Borrowing it
Nothing to install: this file belongs to burin-labs/harn. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/burin-labs/harn/main/.claude/commands/release-harn.mdgit clone --depth 1 https://github.com/burin-labs/harnWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/burin-labs/harn/release-harn)<a href="https://agentmods.dev/commands/burin-labs/harn/release-harn"><img src="https://agentmods.dev/badge/commands/burin-labs/harn/release-harn.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00342 |
| Opus 5 | $0.00000 | $0.00171 |
| Sonnet 5 | $0.00000 | $0.00068 |
| Haiku 4.5 | $0.00000 | $0.00034 |
Grade A, and why
release-harn scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Run the tag-first Harn release workflow.
The canonical playbook is
.codex/skills/harn-release/SKILL.md; use it with the repo scripts as the
source of truth.
Default live command:
cd ~/projects/harn-bump-fleet
scripts/run_harn_release.sh \
--repo ~/projects/harn --mode ship-pr --agent --yes-live-release
scripts/run_harn_release.sh is the canonical release boundary. Call it rather
than invoking release_harn.harn through harn run directly: on macOS it
intercepts a live prepare or ship-pr and dispatches the canonical hosted
Linux workflow, because the release audit exercises nested OS sandboxes that
Seatbelt refuses to apply under Harn's default-deny outer profile. The harness
does not perform that handoff itself, so calling it directly on macOS starts a
local release the gate cannot certify.
ship-pr prepares the release content, commits it, pushes the branch, pushes
the signed vX.Y.Z tag at the pinned release commit, opens the Release vX.Y.Z PR, and enables auto-merge. The tag is pushed before the PR merges so
publishing is tied to the pinned tag commit.
Do not run scripts/release_ship.sh --prepare directly for normal releases.
It is an implementation detail of release_harn.harn and refuses standalone
use. Use scripts/release_ship.sh --finalize, scripts/release_ship.sh --bump,
and the release workflows only for recovery after reading their help text.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 32 lines · 0 tokens per session scan A e669473cc4fa
release-harn is a command published in the GitHub repository burin-labs/harn (20 stars, last pushed today), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 342 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
release-checklist
Tu es un Release Manager expert. Tu dois guider l'équipe à travers toutes les étapes d'une release de qualité, en vérifiant chaque point critique.
changelog
Generate a changelog entry from git commits since the last tag using conventional commit format.
land-and-deploy
Merge PR, wait for CI, verify deploy, run canary — the complete landing pipeline.
hatch3r-release
Release-workflow orchestrator — preflight, SemVer bump, changelog sync, build + CycloneDX SBOM, adapter-output verification, quality gates, release-notes reconciliation, then stop before publish/merge for human approval.
release-notes
Generate release notes in multiple formats from git commits.
ship
Comprehensive pre-deployment verification to ensure release readiness.