create-repo-agent

โดย langfuse

ใช้เมื่อออกแบบ, ดำเนินการ, ตรวจสอบ, หรือเสริมความปลอดภัยให้กับ autonomous agents ที่เป็นของ Langfuse repo โดยเฉพาะ GitHub Actions ที่เรียกใช้ Claude, Codex, หรือ…

npx skills add https://github.com/langfuse/langfuse --skill create-repo-agent

Create Repo Agent

Purpose

Build repo agents that can run unattended without granting the model broad write credentials, arbitrary shell, or uncontrolled network access. The default architecture is a read-only audit job that produces a validated patch artifact plus a separate publisher job that owns GitHub writes.

Use this skill together with the domain skill for the files the agent will maintain. For example, a pricing agent must also use add-model-price.

Required Reading

For every repo agent task, read these references before designing or editing:

  1. references/security-standards.md
  2. references/workflow-blueprint.md when implementing or changing a GitHub Actions workflow
  3. references/review-checklist.md before final review or PR publication

Workflow

  1. Define the exact maintenance objective, allowed files, external sources, expected no-change behavior, and PR ownership.
  2. Choose the least-capable runtime: prefer a scheduled/manual GitHub Action with read-only repository checkout and no write credentials in the LLM step.
  3. Encode the prompt with explicit allowed edit surfaces, hard constraints, source-evidence requirements, and structured output.
  4. Give the agent only scoped file tools, domain-scoped fetch tools, and exact deterministic validator commands.
  5. Validate the diff independently of the agent, including untracked files, path allowlists, git diff --check, line-count limits, and domain-specific validators.
  6. Publish from a separate job or step after validation, using a bot credential only for branch push and PR create/update.
  7. If self-improvement is allowed, constrain it to named workflow or skill-reference files and require security invariants to remain unchanged.
  8. Run agent setup checks when .agents/** changes, then publish a normal human-reviewable PR.

Non-Negotiables

  • Never expose a write-capable GitHub token, PAT, GitHub App token, OIDC token, SSH key, cloud credential, or package-publishing token to the LLM agent step.
  • Never rely on prompt instructions as the only security boundary. Enforce file and command limits outside the agent.
  • Never stage a directory wholesale. Stage only the validated file list.
  • Never ignore untracked files in diff validation.
  • Never let self-improvement bypass the same diff allowlist and human PR review as normal edits.
  • Never grant arbitrary Bash, curl, wget, gh, git push, package-manager, interpreter, environment-dump, or process-inspection tools to the LLM agent.
  • Never add id-token: write unless the agent truly needs OIDC and the trust relationship is reviewed explicitly.

Skills เพิ่มเติมจาก langfuse

frontend-browser-review
langfuse
ใช้ทักษะนี้เมื่อการเปลี่ยนแปลงส่งผลต่อสิ่งที่ผู้ใช้เห็นหรือทำในเบราว์เซอร์
frontend-large-feature-architecture
langfuse
ใช้เมื่อสร้าง เปลี่ยนแปลง หรือปรับโครงสร้างฟีเจอร์ frontend ขนาดใหญ่ของ Langfuse, รายการแบบ virtualized, ตารางขนาดใหญ่, คอมโพเนนต์ตัวควบคุม, ฟีเจอร์เฉพาะที่…
skill-developer
langfuse
สร้างและจัดการทักษะ Claude Code ตามแนวทางปฏิบัติที่ดีที่สุดของ Anthropic ใช้เมื่อสร้างทักษะใหม่ แก้ไข skill-rules.json ทำความเข้าใจทริกเกอร์…
langfuse-prompt-migration
langfuse
โยกย้ายพรอมต์ที่ถูกเขียนตายตัวไปยัง Langfuse เพื่อการควบคุมเวอร์ชันและการปรับเปลี่ยนโดยไม่ต้องดีพลอย ใช้เมื่อผู้ใช้ต้องการทำให้พรอมต์เป็นภายนอก ย้ายพรอมต์ไปยัง Langfuse…
incident-alert-tickets
langfuse
Read and, after human approval, update the Linear `incident-alert` knowledge base. Use before and after investigating a named Datadog monitor,…
refactor-react-effects
langfuse
ปรับปรุงการใช้งาน React useEffect ที่ไม่จำเป็นในโค้ด frontend ของ Langfuse ใช้เมื่อเพิ่ม ตรวจสอบ หรือลบ effects; เริ่มต้นฟอร์มหรือ state ของ UI ในเครื่องจาก...
sentry-instrumentation
langfuse
Decide whether and how errors report to Sentry. Use when touching capture or error-handling paths in `web/**`, triaging Sentry noise, or changing Sentry…
posthog-instrumentation
langfuse
Product analytics with posthog. Use when adding a meaningful user action or feature in `web/**`, touching PostHog capture code, or answering product-usage…