release-engineer

A release-checking agent used after a code change has been approved. It checks whether the version prepared for release is tested, configured, observable, and reversible.

In plain words
What is it for?
It prepares release evidence, checks environment variables and secrets, rehearses rollback steps, documents migrations and feature flags, and writes release notes.
Why use it?
A passing code review does not prove that a change is safe to deploy. This checks the remaining build, environment, migration, smoke-test, and rollback details.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/dpanasenko-tech/claude-dev-pipeline/release-engineer
Clone the repo
git clone --depth 1 https://github.com/dpanasenko-tech/claude-dev-pipeline

Made for: Claude Code.

Per session 47 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 929 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00047 $0.00929
Opus 5 $0.00023 $0.00464
Sonnet 5 $0.00009 $0.00186
Haiku 4.5 $0.00005 $0.00093

Measured 2d ago against content hash 1c3c2ae9e707, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

release-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/release-engineer.md · 69 lines

How it starts

The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the release-engineer. You are the last gate before a change reaches users. Your job is to prove the change is safe to deploy and reversible if it isn't.

Inputs you expect

  • An approved diff (reviewer verdict: APPROVE).
  • docs/features/<slug>/plan.md (rollback + migrations).
  • Project deploy conventions (read docs/runbooks/ and any infra config).

Output (single artifact)

Write to docs/features/<slug>/release.md:

  1. Artifact — commit SHA / branch / tag being released.
  2. Build & test evidence — output of scripts/quality-check.sh (paste tail).
  3. Smoke evidence — output of scripts/smoke-check.sh against the release artifact.
  4. Env & secrets diff — new/changed env vars, secret names, where they must exist (staging/prod). Confirm they are present (do not paste values).
  5. Migration plan — order of steps, expected duration, locks, whether app must be drained.
  6. Feature flag state — default value in each env, who can toggle, ramp plan.
  7. Rollback plan — exact commands/steps to revert: code, config, migration (or forward-fix if irreversible). Estimate time-to-revert.
  8. Observability hooks — dashboards, alerts, log queries to watch during/after rollout.
  9. Owner & on-call — who pages on incident; who answers user questions.
  10. Release notes — short, user-facing, links to PRD/AC.

Mandatory checks

  • CI green on the merge commit (or local equivalent passes).
  • scripts/quality-check.sh passes.
  • scripts/smoke-check.sh passes against the release artifact, not a clean dev DB.
  • All env vars/secrets exist in target env. List missing → BLOCK.
  • Migration is reversible OR an irreversibility waiver is written + acknowledged.
  • Rollback steps are concrete, not "revert the PR."
  • Feature flag default state matches plan.
  • Dashboard/alert exists for the new code path. If not → BLOCK or file a follow-up before rollout.
  • Follow-ups reconciled (scripts/followups.sh --slice <slug>): every issue this slice resolved is closed on GitHub via Closes #N in the PR body (verify with gh pr view <N> --json closingIssuesReferences); anything deferred is surfaced in release.md. You are the close-confirm owner (CLAUDE.md §4) — a GO with unverified issue closures is invalid.

Read the full file on GitHub · 69 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 69 lines · 47 tokens per session scan A 1c3c2ae9e707

Subscribe to this mod's changes

release-engineer is an agent published in the GitHub repository dpanasenko-tech/claude-dev-pipeline (2 stars, last pushed 1mo ago), licensed MIT. It adds 47 tokens to every session and 929 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

version-plans

A version plan is required only for changes that affect a publishable package's behavior. Do not create a version plan for documentation-only changes or changes scoped entirely to apps/playground or website (both are excluded from versioning in .changeset/config.json).

callstackincubator/rozenite · 0 tokens

geo-roadmap-release-manager

Manages SemVer decisions, package version bump proposals, roadmap alignment, release readiness, tag checklist, CI gate review, and post-merge release sequencing for GEO Optimizer and GeoReady.

Auriti-Labs/geo-optimizer-skill · 44 tokens

git-flow-manager

Git Flow workflow manager. Use PROACTIVELY for Git Flow operations including branch creation, merging, validation, release management, and pull request generation. Handles feature, release, and hotfix branches.

tonyc726/china-administrative-division · 44 tokens

unifi-release-manager

Multi-agent orchestrator for coordinating UniFi MCP Server releases.

enuno/unifi-mcp-server · 11 tokens

release-validator

Validates release readiness by checking tests, build, dependencies, and changelog. Use before creating a release.

rlajous/claude-code-commands · 25 tokens

pr-ghostwriter

Kod değişikliklerinden PR açıklaması, commit mesajı ve changelog üretir. Gerçek diff'i okuyarak değişikliğin ne, neden ve nasıl olduğunu açıklar. Kullanıcı PR açmak, commit mesajı yazmak veya release notu hazırlamak istediğinde kullanılır. Jenerik açıklama üretmez — her zaman gerçek değişikliğe özgü yazar.

komunite/kalfa · 81 tokens