Get Unpublished ChangesCAUTION
OmO: Just type "mass ulw" keyword with your prompt. Now you are the master of graph engineering.
Overview
OmO: Just type "mass ulw" keyword with your prompt. Now you are the master of graph engineering.
3da8ec0ef9b3OBSERVED · 2026-09-23Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| codex | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: get-unpublished-changes
description: "Compare HEAD with the latest published npm versions and list all unpublished changes by release layer. Triggers: unpublished changes, changelog, what changed, whats new."
---
IMMEDIATELY output the analysis. NO questions. NO preamble.
## CRITICAL: DO NOT just copy commit messages!
For each commit, you MUST:
1. Read the actual diff to understand WHAT CHANGED
2. Describe the REAL change in plain language
3. Explain WHY it matters (if not obvious)
## Release Layers
Analyze every change against these exact layers:
| Layer | Includes | Version question |
|---|---|---|
| `omo pure components` | `packages/*-core`, MCP packages, `packages/shared-skills`, reusable scripts | Do shared components need a patch/minor/major release note even if adapters only consume them internally? |
| `omo opencode` | Root `oh-my-opencode` / `oh-my-openagent`, `src/`, `.opencode/`, `.agents/`, CLI, config, hooks, tools, docs | What semver bump should the OpenCode/OpenAgent npm packages use? |
| `omo codex` | `packages/omo-codex`, `lazycodex-ai`, Codex plugin metadata/hooks, bundled MCP runtimes, `code-yeongyu/lazycodex` marketplace payload | Does LazyCodex need the same bump, a Codex-only note, or a marketplace release? |
Exclude commits and paths matching `senpi`, `omo-senpi`, `senpi-task`, `pi-goal`, or `pi-webfetch` from user-facing notes and version recommendations. Record them only in a separate internal-adapter exclusion ledger.
## Steps:
1. Detect latest published versions for `oh-my-opencode`, `oh-my-openagent`, and `lazycodex-ai`.
2. Run `git diff v{published-version}..HEAD` to see actual changes.
3. Classify every file into one or more release layers before grouping by feat/fix/refactor/docs.
4. Describe the REAL changes and why each layer cares.
5. Note breaking changes by affected layer.
6. Recommend a layer-specific version bump and one overall workflow bump.
## Output Format:
- feat: "Added X that does Y" (not just "add X feature")
- fix: "Fixed bug where X happened, now Y" (not just "fix X bug")
- refactor: "Changed X from A to B, now supports C" (not just "rename X")
Include:
- `Layered Impact Matrix`: rows for `omo pure components`, `omo opencode`, `omo codex`
- `Layer-specific Version Recommendation`: patch/minor/major per layer plus one overall release bumpTrust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
.claude/commands
.claude/skills
CLAUDE.md
Gates applied: no_behavioural_pass.
3da8ec0ef9b3full audit observations/trust-audit/skill/code-yeongyu__get-unpublished-changes.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 3da8ec0ef9b3 | CAUTION | B | 89 | first audit |
Questions
What does the Get Unpublished Changes skill do?
OmO: Just type "mass ulw" keyword with your prompt. Now you are the master of graph engineering.
Is Get Unpublished Changes safe to install?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Get Unpublished Changes access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Get Unpublished Changes work with?
Its documentation mentions codex. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (3da8ec0ef9b3), read on 2026-09-23. The repository is watched, and a new audit runs when it changes — this is the first audit.