# Agent Skill Release Checklist — UtilitySmithLabs

**Free working checklist, revision 2026-10-09. No account, API or payment required.**

This document is a workflow aid, not a security certification. A readable `SKILL.md` does not prove it will safely run in OpenClaw, Codex, Claude Code or Copilot.

## Stage 1 — Inventory and provenance

- [ ] Keep a pristine copy of the original skill and record a SHA-256 for each shipped file.
- [ ] List every referenced script and asset, including binary files, symlinks, external downloads and nested dependencies.
- [ ] Validate metadata and folder naming with the official Agent Skills specification and reference validator.
- [ ] Inspect licenses, redistribution rights and requested OS/runtime/dependencies.

## Stage 2 — Security and policy

- [ ] Run an established multi-engine scanner such as Cisco Skill Scanner. Save its version, configuration, warnings, raw results and input hashes.
- [ ] Manually inspect network calls, credential access, command execution, prompt-injection boundaries and executable downloaded code.
- [ ] Check approval gates for sending messages, posting, deleting, publishing, spending money or making account changes.
- [ ] Verify the workflow never requests personal identity documents, passwords, 2FA or another person's credentials outside official processes.
- [ ] Never downgrade risk solely because a single static scanner has zero findings.

## Stage 3 — Autonomous execution, not just discovery

- [ ] Test the exact supported host / version / operating system with an authorized model and an isolated workspace.
- [ ] Execute a read-only task; compare its answer against a predetermined expected result.
- [ ] Simulate a consequential action and verify the agent stops for an explicit human approval *before* it executes.
- [ ] Inject one controlled transient tool error and one duplicate/replay; ensure bounded retry, idempotency and correct audit records.
- [ ] Test disabled-skill behavior, clean rollback and workspace isolation.

## Stage 4 — Buyer evidence

- [ ] Re-run at least three different scenarios in clean sessions and preserve the results, pass/fail and tool traces.
- [ ] Compare the **same cases** to the chosen free baseline: recall, false positives, tasks completed, installation time, human time, and total cost.
- [ ] Ask a person who did not build the kit to install and complete one representative task without guidance.
- [ ] Make marketing copy match the exact buyer ZIP. Verify its SHA-256, license, support information and actual purchase-to-download delivery.
- [ ] Declare platform-specific support; never claim universal safety, zero failures or general superiority from a handful of curated examples.

### Useful independent references
- [Official Agent Skills specification](https://agentskills.io/specification)
- [Cisco open source Skill Scanner](https://github.com/cisco-ai-defense/skill-scanner)
- [OpenClaw skills guide](https://docs.openclaw.ai/tools/skills)

### What our free checker does, and does not do

The browser preflight checks a single pasted `SKILL.md` with bounded static rules. It does **not** inspect nested scripts, execute the skill, certify it, or replace the deeper Cisco scanner. Use it as one early step.

[Open the free local preflight](./index.html). The paid-expanded kit is in independent testing and is not for sale yet.
