github-release-skill
Description
Claude Code skill plugin for safe, automated GitHub releases with supply chain security.
Installation
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open the source below and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
README
github-release-skill
Claude Code skill plugin for safe, automated GitHub releases with supply chain security.
Problem
AI coding agents (Claude Code, Copilot, etc.) naturally reach for `gh release create` when asked to "create a release". This:
- Creates lightweight unsigned tags instead of signed annotated tags
- Creates immutable releases that permanently burn tag names (no recovery)
- Bypasses CI pipelines that handle SBOMs, attestations, and signing
This skill prevents these mistakes structurally via hooks and provides the correct release orchestration.
Features
- Guard hooks: Block
gh release create/delete/editand lightweight tag creation at the tool level - Ecosystem detection: Auto-detect project type (TYPO3, PHP, Node.js, Go, Python, Rust, skill repos)
- Version management: Suggest next semver version from conventional commits, update all version files
- Release orchestration: Version bump PR → merge → signed tag → CI handles the rest
- Health checks: Validate release workflow, tag integrity, supply chain security
- CI templates: Release workflow templates with SBOM, cosign, attestation support
Commands
| Command | Description |
|---|---|
/release |
Full release: detect, bump, PR, tag, CI |
/release-prepare |
Version bump PR only (tag manually) |
/release-status |
Release health check |
Installation
Claude Code Marketplace (recommended)
Installed automatically via the Netresearch marketplace.
Composer
composer require --dev netresearch/github-release-skill
Manual
Download the latest release and extract to `~/.claude/plugins/`.
How It Works
- Hooks intercept dangerous commands before execution
- Ecosystem detection finds all version files in the project
- Version bump updates all files and promotes CHANGELOG
- PR workflow ensures changes go through review and CI
...
Related Skills
Fastapi Review
Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu
Security Defense in Depth
Implement multi-layered testing and security best practices.
Security SecLists Official Repository
[OWASP Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
Security Threat Hunting with Sigma Rules
Use Sigma detection rules to hunt for threats and analyze security events
Security Maintenance Walkthrough - 2026-03-29
- Re-triaged the full 2026-03-15 security finding set against current `main` and wrote a fresh current-head re
Security Google Workspace Model Armor
Filter user-generated content for safety
Security Related Agents
Django Reviewer
Expert Django code reviewer specializing in ORM correctness, DRF patterns, migration safety, security misconfi
Token Auditor
Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d
Gitnexus Security Boundary Reviewer
GitNexus security and trust-boundary reviewer. Use for auth, permissions, secrets, injection, unsafe parsing,