Official agent skill

Aicr Reviewing Component Drift

by NVIDIA in NVIDIA/aicr

A skill your agent uses when reviewing the weekly AICR component drift report — the Slack digest and drift-report.json artifact produced by Registry Drift Report (registry-drift.yaml) listing which…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Aicr Reviewing Component Drift

skills CLI
$ npx skills add NVIDIA/aicr --skill aicr-reviewing-component-drift -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/aicr aicr-reviewing-component-drift --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/aicr.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/aicr-reviewing-component-drift .claude/skills/aicr-reviewing-component-drift && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aicr-reviewing-component-drift
GitHub stars
440
Token cost
~2.8k tokens
SKILL.md length
1,412 words
Files
2
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when reviewing the weekly AICR component drift report — the Slack digest and drift-report.json artifact produced by Registry Drift Report (registry-drift.yaml) listing which…

  • Works in 5 steps: Read the state file → Resolve the input → Gather evidence per component → …
  • Review this weeks drift
  • SKILL.md covers When to Use, Step 1 — Read the state file, Step 2 — Resolve the input and Step 3 — Gather evidence per…, plus 3 more sections
  • Calls gh and make

What it does

Aicr Reviewing Component Drift is an agent skill from NVIDIA/aicr, published by the product's own GitHub organization. Use when reviewing the weekly AICR component drift report — the Slack digest and drift-report.json artifact produced by Registry Drift Report (registry-drift.yaml) listing which recipes/registry.yaml chart pins have moved upstream. Triggers on "review this week's drift", "component drift", "/aicr-reviewing-component-drift", "should we bump <component", "what changed in <chart", a pasted drift digest from Slack, or release prep that needs to know which chart pins are safe to advance. Gathers values-path…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `drift-state.yaml`).

It sits in DevOps & Cloud, covering Container orchestration and Changelog and release notes. It works with Slack, Kubernetes and NVIDIA AI Platform. The repository describes itself as: Tooling for optimized, validated, and reproducible GPU-accelerated AI runtime in Kubernetes. The licence is Apache-2.0.

When your agent uses it

  • Review this weeks drift
  • Component drift
  • /aicr-reviewing-component-drift
  • Should we bump <component

Example prompts

  • “review this week”
  • “component drift”
  • “/aicr-reviewing-component-drift”
  • “/aicr-reviewing-component-drift”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Read the state file
  2. Resolve the input
  3. Gather evidence per component
  4. Write the recommendation
  5. Update the state file

What it can do on your machine

Read from SKILL.md and the folder at commit e8f18da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aicr Reviewing Component Drift loads about 2.8k tokens when it runs. Until then it costs about 203 tokens; SKILL.md has 1,412 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~203
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/aicr at commit e8f18da, republished under its Apache-2.0 licence (© NVIDIA). 1,412 words, ~2,817 tokens.

Download SKILL.mdSave it as .claude/skills/aicr-reviewing-component-drift/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
aicr-reviewing-component-drift
description
Use when reviewing the weekly AICR component drift report — the Slack digest and drift-report.json artifact produced by Registry Drift Report (registry-drift.yaml) listing which recipes/registry.yaml chart pins have moved upstream. Triggers on "review this week's drift", "component drift", "/aicr-reviewing-component-drift", "should we bump <component>", "what changed in <chart>", a pasted drift digest from Slack, or release prep that needs to know which chart pins are safe to advance. Gathers values-path compatibility, lockstep-family, image/BOM, CRD/upgrade-record, upstream release-note, and Kubernetes-compatibility evidence per component, then writes a ranked take/hold/defer recommendation. Recommends only — it never edits the registry, files an issue, or opens a PR.

AICR Component Drift Review

Turns a weekly drift report into a decision. The workflow (https://github.com/NVIDIA/aicr/actions/workflows/registry-drift.yaml) answers "what moved"; this skill answers "what should we take, and what does taking it cost". An AICR component bump is never a version-string edit, which is exactly why the workflow does not open PRs.

When to Use

  • The weekly drift digest landed in Slack and someone asks what to do about it
  • Release prep needs to know which chart pins can safely advance
  • Someone asks whether a specific component should be bumped

Do NOT use this skill to perform a bump. It produces a recommendation; the edit, the make bom-docs run, and the PR are separate, human-initiated work.

Step 1 — Read the state file

Read drift-state.yaml beside this file before anything else. It records what was reviewed at which candidate set and why anything was held, so a component whose candidates have not changed since last week is confirmed, not re-derived. Update it in Step 5.

Reuse a verdict only after comparing the whole candidate set — current, latest, and every entry in alternatives[] — against what the entry records. A verdict keyed on the version pair alone goes stale silently, because a new candidate can appear while current and latest both stay put: kai-scheduler sat at v0.16.9 -> v0.20.1 across two runs while a patch v0.16.10 arrived beside it, and v0.16.10 is the one worth taking. If any candidate was added, removed, or changed, re-derive.

An entry with no recorded candidates predates that field. Treat it as changed and re-derive it; do not read the absence as "nothing new".

Step 2 — Resolve the input

In order of preference:

  1. An explicit run, downloaded into a scratch directory rather than the working tree (gh run download extracts in place; without --dir the two report files land as untracked files in this checkout and collide with themselves on a second run):

    bash
    dir=$(mktemp -d "${TMPDIR:-/tmp}/aicr-drift.XXXXXX")
    gh run download <id> -R NVIDIA/aicr -n drift-report --dir "$dir"

    Read drift-report.json and drift-report-raw.json from "$dir".

  2. The latest run: gh run list -R NVIDIA/aicr --workflow=registry-drift.yaml --status=success --event schedule --limit 1 --json databaseId then the same scratch-directory download as above (mktemp -d + gh run download <id> -R NVIDIA/aicr -n drift-report --dir "$dir").

    The default is deliberately the weekly scheduled run on the default branch — registry-drift.yaml also runs on workflow_dispatch and, for a same-repo PR touching the drift surface, on pull_request; every successful path uploads the same drift-report artifact name, so an unfiltered "latest successful run" could just as easily be a PR-validation run and put the review against unmerged changes. --event schedule excludes both. Reviewing a manual or PR-validation report is still supported — pass --run <id> explicitly (option 1) rather than relying on the default.

  3. A local drift-report.json path the user provides

  4. A pasted Slack digest — it carries counts and a report artifact link, no component names, so take the run ID out of that link and download the artifact per option 1. If the artifact has expired, re-derive the drift set from recipes/registry.yaml and the upstream registry (helm show chart for HTTP repos, crane ls for oci://). That re-derivation is unfiltered: it does not apply Renovate's minimumReleaseAge (3 days, .github/renovate.json5) or internalChecksFilter: "strict", so it can surface a release younger than the cooldown or one Renovate's strict filter would reject. Use it only to identify which components to look at — never to justify a bump on its own; the artifact remains the authoritative source for whether a version is actually eligible.

Confirm schemaVersion is 1. A higher number means this skill is stale — read tools/drift-report/report.go before trusting the field names.

Report unresolved[] to the user before reviewing anything: those pins are unknown, not current, and a persistent entry is a broken datasource worth fixing ahead of any bump.

Read alternatives[] on every row that has one. latest is the largest step Renovate offers, not the only one and not necessarily the one to take. A row carrying alternatives has a smaller step available — usually the one worth recommending, since it crosses fewer upstream changes. Name both in the verdict and say which you are recommending; a verdict that discusses only latest when the row offered a minor beside a major has reviewed the wrong upgrade (#2791).

The field is absent when Renovate offered exactly one candidate, which is the common case. It is additive, so schemaVersion stays 1.

Show full SKILL.md (698 more words)Show less

Step 3 — Gather evidence per component

Ordered by how often each is what actually bites.

  1. Values-path compatibility. Pull both chart versions and diff their values, then verify every path AICR depends on still exists:

    • keys set in recipes/components/<name>/values.yaml
    • values: blocks in recipes/overlays/*.yaml and recipes/mixins/*.yaml that target the component
    • the component's nodeScheduling.nodeSelectorPaths and tolerationPaths in recipes/registry.yaml

    The third is the silent one: a renamed master.nodeSelector leaves AICR rendering valid YAML that no longer schedules anything correctly, and no current test catches it. Treat a missing path as a blocking finding.

  2. Lockstep families. These move together; never recommend a partial bump:

    • slinky-slurm-operator-crds, slinky-slurm-operator, slinky-slurm
    • mariadb-operator-crds, mariadb-operator, slurm-accounting-mariadb
    • agentgateway-crds, agentgateway
    • prometheus-operator-crds, kube-prometheus-stack, keyed on appVersion, not chart version (the two chart sequences are unrelated). A lagging CRDs pin also breaks nvsentinel and k8s-ephemeral-storage-metrics, which create resources defined by those CRDs. TestPrometheusOperatorAppVersionLockstep enforces this.
    • prometheus-adapter / prometheus-adapter-ocp, nvidia-dra-driver-gpu / nvidia-dra-driver-gpu-ocp, and k8s-nim-operator / k8s-nim-operator-ocp — these three -ocp twins carry a defaultRepository identical to their base, so BuildReport already collapses each pair into one report row; name both in the verdict anyway. The other four -ocp components (gpu-operator-ocp, network-operator-ocp, nfd-ocp, cert-manager-ocp) have defaultRepository: "" and are manifest-only — BuildReport drops them before Tracked++, so they never appear in the report at all (they surface in untrackedComponents instead). Do not assume a base component's row already accounts for one of these four; there is no shared row to collapse into.
  3. Image and BOM delta. Render old against new and diff the image list. make bom-docs is the repo's renderer; a new image means new vulnerability surface, and a new registry host means tools/registry-inventory's allowlist needs extending too.

  4. CRD and upgrade-record impact. For CRD-bearing charts (kueue, gatekeeper, mariadb, slinky, prometheus-operator-crds, nvsentinel), check whether the transition needs an ADR-021 record: see pkg/upgrade and tools/check-upgrade-records.

  5. Upstream breaking changes. Where the chart maps to a GitHub project, read the releases between the two versions (gh release list -R <owner>/<repo>), looking for removed flags, renamed values, and required migration steps.

  6. Kubernetes compatibility and blast radius. Compare the new chart's kubeVersion against the K8s.server.version constraints of the overlays that pull the component, and check whether recipes/checks/<name>/health-check.yaml exists and whether its assertions still hold against the new chart's resource names.

Step 4 — Write the recommendation

Write Markdown to a temp file ("$TMPDIR"/aicr-drift-review-<date>.md) and summarize it in chat. Rank components by (blocking findings, then update type, then age of the pin). Per component:

  • Verdict: take / hold / defer, one line of why. When the row carries alternatives, name which version the verdict is about — a bare "take" is ambiguous once more than one is on offer
  • Evidence: the findings from Step 3 that produced the verdict, with the specific values path, image, or release note that matters
  • Cost: what a bump would require — a values-file edit, a new upgrade record, a BOM refresh, a health-check update, an allowlist entry

Do not edit the registry, file issues, or open PRs. Ask before doing anything outward-facing.

Step 5 — Update the state file

Record every component reviewed: the version pair, the full candidate set the verdict was formed against, which candidate the verdict recommends, the date, and for a hold or defer the condition that would change it. Next week's digest repeats the same components by design — this file is what keeps the review from repeating with it.

candidates is what Step 1 compares against, so record it verbatim from the report rather than summarizing: an entry that omits a candidate makes next week's run confirm a verdict that never considered it. recommends is only meaningful when the row had alternatives; omit it otherwise, since the single candidate is already named by to.

Gotchas

  • crane ls on ghcr.io works in the sandbox; NGC (nvcr.io, and helm.ngc.nvidia.com over curl) and some TLS paths need dangerouslyDisableSandbox: true. Try sandboxed first.
  • OCI chart repositories list cosign signature and attestation tags alongside real chart tags. Ignore anything that is not a version.
  • recipes/overlays/aks.yaml pins kube-prometheus-stack to 83.7.0 deliberately (#700, declared in versionPinExemptions in pkg/recipe/version_pin_guard_test.go). A kube-prometheus-stack bump has to reckon with that exemption; do not propose removing it casually.
  • aws-efa's chart is tracked but its device-plugin image is in Renovate's ignoreDeps and must be coordinated with EKS add-on releases.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/aicr-reviewing-component-drift of NVIDIA/aicr.

  • SKILL.md
  • drift-state.yaml

Open the folder on GitHubat commit e8f18da

Compare with similar skills

Aicr Reviewing Component Drift next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aicr Reviewing Component Drift compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aicr Reviewing Component Drift this skillNVIDIA/aicr440—~2.8kAutomated safety check: PassApache-2.0
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider174—~2.6kAutomated safety check: PassCustom licence
Release Cut And Demo Rollcarverauto/serviceradar921—~3.9kAutomated safety check: PassApache-2.0
Release And CIeser/stack128—~665Automated safety check: PassCustom licence
Nim Operator InstallNVIDIA/k8s-nim-operator159—~4.7kAutomated safety check: PassApache-2.0
Nim Operator UninstallNVIDIA/k8s-nim-operator159—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release Cut And Demo Roll

    carverauto/serviceradar

    Cut a ServiceRadar release and roll the Kubernetes demo namespace to the resulting published semver image tag through the guarded ArgoCD release branch.

    921 GitHub stars~3.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release And CI

    eser/stack

    Releases and CI for eserstack: the shared version of all packages, the release command, the tag-driven build.yml run, JSR and npm publishing, changelog and breaking changes, release recovery, GitHub…

    128 GitHub stars~665 tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Nim Operator Install

    NVIDIA/k8s-nim-operator

    Official

    Install NVIDIA NIM Operator on Kubernetes with prerequisite checks, optional NVIDIA GPU Operator dependency installation, public or local Helm chart selection, optional Dynamo support, and optional…

    159 GitHub stars~4.7k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Nim Operator Uninstall

    NVIDIA/k8s-nim-operator

    Official

    Safely uninstall NVIDIA NIM Operator from Kubernetes with inventory checks, explicit approval gates for destructive actions, optional custom resource cleanup, optional CRD removal, and…

    159 GitHub stars~3.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Official

    A skill your agent uses when validating DCGM Exporter in a local GPU-backed k3d/Kubernetes environment.

    1.9k GitHub stars~116 tokensUpdated 21 days ago
    DevOps & CloudAuto-check passed

More from NVIDIA/aicr

All 10 skills in this repo
  • Official

    Multi-agent PR review using Claude Code, Codex, and CodeRabbit.

    440 GitHub stars~15k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when analyzing an AICR snapshot YAML file, reviewing cluster state, comparing provider characteristics, extracting GPU/network topology insights, or generating a cluster…

    440 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds an interactive guided demo script (demos/.sh), live or self-paced, with the Frame → Tell → Show → Close pattern.

    440 GitHub stars~929 tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when building a self-contained HTML slide deck or visual talking-point for a technical concept or workflow (e.g.

    440 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Official

    A skill your agent uses when drafting the human-readable GitHub release notes summary for an upcoming AICR release.

    440 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Aicr Uat Report

    NVIDIA/aicr

    Official

    A skill your agent uses when reporting on UAT health across services and GPU targets — which service (EKS/GKE/AKS) x GPU (H100/GB200) x intent combinations are passing or failing in the UAT Run…

    440 GitHub stars~3.2k tokensUpdated today
    Auto-check passed

Questions about Aicr Reviewing Component Drift

What does Aicr Reviewing Component Drift do?

A skill your agent uses when reviewing the weekly AICR component drift report — the Slack digest and drift-report.json artifact produced by Registry Drift Report (registry-drift.yaml) listing which…. Aicr Reviewing Component Drift is an agent skill from NVIDIA/aicr, published by the product's own GitHub organization.yaml chart pins have moved upstream.

When should I use Aicr Reviewing Component Drift?

Aicr Reviewing Component Drift fits situations like: review this weeks drift; component drift; /aicr-reviewing-component-drift; should we bump <component.

How do I install Aicr Reviewing Component Drift in Claude Code?

Run `npx skills add NVIDIA/aicr --skill aicr-reviewing-component-drift -a claude-code`. Or copy the skill folder (.agents/skills/aicr-reviewing-component-drift in NVIDIA/aicr) into .claude/skills/aicr-reviewing-component-drift in your project. Claude Code loads it when a task matches its description.

How do I install Aicr Reviewing Component Drift in Codex?

Run `npx skills add NVIDIA/aicr --skill aicr-reviewing-component-drift -a codex`. Or copy the skill folder (.agents/skills/aicr-reviewing-component-drift in NVIDIA/aicr) into .agents/skills/aicr-reviewing-component-drift in your project. Codex loads it when a task matches its description.

Can I use Aicr Reviewing Component Drift in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/aicr --skill aicr-reviewing-component-drift -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aicr-reviewing-component-drift, .gemini/skills/aicr-reviewing-component-drift, .github/skills/aicr-reviewing-component-drift and .opencode/skills/aicr-reviewing-component-drift in your project.

What does Aicr Reviewing Component Drift need to run?

Going by SKILL.md and its folder, Aicr Reviewing Component Drift needs the command-line tools its instructions call (gh and make).

Does Aicr Reviewing Component Drift access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Aicr Reviewing Component Drift safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aicr Reviewing Component Drift use?

Aicr Reviewing Component Drift is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aicr Reviewing Component Drift use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aicr Reviewing Component Drift?

Skills that share tags, products or a category with Aicr Reviewing Component Drift: Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars), Release Cut And Demo Roll (carverauto/serviceradar, 921 stars), Release And CI (eser/stack, 128 stars) and Nim Operator Install (NVIDIA/k8s-nim-operator, 159 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aicr Reviewing Component Drift?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/aicr, which has 440 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 10, 2026.

Source: NVIDIA/aicr on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.