Agent skill

Verify Release

by openclaw in openclaw/openclaw

Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…

MITAuto-check passedTesting & QA

Install Verify Release

skills CLI
$ npx skills add openclaw/openclaw --skill verify-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/openclaw verify-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/verify-release .claude/skills/verify-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-release
GitHub stars
392k
Token cost
~2.4k tokens
SKILL.md length
1,182 words
Files
1
Skills in repo
93
Repo updated
First seen
Licence
MIT

At a glance

Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…

  • Works in 5 steps: GitHub release → Root npm → Plugin publish set → …
  • Tasks that involve QA and bug reports
  • SKILL.md covers Rules, Regular beta/stable checks, Extended-stable checks and Shared live smoke, plus 1 more section
  • Calls gh, npm and node; reaches api.github.com; needs OPENAI_API_KEY

What it does

Verify Release is an agent skill from openclaw/openclaw. Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release track.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering QA and bug reports and Supply chain security. It works with npm and GitHub. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.

When your agent uses it

  • Tasks that involve QA and bug reports
  • Tasks that involve Supply chain security

Example prompts

  • “/verify-release”

Requirements

  • Docker
  • A credential in OPENAI_API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. GitHub release
  2. Root npm
  3. Plugin publish set
  4. ClawHub
  5. Release workflows

What it can do on your machine

Read from SKILL.md and the folder at commit 1eb5970. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • node
    • docker
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Release loads about 2.4k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 1,182 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/openclaw at commit 1eb5970, republished under its MIT licence (© openclaw). 1,182 words, ~2,439 tokens.

Download SKILL.mdSave it as .claude/skills/verify-release/SKILL.md (or your agent's skills folder).
name
verify-release
description
Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release track.

Verify Release

Use this when asked whether an OpenClaw release is fully released, published, promoted, smoke-tested, or live-verified. This is a verification skill, not a publish skill; use $release-openclaw-maintainer before changing release state.

Rules

  • Resolve short suffixes like .27 to the concrete CalVer version from the current date/context, then say the resolved version.
  • Resolve the track first. Both tracks use the shared GitHub Release evidence ledger. Regular beta/stable also uses the platform graph; extended-stable uses its canonical branch, npm selector, and Gateway surfaces. Do not require one track's native or ClawHub artifacts from the other.
  • Verify live state. Do not trust local checkout state, release notes, or old memory as current truth.
  • If the checkout is dirty or divergent, use it only for scripts/reference. For version metadata, fetch from GitHub release/tag or unpack the tag tarball under /tmp.
  • Never print secrets. Use inherited live keys only for scoped smoke commands.
  • Keep the final terse: yes/no, evidence bullets, caveats, cleanup.

Regular beta/stable checks

Use these checks only for the regular orchestrated release track.

  1. GitHub release:
    • gh release view v<VERSION> --repo openclaw/openclaw --json tagName,name,publishedAt,isDraft,isPrerelease,targetCommitish,url,body,assets
    • Confirm stable releases are not draft/prerelease.
    • Confirm release body has npm, CI, plugin npm, ClawHub, mac/appcast evidence links when expected.
    • Confirm assets expected for stable mac releases are uploaded: zip, dmg, dSYM, dependency evidence, immutable full-validation manifest, postpublish evidence, and stable-main closeout manifest.
    • Download each immutable evidence asset and its .sha256 companion, then verify the checksum before trusting the release record.
  2. Root npm:
    • npm view openclaw@<VERSION> version dist-tags.latest dist.tarball dist.integrity time.<VERSION> --json
    • latest must equal <VERSION> for stable.
    • Record tarball, integrity, publish time.
    • Confirm the release postpublish evidence records npmRegistrySignaturesVerified: true and npmProvenanceAttestationMatched: true.
  3. Plugin publish set:
    • Get exact tag metadata from GitHub, not the local checkout when dirty: download https://api.github.com/repos/openclaw/openclaw/tarball/v<VERSION> into /tmp/openclaw-v<VERSION>-src.
    • Derive the full expected npm and ClawHub package sets for the release track with the canonical publication planners/collector from the recorded release Tooling SHA, using the exact tag's package metadata. Do not count raw publish flags: openclaw.build.bundledDist === true explicitly defers external publication even when publish flags are set. Record deferred package names and reasons separately.
    • Reconcile expected package identities, versions, and counts across original publication, previously published versions, and selected recovery runs using immutable publication plans, registry readback, and workflow jobs. A selected recovery subset must not narrow the full expected release set: gh api repos/openclaw/openclaw/actions/runs/<RUN>/jobs --paginate.
    • Each expected npm plugin must have version <VERSION> and dist-tags.latest === <VERSION>.
  4. ClawHub:
    • Check the Plugin ClawHub Release workflow conclusion and publish job count.
    • Use OpenClaw itself for live registry proof: openclaw plugins search <known-plugin> --json.
    • Install one official plugin at the exact requested release version from ClawHub in an isolated HOME: openclaw plugins install clawhub:@openclaw/matrix@<VERSION>. Prefer matrix unless that plugin is not in the expected set. ClawHub versions belong in the spec; --pin is only supported for npm installs.
  5. Release workflows:
    • Verify conclusions for release notes evidence links: Full Release Validation, OpenClaw Release Checks, OpenClaw NPM Release, Plugin NPM Release, Plugin ClawHub Release, mac preflight/validation/publish when stable mac assets are expected.
    • For stable, verify OpenClaw Stable Main Closeout succeeded and its manifest records the matching release tag, current rollback drill, stable soak, and blocking performance evidence.
    • Summarize only relevant successful/failed jobs; ignore routine skipped optional lanes unless the release body promised them.
Show full SKILL.md (633 more words)Show less

Extended-stable checks

Extended-stable has a GitHub Release with shared release evidence but no native or ClawHub artifacts. Verify it alongside the live tag, workflow, registry, provenance, and image state.

  1. Identity: require final v<VERSION> at patch 33+, with no suffix, contained in extended-stable/YYYY.M.33. Only an active candidate must equal the tip. Root and every publishable official plugin must declare <VERSION>. Require the Git tag and a public, non-prerelease GitHub Release whose title and canonical body match the tag. Require isLatest=false, the dependency evidence, immutable Full Release Validation manifest, postpublish evidence, and their checksums. Require no native or ClawHub assets.
  2. Workflow chain: find the successful parent release run plus its preflight, complete validation, plugin npm, and core publish children. Require a protected release-publish/* parent and canonical release-ci/* validation producer with verified workflow SHA provenance. Validation must use rerun_group=all, release_profile=stable, blocking soak/performance, and the saved attempt. Core publish must reference all three run IDs and bind its manifest, workflow ref, and tarball digest to the release SHA.
  3. Registry: require exact and extended-stable selectors to return <VERSION> for root, every preflight corePackageTarballs entry, and every publishToNpm === true official plugin derived from the tag. Compare the plugin plan, jobs, and complete readback; never infer inventory from diffs.
  4. Provenance: from trusted current tooling, run node --import tsx scripts/openclaw-npm-postpublish-verify.ts <VERSION>. Require signatures, canonical-branch provenance, and publish/preflight digest binding to the release SHA. Preserve output and workflow URLs.
  5. Docker: verify exact default, slim, browser, and architecture images and attestations in both registries. Only the three extended-stable* aliases may resolve to those digests. Require the successful OpenClaw Release Publish parent run and its completed Docker verification. The normal route finalizes afterward; an explicitly requested fast path may activate GitHub first. Repair aliases through current-main Docker Channel Promotion for the exact tag, without rebuilding.
  6. Recovery: never republish. Use promote_extended_stable in the openclaw/releases dist-tag workflow for the root selector (an unsuffixed final patch 33+) and approved credential-isolated tooling for others, then repeat complete readback. Do not require ClawHub, native/mobile apps, website, private dist-tags, or regular latest. Require shared release evidence, but do not require regular native or ClawHub assets.

Shared live smoke

After the track-specific publication checks pass:

  1. Published package smoke:
    • In /tmp, isolated HOME: npm exec --yes --package openclaw@<VERSION> -- openclaw --version.
    • Run at least one harmless command that touches the published CLI surface, for example plugins --help or gateway --help.
  2. Dev Gateway live model smoke:
    • Use temp HOME/workspace, not the user's normal state: HOME=/tmp/openclaw-release-smoke/home OPENCLAW_WORKSPACE=/tmp/openclaw-release-smoke/work pnpm openclaw --dev gateway run --auth none --force --verbose.
    • Resolve the launched Gateway's bound port from its startup output or log.
    • For --auth none, require unauthenticated GET http://127.0.0.1:<PORT>/healthz to return HTTP 200 with the exact JSON object {"ok":true,"status":"live"}.
    • Reserve gateway health --json for intentionally credentialed or device-paired smoke, passing the explicit credential required by that Gateway.
    • Run one Gateway-backed agent turn with inherited OPENAI_API_KEY, short prompt, explicit session key, JSON output, and a known-available model.
    • If the configured default model fails as unavailable, record that caveat and retry with the newest known-good OpenAI model instead of declaring the release failed.
    • Stop the gateway and verify the port is not listening.

Caveats To Report

  • Dist-tag caveat: stable latest is release truth; if optional beta mirrors still point at a beta version, report it as a caveat, not a stable-release blocker, unless the user asked to verify beta promotion.
  • Track caveat: name the track and intentionally absent surfaces. Do not call missing regular-release artifacts an extended-stable failure.
  • Divergent checkout caveat: say when local source SHA differs from release tag or origin and which live sources were used instead.
  • Smoke caveat: distinguish Gateway-backed agent success from local embedded fallback. A valid auth-none live smoke has the exact /healthz result plus a successful Gateway-backed agent turn and the Gateway log/run id for that call.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/verify-release of openclaw/openclaw.

Open the folder on GitHubat commit 1eb5970

Compare with similar skills

Verify Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Release this skillopenclaw/openclaw392k—~2.4kAutomated safety check: PassMIT
Handsontable Demo Page Generatorhandsontable/handsontable22k—~1.8kAutomated safety check: PassCustom licence
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT
Proactive Security Monitorepam/ai-dial-chat504—~1.9kAutomated safety check: PassApache-2.0
Weavebench Cua ReproduceAMAP-ML/LongHorizon-Harness1.7k—~1.6kAutomated safety check: PassMIT

Similar skills

  • Handsontable Demo Page Generator

    handsontable/handsontable

    Builds two throwaway HTML test pages for a Handsontable pull request, one on the released CDN version and one on the local build, to compare behavior side by side.

    22k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Proactive supply-chain watch for this repo. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • Weavebench Cua Reproduce

    AMAP-ML/LongHorizon-Harness

    Reproduce CUA-Harness experiments on WeaveBench from a GitHub checkout.

    1.7k GitHub stars~1.6k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Evidence-Driven Testing

    michaelshimeles/skills

    Records an annotated screen recording of the agent testing an app hands-on, then posts the video and a results summary to the PR and tracker issue.

    1.3k GitHub starsUsed in 1 repo~3.9k tokens
    Testing & QAAuto-check passed

More from openclaw/openclaw

All 93 skills in this repo
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Tmux

    openclaw/openclaw

    Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.

    392k GitHub starsUsed in 2 repos~640 tokens
    Auto-check passed
  • Feishu Doc

    openclaw/openclaw

    Feishu document read/write workflows. An agent skill from openclaw/openclaw.

    392k GitHub stars~516 tokensUpdated today
    Auto-check passed
  • Openclaw PR Maintainer

    openclaw/openclaw

    Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.

    392k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Browser Automation

    openclaw/openclaw

    A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.

    392k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Clawsweeper

    openclaw/openclaw

    A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…

    392k GitHub stars~3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Verify Release

What does Verify Release do?

Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release…. Verify Release is an agent skill from openclaw/openclaw. Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release track.

When should I use Verify Release?

Verify Release fits situations like: tasks that involve QA and bug reports; tasks that involve Supply chain security.

How do I install Verify Release in Claude Code?

Run `npx skills add openclaw/openclaw --skill verify-release -a claude-code`. Or copy the skill folder (.agents/skills/verify-release in openclaw/openclaw) into .claude/skills/verify-release in your project. Claude Code loads it when a task matches its description.

How do I install Verify Release in Codex?

Run `npx skills add openclaw/openclaw --skill verify-release -a codex`. Or copy the skill folder (.agents/skills/verify-release in openclaw/openclaw) into .agents/skills/verify-release in your project. Codex loads it when a task matches its description.

Can I use Verify Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill verify-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-release, .gemini/skills/verify-release, .github/skills/verify-release and .opencode/skills/verify-release in your project.

What does Verify Release need to run?

Going by SKILL.md and its folder, Verify Release needs the command-line tools its instructions call (gh, npm, node, docker and pnpm) and credentials named OPENAI_API_KEY. Our summary lists: Docker; A credential in OPENAI_API_KEY.

Does Verify Release access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Verify Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Release use?

Verify Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Release use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Release?

Skills that share tags, products or a category with Verify Release: Handsontable Demo Page Generator (handsontable/handsontable, 22k stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Stash Supply Chain Security (cipherstash/stack, 157 stars) and Proactive Security Monitor (epam/ai-dial-chat, 504 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Release?

openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,610 GitHub stars. The repository holds 93 skills in this directory. The repository was last updated on October 8, 2026.

Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.