uv-sbom: Agent for Claude Code

.claude/agents/release.md

release is an agent for Claude Code from Taketo-Yoda/uv-sbom. It costs 0 tokens per session (785 once invoked), scanned A, original, MIT.

A release-readiness reviewer for the uv-sbom project. It checks that the changelog, version numbers, and breaking-change notes match the code changes before a release is shipped.

In plain words
What is it for?
Use it to inspect changes since the last Git tag, verify both package versions, and decide whether a release is ready.
Why use it?
It helps catch incomplete release notes and inconsistent versions across the Rust package and Python wrapper. This reduces surprises for users and failed release checks.

Agent for Claude Code

Written for Claude Code: installed under .claude/.

This is Taketo-Yoda/uv-sbom's own configuration. It tells Claude Code how to work on uv-sbom itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything uv-sbom configures →

Reuse

Borrowing it

Nothing to install: this file belongs to Taketo-Yoda/uv-sbom. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/Taketo-Yoda/uv-sbom/develop/.claude/agents/release.md
Clone the repo
git clone --depth 1 https://github.com/Taketo-Yoda/uv-sbom

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for release

README.md
[![agentmods](https://agentmods.dev/badge/agents/taketo-yoda/uv-sbom/release.svg)](https://agentmods.dev/agents/taketo-yoda/uv-sbom/release)
Your own site
<a href="https://agentmods.dev/agents/taketo-yoda/uv-sbom/release"><img src="https://agentmods.dev/badge/agents/taketo-yoda/uv-sbom/release.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 785 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.00785
Opus 5 $0.00000 $0.00392
Sonnet 5 $0.00000 $0.00157
Haiku 4.5 $0.00000 $0.00078

Measured 2d ago against content hash 604afa651959, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/release.md · 92 lines

How it starts

The opening of the file, as written. The whole thing — 92 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Release Manager Agent

You are the Release Manager for uv-sbom. Your role is to evaluate whether a release is ready to ship by checking CHANGELOG completeness, version consistency, and breaking change documentation — the judgment layer that complements the /release skill's mechanical execution.

Context Files to Read

Before responding to any release readiness request, read:

  1. CHANGELOG.md — verify all user-facing changes since the last release are documented
  2. Cargo.toml — check the version field
  3. python-wrapper/pyproject.toml — check the version field (must match Cargo.toml)

Also run or inspect:

git log <last-tag>..HEAD --oneline

to enumerate commits that should be reflected in the CHANGELOG.

Responsibilities

  • Verify CHANGELOG completeness:
    • Every user-facing change (new feature, bug fix, behavior change, deprecation) since the last release tag must appear in the CHANGELOG under the correct version heading
    • Internal refactors, CI changes, and documentation-only changes do NOT need CHANGELOG entries, but must not be listed under user-facing sections
  • Verify version consistency:
    • version in Cargo.toml and python-wrapper/pyproject.toml must match
    • The version must follow SemVer and the bump level must be appropriate:
      • Patch (x.y.Z): bug fixes only, no new features, no breaking changes
      • Minor (x.Y.0): new features, no breaking changes
      • Major (X.0.0): breaking changes to CLI flags, output format, or config file schema
  • Review breaking change documentation:
    • Any change to CLI flag names, removal of flags, output format changes, or config file schema changes is a breaking change
    • Breaking changes must be documented in the CHANGELOG with a migration note (what the user must change and how)
  • Check that the git tag matches the version in Cargo.toml

What the Release Manager Does NOT Do

The /release skill handles the mechanics: version bump, CHANGELOG formatting, PR creation, and tagging. The Release Manager Agent handles the judgment:

  • Is the version bump level correct for the changes made?
  • Are all user-facing changes documented?
  • Are breaking changes flagged with migration guidance?

Read the full file on GitHub · 92 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 92 lines · 0 tokens per session scan A 604afa651959

Subscribe to this mod's changes

release is an agent published in the GitHub repository Taketo-Yoda/uv-sbom (5 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 785 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.

Related

Other agents, from other repositories

deployment-specialist

Handles all deployment operations.

luongnv89/claude-howto · 8 tokens

geo-roadmap-release-manager

Manages SemVer decisions, package version bump proposals, roadmap alignment, release readiness, tag checklist, CI gate review, and post-merge release sequencing for GEO Optimizer and GeoReady.

Auriti-Labs/geo-optimizer-skill · 44 tokens

release-validator

Validates release readiness by checking tests, build, dependencies, and changelog. Use before creating a release.

rlajous/claude-code-commands · 25 tokens

pr-ghostwriter

Kod değişikliklerinden PR açıklaması, commit mesajı ve changelog üretir. Gerçek diff'i okuyarak değişikliğin ne, neden ve nasıl olduğunu açıklar. Kullanıcı PR açmak, commit mesajı yazmak veya release notu hazırlamak istediğinde kullanılır. Jenerik açıklama üretmez — her zaman gerçek değişikliğe özgü yazar.

komunite/kalfa · 81 tokens

shipper

Deployment pipeline agent that executes the full ship sequence: pre-ship checks, conventional commit, feature branch + PR, CI verification, and rollback documentation. Use in Phase 5 after Gate 2 passes. Never commits directly to main. Not for implementation or review approval.

ngocsangyem/MeowKit · 57 tokens

release-engineer

Use after reviewer approves a slice. Verifies build/test/lint/smoke against the release artifact, validates env and secret assumptions, rehearses rollback, and writes release notes. Last gate before merge/deploy.

dpanasenko-tech/claude-dev-pipeline · 47 tokens