Patch NotesSAFE
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Overview
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
42a36917b8beOBSERVED · 2026-10-05What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: patch-notes
description: "Player-facing patch notes from git history and changelogs. Translates developer language into player communication."
argument-hint: "[version] [--style brief|detailed|full]"
user-invocable: true
allowed-tools: Read, Glob, Grep, Write, Bash, Bash(bash "*/.claude/skills/patch-notes/../../hooks/yaml-helper.sh" resolve_config *)
model: sonnet
---
!`bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation`
**Automation mode**: Resolve `modes.automation` (`project.local.yaml` →
`project.yaml` → default `collaborative`). Every `AskUserQuestion` call and
every file write follows `.claude/docs/automation-modes.md`
(collaborative asks always · guided major-only · autonomous logs and proceeds;
`automation_always_ask` categories always prompt).
## Provenance check — before reading any history
**Confirm the history you are about to read belongs to THIS game.** Run this
before Phase 2 and stop if it fails.
1. Sample the recent log: `git log --oneline -20`. **If it is empty or git is
unavailable, skip this check** — there is nothing to classify, and Phase 2's
no-changelog-data branch is the right stop.
2. **Classify every commit in the range, one at a time**, into exactly one of:
- **Game** — changes the game the player plays: mechanics, content, balance,
art, audio, UI, a bug in any of those.
- **Framework / maintenance** — changes CCGS itself or the project's tooling:
subjects naming skills, hooks, agents, the test plan, CI, the framework's
own docs. **Excluded from player-facing notes, but not a reason to stop.**
- **Unclear** — treat as framework. A commit you cannot confidently place is
not one to write player copy from.
3. Then decide from the counts:
- **At least one Game commit** → proceed, using **only** those. Say how many
of how many you used, so the reader can see the filter ran.
- **Zero Game commits** → stop, using the message below, and give the count (0 of how many) so the reader can see the filter ran.
> **Filter per commit; do not stop on a repo that merely contains maintenance
> work.** Every project built on this framework accumulates commits touching
> hooks, CI and skills — the game repo *is* the framework repo. An earlier
> version of this check listed "subjects naming the framework, its skills, hooks,
> agents or test plan" as a hard STOP, which fires on virtually every real
> project and contradicted its own step 2 whenever a history was mostly the
> game's. The danger was never that such commits *exist*; it is that they get
> **rendered as player-facing copy**. Excluding them addresses that exactly, and
> a repo-level stop does not.
Corroborate before you proceed, cheaply: the Game commits should name systems
that appear in `design/` and the code root (`src/`, `Assets/` or `Source/`). If
they name a product those directories
never mention, that is the real wrong-history signal — stop.
If **no** commit in the range is this game's, say so and stop:
> "The git history in this repo does not appear to belong to [game]: 0 of the [N]
> recent commits are Game commits. The recent
> commits describe [what they actually describe]. I cannot generate release notes
> from it — point me at the right history, or supply the change list directly."
Verdict: **BLOCKED** — stop here without generating notes.
**Why this is a hard stop, not a warning.** This exact failure is real, not
hypothetical: a batch of framework-internal commits produced player-facing copy
reading *"Fixed an issue where progress from your last session could be lost on launch"*
— a session-hook timeout rendered as a gameplay fix for a game with **no save
system**. It was fluent, plausible, and entirely false. A reader cannot tell the
difference; only this check can.
---
## Phase 1: Parse Arguments
- `version`: the release version to generate notes for (e.g., `1.2.0`)
- `--style`: output style — `brief` (bullet points), `detailed` (with context), `full` (with developer commentary). Default: `detailed`.
If no version is provided, ask the user before proceeding.
---
## Phase 2: Gather Change Data
- Read the internal changelog at `production/releases/[version]/changelog.md` if it exists
- Also check `docs/CHANGELOG.md` for the relevant version entry
- Run `git log` between the previous release tag and current tag/HEAD as a fallback
- Read sprint retrospectives in `production/sprints/` for context
- Read any balance change documents in `design/balance/`
- Read bug fix records from QA if available
**If no changelog data is available** (neither `production/releases/[version]/changelog.md`
nor a `docs/CHANGELOG.md` entry for this version exists, and git log is empty or unavailable):
> "No changelog data found for [version]. Run `/changelog [version]` first to generate the
> internal changelog, then re-run `/patch-notes [version]`."
Verdict: **BLOCKED** — stop here without generating notes.
---
## Phase 2b: Detect Tone Guide and Template
**Tone guide detection** — before drafting notes, check for writing style guidance:
1. Check `.claude/docs/technical-preferences.md` for any "tone", "voice", or "style"
fields or sections.
2. Check `docs/PATCH-NOTES-STYLE.md` if it exists.
3. Check `design/community/tone-guide.md` if it exists.
4. If any source contains tone/voice/style instructions, extract them and apply
them to the language and framing of the generated notes.
5. If no tone guidance is found anywhere, default to:
player-friendly, non-technical language; enthusiastic but not hyperbolic;
focus on what the player experiences, not what the developer changed.
**Template detection** — check whether a patch notes template exists:
1. Glob for `docs/patch-notes-template.md` and `.claude/docs/templates/patch-notes-template.md`.
2. If found at either location, read it and use it as the output structure for Phase 4
instead of the built-in style templates (Brief / Detailed / Full). Fill in the
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
42a36917b8befull audit observations/trust-audit/skill/donchitos__patch-notes.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 42a36917b8be | SAFE | B | 89 | first audit |
Questions
What does the Patch Notes skill do?
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Is Patch Notes safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Patch Notes access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (42a36917b8be), read on 2026-10-05. The repository is watched, and a new audit runs when it changes — this is the first audit.