Repository navigation
Optimize the release-management skill family #1345
Copy link
Copy link
Closed
Labels
capability:resolveClose-out: invalidate, dedupe, CVE allocate, announcementClose-out: invalidate, dedupe, CVE allocate, announcementcapability:statsRead-only dashboards, metrics, governance evidenceRead-only dashboards, metrics, governance evidencecapability:triageSweep + classify + propose dispositionSweep + classify + propose dispositionenhancementNew feature or requestNew feature or requestfamily:ci.github workflows, prek, validators.github workflows, prek, validatorsfamily:docsDocs, MISSION.md, READMEsDocs, MISSION.md, READMEsfamily:release-managementrelease-* skillsrelease-* skillsfamily:setupsetup-* skillssetup-* skillsfamily:toolstools/*tools/*kind:perfToken / latency / API-call budgetToken / latency / API-call budgetsubstrate:framework-devTool substrate: build / validate / eval the framework itselfTool substrate: build / validate / eval the framework itselfsubstrate:releaseTool substrate: release-artefact helpers (reproducible archive build, lint, comparison)Tool substrate: release-artefact helpers (reproducible archive build, lint, comparison)substrate:sandboxTool substrate: agent isolation, egress control, settings auditTool substrate: agent isolation, egress control, settings audit
Description
Activity
- addedenhancementNew feature or requestNew feature or requestkind:perfToken / latency / API-call budgetToken / latency / API-call budgetfamily:release-managementrelease-* skillsrelease-* skills
on Sep 22, 2026 The release-management optimisation is complete.
Savings
Measured across all 10 release skills, from before the first PR to
mainwith every pass merged:Before Now Change SKILL.mdbodies, read on every run (measured_tokens)78,241 65,114 −17% A release-preparerun (SKILL.md+ the sub-command it executes)14,285 6,600–9,300 −35–55% Advertised descriptions, loaded in every session ( docs/setup/marketplace.md)~1.4k ~0.8k −43% The split and the description pass cut most of the cost. The wording pass saved little, because the extraction and the split had already made the skills lean.
What was done
- Deterministic steps moved into code. The steps the model used to perform by hand now run in code:
tools/release-confighandles config loading and every skill's Step 0 checks (perf(release-management): one tool for config loading and pre-flight checks #1510);tools/release-verifyhandles verify-rc's signature, checksum, binary, symlink and version checks and the verdict (perf(release-verify-rc): move the deterministic checks into tools/release-verify #1511);- sibling scripts handle vote counting, the audit record, retention, the key check and prepare's version helpers (perf(release-management): sibling scripts for the deterministic steps #1512).
These save few tokens; their value is that the checks are deterministic and tested. The skills had disagreed on several rules, and each is now settled to one rule, as the maintainer decided: - RC numbering starts at
rc1; - convenience artefacts have their own version scheme;
- there is one approver-roster key;
non_asfis derived fromorganization:;- the automated-signing gate is the organisation manifest's;
- an expired key blocks;
- only a voter's latest vote counts, by thread order.
- Security review findings fixed:
- quoted paste recipes;
- stale signatures fail;
- local paths stay out of reports;
- revoked keys are refused;
- vote identities can't collide;
- pre-releases never decide retention;
- the audit record is escaped (perf(release-verify-rc): move the deterministic checks into tools/release-verify #1511, perf(release-management): sibling scripts for the deterministic steps #1512, fix(release-config): initialise skill before parsing it #1514).
- Split. Steps a run uses only conditionally load on demand (perf(release-management): load conditional steps only when they run #1515).
- Wording pass on all ten skills (perf(release-management): wording pass on the release skills #1517), with a check that no condition or prohibition was lost.
- Descriptions for the five skills over budget (perf(release-management): shorter descriptions for five release skills #1519).
- Behaviour fixes:
- PR and comment bodies go through a file (fix(release-management): pass PR and comment bodies through a file #1502);
- the
[VOTE]expedited reason keeps CVE IDs out until the advisory ships (fix(release-vote-draft): keep CVE IDs and security framing out of the expedited reason #1509); release-rc-cutmakes its two GitHub calls through vetted operations (fix(release-rc-cut): route its two GitHub calls through vetted operations #1518).
- Tests. The new tools carry unit tests, and a new pre-commit hook runs the skills' sibling-script tests. Eval cases were added for each settled rule.
Still over the 500-line cap:
release-rc-cut,-verify-rc,-announce-draft,-vote-draftand-audit-report. What remains in them is used on every run, so splitting further would save no tokens.- Deterministic steps moved into code. The steps the model used to perform by hand now run in code:
- addedcapability:resolveClose-out: invalidate, dedupe, CVE allocate, announcementClose-out: invalidate, dedupe, CVE allocate, announcementcapability:statsRead-only dashboards, metrics, governance evidenceRead-only dashboards, metrics, governance evidencefamily:setupsetup-* skillssetup-* skillsfamily:toolstools/*tools/*family:docsDocs, MISSION.md, READMEsDocs, MISSION.md, READMEsfamily:ci.github workflows, prek, validators.github workflows, prek, validatorscapability:triageSweep + classify + propose dispositionSweep + classify + propose dispositionsubstrate:framework-devTool substrate: build / validate / eval the framework itselfTool substrate: build / validate / eval the framework itselfsubstrate:releaseTool substrate: release-artefact helpers (reproducible archive build, lint, comparison)Tool substrate: release-artefact helpers (reproducible archive build, lint, comparison)substrate:sandboxTool substrate: agent isolation, egress control, settings auditTool substrate: agent isolation, egress control, settings audit
on Oct 5, 2026
Metadata
Metadata
Assignees
Labels
capability:resolveClose-out: invalidate, dedupe, CVE allocate, announcementClose-out: invalidate, dedupe, CVE allocate, announcementcapability:statsRead-only dashboards, metrics, governance evidenceRead-only dashboards, metrics, governance evidencecapability:triageSweep + classify + propose dispositionSweep + classify + propose dispositionenhancementNew feature or requestNew feature or requestfamily:ci.github workflows, prek, validators.github workflows, prek, validatorsfamily:docsDocs, MISSION.md, READMEsDocs, MISSION.md, READMEsfamily:release-managementrelease-* skillsrelease-* skillsfamily:setupsetup-* skillssetup-* skillsfamily:toolstools/*tools/*kind:perfToken / latency / API-call budgetToken / latency / API-call budgetsubstrate:framework-devTool substrate: build / validate / eval the framework itselfTool substrate: build / validate / eval the framework itselfsubstrate:releaseTool substrate: release-artefact helpers (reproducible archive build, lint, comparison)Tool substrate: release-artefact helpers (reproducible archive build, lint, comparison)substrate:sandboxTool substrate: agent isolation, egress control, settings auditTool substrate: agent isolation, egress control, settings audit
Part of #1342 — apply the setup-family optimization recipe to the
release-managementfamily.10 skills, 73,971 body tokens in total; 4 over the 200-token always-on budget, 8 over the 5,000-token body budget.
release-rc-cutrelease-preparerelease-verify-rcrelease-keys-syncrelease-promoterelease-vote-draftrelease-announce-draftrelease-audit-reportrelease-vote-tallyrelease-archive-sweepBody tokens are from
docs/mode-economics.md; always-on figures are a chars ÷ 4 estimate ofdescription+when_to_use. ⚠ marks a budget exceeded. Line counts include the generated pre-flight block.Order of work (per the umbrella):
Record any inconsistencies found but not fixed (eval-coupled wording, stale headings) in the PR description.