CtrlK
BlogDocsLog inGet started
Tessl Logo

github-release

Prepare and publish GitHub releases. Sanitizes code for public release (secrets scan, personal artifacts, LICENSE/README validation), creates version tags, and publishes via gh CLI. Trigger with 'release', 'publish', 'open source', 'prepare for release', 'create release', or 'github release'.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, token-efficient workflow with strong sequencing, explicit blockers/validation, and clearly signaled one-level-deep references. The main improvable points are parameter placeholders in the publish commands and redundancy between the inline Phase 1 checks and safety-checklist.md.

Suggestions

Replace '--notes "[auto-generated from commits]"' with the actual commit-derived notes command (or inline the LAST_TAG/git log snippet) so step 5 is copy-paste executable.

Trim the duplicated checks between Phase 1 and references/safety-checklist.md — keep only the blocker-critical commands inline and point to the reference for warnings and patterns.

Note that build/audit steps are Node-specific or provide a conditional for non-JS projects (e.g., 'if package.json exists'), since the skill otherwise claims general repo applicability.

DimensionReasoningScore

Conciseness

The body is lean: every step is a command plus a one-line conditional ('If secrets found: **STOP**. Remove secrets, move to environment variables.'), with zero padding and no explanation of concepts Claude already knows. Not 4 because there is no over-explanation to trim — fallbacks and error paths are stated as tersely as possible.

5 / 5

Actionability

Nearly all steps give copy-paste-ready commands (gitleaks detect, git tag -a, gh release create) with fallbacks when tools are missing. Not 5 because placeholders like 'v[version]' and '--notes "[auto-generated from commits]"' are not literally executable — the notes-generation command lives only in the reference file — and `npm run build`/`npm audit` silently assume a Node project.

4 / 5

Workflow Clarity

Two clearly sequenced phases with explicit validation checkpoints: a BLOCKER-labeled secrets scan with '**STOP**', non-blocking checks labeled as such, tag-existence verification with a user-decision path, and error-recovery loops (gitleaks missing → manual checks; secrets in history → BFG; push/release mechanics in the reference). Not 4 because recovery paths for the risky operations are explicit rather than implied.

5 / 5

Progressive Disclosure

A clean 'When | Read' table at the end points to two real, one-level-deep reference files (references/safety-checklist.md, references/release-workflow.md — both exist and hold genuinely deeper detail like secret patterns and monorepo tagging). Not 5 because Phase 1 of the body duplicates much of safety-checklist.md (gitleaks, README, .gitignore, audit checks appear in both), so content placement has minor redundancy; not 3 because navigation is clear and the split is otherwise appropriate.

4 / 5

Total

18

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that concretely states what the skill does (sanitize, tag, publish via gh CLI) and gives an explicit trigger clause with natural phrases. The only weaknesses are a couple of missing trigger synonyms and the slight overlap risk from the broad terms 'publish' and 'open source'.

Suggestions

Add a few more natural trigger synonyms such as 'new version', 'tag a release', or 'cut a release' to broaden trigger coverage.

Qualify 'publish' with the GitHub context (e.g., 'publish a GitHub release') to reduce conflict risk with npm-publish or blog-publishing skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'Sanitizes code for public release (secrets scan, personal artifacts, LICENSE/README validation), creates version tags, and publishes via gh CLI' — covering the full pipeline comprehensively with sub-details. Not 4 because coverage of the what is complete rather than having minor gaps; not below since every action named is concrete, not generic.

5 / 5

Completeness

Both what ('Sanitizes code... creates version tags, and publishes via gh CLI') and when ('Trigger with...') are explicitly and concretely stated, matching the anchor-5 example structure exactly. Neither the what nor the when is vague or implied.

5 / 5

Trigger Term Quality

Trigger phrases 'release', 'publish', 'open source', 'prepare for release', 'create release', 'github release' are natural and varied. Not 5 because a few common synonyms users would say are missing (e.g., 'new version', 'tag a release', 'cut a release', 'version tag'); not 3 because coverage is well beyond 'some relevant keywords'.

4 / 5

Distinctiveness Conflict Risk

The GitHub-release niche is clear and mostly distinct, but the generic trigger 'publish' (and to a lesser extent 'open source') could overlap with related skills like npm-publish or documentation/blog publishing. Not 5 due to that minor overlap risk with closely related skills; not 3 because the domain and distinct triggers ('github release', 'create release') are unmistakable.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
jezweb/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.