release-note-csoar

A command for creating Cloud SOAR release notes. Cloud SOAR is an automation service for security operations, including integrations and playbooks, which are repeatable response workflows.

In plain words
What is it for?
Use it to document integrations, playbooks, platform updates, API changes, and bug fixes.
Why use it?
It provides the right structure for separating content releases from application updates and for recording changes consistently.

Command for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/sumologic/sumologic-documentation/release-note-csoar
Clone the repo
git clone --depth 1 https://github.com/SumoLogic/sumologic-documentation

Made for: Claude Code.

Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 5,043 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.05043
Opus 5 $0.00000 $0.02521
Sonnet 5 $0.00000 $0.01009
Haiku 4.5 $0.00000 $0.00504

Measured 2d ago against content hash faf9d43ef0a0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

release-note-csoar scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/commands/release-note-csoar.md · 606 lines

How it starts

The opening of the file, as written. The whole thing — 606 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Create New Cloud SOAR Release Note

Automates the creation of Cloud SOAR (Automation Service) release notes for platform updates, integration changes, and bug fixes.

What this command does

When you invoke release-note-csoar, Claude will guide you through:

  1. Determine release type. Content Release or Application Update
  2. Gather release details. Date, changes, integrations, playbooks, or platform updates
  3. Create markdown file. Generate file with proper frontmatter and structure
  4. Format content. Apply correct formatting for the release type
  5. Validate and preview. Check structure and provide next steps

When to use this command

  • Publishing new integrations and playbooks (Content Release)
  • Publishing Cloud SOAR platform updates (Application Update)
  • Documenting integration updates or bug fixes
  • Announcing new API endpoints or features
  • Releasing playbook improvements

Release types

Content Release (-content-release.md)

For releases focused on new content (integrations and playbooks):

  • New integrations: Brand new integrations added to App Central
  • Updated integrations: Improvements to existing integrations
  • New playbooks: New playbooks with ID numbers and titles
  • Simple format: Just lists of what's new/updated, minimal descriptions

Typical cadence: Monthly or as content batches are released

Application Update (-application-update.md)

For platform features, enhancements, and bug fixes:

  • Platform features: New capabilities, UX improvements, APIs
  • Integration changes: With detailed descriptions of what changed
  • Bug fixes: Issues resolved in integrations, platform, or playbooks
  • Detailed format: Sections with descriptions and context

Typical cadence: Monthly, published early the following month

Release structure (varies by type)

Content Release Structure

Simple format with just lists:

  1. Intro paragraph - Brief description of release
  2. Integrations (H3) - Bulleted list of [New]/[Updated] integrations
  3. Playbooks (H3) - Bulleted list of [New] playbooks with IDs and titles

Read the full file on GitHub · 606 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 606 lines · 0 tokens per session scan A faf9d43ef0a0

Subscribe to this mod's changes

release-note-csoar is a command published in the GitHub repository SumoLogic/sumologic-documentation (42 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 5,043 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.