Agent skill

Runbook

by sd0xdev in sd0xdev/sd0x-harness

Generate and update feature release runbooks from existing docs and codebase.

MITAuto-check passedDevOps & Cloud

Install Runbook

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill runbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness runbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/runbook .claude/skills/runbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
runbook
GitHub stars
192
Token cost
~2.7k tokens
SKILL.md length
1,097 words
Files
4 (incl. references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Generate and update feature release runbooks from existing docs and codebase.

  • Works in 4 steps: Context Resolution → Content Discovery (Create/Update modes) → Generate / Update → …
  • : creating operational runbook
  • SKILL.md covers Trigger, When NOT to Use, Usage and Workflow, plus 9 more sections
  • Calls node and git

What it does

Runbook is an agent skill from sd0xdev/sd0x-harness. Generate and update feature release runbooks from existing docs and codebase. Use when: creating operational runbook, release handbook, deployment checklist, pre-release preparation. Not for: incident response (v2), code review (use codex-code-review), architecture design (use architecture).

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/check-output.md`, `references/discovery-heuristics.md` and `references/template.md`).

It sits in DevOps & Cloud, covering Runbooks and postmortems. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : creating operational runbook
  • Release handbook
  • Deployment checklist
  • Pre-release preparation

Example prompts

  • “/runbook”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash(git:*), Bash(node:*), Write, Edit, Agent, AskUserQuestion

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Context Resolution
  2. Content Discovery (Create/Update modes)
  3. Generate / Update
  4. Check Mode (--check)

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash(git:*)
    • Bash(node:*)
    • Write
    • Edit
    • Agent
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Runbook loads about 2.7k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 75 tokens; SKILL.md has 1,097 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 1,097 words, ~2,748 tokens.

Download SKILL.mdSave it as .claude/skills/runbook/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
runbook
description
Generate and update feature release runbooks from existing docs and codebase. Use when: creating operational runbook, release handbook, deployment checklist, pre-release preparation. Not for: incident response (v2), code review (use codex-code-review), architecture design (use architecture).
allowed-tools
Read, Grep, Glob, Bash(git:*), Bash(node:*), Write, Edit, Agent, AskUserQuestion

Runbook Generation Skill

Trigger

  • Keywords: runbook, release runbook, deployment handbook, release handbook, operational guide, pre-release checklist, rollback plan

When NOT to Use

ScenarioAlternative
Incident response runbookv2 (not yet implemented)
Code review/codex-review-fast
Architecture design/architecture
Tech spec writing/tech-spec
Request tracking/create-request

Usage

bash
/runbook                              # Auto-detect feature, create or update
/runbook <feature-keyword>            # Specify feature
/runbook --update                     # Force update mode
/runbook --check                      # Read-only staleness validation
/runbook --request <path|title>       # Specify target request (multi-request features)

Workflow

mermaid
sequenceDiagram
    participant U as User
    participant S as /runbook
    participant FR as Feature Resolver
    participant CB as Codebase
    participant RB as runbook-release.md

    U->>S: /runbook [feature] [--update|--check] [--request path]
    S->>FR: node scripts/resolve-feature.js
    FR-->>S: {key, doc_inventory, source sets}
    S->>S: Mode dispatch + Request selection

    alt Create Mode
        S->>CB: Read current_authority + requests/*.md
        S->>CB: Scoped discovery (5-priority cascade)
        S->>RB: Write runbook-release.md from template
    else Update Mode
        S->>RB: Read existing runbook + provenance
        S->>CB: Compare current state vs provenance SHAs
        S->>RB: Edit changed sections only
    else Check Mode
        S->>RB: Read existing runbook + provenance
        S->>CB: Validate per-section SHAs
        S-->>U: Report: Fresh/Stale/Missing/Unknown
    end

Phase 0: Context Resolution

Resolve feature using the 5-level cascade:

The wrapper, not the CLI directly: resolve-feature.js owns the failure payload, so the full shape with scan_error: true arrives however the CLI fails — a nonzero exit, a signal, a partial write, a payload that is not the agreed shape. (It cannot survive node itself being unavailable: nothing running under node can. What it removes is the CLI's failure domain, not the interpreter's.) Calling the CLI with || echo '{}' produces a payload the gate below cannot recognise as a failure.

Decide the branch yourself, then run one command. This skill grants Bash(node:*), which matches a direct node … invocation and nothing else — a shell if/[ … ]/$(…) compound is not a node command and cannot run here. Parse $ARGUMENTS first (Step 1 below), then issue exactly one of:

bash
node scripts/resolve-feature.js --feature <the feature key from $ARGUMENTS>
bash
node scripts/resolve-feature.js

Use the first when $ARGUMENTS carried a positional feature key, the second otherwise. Pass the key as a separate argv token — never interpolate it into a larger shell expression.

SourceMapping
/runbook authPositional key auth → --feature auth (two separate argv tokens)
/runbook (no arg)No --feature, resolver uses branch/diff/fallback
/runbook --checkNo --feature, parse flags only
StepAction
1Parse $ARGUMENTS for feature key or --check/--update/--request flags
2Run feature resolver, get key, doc_inventory, and the four source sets (current_authority, design_records, work_records, history_records)
2bIf scan_error !== false, stop — not === true: a payload missing the field is a failure too. See the gate below
3Check for runbook-release.md specifically in feature directory (not any runbook-*.md)
4Determine mode: create (runbook-release.md absent) / update (runbook-release.md exists) / check (--check flag)

scan_error gate. Gate on scan_error !== false, not on scan_error === true. When it is not exactly false the four source sets are unknown, not empty — the corpus could not be enumerated (unreadable directory, broken taxonomy, no repository), or the resolver never ran and a shell fallback supplied a payload with no such field at all. {} is the shape that made the stricter test useless: it has no scan_error, so === true is false and the gate passes a payload that contains nothing. Do not proceed as though the feature has no authority documents — report and take the ⚠️ Need Human exit. A key may still be present, so a non-null key is not evidence the sets are complete.

Note: Mode dispatch keys off the specific file runbook-release.md, not any runbook-typed doc in doc_inventory. A feature may have runbook-deploy.md (a different topic) without triggering update mode for the release runbook.

Request Selection
ConditionBehavior
--request specifiedUse specified request
Single active requestAuto-select
Multiple active requestsAskUserQuestion: list requests, let user choose
No active requestsUse most recent request (warn)

Phase 1: Content Discovery (Create/Update modes)

Use scoped discovery cascade — narrow to wide, with confidence degradation:

PriorityScopeConfidence
1Request Related Files pathsHigh
2current_authority — code, rules/, and the docs that claim to be currentHigh
3design_records (tech spec, architecture)Medium — intent only, mark steps unverified
4Feature-local paths (docs/features/{feature}/)Medium
5Repo-wide grepLow (tag results)

A P1 path is classified before it is used. Related Files is High confidence because the request author named those paths deliberately — not because a path in that table is exempt from the role split. Resolve each one first: a path landing in design_records (a tech spec, an architecture doc) is treated as P3 — Medium, marked unverified — even though it arrived via P1. Otherwise the row the split removed comes straight back through the front door, since a request's Related Files table routinely names 2-tech-spec.md.

Priorities 2 and 3 used to be one row reading "canonical docs (tech-spec, architecture) — High", which is the confusion this feature exists to remove: a tech spec is a design record, and a runbook built from one describes a procedure that may never have been built.

See references/discovery-heuristics.md for per-section mapping.

Show full SKILL.md (421 more words)Show less
Security — Redaction Rules

When mining configs/workflows/logs into committed markdown:

ProhibitedReplacement
API keys, tokens, secrets${ENV_VAR_NAME} placeholder
Webhook URLs with credentials<webhook-url> symbolic reference
Internal-only endpoints<internal-endpoint> placeholder
Database connection strings${DATABASE_URL} placeholder

Phase 2: Generate / Update

Create Mode
  1. Read current_authority first — a runbook describes what operators will actually run, so the sources are code, rules/, and the docs that claim to be current. Fall back to design_records (tech spec, architecture) only for the intent behind a step, and mark any step sourced that way as unverified in the provenance manifest: a design record may describe a procedure that was never built
  2. Read active request(s) by enumerating docs/features/{feature}/requests/*.md — not by filtering work_records. That set answers "is this document a work record", and a ticket that resolves to some other role — authority Yes, or a Doc role naming one of the other three — leaves it while staying an open ticket; selecting from the set would drop exactly that ticket's AC, scope and related files
  3. Run scoped discovery for each template section
  4. Fill template from references/template.md
  5. Embed <!-- runbook-provenance --> manifest with source SHAs
  6. Write to docs/features/{feature}/runbook-release.md
Update Mode
  1. Read existing runbook-release.md and parse <!-- runbook-provenance --> block
  2. Compare each sources[].sha against git hash-object <file>
  3. Identify stale sections (any source SHA mismatch)
  4. Re-run discovery for stale sections only
  5. Edit stale sections via Edit tool (preserve fresh sections)
  6. Update provenance manifest with new SHAs

Phase 3: Check Mode (--check)

Read-only validation — does not modify the runbook file.

  1. Read existing runbook-release.md and parse provenance manifest
  2. For each section, compare sources[].sha against current git hash-object
  3. Classify: Fresh / Stale / Missing / Unknown (see references/check-output.md)
  4. Output report with per-section status and SHA diffs
  5. Emit verdict: Ready / Stale / Incomplete

Output

ModeOutputLocation
CreateNew runbookdocs/features/{feature}/runbook-release.md
UpdateUpdated sectionsSame file, incremental edit
CheckConsole reportstdout only (no file modification)

Verification

  • Feature resolved via node scripts/resolve-feature.js, and scan_error was exactly false
  • Runbook detected in doc_inventory (ancillary/runbook type)
  • Template has all 9 sections (see references/template.md)
  • Provenance manifest embedded with multi-source SHA tracking
  • Discovery uses scoped cascade (not repo-wide grep as first option)
  • Redaction rules applied (no secrets in committed markdown)
  • --check mode is read-only (no file writes)

Auto-Loop Integration

This skill produces .md output. Per @rules/auto-loop.md:

EventAction
Create/Update writes .md/codex-review-doc auto-triggered
Check mode (no writes)No review needed

References

FilePurpose
references/template.md9-section runbook template with provenance block
references/discovery-heuristics.mdScoped discovery cascade and per-section mapping
references/check-output.md--check mode output template and verdict logic

Examples

Input: /runbook
Action: Auto-detect feature → create runbook-release.md → /codex-review-doc

Input: /runbook auth --check
Action: Read auth/runbook-release.md → validate provenance SHAs → output report

Input: /runbook --update --request docs/features/auth/requests/2026-04-01-login-fix.md
Action: Read existing runbook → diff stale sections → update → /codex-review-doc

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/runbook of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/check-output.md
  • references/discovery-heuristics.md
  • references/template.md

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Runbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Runbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Runbook this skillsd0xdev/sd0x-harness192—~2.7kAutomated safety check: PassMIT
Trader Memory Coretradermonty/claude-trading-skills3k2 repos~4.3kAutomated safety check: PassMIT
Author Migrationnrwl/nx29k—~12kAutomated safety check: NotesMIT
Write Notes Like Deepseekczm15053/write-notes-like-deepseek477—~1.9kAutomated safety check: PassNone
OpenRig Upgrade Proceduremvschwarz/openrig5.5k—~2.9kAutomated safety check: PassApache-2.0
GreptimeDB Release RunbookGreptimeTeam/greptimedb6.7k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Trader Memory Core

    tradermonty/claude-trading-skills

    Track investment theses across their lifecycle — from screening idea to closed position with postmortem.

    3k GitHub starsUsed in 2 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Author or scope a first-party Nx migration. An agent skill from nrwl/nx.

    29k GitHub stars~12k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Write Notes Like Deepseek

    czm15053/write-notes-like-deepseek

    A skill your agent uses when a change is non-trivial by DSH standards (behavior, architecture, cross-file contracts, process/tooling, testing strategy, or on-disk/wire/config formats), when choosing…

    477 GitHub stars~1.9k tokensUpdated 15 days ago
    DevOps & CloudAuto-check passed
  • OpenRig Upgrade Procedure

    mvschwarz/openrig

    Walks an agent through upgrading the OpenRig CLI and daemon one observed step at a time, keeping live seats alive and reconciling managed plugin files.

    5.5k GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GreptimeDB Release Runbook

    GreptimeTeam/greptimedb

    Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.

    6.7k GitHub stars~1.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Statem

    henryqin1997/statem

    A skill your agent uses when a long coding or research task should be managed with statem state-machine runbooks, including creating specs, starting or resuming runs, checking current state…

    1.3k GitHub stars~1.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Runbook

What does Runbook do?

Generate and update feature release runbooks from existing docs and codebase. Runbook is an agent skill from sd0xdev/sd0x-harness. Generate and update feature release runbooks from existing docs and codebase.

When should I use Runbook?

Runbook fits situations like: : creating operational runbook; release handbook; deployment checklist; pre-release preparation.

How do I install Runbook in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill runbook -a claude-code`. Or copy the skill folder (skills/runbook in sd0xdev/sd0x-harness) into .claude/skills/runbook in your project. Claude Code loads it when a task matches its description.

How do I install Runbook in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill runbook -a codex`. Or copy the skill folder (skills/runbook in sd0xdev/sd0x-harness) into .agents/skills/runbook in your project. Codex loads it when a task matches its description.

Can I use Runbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill runbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runbook, .gemini/skills/runbook, .github/skills/runbook and .opencode/skills/runbook in your project.

What does Runbook need to run?

Going by SKILL.md and its folder, Runbook needs the command-line tools its instructions call (node and git). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(git:*), Bash(node:*), Write, Edit, Agent, AskUserQuestion.

Does Runbook access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Runbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Runbook use?

Runbook is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Runbook use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Runbook?

Skills that share tags, products or a category with Runbook: Trader Memory Core (tradermonty/claude-trading-skills, 3k stars), Author Migration (nrwl/nx, 29k stars), Write Notes Like Deepseek (czm15053/write-notes-like-deepseek, 477 stars) and OpenRig Upgrade Procedure (mvschwarz/openrig, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Runbook?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.