create-repo-agent

द्वारा langfuse

लैंगफ्यूज़ रिपॉजिटरी के स्वायत्त एजेंटों, विशेष रूप से GitHub Actions जो Claude, Codex, या… को आमंत्रित करते हैं, को डिज़ाइन, कार्यान्वित, समीक्षा या सुरक्षित करते समय उपयोग करें।

npx skills add https://github.com/langfuse/langfuse --skill create-repo-agent

Create Repo Agent

Purpose

Build repo agents that can run unattended without granting the model broad write credentials, arbitrary shell, or uncontrolled network access. The default architecture is a read-only audit job that produces a validated patch artifact plus a separate publisher job that owns GitHub writes.

Use this skill together with the domain skill for the files the agent will maintain. For example, a pricing agent must also use add-model-price.

Required Reading

For every repo agent task, read these references before designing or editing:

  1. references/security-standards.md
  2. references/workflow-blueprint.md when implementing or changing a GitHub Actions workflow
  3. references/review-checklist.md before final review or PR publication

Workflow

  1. Define the exact maintenance objective, allowed files, external sources, expected no-change behavior, and PR ownership.
  2. Choose the least-capable runtime: prefer a scheduled/manual GitHub Action with read-only repository checkout and no write credentials in the LLM step.
  3. Encode the prompt with explicit allowed edit surfaces, hard constraints, source-evidence requirements, and structured output.
  4. Give the agent only scoped file tools, domain-scoped fetch tools, and exact deterministic validator commands.
  5. Validate the diff independently of the agent, including untracked files, path allowlists, git diff --check, line-count limits, and domain-specific validators.
  6. Publish from a separate job or step after validation, using a bot credential only for branch push and PR create/update.
  7. If self-improvement is allowed, constrain it to named workflow or skill-reference files and require security invariants to remain unchanged.
  8. Run agent setup checks when .agents/** changes, then publish a normal human-reviewable PR.

Non-Negotiables

  • Never expose a write-capable GitHub token, PAT, GitHub App token, OIDC token, SSH key, cloud credential, or package-publishing token to the LLM agent step.
  • Never rely on prompt instructions as the only security boundary. Enforce file and command limits outside the agent.
  • Never stage a directory wholesale. Stage only the validated file list.
  • Never ignore untracked files in diff validation.
  • Never let self-improvement bypass the same diff allowlist and human PR review as normal edits.
  • Never grant arbitrary Bash, curl, wget, gh, git push, package-manager, interpreter, environment-dump, or process-inspection tools to the LLM agent.
  • Never add id-token: write unless the agent truly needs OIDC and the trust relationship is reviewed explicitly.

langfuse की और Skills

frontend-browser-review
langfuse
इस कौशल का उपयोग तब करें जब कोई बदलाव ब्राउज़र में उपयोगकर्ताओं द्वारा देखे या किए जाने वाले कार्यों को प्रभावित करता है।
frontend-large-feature-architecture
langfuse
बड़े Langfuse फ्रंटएंड फीचर्स, वर्चुअलाइज्ड लिस्ट, बड़े टेबल, कंट्रोलर कंपोनेंट्स, लोकल फीचर… बनाने, बदलने या रीफैक्टर करने में उपयोग करें।
skill-developer
langfuse
एन्थ्रोपिक की सर्वोत्तम प्रथाओं का पालन करते हुए क्लॉड कोड कौशल बनाएं और प्रबंधित करें। नए कौशल बनाते समय, skill-rules.json संशोधित करते समय, ट्रिगर समझते समय उपयोग करें…
langfuse-prompt-migration
langfuse
हार्डकोडेड प्रॉम्प्ट को संस्करण नियंत्रण और डिप्लॉयमेंट-मुक्त पुनरावृत्ति के लिए Langfuse में माइग्रेट करें। उपयोग तब करें जब उपयोगकर्ता प्रॉम्प्ट को बाहरी बनाना चाहता है, प्रॉम्प्ट को Langfuse में स्थानांतरित करना चाहता है,…
incident-alert-tickets
langfuse
Read and, after human approval, update the Linear `incident-alert` knowledge base. Use before and after investigating a named Datadog monitor,…
refactor-react-effects
langfuse
Langfuse फ्रंटेंड कोड में अनावश्यक React useEffect उपयोग को रिफैक्टर करें। इफेक्ट्स जोड़ते, समीक्षा करते या हटाते समय उपयोग करें; फॉर्म या स्थानीय UI स्थिति को प्रारंभ करते समय…
sentry-instrumentation
langfuse
Decide whether and how errors report to Sentry. Use when touching capture or error-handling paths in `web/**`, triaging Sentry noise, or changing Sentry…
posthog-instrumentation
langfuse
Product analytics with posthog. Use when adding a meaningful user action or feature in `web/**`, touching PostHog capture code, or answering product-usage…