agentCLAWHUBUnverified

qa-release-risk-governance

当版本要发布了、需要决定"能不能发"、或者需要设计灰度/回滚方案时使用此技能。系统化评估变更风险(变更范围/影响面/回退成本),设计灰度发布策略(按用户/区域/流量比例),制定回滚方案和线上监控计划。不要问"这个版本稳不稳"——要问"如果出问题了,我们能在几分钟内发现并回滚"。产出发布风险评估报告和灰度发布方案。 触发场景:发布风险、灰度策略、回滚方案、风险评估、版本发布、紧急发布、大版本发布前风险评估时。 Use when the user asks about: release readiness assessment — canary rollout, rollback planning, release risk evaluation, and production monitoring thresholds. Skill: qa-release-risk-governance Owner: kokxi Summary: 当版本要发布了、需要决定"能不能发"、或者需要设计灰度/回滚方案时使用此技能。系统化评估变更风险(变更范围/影响面/回退成本),设计灰度发布策略(按用户/区域/流量比例),制定回滚方案和线上监控计划。不要问"这个版本稳不稳"——要问"如果出问题了,我们能在几分钟内发现并回滚"。产出发布风险评估报告和灰度发布方案。 触发场景:发布风险、灰度策略、回滚方案、风险评估、版本发布、紧急发布、大版本发布前风险评估时。 Use when the user asks about: release readiness assessment — canary rollout, rollback planning, release risk evaluation, and production monitoring thresholds.

OpenClaw

Rank

62

Safety

84

Downloads

1.1k

Updated

Oct 11, 2026

Version

1.8.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.1K downloadsadoption · observed Oct 11, 2026
Latest release
1.8.0release · observed Sep 29, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s170jw3s1atcj5jwhqb4r7v7eh8912kp:qa-release-risk-governance
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-release-risk-governance/snapshot"

Documentation

CLAWHUB

72,086 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: qa-release-risk-governance
description: >-
  当版本要发布了、需要决定"能不能发"、或者需要设计灰度/回滚方案时使用此技能。系统化评估变更风险(变更范围/影响面/回退成本),设计灰度发布策略(按用户/区域/流量比例),制定回滚方案和线上监控计划。不要问"这个版本稳不稳"——要问"如果出问题了,我们能在几分钟内发现并回滚"。产出发布风险评估报告和灰度发布方案。 触发场景:发布风险、灰度策略、回滚方案、风险评估、版本发布、紧急发布、大版本发布前风险评估时。 Use when the user asks about: release readiness assessment — canary rollout, rollback planning, release risk evaluation, and production monitoring thresholds.
license: MIT
allowed-tools: Read Grep Glob
metadata:
  display-name: "Release Risk Governance"
  version: "1.8.0"
  when-to-use: "用户说\"发布风险\"、\"灰度策略\"、\"回滚方案\"、\"风险评估\"、\"版本发布\"、\"紧急发布\"、需要评估发布风险、大版本发布前风险评估时"
  related-skills: "{\"upstream\":[\"qa-test-strategy-design\",\"qa-risk-intuition\"],\"downstream\":[\"qa-quality-metrics\",\"qa-shift-right\",\"qa-stakeholder-communication\"]}"
  references: "[\"references/canary-rollout.md\"]"
  input-format: "{\"required\":[{\"name\":\"测试策略\",\"type\":\"object\",\"description\":\"来自qa-test-strategy-design的测试策略\"},{\"name\":\"风险评估\",\"type\":\"object\",\"description\":\"来自qa-risk-intuition的风险评估\"},{\"name\":\"发布计划\",\"type\":\"string\",\"description\":\"发布时间线和范围\"}],\"optional\":[{\"name\":\"质量度量\",\"type\":\"object\",\"description\":\"来自qa-quality-metrics的质量数据\"}]}"
  output-format: "{\"traceability\":[\"每次发布评估带唯一ID(REL-XXXX)\"],\"structure\":[{\"release_decision\":\"发布决策建议\"},{\"risk_summary\":\"风险摘要\"},{\"blocking_issues\":\"阻塞性问题清单\"},{\"rollback_plan\":\"回滚方案\"},{\"monitoring_recommendations\":\"上线监控建议\"}]}"
  error-recovery-guidance: "{\"on_failure\":\"发布评估发现阻塞性问题时回退到测试策略补齐\",\"retry_behavior\":\"修复阻塞问题后重新评估发布\"}"
  categories: "[\"Development\",\"Testing\",\"DevOps\"]"
  depth-requirement: "{\"reference_value\":\"根据发布规模调整评估深度:简单×1/中等×2/复杂×3\",\"minimum\":\"至少覆盖变更风险、灰度策略、回滚方案、监控计划4项\"}"
---
> ⚠️ 本技能单独使用效果有限,建议配合完整技能集(12 步工作流)使用。安装:npx skills add Kokxi/qa-test-skills

> **⚠️ 安全警告**:本技能的示例可能涉及发布决策、灰度方案和回滚操作。
> 实际使用时请勿直接执行发布或回滚,先确认审批权限、灰度比例和回滚预案。
> 本技能仅在 workspace/ 输出评估文件,不持久化、不外传、不跨会话复用。

# 发布风险管理

## 核心原则

发布决策不仅仅是"Bug都修完了没",而是综合判断变更影响面、灰度策略、回滚能力。

## 发布风险评估矩阵

### 维度1:变更特征分析

```text
变更范围:
├─ 代码变更量:新增/修改/删除行数
├─ 文件影响面:涉及多少文件
├─ 模块影响面:涉及多少模块
├─ 接口影响面:涉及多少接口
└─ 数据影响面:涉及多少数据表

风险等级:
- 大变更:>1000行/>20文件/>5模块
- 中变更:500-1000行/10-20文件/3-5模块
- 小变更:<500行/<10文件/<3模块
```

### 维度2:变更类型风险

```text
高风险变更:
├─ 数据库变更:表结构/索引/数据迁移
├─ 核心逻辑变更:支付/认证/权限
├─ 配置变更:生产环境配置
├─ 依赖变更:第三方库/服务升级
└─ 架构变更:服务拆分/合并

中风险变更:
├─ 业务规则变更:计算逻辑/流程
├─ 接口变更:入参/出参/协议
├─ UI变更:页面/交互/样式
└─ 性能优化:缓存/异步/并发

低风险变更:
├─ Bug修复:不影响主流程
├─ 文案修改:提示信息/文档
├─ 日志调整:日志级别/格式
└─ 测试相关:测试代码/配置
```

### 维度3:业务影响评估

```text
影响范围:
├─ 用户影响:影响多少用户
├─ 功能影响:影响哪些功能
├─ 收入影响:是否影响交易
├─ 声誉影响:是否影响品牌形象
└─ 合规影响:是否影响合规要求

影响等级:
- 高影响:核心功能/大量用户/收入相关
- 中影响:次要功能/部分用户
- 低影响:边缘功能/少量用户
```

## 加载时机

| 什么时候读 | 读哪个 |
|-----------|--------|
| 设计灰度放量阶梯与回滚阈值时 | [`references/canary-rollout.md`](references/canary-rollout.md) |

> `灰度策略设计`的完整内容已下沉至 `references/canary-rollout.md`,避免每次触发都占用上下文。

## 回滚方案设计

### 回滚类型

```text
回滚方式:
├─ 代码回滚:回滚代码版本
│   ├─ 适用:代码变更导致的问题
│   ├─ 步骤:git revert → 部

_meta.json

{
  "ownerId": "kn71y9b23csfx0ykgm55d5m9x5891zt8",
  "slug": "qa-release-risk-governance",
  "version": "1.8.0",
  "publishedAt": 1790656052783
}

references/canary-rollout.md

# 灰度发布与回滚策略详解

> 本文是 `qa-release-risk-governance` 的**灰度发布与回滚策略详解**。设计灰度放量阶梯与回滚阈值时读本文;
其余部分留在 SKILL.md,不必读本文。

---


> 📌 本节与 qa-shift-right「阶段1:灰度发布」内容同步,修改时请同步更新两处。

### 灰度维度

```text
灰度策略:
├─ 用户灰度:按用户ID/比例
│   ├─ 内部员工 → 白名单用户 → 10% → 50% → 100%
│   └─ 适用:新功能/高风险功能
│
├─ 流量灰度:按流量比例
│   ├─ 1% → 10% → 30% → 50% → 100%
│   └─ 适用:性能优化/算法变更
│
├─ 地域灰度:按地域
│   ├─ 某城市 → 某省份 → 全国
│   └─ 适用:地域性功能
│
└─ 时间灰度:按时间段
    ├─ 低峰期 → 高峰期
    └─ 适用:定时任务/批处理
```

### 灰度监控指标

```text
监控指标:
├─ 业务指标:
│   ├─ 订单量/交易量
│   ├─ 转化率/成功率
│   └─ 用户活跃度
│
├─ 技术指标:
│   ├─ 错误率/异常率
│   ├─ 响应时间/吞吐量
│   └─ 资源使用率
│
└─ 用户反馈:
    ├─ 投诉量
    ├─ 客服咨询量
    └─ 社交媒体反馈
```

### 灰度回滚条件

```text
回滚触发条件:
├─ 业务指标异常:
│   ├─ 订单量下降 > 20%
│   ├─ 成功率下降 > 5%
│   └─ 用户投诉增加 > 50%
│
├─ 技术指标异常:
│   ├─ 错误率 > 1%
│   ├─ 响应时间增加 > 50%
│   └─ CPU/内存使用率 > 80%
│
└─ 用户反馈异常:
    ├─ 投诉量激增
    └─ 负面舆情
```

skill-card.md

## Description:

Assesses release readiness and change risk, then recommends canary rollout, rollback, and production monitoring plans.

This skill is ready for commercial/non-commercial use.

## Publisher:

[kokxi](https://clawhub.ai/user/kokxi)

### License/Terms of Use:

MIT-0

## Use Case:

Release managers, QA teams, and developers use this skill to evaluate change and business risks, recommend release decisions, and plan staged rollout, rollback, and monitoring before production deployment.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The optional command to install the broader skill set is unpinned.

Mitigation: Review the source and use a pinned, trusted version before running the install command.

Risk: Release or rollback recommendations could be mistaken for authorization to act in production.

Mitigation: Require normal production approvals and confirm rollout scope, monitoring thresholds, and rollback readiness before execution.

## Reference(s):

- [Canary rollout and rollback strategy](references/canary-rollout.md)

## Skill Output:

**Output Type(s):** [Analysis, Guidance]

**Output Format:** [Markdown release-risk assessment and canary rollout plan]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Each assessment carries a REL-XXXX identifier and includes a release recommendation, risk summary, blockers, rollback plan, and monitoring recommendations.]

## Skill Version(s):

1.8.0 (source: ClawHub release and skill metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/kokxi/skills/qa-release-risk-governance",
      "sourceUrl": "https://clawhub.ai/kokxi/skills/qa-release-risk-governance",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T08:27:37.054Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-release-risk-governance/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-release-risk-governance/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T08:27:37.054Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.1K downloads",
      "href": "https://clawhub.ai/kokxi/qa-release-risk-governance",
      "sourceUrl": "https://clawhub.ai/kokxi/qa-release-risk-governance",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T08:27:37.054Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.8.0",
      "href": "https://clawhub.ai/kokxi/qa-release-risk-governance",
      "sourceUrl": "https://clawhub.ai/kokxi/qa-release-risk-governance",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-29T04:27:32.783Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-release-risk-governance/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-release-risk-governance/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.8.0",
      "description": "- Migrated gray release (canary rollout) strategy content to a new references/canary-rollout.md file for modularity and reduced context size. - Modernized skill metadata: moved config to a structured metadata block, using JSON for related fields. - Updated skill description and usage guidance, now including English triggers (e.g., release readiness, canary rollout). - Removed legacy skill-card.md file; all critical summaries now in SKILL.md and metadata. - No changes to risk matrix or core risk governance logic.",
      "href": "https://clawhub.ai/kokxi/qa-release-risk-governance",
      "sourceUrl": "https://clawhub.ai/kokxi/qa-release-risk-governance",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-29T04:27:32.783Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to qa-release-risk-governance and adjacent AI workflows.