leadup-release-manager — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited leadup-release-manager (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Take a finished work batch (commits, PRs, feature branch, sprint) and produce a release pack: summary, changed modules, env / migration changes, test status, risks, rollback plan, client communication, and a single go/no-go recommendation.
Use when the user is approaching a release / deploy. Do not trigger for ongoing project status updates (use leadup-status-updater), the yes-or-no deploy verdict only (use leadup-deploy-checker), or writing QA test cases (use leadup-qa-test-case-generator).
Trigger phrases: "release", "release notes", "deploy checklist", "version release", "go live", "production release", "ship it", "changelog for release".
main..release/v0.4.0 or last N commits).leadup-server / Vercel / other)./ all users).
Ask at most 2 clarifying questions if the branch or audience is unclear.
references/release-checklist.md — pre-release gate, rollback,comms.
assets/release-notes.template.md — output shape.leadup-deploy-checker — for the READY/NOT READY verdict.leadup-qa-test-case-generator — to confirm test coverage.leadup-security-review — for sensitive releases.leadup-pii-risk-reviewer — if PII surface changes.leadup-human-content-editor — to polish client-facing releasenotes.
leadup-status-updater — to reflect the release in STATUS.md.Internal.
long).
third-party key.
data rollback strategy.
public-changelog entry. Pass copy through leadup-human-content-editor before publishing.
One Markdown release pack with these sections, in this order:
isn't documented.
leadup-security-review if anything looks suspicious.
leadup-human-content-editor polish.
windows, and data migrations in plain language.
communication.
reviewed by leadup-pii-risk-reviewer.
test status unknown, sensitive PII / payment changes unreviewed, env vars missing in target.
STATUS.md after the release.→ soft → full; reuse leadup-ai-feature-planner rollout pattern.
alternative (additive then cleanup later).
leadup-qa-test-case-generator + run;block release until pass.
audience (India weekday 1–4am IST often safest).
env vars, health checks via leadup-deploy-checker.
the QA pass.
leadup-deploy-checker)leadup-qa-test-case-generator)leadup-status-updater)refund + 1 schema migration", return a release pack with grouped changes, migration forward + rollback notes, env-var diff, manual + automated test status, top 3 risks with mitigation, a rollback plan with exact commands, client-comms templates, and a Go/No-Go.
QA pass yet", return No-Go with the top reason, list what needs to change to flip to Go, and route the work to leadup-qa-test-case-generator and leadup-deploy-checker.
leadup-deploy-checker, leadup-human-content-editor,and leadup-status-updater explicit.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.