verify-release
moltbot/clawdbot/.agents/skills/verify-release/SKILL.md
Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release track.
Skill391k starsChanged yesterday
- Reads credentials
What's in it
- Verify Release
- Rules
- Regular beta/stable checks
- Extended-stable checks
- Shared live smoke
- Caveats To Report
---
name: verify-release
description: "Verify regular or extended-stable OpenClaw releases against the exact publication surfaces, workflow identities, package provenance, smoke tests, and live Gateway behavior expected for that release track."
---
# Verify Release
Use this when asked whether an OpenClaw release is fully released, published,
promoted, smoke-tested, or live-verified. This is a verification skill, not a
publish skill; use `$release-openclaw-maintainer` before changing release state.
## Rules
- Resolve short suffixes like `.27` to the concrete CalVer version from the
current date/context, then say the resolved version.
- Resolve the track first. Both tracks use the shared GitHub Release evidence
ledger. Regular beta/stable also uses the platform graph; extended-stable
uses its canonical branch, npm selector, and Gateway surfaces. Do not require
one track's native or ClawHub artifacts from the other.
- Verify live state. Do not trust local checkout state, release notes, or old
memory as current truth.
- If the checkout is dirty or divergent, use it only for scripts/reference.
For version metadata, fetch from GitHub release/tag or unpack the tag tarball
under `/tmp`.
- Never print secrets. Use inherited live keys only for scoped smoke commands.
- Keep the final terse: `yes/no`, evidence bullets, caveats, cleanup.
## Regular beta/stable checks
Use these checks only for the regular orchestrated release track.
1. GitHub release:
- `gh release view v<VERSION> --repo openclaw/openclaw --json tagName,name,publishedAt,isDraft,isPrerelease,targetCommitish,url,body,assets`
- Confirm stable releases are not draft/prerelease.
- Confirm release body has npm, CI, plugin npm, ClawHub, mac/appcast evidence
links when expected.
- Confirm assets expected for stable mac releases are uploaded: zip, dmg,
dSYM, dependency evidence, immutable full-validation manifest,
postpublish evidence, and stable-main closeout manifest.
- Download each immutable evidence asset and its `.sha256` companion, then
verify the checksum before trusting the release record.
2. Root npm:
- `npm view openclaw@<VERSION> version dist-tags.latest dist.tarball dist.integrity time.<VERSION> --json`
- `latest` must equal `<VERSION>` for stable.
- Record tarball, integrity, publish time.
- Confirm the release postpublish evidence records
`npmRegistrySignaturesVerified: true` and
`npmProvenanceAttestationMatched: true`.
3. Plugin publish set:
- Get exact tag metadata from GitHub, not the local checkout when dirty:
download `https://api.github.com/repos/openclaw/openclaw/tarball/v<VERSION>`
into `/tmp/openclaw-v<VERSION>-src`.
- Derive the full expected npm and ClawHub package sets for the release track
with the canonical publication planners/collector from the recorded release
Tooling SHA, using the exact tag's package metadata.
Do not count raw publish flags: `openclaw.build.bundledDist === true`
explicitly defers external publication even when publish flags are set.
Record deferred package names and reasons separately.
- Reconcile expected package identities, versions, and counts across original
publication, previously published versions, and selected recovery runs using
immutable publication plans, registry readback, and workflow jobs. A selected
recovery subset must not narrow the full expected release set:
`gh api repos/openclaw/openclaw/actions/runs/<RUN>/jobs --paginate`.
- Each expected npm plugin must have version `<VERSION>` and
`dist-tags.latest === <VERSION>`.
4. ClawHub:
- Check the Plugin ClawHub Release workflow conclusion and publish job count.
- Use OpenClaw itself for live registry proof:
`openclaw plugins search <known-plugin> --json`.
- Install one official plugin at the exact requested release version from
ClawHub in an isolated HOME:
`openclaw plugins install clawhub:@openclaw/matrix@<VERSION>`.
Prefer `matrix` unless that plugin is not in the expected set. ClawHub
versions belong in the spec; `--pin` is only supported for npm installs.
5. Release workflows:
- Verify conclusions for release notes evidence links:
Full Release Validation, OpenClaw Release Checks, OpenClaw NPM Release,
Plugin NPM Release, Plugin ClawHub Release, mac preflight/validation/publish
when stable mac assets are expected.
- For stable, verify `OpenClaw Stable Main Closeout` succeeded and its
manifest records the matching release tag, current rollback drill, stable
soak, and blocking performance evidence.
- Summarize only relevant successful/failed jobs; ignore routine skipped
optional lanes unless the release body promised them.
## Extended-stable checks
Extended-stable has a GitHub Release with shared release evidence but no native
or ClawHub artifacts. Verify it alongside
the live tag, workflow, registry, provenance, and image state.
1. **Identity:** require final `v<VERSION>` at patch `33+`, with no suffix,
contained in `extended-stable/YYYY.M.33`. Only an active candidate must equal
the tip. Root and every publishable official plugin must declare `<VERSION>`.
Require the Git tag and a public, non-prerelease GitHub Release whose title
and canonical body match the tag. Require `isLatest=false`, the dependency
evidence, immutable Full Release Validation manifest, postpublish evidence,
and their checksums. Require no native or ClawHub assets.
2. **Workflow chain:** find the successful parent release run plus its
preflight, complete validation, plugin npm, and core publish children.
Require a protected `release-publish/*` parent and canonical `release-ci/*`
validation producer with verified workflow SHA provenance. Validation must
use `rerun_group=all`, `release_profile=stable`, blocking soak/performance,
and the saved attempt. Core publish must reference all three run IDs and bind
its manifest, workflow ref, and tarball digest to the release SHA.
3. **Registry:** require exact and `extended-stable` selectors to return
`<VERSION>` for root, every preflight `corePackageTarballs` entry, and every
`publishToNpm === true` official plugin derived from the tag. Compare the
plugin plan, jobs, and complete readback; never infer inventory from diffs.
4. **Provenance:** from trusted current tooling, run
`node --import tsx scripts/openclaw-npm-postpublish-verify.ts <VERSION>`.
Require signatures, canonical-branch provenance, and publish/preflight
digest binding to the release SHA. Preserve output and workflow URLs.
5. **Docker:** verify exact default, slim, browser, and architecture images and
attestations in both registries. Only the three `extended-stable*` aliases may
resolve to those digests. Require the successful `OpenClaw Release Publish`
parent run and its completed Docker verification. The normal route finalizes
afterward; an explicitly requested fast path may activate GitHub first. Repair
aliases through current-main `Docker Channel Promotion` for the exact tag,
without rebuilding.
6. **Recovery:** never republish. Use `promote_extended_stable` in the
`openclaw/releases` dist-tag workflow for the root selector (an unsuffixed
final patch `33+`) and approved credential-isolated tooling for others, then repeat
complete readback. Do not require ClawHub, native/mobile apps, website,
private dist-tags, or regular `latest`. Require shared release evidence, but
do not require regular native or ClawHub assets.
## Shared live smoke
After the track-specific publication checks pass:
1. Published package smoke:
- In `/tmp`, isolated HOME:
`npm exec --yes --package openclaw@<VERSION> -- openclaw --version`.
- Run at least one harmless command that touches the published CLI surface,
for example `plugins --help` or `gateway --help`.
2. Dev Gateway live model smoke:
- Use temp HOME/workspace, not the user's normal state:
`HOME=/tmp/openclaw-release-smoke/home OPENCLAW_WORKSPACE=/tmp/openclaw-release-smoke/work pnpm openclaw --dev gateway run --auth none --force --verbose`.
- Resolve the launched Gateway's bound port from its startup output or log.
- For `--auth none`, require unauthenticated
`GET http://127.0.0.1:<PORT>/healthz` to return HTTP 200 with the exact JSON
object `{"ok":true,"status":"live"}`.
- Reserve `gateway health --json` for intentionally credentialed or
device-paired smoke, passing the explicit credential required by that
Gateway.
- Run one Gateway-backed agent turn with inherited `OPENAI_API_KEY`, short
prompt, explicit session key, JSON output, and a known-available model.
- If the configured default model fails as unavailable, record that caveat
and retry with the newest known-good OpenAI model instead of declaring the
release failed.
- Stop the gateway and verify the port is not listening.
## Caveats To Report
- Dist-tag caveat: stable `latest` is release truth; if optional `beta` mirrors
still point at a beta version, report it as a caveat, not a stable-release
blocker, unless the user asked to verify beta promotion.
- Track caveat: name the track and intentionally absent surfaces. Do not call
missing regular-release artifacts an extended-stable failure.
- Divergent checkout caveat: say when local source SHA differs from release tag
or origin and which live sources were used instead.
- Smoke caveat: distinguish Gateway-backed agent success from local embedded
fallback. A valid auth-none live smoke has the exact `/healthz` result plus a
successful Gateway-backed agent turn and the Gateway log/run id for that call.
More agent context in moltbot/clawdbot
105 other files this repository gives its agents, the first 60 shown.
Skill
- agent-transcript.agents/skills/agent-transcript/SKILL.md
- auto-qa.agents/skills/auto-qa/SKILL.md
- autoreview.agents/skills/autoreview/SKILL.md
- channel-message-flows.agents/skills/channel-message-flows/SKILL.md
- clawdtributor.agents/skills/clawdtributor/SKILL.md
- claw-score.agents/skills/claw-score/SKILL.md
- clawsweeper.agents/skills/clawsweeper/SKILL.md
- control-ui-e2e.agents/skills/control-ui-e2e/SKILL.md
- crabbox.agents/skills/crabbox/SKILL.md
- deslop.agents/skills/deslop/SKILL.md
- discord-clawd.agents/skills/discord-clawd/SKILL.md
- discord-e2e.agents/skills/discord-e2e/SKILL.md
- discord-user-post.agents/skills/discord-user-post/SKILL.md
- discrawl.agents/skills/discrawl/SKILL.md
- gitcrawl.agents/skills/gitcrawl/SKILL.md
- graincrawl.agents/skills/graincrawl/SKILL.md
- notcrawl.agents/skills/notcrawl/SKILL.md
- openclaw-changelog-update.agents/skills/openclaw-changelog-update/SKILL.md
- openclaw-ci-limits.agents/skills/openclaw-ci-limits/SKILL.md
- openclaw-debugging.agents/skills/openclaw-debugging/SKILL.md
- openclaw-docker-e2e-authoring.agents/skills/openclaw-docker-e2e-authoring/SKILL.md
- openclaw-ghsa-maintainer.agents/skills/openclaw-ghsa-maintainer/SKILL.md
- openclaw-live-updater.agents/skills/openclaw-live-updater/SKILL.md
- openclaw-parallels-smoke.agents/skills/openclaw-parallels-smoke/SKILL.md
- openclaw-pr-maintainer.agents/skills/openclaw-pr-maintainer/SKILL.md
- openclaw-qa-testing.agents/skills/openclaw-qa-testing/SKILL.md
- openclaw-refactor-docs.agents/skills/openclaw-refactor-docs/SKILL.md
- openclaw-release-validation.agents/skills/openclaw-release-validation/SKILL.md
- openclaw-repair-sweep.agents/skills/openclaw-repair-sweep/SKILL.md
- openclaw-secret-scanning-maintainer.agents/skills/openclaw-secret-scanning-maintainer/SKILL.md
- openclaw-test-heap-leaks.agents/skills/openclaw-test-heap-leaks/SKILL.md
- openclaw-testing.agents/skills/openclaw-testing/SKILL.md
- openclaw-test-performance.agents/skills/openclaw-test-performance/SKILL.md
- openclaw-update.agents/skills/openclaw-update/SKILL.md
- parallels-discord-roundtrip.agents/skills/parallels-discord-roundtrip/SKILL.md
- proof-video.agents/skills/proof-video/SKILL.md
- prototype-openclaw-tui.agents/skills/prototype-openclaw-tui/SKILL.md
- release-openclaw-announcement.agents/skills/release-openclaw-announcement/SKILL.md
- release-openclaw-ci.agents/skills/release-openclaw-ci/SKILL.md
- release-openclaw-mac.agents/skills/release-openclaw-mac/SKILL.md
- release-openclaw-maintainer.agents/skills/release-openclaw-maintainer/SKILL.md
- release-openclaw-plugin-testing.agents/skills/release-openclaw-plugin-testing/SKILL.md
- security-triage.agents/skills/security-triage/SKILL.md
- slack-e2e.agents/skills/slack-e2e/SKILL.md
- slacrawl.agents/skills/slacrawl/SKILL.md
- tag-duplicate-prs-issues.agents/skills/tag-duplicate-prs-issues/SKILL.md
- technical-documentation.agents/skills/technical-documentation/SKILL.md
- telegram-e2e-userbot.agents/skills/telegram-e2e-userbot/SKILL.md
- test-audit.agents/skills/test-audit/SKILL.md
- update-team-server.agents/skills/update-team-server/SKILL.md
- 1passwordskills/1password/SKILL.md
- apple-notesskills/apple-notes/SKILL.md
- apple-remindersskills/apple-reminders/SKILL.md
- bear-notesskills/bear-notes/SKILL.md
Also found in 6 other repositories
The same file, byte for byte, in the weekly crawl of public GitHub.
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool registry_write, action report. How to connect one.

