warden-sweep
bởi sentry
Quét toàn bộ mã nguồn trong kho lưu trữ. Quét từng tệp bằng Warden, xác minh kết quả thông qua truy vết sâu, tạo PR nháp cho các vấn đề đã được xác thực. Sử dụng khi được yêu cầu…
npx skills add https://github.com/getsentry/warden --skill warden-sweepWarden Sweep
Run a full-repository Warden sweep: scan files, verify findings, create a tracking issue, open draft PRs for validated issues, and organize the final report.
Requires: warden, gh, git, jq, uv.
Run commands from the repository root. Use the host's skill-root path for bundled scripts and references.
Output goes to .warden/sweeps/<run-id>/.
References
Load only the reference for the current phase:
| Need | Read |
|---|---|
| Script arguments, outputs, and side effects | references/script-interfaces.md |
| Phase 1 scan workflow | references/scan-phase.md |
| Phase 2 verification workflow | references/verify-phase.md |
| Phase 3 tracking issue workflow | references/issue-phase.md |
| Phase 4 patch and draft PR workflow | references/patch-phase.md |
| Phase 5 organize and final report workflow | references/organize-phase.md |
| Resume behavior and artifact layout | references/resume-and-artifacts.md |
| Verification task prompt template | references/verify-prompt.md |
| Patch task prompt template | references/patch-prompt.md |
Workflow
Track progress across phases:
- Phase 1: Scan repository files with Warden.
- Phase 2: Verify findings before patching.
- Phase 3: Create a tracking issue.
- Phase 4: Patch verified findings and open draft PRs.
- Phase 5: Organize results and produce the final report.
Phase Order
- Read
references/script-interfaces.mdonce before running scripts. - Run Phase 1 from
references/scan-phase.md. SaverunIdandsweepDir. - Run Phase 2 from
references/verify-phase.md. Verify every finding before patching. - Run Phase 3 from
references/issue-phase.md. Continue if issue creation fails. - Run Phase 4 from
references/patch-phase.md. Patch sequentially, one finding at a time. - Run Phase 5 from
references/organize-phase.md. - For interrupted or partial runs, read
references/resume-and-artifacts.mdand continue from the first incomplete phase.
Non-Negotiable Rules
- Verify findings before creating fixes.
- Use draft PRs for generated patches.
- Branch every patch from the repository default branch.
- Patch findings sequentially; do not run patch workers in parallel.
- Skip existing entries in sweep artifacts instead of duplicating work.
- Record failures in sweep data and continue to the next finding when possible.
- Clean up each worktree after patch success or failure.
Final Response
After organizing, report:
## Sweep Complete
| Metric | Count |
|--------|-------|
| Files scanned | {filesScanned} |
| Findings verified | {verified} |
| PRs created | {prsCreated} |
| Security findings | {securityFindings} |
Full report: `{summaryPath}`