Borrowing it
Nothing to install: this file belongs to airtaxi/LidGuard. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/airtaxi/LidGuard/master/.codex/skills/lidguard-release-validation/SKILL.mdgit clone --depth 1 https://github.com/airtaxi/LidGuardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/airtaxi/lidguard/lidguard-release-validation)<a href="https://agentmods.dev/skills/airtaxi/lidguard/lidguard-release-validation"><img src="https://agentmods.dev/badge/skills/airtaxi/lidguard/lidguard-release-validation/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/airtaxi/lidguard/lidguard-release-validation"><img src="https://agentmods.dev/badge/skills/airtaxi/lidguard/lidguard-release-validation.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00050 | $0.01884 |
| Opus 5 | $0.00025 | $0.00942 |
| Sonnet 5 | $0.00010 | $0.00377 |
| Haiku 4.5 | $0.00005 | $0.00188 |
Grade B, and why
lidguard-release-validation scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
- Validate `linux-permission status|check|install|remove` on non-root and root paths, including busctl `CanSuspend` / `CanHibernate`, managed marker refusal for unmanaged polkit files, sudo failure paths, and removal saf How it starts
The opening of the file, as written. The whole thing — 88 lines — stays where its author put it; the contents beside it link to each section on GitHub.
LidGuard Release Validation
Build Validation Note
- Local build, test, publish, pack, and reinstall validation commands can fail once because of transient Windows Defender file-lock interference.
- Retry the same validation command before taking any broader recovery action; when this specific issue is the cause, a retry is typically enough.
- Do not bring down any build server just because the first validation attempt failed with this known Defender issue.
- When validating multiple Runtime Identifiers locally from the same worktree, run the commands sequentially rather than in parallel. Concurrent
dotnet buildor restore activity against the same project can race on sharedobjartifacts and produce false-negative reference or restore failures that disappear on a clean sequential rerun.
Current Validation Scope
- Current manual runtime validation has only covered Windows with Codex.
- Windows, Linux, and macOS RID compile validation can catch platform compilation regressions, but it is not a substitute for runtime behavior validation on each target OS.
- Linux systemd/logind runtime behavior, macOS runtime behavior, Claude Code hooks, GitHub Copilot CLI hooks, OpenCode hooks, Provider MCP flows, and cross-provider concurrent-session behavior still need real environment validation before being treated as verified.
Missing Work
The Windows, Linux, and macOS CLI hook receiving path is implemented for Codex, Claude Code, GitHub Copilot CLI, and OpenCode. Remaining work is now focused on lifecycle polish and automated regression coverage.
- Implement immediate runtime shutdown after the last session stops once the remaining post-stop cleanup work is complete.
- Validate Linux behavior on a real systemd/logind laptop:
systemd-inhibitlifecycle,handle-lid-switchinhibition,systemctl suspend/systemctl hibernate, closed-lid plus monitor-count suspend eligibility,/proc/acpi/button/lidlid-state reads,/sys/class/drmmonitor detection,/sys/class/thermaltemperature aggregation, Emergency Hibernation, and suspend history logging. - Validate
linux-permission status|check|install|removeon non-root and root paths, including busctlCanSuspend/CanHibernate, managed marker refusal for unmanaged polkit files, sudo failure paths, and removal safety. - Validate Linux post-stop sound behavior with no player installed,
pw-play,paplay,aplay, missing desktop sound-theme assets,.wavpaths, andpactlvolume override capture/apply/restore failure paths. - Validate macOS behavior on a real MacBook:
caffeinatelifecycle,pmset disablesleepbackup/restore,pmset sleepnow, temporaryhibernatemode 25hibernate with deferred recovery restore, closed-lid plus monitor-count suspend eligibility,ioreglid-state reads,system_profilermonitor detection, best-effort Apple SiliconIOHIDEventSystemClientandpowermetricstemperature aggregation, Emergency Hibernation, and suspend history logging. - Validate
macos-permission status|check|install|removeon non-root and root paths, including managed marker refusal for unmanaged sudoers files,visudovalidation, non-interactive sudo failure paths, and removal safety. - Validate macOS post-stop sound behavior with missing
afplay, SystemSounds mapping,.wavpaths, andosascriptvolume override capture/apply/restore failure paths. - Add automated regression tests or verification scripts for the already manually verified provider behavior, Windows behavior, Linux systemd/logind behavior, and macOS behavior: latest Codex hook behavior, Claude Code hook stdout behavior, GitHub Copilot CLI hook output behavior, OpenCode plugin and MCP config behavior, GitHub Copilot CLI user-level
~/.copilot/hooks/loading and inline~/.copilot/settings.jsonhook composition, GitHub Copilot CLI session id stability,PowerReadACValueIndex/PowerReadDCValueIndexread/write behavior under normal user permissions, Linux inhibitor lifecycle, Linux polkit rule management, macOS parser/permission management, and Group Policy or MDM blocked power setting fallback messages. - Add direct Codex soft-lock support only if Codex later exposes a notification or machine-readable pending-state hook surface.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 88 lines · 50 tokens per session scan B 731327b954f7
lidguard-release-validation is a skill published in the GitHub repository airtaxi/LidGuard (11 stars, last pushed 3d ago), licensed MIT. It adds 50 tokens to every session and 1,884 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it B with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
codew-release-qa-sweep
Use before claiming Codewhale release work is done: run the full gate sweep and list the manual QA targets.
verify-and-ship
Run all quality checks (tests, lint, typecheck), fix failures, update the changelog, commit, push, and create/update the pull request or merge request.
ship-workflow
Automated release pipeline: merges main, runs tests, pre-landing review, version bump, changelog, bisectable commits, and PR creation. Triggers on: "ship it", "release this", "prepare for release", "open a PR", "push and PR", "land this", "/ship-workflow".
AI Release Guardian
Analyze a git diff, map affected risks, select the tests that matter, detect coverage gaps on changed lines, run configurable quality gates, and produce a go/no-go release report with cited evidence. Recommends only; never merges or deploys.
mathodology-dev-test-release
Use when checking skill metadata, references or repository boundaries, or preparing an explicitly requested skills release.
repo-harness-check
Verification entrypoint for repo-harness workflow readiness. Runs workflow gates, task sync, contract checks, inspector, and migration dry-run before merge or release.