Conversation
The prompt forces a CI-gap check before any extra work, maps ldcli dependency bumps onto CLI, store, UI, or test-only modes, and requires video only when a user-visible surface was actually exercised. Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
The cobra branch is 36 commits behind main, and `dev-server start` requires --access-token even for an empty local boot. Document both, and add the dry-run report as an example of the output contract. Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
The playbooks should describe durable ldcli surfaces and modes, not the current Dependabot queue or a one-off cobra dry-run. Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
Runs now opt out of analytics and use temporary XDG state/config dirs and a non-default port, so they neither send production telemetry nor touch a contributor's dev-server data. Stale branches are tested as a local merge onto main, grouped PRs take the union of checks, UI bumps flag a missing dist/ rebuild, and escalation is separate from the test mode. Reports stay off the public PR unless the automation is configured to post them. Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
isolate.sh opts out of analytics and the update check and points XDG state and config at a temp directory. prepare-tree.sh merges a PR onto the latest main through named refs, since FETCH_HEAD resolves to main after a two-ref fetch. store-smoke.sh boots the dev-server and checks the UI, API, databases, and a restart. cleanup.sh removes the worktree, refs, and temp directory. Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
Moves the prompt into .agents/skills/verify-dependabot-pr with disable-model-invocation, so contributors' agents don't pick it up unprompted. Splits per-check procedures, the package table, video steps, and the report template into files loaded on demand, and rewrites the instructions in plain language. Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
Co-authored-by: Ramon Niebla <nieblara@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requirements
Related issues
n/a
Describe the solution you've provided
A skill that tells a maintainer-run agent how to check a Dependabot PR for problems CI can't catch, and write a report with a verdict. The agent never approves, merges, or pushes.
It lives in
.agents/skills/verify-dependabot-pr/. Its description limits it to maintainers asking to verify a Dependabot PR, so agents should only pick it up for that request.SKILL.md: the rules, a step checklist, escalation reasons, and verdicts (merge-ok,ci-sufficient,hold,escalate). It separates setup failures (fix and retry) from real failures (hold, with the error), and treats PR text and release notes as data rather than instructions.references/checks.md: what to run for each kind of package, loaded only for the checks a PR needs.references/surfaces.md: which check each dependency needs. It describes what each package does rather than listing file paths, so it goes stale more slowly.references/video.mdandassets/report.md: when to record a clip, and the report template.scripts/:isolate.shopts out of analytics and the update check, and points ldcli's config and dev-server data at a temp directory on a free port.prepare-tree.shmerges the PR onto the latestmainin a temp worktree, and exits 2 on a conflict.store-smoke.shboots the dev-server with a dummy token, then checks the UI, the API, both databases, and a restart.cleanup.shremoves the worktree, refs, and temp directory.Describe alternatives you've considered
.cursor/automations/, as the earlier revision did. Cursor doesn't load that directory, and a skill is found by any agent that supports the Agent Skills format.disable-model-invocation: trueso the skill only runs when invoked by name. Left off so agents can pick it up from a natural request; the narrow description is what keeps it from triggering on unrelated dependency work.Additional context
What the scripts were tested against:
main):prepare-tree.shmerged it ontomain, andstore-smoke.shpassed every check. Everything ldcli wrote landed under the temp directory.prepare-tree.shreported the conflict inpackage-lock.json, exited 2, and left no merge in progress.cleanup.shremoved the worktree, therefs/verify/*refs, and the temp directory, including when run from inside the worktree.The earlier revision's stale-branch commands used
FETCH_HEADafter fetching two refs.FETCH_HEADresolved tomain, so those commands comparedmainwith itself.prepare-tree.shfetches into named refs instead.To run this from an automation on a Dependabot PR, a prompt like "Read
.agents/skills/verify-dependabot-pr/SKILL.mdand follow it for {PR URL}. Return the report." works in any host that can read files.