release-notes — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited release-notes (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
What user-facing release-note text is supported by the available evidence, and what limitations must be disclosed?
Use this skill when the user asks to:
Do not use this skill to create Git tags, publish hosted releases, call release APIs, push files, change versions, or edit changelog structure.
Route to:
tag-release for Git tag creation.publish-release skill or manual workflow for hosted release publication.version-bump for version changes.changelog-maintenance for changelog file maintenance.conventional-commits for commit message work.Inspect or establish:
This skill drafts or locally updates release-note text only. It does not create Git tags, publish hosted releases, call GitHub Releases APIs, push files, or change version files.
You MAY:
You MUST:
You MUST NOT:
| State | Evidence | Risk | Default Action | Confirmation | Verification |
|---|---|---|---|---|---|
| Clear range and changelog | range and changelog | R1 | Draft release notes | no | self-check against evidence |
| Missing range | user context only | R1 | Draft limited notes or ask if blocking | no | limitation note |
| Commit log only | commit range | R1 | Summarize with caveats | no | unsupported claims removed |
| Internal-only changes | commits/changelog | R1 | Exclude or group separately | no | audience check |
| Breaking change evidenced | commits/API/migration | R1 | Include prominent section | no | evidence trace |
| Security/performance claim without evidence | requested text | R1 | Omit or qualify claim | no | evidence check |
| User asks to write local release-note file | target file and explicit request | R2 | Edit only requested file after evidence review | no if explicit | diff inspection |
| User asks Git tag creation | out of scope | Out of scope | Route to tag-release | yes for routed action | not applicable |
| User asks hosted release publication | out of scope | Out of scope | Route to future publish workflow or stop | yes for routed action | not applicable |
Allowed:
Forbidden:
Minimum verification:
Verify:
Final response should include:
## Result
- Release-note text or file update summary.
## Evidence
- Range, changelog, commits, PRs/issues, version used.
## Verification
- Claim self-check and diff check if mutated.
## Limitations
- Missing evidence, unverified claims, or publication out of scope.Stop when release range, audience, or evidence is missing in a way that would make notes misleading.
Requires explicit user intent for local file mutation. Route Git tags, hosted release publication, package publication, version changes, and remote/shared mutation out of this skill.
Load:
references/audience-rules.md when tone or audience is unclear.references/templates.md when output format is requested.references/evidence-sources.md when range/source choice is unclear.references/examples.md when the user asks for examples.references/failure-modes.md for unsupported claim risks.references/verification.md for evidence checks.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.