agr-release — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agr-release (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill walks through the full release process for the agr package. The release is tag-driven: pushing a vX.Y.Z tag triggers the GitHub Actions pipeline that runs quality checks, builds the package, publishes to PyPI, and creates a GitHub Release.
Your job is to prepare everything so that when the tag is pushed, the pipeline succeeds on the first try.
Verify the preconditions. If any fail, stop and tell the user.
git status should show no uncommitted changesgit pull to make sure you're not behindAsk the user what kind of release this is:
If the user already said what type they want, don't ask again.
Before touching any files, understand what's being released.
# See all commits since the last release tag
git log $(git describe --tags --abbrev=0)..HEAD --onelineAlso check the [Unreleased] section in CHANGELOG.md — it may already have entries. Cross-reference with the git log to make sure nothing is missing. If there are commits that aren't reflected in the changelog, add them.
Group changes into the standard Keep a Changelog categories:
Run all three locally before proceeding. These are the same checks the CI pipeline runs, so catching failures here saves a round-trip.
uv run ruff check .
uv run ruff format --check .
uv run pytest -m "not e2e and not network and not slow"
uv run ty checkIf anything fails, fix it before continuing. The release commit should pass CI cleanly.
Not every release needs doc changes — use judgement. Docs updates are warranted when:
The docs to consider:
README.md — the primary entry point, should reflect current capabilitiesdocs/docs/reference.md — CLI command referencedocs/docs/index.md — landing page / getting starteddocs/docs/ as relevant (sdk.md, configuration.md, etc.)skills/ — if any exist and are affected by the changesIf nothing user-facing changed (internal refactors, test improvements, dependency bumps), skip this step and move on.
The version lives in pyproject.toml (the single source of truth — importlib.metadata picks it up at runtime via agr/__init__.py):
pyproject.toml line 7: version = "X.Y.Z"Calculate the new version based on the current version and the release type the user chose.
For beta releases, append b1 (or increment the beta number if one already exists):
0.7.10 → 0.7.11b1 (first beta of next patch)0.7.11b1 → 0.7.11b2 (next beta)0.7.11b2 → 0.7.11 (promote beta to stable)In CHANGELOG.md:
## [Unreleased] with ## [X.Y.Z] - YYYY-MM-DD (today's date)## [Unreleased] section at the topscanning the changelog understands what changed without reading the code
The changelog format matters because the GitHub Actions pipeline extracts the version's section to use as release notes. Malformed entries = bad release notes.
# Stage the changed files
git add pyproject.toml agr/__init__.py CHANGELOG.md
# Plus any docs files you updated
# Commit
git commit -m "release: vX.Y.Z"
# Tag
git tag vX.Y.Z
# Push commit and tag
git push origin main
git push origin vX.Y.ZWait for the user to confirm before pushing. Show them a summary of what will be pushed:
After pushing the tag, monitor the GitHub Actions pipeline:
# Watch the workflow run
gh run list --workflow=publish.yml --limit=1
gh run watch $(gh run list --workflow=publish.yml --limit=1 --json databaseId -q '.[0].databaseId')The pipeline has four stages:
uv build + verifyIf any stage fails, read the logs and help the user fix it:
gh run view <run-id> --log-failedCommon failure modes:
Once the pipeline succeeds, confirm:
# Check PyPI (may take a minute to propagate)
pip index versions agr
# Check the GitHub release exists
gh release view vX.Y.ZTell the user the release is live and share the links:
gh release viewIf the pipeline fails and you need to retry:
git tag -d vX.Y.Z && git push origin :refs/tags/vX.Y.ZThis is destructive — confirm with the user before deleting tags.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.