# Release Audit

> >

- **Type:** Skill
- **Install:** `agentstack add skill-urmzd-dotfiles-release-audit`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [urmzd](https://agentstack.voostack.com/s/urmzd)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [urmzd](https://github.com/urmzd)
- **Source:** https://github.com/urmzd/dotfiles/tree/main/dot_agents/skills/release-audit

## Install

```sh
agentstack add skill-urmzd-dotfiles-release-audit
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Release Audit

Audit releases, tags, and assets for consistency.

## Steps

1. **Determine scope**: If a directory of repos is given, discover all git repos one level deep. Otherwise use the current repo.

2. **For each repo**, gather:
   - All tags: `git tag -l`
   - All releases: `gh release list --limit 50 --json tagName,name,isDraft,isPrerelease,assets`
   - **Detect sr.yaml**: check whether `sr.yaml` exists at the repo root. Only if present, read it to understand expected release behavior. If absent, skip all sr-specific checks for this repo (do not report a "missing sr.yaml" issue -- not every repo uses sr).
   - Floating tags: tags like `v1`, `v2` that point to the same commit as a full semver tag

3. **Check for issues**:
   - **Orphaned tags**: tags with no corresponding GitHub release
   - **Releases without assets**: releases that should have binaries/checksums but don't
   - **Draft releases**: releases stuck in draft state
   - **Floating tag drift**: major version tags (e.g., `v1`) not pointing to the latest patch
   - **sr.yaml issues** (only when sr.yaml was detected in step 2): misconfigured plugins, version file mismatches between sr.yaml and the actual version files
   - **Pre-release remnants**: old pre-release versions that were never promoted

4. **Report**: For each repo, show:
   ```text
   ## repo-name
   - Latest release: v1.2.3 (2024-01-15)
   - Total releases: 12 | Tags: 15
   - Issues:
     - ⚠ 3 orphaned tags: v0.1.0, v0.2.0, v0.3.0
     - ⚠ Floating tag v1 behind latest (points to v1.1.0, latest is v1.2.3)
     - ✓ All releases have assets
   ```

5. **Summary**: One-line-per-repo table at the end with issue counts.

## Rules

- Don't delete or modify tags/releases. This is read-only audit.
- If `gh` isn't authenticated, fall back to git-only checks (tags, sr.yaml).
- For multi-repo scans, run checks in parallel where possible.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [urmzd](https://github.com/urmzd)
- **Source:** [urmzd/dotfiles](https://github.com/urmzd/dotfiles)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-urmzd-dotfiles-release-audit
- Seller: https://agentstack.voostack.com/s/urmzd
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
