Agent skill

Skill Release Gate

by rohitg00 in rohitg00/ai-engineering-from-scratch

Evaluates an Agent Skill bundle before release for structure, trigger quality, artifact improvement, script correctness, safety, installed-tree integrity and host portability.

MITAuto-check passedAgent Workflows

Install Skill Release Gate

skills CLI
$ npx skills add rohitg00/ai-engineering-from-scratch --skill skill-release-gate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rohitg00/ai-engineering-from-scratch skill-release-gate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rohitg00/ai-engineering-from-scratch.git skills-src && mkdir -p .claude/skills && cp -r skills-src/phases/13-tools-and-protocols/27-skill-evals-packaging-and-portability/outputs/skill-release-gate .claude/skills/skill-release-gate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-release-gate
GitHub stars
66k
Token cost
~1k tokens
SKILL.md length
477 words
Files
8 (incl. scripts, references, assets)
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Evaluates an Agent Skill bundle before release for structure, trigger quality, artifact improvement, script correctness, safety, installed-tree integrity and host portability.

  • Works in 11 steps: Resolve SKILL_ROOT to the absolute… → Resolve TARGET_ROOT from the original… → Read references/eval-contract.md from… → …
  • Checking a skill bundle before publishing it
  • SKILL.md covers Workflow, Output contract and Failure behavior
  • Runs Python scripts from its folder

What it does

Before you publish or distribute a skill directory, the agent resolves the installed skill's own folder and the candidate bundle as absolute paths, reads an eval-contract reference, and inspects the candidate's evaluation data: positive and near-miss trigger cases, baseline and with-skill artifact assertions, script and safety evidence, and declared runtime capabilities in a hosts file whose file hashes are checked against a manifest.

The skill separates a local fixture run from production readiness. For production, deterministic predictions, artifacts, evidence and host capabilities must be replaced with captured results bound to non-empty sources and SHA-256 provenance digests. An external attestation file stored outside the bundle must also be supplied, together with a trusted digest of its bytes from a separate release channel. Before running the evaluator, scripts/evaluate_skill.py, the agent shows the exact command line it will use.

The report returns flags named checksPassed, fixturePassed, localEvidenceReady, trustAnchorValid, productionReady and passed, along with the evidence root, failed checks, precision, recall, raw trigger observations, per-case repeated-run rates, artifact comparisons, safety evidence, installed-tree verification and a portability matrix.

When your agent uses it

  • Checking a skill bundle before publishing it
  • Measuring whether a skill's trigger description fires on the right requests
  • Verifying that a skill's scripts and safety checks pass
  • Checking portability across target agent hosts

Example prompts

  • “Run the release gate on ./skills/pdf-forms before I publish it.”
  • “Check whether my new skill's trigger cases and near-miss cases behave as expected.”
  • “Show me the exact evaluator command you will run against my bundle before executing it.”

Requirements

  • Python 3, for scripts/evaluate_skill.py
  • The candidate skill bundle with its evals and assets folders

Workflow steps

11 steps, taken from the first numbered list in SKILL.md.

  1. Resolve SKILL_ROOT to the absolute directory containing this installed
  2. Resolve TARGET_ROOT from the original workspace working directory and
  3. Read references/eval-contract.md from SKILL_ROOT.
  4. Inspect the positive and near-miss trigger cases in
  5. Inspect the shared baseline and with-skill assertions in
  6. Inspect the explicit script and safety results in
  7. Inspect the declared runtime capabilities in
  8. For production, replace deterministic predictions, artifacts, evidence,
  9. Obtain an external JSON attestation whose evidenceRoot matches the report,
  10. Before execution, show the exact resolved argv. The installed evaluator is
  11. Return checksPassed, fixturePassed, localEvidenceReady,

What it can do on your machine

Read from SKILL.md and the folder at commit 463147c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Release Gate loads about 1k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 53 tokens; SKILL.md has 477 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from rohitg00/ai-engineering-from-scratch at commit 463147c, republished under its MIT licence (© rohitg00). 477 words, ~1,007 tokens.

Download SKILL.mdSave it as .claude/skills/skill-release-gate/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
skill-release-gate
description
Evaluate an Agent Skill bundle for structural integrity, trigger quality, artifact improvement, script correctness, safety, installed-tree integrity, and target-host portability before release.
license
MIT
metadata.lesson
27

Skill release gate

Use this skill before publishing or distributing an Agent Skill directory bundle.

Workflow

  1. Resolve SKILL_ROOT to the absolute directory containing this installed SKILL.md. Do not assume the process cwd is the installed bundle.
  2. Resolve TARGET_ROOT from the original workspace working directory and resolve the user-supplied candidate as an absolute TARGET_BUNDLE.
  3. Read references/eval-contract.md from SKILL_ROOT.
  4. Inspect the positive and near-miss trigger cases in evals/cases.json under TARGET_BUNDLE.
  5. Inspect the shared baseline and with-skill assertions in evals/artifacts.json under TARGET_BUNDLE.
  6. Inspect the explicit script and safety results in evals/evidence.json under TARGET_BUNDLE.
  7. Inspect the declared runtime capabilities in assets/hosts.json under TARGET_BUNDLE and verify the target file hashes against its assets/manifest.json.
  8. For production, replace deterministic predictions, artifacts, evidence, and host capabilities with captured results; set all four captured modes; and bind every raw trigger observation, both artifacts, the complete evidence set, and the non-empty host matrix to non-empty sources and matching SHA-256 provenance digests. These local checks can set localEvidenceReady, but locally recomputable hashes do not prove capture.
  9. Obtain an external JSON attestation whose evidenceRoot matches the report, plus the SHA-256 of its exact bytes from a separate trusted policy or release channel. The attestation must be a regular file outside the target bundle.
  10. Before execution, show the exact resolved argv. The installed evaluator is scripts/evaluate_skill.py under SKILL_ROOT. For the shipped lesson fixture, build argv from python3, that absolute evaluator path, --fixture-demo, and the absolute TARGET_BUNDLE. For production, use the same installed script with --attestation, --trusted-attestation-sha256, and the absolute TARGET_BUNDLE, without --fixture-demo.
  11. Return checksPassed, fixturePassed, localEvidenceReady, trustAnchorValid, productionReady, and passed with the evidence root, evaluation modes, failed checks, precision, recall, every raw trigger observation, per-case repeated-run rates, artifact comparison, script and safety evidence, installed-tree verification, and portability matrix. Include the resolved script path, resolved target path, cwd, exact argv, and exit code. Mark unavailable observations unverified.
Show full SKILL.md (163 more words)Show less

Output contract

Return the complete JSON evaluation report. Preserve every layer-specific check and its evidence so a passing aggregate cannot hide a routing, artifact, script, safety, installed-tree, or portability failure. fixturePassed reports a successful teaching fixture. localEvidenceReady reports only local digest integrity. passed is true only when productionReady also has a valid out-of-bundle trust anchor.

Failure behavior

If configuration is invalid, provenance is absent or mismatched, the trusted attestation is missing or invalid, a file hash differs, a required capability is absent, or any production gate fails, stop with a nonzero result and report the failed layer. The explicit --fixture-demo path may exit successfully only when fixturePassed is true, and it never makes a release claim. Never publish, install elsewhere, repair evidence, create the trust decision, or weaken a threshold automatically.

Do not publish a bundle merely because SKILL.md parses or one positive prompt activates. Do not label a package portable when a target drops required companion files or ignores required runtime extensions.

© rohitg00, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in phases/13-tools-and-protocols/27-skill-evals-packaging-and-portability/outputs/skill-release-gate of rohitg00/ai-engineering-from-scratch.

  • SKILL.md
  • assets/hosts.json
  • assets/manifest.json
  • evals/artifacts.json
  • evals/cases.json
  • evals/evidence.json
  • references/eval-contract.md
  • scripts/evaluate_skill.py

Open the folder on GitHubat commit 463147c

Compare with similar skills

Skill Release Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Release Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Release Gate this skillrohitg00/ai-engineering-from-scratch66k—~1kAutomated safety check: PassMIT
Darwin Skill Optimizeralchaincyf/darwin-skill6.2k1 repos~4.7kAutomated safety check: PassMIT
Skill Authoring and Refactoring2025Emma/vibe-coding-cn23k2 repos~2kAutomated safety check: PassMIT
Auto Skill Buildertradecatlabs/vibe-coding-cn17k1 repos~2.4kAutomated safety check: PassMIT
Open-Science Skill Creatoraipoch/open-science5.5k—~1.7kAutomated safety check: PassApache-2.0
Skill JudgeshareAI-lab/Kode-CLI5.2k4 repos~7.5kAutomated safety check: PassApache-2.0

Similar skills

  • Darwin Skill Optimizer

    alchaincyf/darwin-skill

    Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.

    6.2k GitHub starsUsed in 1 repo~4.7k tokens
    Agent WorkflowsAuto-check passed
  • Skill Authoring and Refactoring

    2025Emma/vibe-coding-cn

    Builds new skills from scattered docs, specs or code, and refactors existing skills for clear triggers, reliable activation and a quality checklist.

    23k GitHub starsUsed in 2 repos~2k tokens
    Agent WorkflowsAuto-check passed
  • Auto Skill Builder

    tradecatlabs/vibe-coding-cn

    Meta-skill that turns docs, APIs, code or specs into a reusable skill with references and a quality gate, and refactors skills that are unclear or misfire.

    17k GitHub starsUsed in 1 repo~2.4k tokens
    Agent WorkflowsAuto-check passed
  • Open-Science Skill Creator

    aipoch/open-science

    Creates, revises, evaluates and publishes skills in the Open-Science app through its native host.skills composer, with optional test prompts and benchmarks.

    5.5k GitHub stars~1.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Skill Judge

    shareAI-lab/Kode-CLI

    Evaluates the design quality of an agent skill against official specifications and patterns from existing examples, scoring it and suggesting improvements.

    5.2k GitHub starsUsed in 4 repos~7.5k tokens
    Agent WorkflowsAuto-check passed
  • Skill Quality Reviewer

    Galaxy-Dawn/claude-scholar

    Scores a skill across description, content organization, writing style and structure, then produces letter grades and a prioritized improvement plan.

    5.7k GitHub starsUsed in 1 repo~3k tokens
    Agent WorkflowsAuto-check passed

More from rohitg00/ai-engineering-from-scratch

All 16 skills in this repo
  • AI Engineering Placement Quiz

    rohitg00/ai-engineering-from-scratch

    Runs a 10-question quiz across five areas to place a learner in the AI Engineering from Scratch curriculum, so they skip what they already know.

    66k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • AI Engineering Project Tutor

    rohitg00/ai-engineering-from-scratch

    Tutors a learner through one stage of a hands-on AI engineering project per session: lesson, prediction, code, grader run and reflection, with hints but never full solutions.

    66k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • AI Engineering Phase Quiz

    rohitg00/ai-engineering-from-scratch

    Quizzes you on a completed phase of the AI Engineering from Scratch course, taking a phase number or name and mapping it to that phase's directory.

    66k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Claude Certification Tutor

    rohitg00/ai-engineering-from-scratch

    Guides a learner through one of four independent Claude certification tracks with onboarding, lessons, practice labs, mock exams and remediation.

    66k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • AI Engineering Course Guide

    rohitg00/ai-engineering-from-scratch

    Routes a topic, question or bug to the exact lessons in the AI Engineering from Scratch curriculum and suggests the next command to run.

    66k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • AI Engineering Course Tutor

    rohitg00/ai-engineering-from-scratch

    Teaches the next lesson of the AI Engineering from Scratch curriculum in the terminal, quizzes you at the end and records your progress.

    66k GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Skill Release Gate

What does Skill Release Gate do?

Evaluates an Agent Skill bundle before release for structure, trigger quality, artifact improvement, script correctness, safety, installed-tree integrity and host portability. Before you publish or distribute a skill directory, the agent resolves the installed skill's own folder and the candidate bundle as absolute paths, reads an eval-contract reference, and inspects the candidate's evaluation data: positive and near-miss trigger cases, baseline and with-skill artifact assertions, script and safety evidence, and declared runtime capabilities in a hosts file whose file hashes are checked against a manifest.

When should I use Skill Release Gate?

Skill Release Gate fits situations like: checking a skill bundle before publishing it; measuring whether a skill's trigger description fires on the right requests; verifying that a skill's scripts and safety checks pass; checking portability across target agent hosts.

How do I install Skill Release Gate in Claude Code?

Run `npx skills add rohitg00/ai-engineering-from-scratch --skill skill-release-gate -a claude-code`. Or copy the skill folder (phases/13-tools-and-protocols/27-skill-evals-packaging-and-portability/outputs/skill-release-gate in rohitg00/ai-engineering-from-scratch) into .claude/skills/skill-release-gate in your project. Claude Code loads it when a task matches its description.

How do I install Skill Release Gate in Codex?

Run `npx skills add rohitg00/ai-engineering-from-scratch --skill skill-release-gate -a codex`. Or copy the skill folder (phases/13-tools-and-protocols/27-skill-evals-packaging-and-portability/outputs/skill-release-gate in rohitg00/ai-engineering-from-scratch) into .agents/skills/skill-release-gate in your project. Codex loads it when a task matches its description.

Can I use Skill Release Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rohitg00/ai-engineering-from-scratch --skill skill-release-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-release-gate, .gemini/skills/skill-release-gate, .github/skills/skill-release-gate and .opencode/skills/skill-release-gate in your project.

What does Skill Release Gate need to run?

Going by SKILL.md and its folder, Skill Release Gate needs Python for the scripts in its folder. Our summary lists: Python 3, for scripts/evaluate_skill.py; The candidate skill bundle with its evals and assets folders.

Does Skill Release Gate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Release Gate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Skill Release Gate use?

Skill Release Gate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Release Gate use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 935 tokens, read only when the agent opens those files.

What are the alternatives to Skill Release Gate?

Skills that share tags, products or a category with Skill Release Gate: Darwin Skill Optimizer (alchaincyf/darwin-skill, 6.2k stars), Skill Authoring and Refactoring (2025Emma/vibe-coding-cn, 23k stars), Auto Skill Builder (tradecatlabs/vibe-coding-cn, 17k stars) and Open-Science Skill Creator (aipoch/open-science, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Release Gate?

rohitg00 (a GitHub user) maintains it in rohitg00/ai-engineering-from-scratch, which has 66,287 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 10, 2026.

Source: rohitg00/ai-engineering-from-scratch on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.