CI发布工程师 CI与发布门禁

PassAudited by VirusTotal on May 8, 2026.

Overview

Type: OpenClaw Skill Name: ci-release-gate Version: 1.1.0 The skill bundle defines a CI Release Engineer role focused on release gating, validation checks, and automation safety. The instructions in SKILL.md are standard operational procedures for CI/CD workflows, such as verifying test coverage and ensuring repeatable validation steps, with no evidence of malicious intent, data exfiltration, or unauthorized command execution.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The skill's recommendations may depend on local project standards that are not visible in this artifact review.

Why it was flagged

The skill bases its behavior on project-local documents and other skills that were not included in the review context. This is common for a project-specific release gate, but users should make sure those referenced materials are the intended trusted sources.

Skill content
Source Material

- `AI-ENTRY.md`
- `CLAUDE.md`
- `dev/ai/skills/testing/SKILL.md`
- `dev/ai/skills/planning/SKILL.md`
- `dev/ai/skills/documentation-standards/SKILL.md`
Recommendation

Before relying on it, confirm that the referenced project documents and skills are present, trusted, and consistent with your team's release process.

What this means

The agent may include or initiate escalation to named roles when it finds release blockers, depending on the surrounding agent environment.

Why it was flagged

The skill instructs coordination and notification with other roles. This is aligned with release-gate work, but if the host agent can actually message users or systems, notification boundaries should remain clear.

Skill content
Coordinate with QA and implementation roles if gaps remain. ... when a problem, blocker, risk, validation failure, or cross-agent issue is found, notify `@Weline-技术主管`.
Recommendation

Ensure the agent asks for or follows your expected approval process before sending external notifications or sharing sensitive release details.