From 7a59cc4cf8bf2684b555e2c0590b0e3560e4994d Mon Sep 17 00:00:00 2001 From: Peli Date: Tue, 6 Oct 2026 11:01:16 -0700 Subject: [PATCH 1/5] Enable Rig bootstrap template and 1ES-compatible dependencies Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .../daily-rig-claude-compat.lock.yml | 6 +- .github/workflows/daily-rig-claude-compat.md | 6 +- .../workflows/rig-skill-integration.lock.yml | 18 +- .github/workflows/rig-skill-integration.md | 10 +- .github/workflows/shared/rig.md | 32 + AGENTS.md | 6 +- README.md | 57 +- docs/rig-api-review.md | 12 +- package-lock.json | 737 +++++++++--------- package.json | 9 +- skills/rig/SKILL.md | 26 +- skills/rig/{references => }/agent-api.md | 0 .../claude-workflow-conversion.md | 28 +- skills/rig/{references => }/composition.md | 0 .../rig/{references => }/dynamic-workflows.md | 14 +- skills/rig/{references => }/linting.md | 0 skills/rig/{references => }/prompt-intents.md | 0 skills/rig/{references => }/runtime.md | 48 +- src/rig-skill-workflow.test.ts | 5 +- src/skill.test.ts | 7 +- vitest.config.ts | 8 + 21 files changed, 586 insertions(+), 443 deletions(-) create mode 100644 .github/workflows/shared/rig.md rename skills/rig/{references => }/agent-api.md (100%) rename skills/rig/{references => }/claude-workflow-conversion.md (87%) rename skills/rig/{references => }/composition.md (100%) rename skills/rig/{references => }/dynamic-workflows.md (86%) rename skills/rig/{references => }/linting.md (100%) rename skills/rig/{references => }/prompt-intents.md (100%) rename skills/rig/{references => }/runtime.md (91%) diff --git a/.github/workflows/daily-rig-claude-compat.lock.yml b/.github/workflows/daily-rig-claude-compat.lock.yml index 41b61a4..219a3bd 100644 --- a/.github/workflows/daily-rig-claude-compat.lock.yml +++ b/.github/workflows/daily-rig-claude-compat.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e37aed8a6fa38190a46f6d50d5402773a3c1cf357f4c24f9ba33451efb30d62e","body_hash":"0bee5677caf760a87044da948274b08b94e4f50ea5a06085aafaa3d19b49921c","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-4.6","engine_versions":{"copilot":"1.0.92"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8263f85ec06c561b928ed116dfdc81c523cfeecc96d61b38a8284f2e88d80d75","body_hash":"2f25f0d3965d687fb0f9dc0bbad1cabc4bc2c769641a5e9ebcab2de7f49bc444","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"claude-sonnet-4.6","engine_versions":{"copilot":"1.0.92"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_CI_TRIGGER_TOKEN","GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.31","digest":"sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.31@sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"safeoutputs","tools":["create_pull_request","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -568,7 +568,7 @@ jobs: env: GH_AW_FILE_ROOT: "${{ runner.temp }}/gh-aw" GH_AW_FILE_CONFIG: "{\"files\":[{\"path\":\"safeoutputs/config.json\",\"content_env\":\"GH_AW_SAFE_OUTPUTS_CONFIG\"}]}" - GH_AW_SAFE_OUTPUTS_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/references/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" with: script: | const path = require('path'); @@ -1956,7 +1956,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "*.githubusercontent.com,api.npms.io,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,bun.sh,cdn.jsdelivr.net,codeload.github.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,deb.nodesource.com,deno.land,docs.github.com,esm.sh,get.pnpm.io,github-cloud.githubusercontent.com,github-cloud.s3.amazonaws.com,github.blog,github.com,github.githubassets.com,googleapis.deno.dev,googlechromelabs.github.io,json-schema.org,json.schemastore.org,jsr.io,keyserver.ubuntu.com,lfs.github.com,nodejs.org,npm.pkg.github.com,npmjs.com,npmjs.org,objects.githubusercontent.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,patch-diff.githubusercontent.com,patchdiff.githubusercontent.com,ppa.launchpad.net,raw.githubusercontent.com,registry.bower.io,registry.npmjs.com,registry.npmjs.org,registry.yarnpkg.com,repo.yarnpkg.com,s.symcb.com,s.symcd.com,security.ubuntu.com,skimdb.npmjs.com,storage.googleapis.com,telemetry.vercel.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com,www.npmjs.com,www.npmjs.org,yarnpkg.com" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/references/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_pull_request\":{\"allowed_files\":[\"README.md\",\"skills/rig/SKILL.md\",\"skills/rig/*.md\",\"skills/rig/samples/*.md\",\"skills/rig/rig.ts\",\"skills/rig/engines/anthropic.ts\",\"src/workflow.test.ts\",\"src/rig.test.ts\",\"src/engines/anthropic.test.ts\"],\"draft\":true,\"labels\":[\"automation\",\"ai-agent\"],\"max\":1,\"max_patch_files\":40,\"max_patch_size\":4096,\"protect_top_level_dot_folders\":true,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"CODEOWNERS\",\"DESIGN.md\",\"README.md\",\"CONTRIBUTING.md\",\"SECURITY.md\",\"CODE_OF_CONDUCT.md\",\"AGENTS.md\"],\"protected_files_policy\":\"request-review\",\"reviewers\":[\"copilot\"],\"title_prefix\":\"[rig-claude] \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":2,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}" GH_AW_CI_TRIGGER_TOKEN: ${{ secrets.GH_AW_CI_TRIGGER_TOKEN }} with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/daily-rig-claude-compat.md b/.github/workflows/daily-rig-claude-compat.md index e651084..87e1d4d 100644 --- a/.github/workflows/daily-rig-claude-compat.md +++ b/.github/workflows/daily-rig-claude-compat.md @@ -46,7 +46,7 @@ safe-outputs: allowed-files: - "README.md" - "skills/rig/SKILL.md" - - "skills/rig/references/*.md" + - "skills/rig/*.md" - "skills/rig/samples/*.md" - "skills/rig/rig.ts" - "skills/rig/engines/anthropic.ts" @@ -66,8 +66,8 @@ Read these files before deciding whether to edit anything: - `README.md` - `skills/rig/SKILL.md` -- `skills/rig/references/dynamic-workflows.md` -- `skills/rig/references/claude-workflow-conversion.md` +- `skills/rig/dynamic-workflows.md` +- `skills/rig/claude-workflow-conversion.md` - `skills/rig/rig.ts` - `skills/rig/engines/anthropic.ts` - `src/workflow.test.ts` diff --git a/.github/workflows/rig-skill-integration.lock.yml b/.github/workflows/rig-skill-integration.lock.yml index d17e40d..e6b0fb8 100644 --- a/.github/workflows/rig-skill-integration.lock.yml +++ b/.github/workflows/rig-skill-integration.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"8e266e9f7a66edd0057ec75a6bef022bff9d3cdcb1a01df6fbfd9e3fe856c7d8","body_hash":"6f4dc2fcc0ba95073a0f1f0179efb77ab15c2f021309cf526077ab8622f8517d","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e50526a75587fd43d87cf87ea56655af22d5f834a95ed1d045878a03dbcc2e06","body_hash":"69d4e81f5870a7eb023ebcefa647f886f3e32f91609bc34646cf1f94c95339a4","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"skills":["skills/rig"],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_me","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"safeoutputs","tools":["create_issue","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -27,6 +27,10 @@ # # Intent: Detect regressions in the Rig skill's ability to run typed judgments through the Copilot SDK. # +# Resolved workflow manifest: +# Imports: +# - shared/rig.md +# # Frontmatter env variables: # - RIG_DEBUG: (main workflow) # @@ -301,7 +305,7 @@ jobs: GH_AW_ACTIONS_DIR: ${{ runner.temp }}/gh-aw/actions GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt GH_AW_SAFE_OUTPUTS: ${{ runner.temp }}/gh-aw/safeoutputs/outputs.jsonl - GH_AW_PROMPT_CONFIG: "{\"items\":[{\"content_env\":\"GH_AW_PROMPT_CONTENT_0000\"},{\"file\":\"xpia.md\"},{\"file\":\"temp_folder_prompt.md\"},{\"file\":\"markdown.md\"},{\"file\":\"safe_outputs_mcp_transport_prompt.md\"},{\"file\":\"safe_outputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0001\"},{\"file\":\"safe_outputs_auto_create_issue.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0002\"},{\"file\":\"mcp_cli_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0003\"},{\"file\":\"github_mcp_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0004\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0005\"}],\"system_item_count\":13}" + GH_AW_PROMPT_CONFIG: "{\"items\":[{\"content_env\":\"GH_AW_PROMPT_CONTENT_0000\"},{\"file\":\"xpia.md\"},{\"file\":\"temp_folder_prompt.md\"},{\"file\":\"markdown.md\"},{\"file\":\"safe_outputs_mcp_transport_prompt.md\"},{\"file\":\"safe_outputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0001\"},{\"file\":\"safe_outputs_auto_create_issue.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0002\"},{\"file\":\"mcp_cli_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0003\"},{\"file\":\"github_mcp_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0004\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0005\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0006\"}],\"system_item_count\":13}" GH_AW_EXPR_76DF9333: ${{ github.event.pull_request.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'pull_request' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} GH_AW_EXPR_77C1A4D2: ${{ github.event.comment.id || fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').comment_id }} GH_AW_EXPR_7C248226: ${{ github.event.issue.number || (fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_type == 'issue' && fromJSON(steps.generate_aw_info.outputs.aw_context || '{}').item_number) }} @@ -315,7 +319,8 @@ jobs: GH_AW_PROMPT_CONTENT_0002: "\n" GH_AW_PROMPT_CONTENT_0003: "\nThe following GitHub context information is available for this workflow:\n{{#if github.actor}}\n- **actor**: __GH_AW_GITHUB_ACTOR__\n{{/if}}\n{{#if github.repository}}\n- **repository**: __GH_AW_GITHUB_REPOSITORY__\n{{/if}}\n{{#if github.workspace}}\n- **workspace**: __GH_AW_GITHUB_WORKSPACE__\n{{/if}}\n{{#if github.event.issue.number || (github.aw.context.item_type == 'issue' && github.aw.context.item_number)}}\n- **issue-number**: #__GH_AW_EXPR_7C248226__\n{{/if}}\n{{#if github.event.discussion.number || (github.aw.context.item_type == 'discussion' && github.aw.context.item_number)}}\n- **discussion-number**: #__GH_AW_EXPR_C19C384F__\n{{/if}}\n{{#if github.event.pull_request.number || (github.aw.context.item_type == 'pull_request' && github.aw.context.item_number)}}\n- **pull-request-number**: #__GH_AW_EXPR_76DF9333__\n{{/if}}\n{{#if github.event.comment.id || github.aw.context.comment_id}}\n- **comment-id**: __GH_AW_EXPR_77C1A4D2__\n{{/if}}\n{{#if github.run_id}}\n- **workflow-run-id**: __GH_AW_GITHUB_RUN_ID__\n{{/if}}\n\n\n" GH_AW_PROMPT_CONTENT_0004: "\n" - GH_AW_PROMPT_CONTENT_0005: "{{#runtime-import .github/workflows/rig-skill-integration.md}}\n" + GH_AW_PROMPT_CONTENT_0005: "{{#runtime-import .github/workflows/shared/rig.md}}\n" + GH_AW_PROMPT_CONTENT_0006: "{{#runtime-import .github/workflows/rig-skill-integration.md}}\n" with: script: | const { setupGlobals } = require(process.env.GH_AW_ACTIONS_DIR + '/setup_globals.cjs'); @@ -507,6 +512,11 @@ jobs: evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" + - name: Setup Node.js + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: '24' + package-manager-cache: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -1718,7 +1728,7 @@ jobs: if [[ ! "$GH_AW_MAX_AI_CREDITS" =~ ^[0-9]+$ ]]; then GH_AW_MAX_AI_CREDITS="400" fi - printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.28.31/awf-config.schema.json\",\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-6\",\"gpt-5.4\",\"gpt-5.5\",\"gpt-5.6\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"auto\":[\"copilot/auto\",\"large\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"detection\":[\"small\"],\"evals\":[\"small\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-3.6-flash\":[\"copilot/gemini-3.6*flash*\",\"google/gemini-3.6*flash*\",\"gemini/gemini-3.6*flash*\"],\"gemini-3.7-flash\":[\"copilot/gemini-3.7*flash*\",\"google/gemini-3.7*flash*\",\"gemini/gemini-3.7*flash*\"],\"gemini-3.8-flash\":[\"copilot/gemini-3.8*flash*\",\"google/gemini-3.8*flash*\",\"gemini/gemini-3.8*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"gpt-6\":[\"copilot/gpt-6*\",\"openai/gpt-6*\"],\"grok\":[\"copilot/*grok*\",\"openai/*grok*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"sonnet\",\"gpt-6\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"raptor-mini\":[\"copilot/raptor*\",\"openai/raptor*\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-5*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\",\"anthropic/*sonnet-5*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.28.31,squid=sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d,agent=sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76,api-proxy=sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a,cli-proxy=sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" + printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.28.31/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"api.npms.io\",\"bun.sh\",\"cdn.jsdelivr.net\",\"deb.nodesource.com\",\"deno.land\",\"esm.sh\",\"get.pnpm.io\",\"googleapis.deno.dev\",\"googlechromelabs.github.io\",\"jsr.io\",\"nodejs.org\",\"npm.pkg.github.com\",\"npmjs.com\",\"npmjs.org\",\"registry.bower.io\",\"registry.npmjs.com\",\"registry.npmjs.org\",\"registry.yarnpkg.com\",\"repo.yarnpkg.com\",\"skimdb.npmjs.com\",\"storage.googleapis.com\",\"telemetry.vercel.com\",\"www.npmjs.com\",\"www.npmjs.org\",\"yarnpkg.com\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-6\",\"gpt-5.4\",\"gpt-5.5\",\"gpt-5.6\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"auto\":[\"copilot/auto\",\"large\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"detection\":[\"small\"],\"evals\":[\"small\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-3.6-flash\":[\"copilot/gemini-3.6*flash*\",\"google/gemini-3.6*flash*\",\"gemini/gemini-3.6*flash*\"],\"gemini-3.7-flash\":[\"copilot/gemini-3.7*flash*\",\"google/gemini-3.7*flash*\",\"gemini/gemini-3.7*flash*\"],\"gemini-3.8-flash\":[\"copilot/gemini-3.8*flash*\",\"google/gemini-3.8*flash*\",\"gemini/gemini-3.8*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"gpt-6\":[\"copilot/gpt-6*\",\"openai/gpt-6*\"],\"grok\":[\"copilot/*grok*\",\"openai/*grok*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"sonnet\",\"gpt-6\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"raptor-mini\":[\"copilot/raptor*\",\"openai/raptor*\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-5*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\",\"anthropic/*sonnet-5*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.28.31,squid=sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d,agent=sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76,api-proxy=sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a,cli-proxy=sha256:505df66052e6688cf419ad248a511d17093475bd66a958618078d3c9cdf95083\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" GH_AW_DOCKER_HOST="" diff --git a/.github/workflows/rig-skill-integration.md b/.github/workflows/rig-skill-integration.md index 8645d49..340e8b3 100644 --- a/.github/workflows/rig-skill-integration.md +++ b/.github/workflows/rig-skill-integration.md @@ -15,6 +15,8 @@ engine: copilot-sdk: true skills: - skills/rig +imports: + - shared/rig.md strict: true timeout-minutes: 10 env: @@ -22,8 +24,6 @@ env: tools: bash: ["node"] edit: false -network: - allowed: [defaults, github, node] safe-outputs: noop: report-as-issue: false @@ -51,10 +51,10 @@ post-steps: Read the installed Rig skill and its running/engines reference. Run the following `rig` fence **once**, unchanged, using the installed skill's launcher in inline -mode. First generate a fresh delimiter: `RIG_` followed by -`randomBytes(16).toString("hex")` from Node's `node:crypto`. Verify it is not a +mode. First generate a fresh 7-character pseudo-random alphanumeric delimiter +without a tool call. Verify it is not a complete line of the fence contents; regenerate on collision. Use -`node /run.ts <<'RIG_'`, substituting the +`node /run.ts <<''`, substituting the generated literal in both the single-quoted opener and the unquoted, unindented closing line. Never use a fixed delimiter or a shell variable. Redirect stdout to `/tmp/gh-aw/agent/rig-skill-integration.json`. diff --git a/.github/workflows/shared/rig.md b/.github/workflows/shared/rig.md new file mode 100644 index 0000000..92be3de --- /dev/null +++ b/.github/workflows/shared/rig.md @@ -0,0 +1,32 @@ +--- +runtimes: + node: + version: "24" +tools: + bash: ["node"] +network: + allowed: [defaults, github, node] +--- + + + + +Load the installed `rig` skill and read its Running and engines reference before +creating or running Rig programs. +Run Rig programs with Node.js 24 or later using the installed skill's `run.ts` +launcher and host-provisioned dependencies. Do not install packages from the +agent prompt; report missing dependencies and stop. Use heredocs and redirections +for inline programs and output files, following the skill's fresh-delimiter rules. +Read only named environment variables needed by the program; do not dump the +environment or print credentials. + +When using the Copilot SDK engine, inherit `COPILOT_SDK_URI` and +`COPILOT_CONNECTION_TOKEN`; do not start another server or use `--server`. +If a command is denied, report that specific command, not that all shell access +is unavailable. Do not replace a failed run with fabricated output. + diff --git a/AGENTS.md b/AGENTS.md index 2f5b753..5b383d2 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -9,7 +9,7 @@ Rig is a minimal TypeScript agent harness. The core runtime (`skills/rig/rig.ts` ``` skills/rig/rig.ts — Core runtime (agent, p, copilotEngine, schemas) skills/rig/samples/ — 51 sample agents demonstrating patterns -skills/rig/references/ — Focused documentation loaded on demand from SKILL.md +skills/rig/ — Focused documentation loaded on demand from SKILL.md src/engines/copilot.test.ts — Copilot engine unit tests (vitest) src/rig.test.ts — Unit tests (vitest) scripts/run-sample.test.ts — Sample runner with a stub Copilot SDK client (dry-run) @@ -42,13 +42,13 @@ All imports use the `"rig"` path alias (resolved via tsconfig paths + vitest ali - Treat `skills/rig/SKILL.md` as prompt context: keep only high-frequency construction rules, decisions, and a minimal canonical example. - Target roughly 200 lines or fewer. Use line/word/byte counts as regression signals, not as a reason to compress prose until it is unclear. -- Put detailed API tables, edge cases, provider behavior, and scenario-specific patterns in focused files under `skills/rig/references/`. +- Put detailed API tables, edge cases, provider behavior, and scenario-specific patterns in focused files under `skills/rig/`. - Route every reference from `SKILL.md` with a short “read when” description so an agent can load only the relevant secondary context. - Prefer one representative example, decision tables, and checklists over repeated prose. Remove duplication before adding guidance. - Keep each fact canonical. A compact rule may be summarized in `SKILL.md`, but its examples and edge cases should live in one reference file. - Add new material to `SKILL.md` only when it changes how most Rig programs should be generated; otherwise update or add a focused reference. - When the API changes, update the affected reference and then audit `SKILL.md`, `README.md`, and samples for stale summaries or links. -- Before finishing documentation changes, verify relative links and compare `wc -l -w -c skills/rig/SKILL.md skills/rig/references/*.md` with the previous version. +- Before finishing documentation changes, verify relative links and compare `wc -l -w -c skills/rig/*.md` with the previous version. ## Testing diff --git a/README.md b/README.md index a576594..0a5fd9b 100644 --- a/README.md +++ b/README.md @@ -22,13 +22,34 @@ checkout; for an installed skill, substitute its directory for `skills/rig`. `skills/rig/SKILL.md` is the canonical, publishable skill manifest. +To run from a checkout: + +```bash +git clone https://github.com/githubnext/rig.git +cd rig +npm ci +``` + +On the Microsoft network or VPN, use the 1ES public npm feed without changing +your npm configuration: + +```bash +npm ci --registry=https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/ --replace-registry-host=npmjs +``` + +The dependency overrides pin compatible versions available in that feed, +including Vite and its test/build dependencies. When updating them, verify both +package metadata and tarball availability before refreshing the lockfile. + ## Use Rig in 2 ways ### 1) As a skill for Rig programs that use the Copilot SDK -Pin the skill in your workflow: +Pin the skill and shared launcher template in your workflow: ```yaml +imports: + - githubnext/rig/.github/workflows/shared/rig.md@ engine: id: copilot copilot-sdk: true @@ -38,7 +59,11 @@ tools: bash: ["node"] ``` -Only `node` needs a Bash grant to launch the installed skill. +The [shared Rig template](.github/workflows/shared/rig.md) provisions Node.js 24 +and allows `node`. In this repository, import +`shared/rig.md` instead. Without the template, configure these prerequisites +explicitly; see the [runtime reference](skills/rig/runtime.md#github-agentic-workflows). +Grant `copilot-requests: write` and provision the skill's dependencies in the host. Use heredocs or redirections rather than `cat`/`echo` pipelines. Grant additional commands only for the program's own tool calls. This is a smaller tool allowlist, not a security boundary: Node can still start subprocesses. @@ -92,24 +117,24 @@ supported provider API-key variables. Without those settings it uses Copilot over HTTP at `localhost:7777`. To have the launcher start Copilot over stdio, append `--server` to a run command; this requires an installed, authenticated Copilot CLI. Other engines require their SDK dependencies or CLI and credentials; -see the [runtime reference](skills/rig/references/runtime.md). -Its [integration guide](skills/rig/references/runtime.md#choosing-an-integration) +see the [runtime reference](skills/rig/runtime.md). +Its [integration guide](skills/rig/runtime.md#choosing-an-integration) compares engine capabilities, model selection, tool ownership, and output enforcement. -For every heredoc below, replace `RIG_` with a fresh `RIG_` -delimiter generated using `node:crypto`'s `randomBytes(16).toString("hex")`. +For every heredoc below, replace `` with a fresh 7-character +pseudo-random alphanumeric string; no tool call is needed to generate it. Check it is not an entire line of the contents, single-quote the opener, and repeat the exact unquoted delimiter alone on the closing line. See the -[inline-program guide](skills/rig/references/runtime.md#inline-programs) for the -generation command; do not reuse fixed delimiters or shell variables. +[inline-program guide](skills/rig/runtime.md#inline-programs) for the +delimiter rules; do not reuse fixed delimiters or shell variables. **Design on the fly** — just describe what you want as a string and let the model figure out the rest: ```bash -node skills/rig/run.ts <<'RIG_' +node skills/rig/run.ts <<'' export default "Run npm test, diagnose any failures, apply the smallest safe fix, and repeat up to 3 times."; -RIG_ + ``` Or ask Copilot (with the skill) to generate a full program for you. Describe your goal in natural language and Copilot returns a runnable `rig` markdown fence like this: @@ -144,17 +169,17 @@ export default ralfLoop; Pass the fence contents directly to the launcher with a heredoc: ```bash -node skills/rig/run.ts <<'RIG_' +node skills/rig/run.ts <<'' // Paste the rig fence contents here. -RIG_ + ``` Or run a program file: ```bash -node skills/rig/run.ts src/program.ts <<'RIG_' +node skills/rig/run.ts src/program.ts <<'' Review this diff -RIG_ + ``` Use `--typecheck` to validate a program without running it: @@ -170,6 +195,6 @@ tree; Rig does not download it or invoke npm/npx. ## Docs See [skills/rig/SKILL.md](skills/rig/SKILL.md) for construction rules, -[skills/rig/references/runtime.md](skills/rig/references/runtime.md) for launcher and engine details, and -[skills/rig/references/claude-workflow-conversion.md](skills/rig/references/claude-workflow-conversion.md) +[skills/rig/runtime.md](skills/rig/runtime.md) for launcher and engine details, and +[skills/rig/claude-workflow-conversion.md](skills/rig/claude-workflow-conversion.md) for porting Claude Code dynamic workflows to rig. diff --git a/docs/rig-api-review.md b/docs/rig-api-review.md index 1f36d19..54c03fb 100644 --- a/docs/rig-api-review.md +++ b/docs/rig-api-review.md @@ -42,7 +42,7 @@ scripts, which is the primary reason the workflow layer exists. | `budget.total/spent()/remaining()` | Direct Claude parity, even though rig meters agent calls rather than tokens. | **Recommendation:** document these four explicitly as "intentional parity -duplicates" in `references/claude-workflow-conversion.md` so future reviews do +duplicates" in `skills/rig/claude-workflow-conversion.md` so future reviews do not try to collapse them. ## 3. Duplication that should be removed @@ -167,7 +167,7 @@ caveat that `.use()` accepts *only* addons. ## 5. Claude background-workflow compatibility checklist Every proposal above was checked against the Claude primitive mapping in -`references/claude-workflow-conversion.md`: +`skills/rig/claude-workflow-conversion.md`: | Proposal | Claude primitive affected | Verdict | | --- | --- | --- | @@ -246,7 +246,7 @@ churn to a single reviewable PR. ## 8. Related references -- [Converting Claude dynamic workflows to rig](../skills/rig/references/claude-workflow-conversion.md) -- [Dynamic workflows](../skills/rig/references/dynamic-workflows.md) -- [Agent API and schemas](../skills/rig/references/agent-api.md) -- [Prompt intents](../skills/rig/references/prompt-intents.md) +- [Converting Claude dynamic workflows to rig](../skills/rig/claude-workflow-conversion.md) +- [Dynamic workflows](../skills/rig/dynamic-workflows.md) +- [Agent API and schemas](../skills/rig/agent-api.md) +- [Prompt intents](../skills/rig/prompt-intents.md) diff --git a/package-lock.json b/package-lock.json index d0ce832..c54f2cd 100644 --- a/package-lock.json +++ b/package-lock.json @@ -12,6 +12,7 @@ "@github/copilot-sdk": "^1.0.16", "@openai/codex-sdk": "^0.159.0", "@types/node": "^25.9.1", + "postcss": "8.5.28", "source-map-js": "file:packages/source-map-compat", "typescript": "^5.8.0", "vitest": "^4.1.11", @@ -1613,16 +1614,6 @@ "node": ">=16" } }, - "node_modules/@oxc-project/types": { - "version": "0.152.0", - "resolved": "https://registry.npmjs.org/@oxc-project/types/-/types-0.152.0.tgz", - "integrity": "sha512-oM/5rLBm2tPkg0iBgkH/FOeR3PCDpY19GTgAZjMFM8h9WI9VW7cLgzp6nwtarYKmovavIQZ+Fe/RKX/8C8O/Rw==", - "dev": true, - "license": "MIT", - "funding": { - "url": "https://github.com/sponsors/oxc-project" - } - }, "node_modules/@protobufjs/aspromise": { "version": "1.1.2", "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@protobufjs/aspromise/-/aspromise-1.1.2.tgz", @@ -1689,279 +1680,6 @@ "dev": true, "license": "BSD-3-Clause" }, - "node_modules/@rolldown/binding-android-arm-eabi": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.12.tgz", - "integrity": "sha512-dB/a1214qKfHMXCpgqR4OZT+jS4kTyEXbQGJPqzobt5EwH5rX080pxE37alt3RzvR1bf1Yz/yGqRfrYAxuPw0A==", - "cpu": [ - "arm" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "android" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-android-arm64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.12.tgz", - "integrity": "sha512-7KHFgQ5VJxIHcLlrwrc3Xbds7oTNQT7Pgi9gQCJKrd2VGab/UksIOYp6VD8MzCstGxOKMgNamPwUCfxPdP1OHg==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "android" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-darwin-arm64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.12.tgz", - "integrity": "sha512-3YIhqHD96nA5SaYNRBR16HnGv4oavZvXfD/ayHM+oYZ0WD/8lBAtf6zQua4kEyAvpqrluKXl0lnOBoiNby7x9w==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "darwin" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-darwin-x64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.12.tgz", - "integrity": "sha512-UuuJ35MFw4gmFOrE9pEqIV+K3syIKveph+Qc1/ljHZVdoDW4pz/JHR/eMVom+TZGl/5OOvGJOWaOCVt3ZfqhxA==", - "cpu": [ - "x64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "darwin" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-freebsd-x64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.12.tgz", - "integrity": "sha512-uMvssit0a4W+/7D8CbHUvG719mH3R2jwXAlh/XcPvuHTE0g++LymF88DCGNX0HM2rBOn0xrzgXktIB6fLSJBTQ==", - "cpu": [ - "x64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "freebsd" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-arm-gnueabihf": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.12.tgz", - "integrity": "sha512-XcFu0R0xWnwzSf4IQgFH1rJIckPN1pLy2R+4r9IDB7Yfu/ys9cVqfa4pBrMHj7a3gl8mIR4nRNPg0e5IvEVs6g==", - "cpu": [ - "arm" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-arm64-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.12.tgz", - "integrity": "sha512-260UrKgn8tz39ak+SMDOirKzr7V04M9dWPw5llW00SwBivCZoWcRBKV1d8cXnRkUmSZA3BdiUmBHWk7734Ulpw==", - "cpu": [ - "arm64" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-arm64-musl": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.12.tgz", - "integrity": "sha512-5YK1I9SqDkbPgc1IA8BgDl34suqUS2q0KWnBrirm0E51YjOs6eo6dV6jbQfNE/argHRSvd0QUGgtpIoYx+WWpw==", - "cpu": [ - "arm64" - ], - "dev": true, - "libc": [ - "musl" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-ppc64-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.12.tgz", - "integrity": "sha512-Rkcrmp7eFRg74yL5fXEU91JEWbdEPLevWwGtXpmhbjlD1StScbWTmO94Bhly+Mo+ketKYkdmM1vNUKeWSlx8cQ==", - "cpu": [ - "ppc64" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-s390x-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.12.tgz", - "integrity": "sha512-qvK4DuAsQc2BSjlx+Xr+IzOIvvxbGZqxFwdWfG6F518Erj0GGISyQbJ6pIappnOxlNPzNHvo/L0BwB30GZ+zVw==", - "cpu": [ - "s390x" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-x64-gnu": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.12.tgz", - "integrity": "sha512-Q9uLBO53Xd4QIq1WOycVQyPP1O4HhraEV2qqb3uTrnVw6QZih9duY4vNXOivL1xoUS1/z+W8eF4NMfl2a8Sdjw==", - "cpu": [ - "x64" - ], - "dev": true, - "libc": [ - "glibc" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-linux-x64-musl": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.12.tgz", - "integrity": "sha512-3IBxWFMjbOZskDPKv8Lf9BCnahlKuHthWkYnyIxOH/QcJrFcS4EmcenthApkwr/5+nEqZlLzeYbxeMaX7A5u4g==", - "cpu": [ - "x64" - ], - "dev": true, - "libc": [ - "musl" - ], - "license": "MIT", - "optional": true, - "os": [ - "linux" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-openharmony-arm64": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.12.tgz", - "integrity": "sha512-xtX61xg4LKPkPWilZU1ynKClz5Gj4bf74LML4r3eVLWumKnGjoEr1OSHQhMdbBDoYTi+yjrujvpZe2pUnqCrrA==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "openharmony" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-win32-arm64-msvc": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.12.tgz", - "integrity": "sha512-At7fPB6PCaIjzgIhEZFxuT+BBFqiQibJDT4d3PhiR3f4E7bbMZF4aKblbFfEM3sETRDd1YiQx/+U/g/B/ou5Ew==", - "cpu": [ - "arm64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "win32" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, - "node_modules/@rolldown/binding-win32-x64-msvc": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.12.tgz", - "integrity": "sha512-WIw2haVKwjuYdXkHaoC0mF8Le71TuCBxjrdKqLbJGctbBABj+ClfmNvtbOnzpq3RokNo5+V1qhtSzJyXorsklQ==", - "cpu": [ - "x64" - ], - "dev": true, - "license": "MIT", - "optional": true, - "os": [ - "win32" - ], - "engines": { - "node": "^20.19.0 || >=22.12.0" - } - }, "node_modules/@rolldown/pluginutils": { "version": "1.0.1", "resolved": "https://registry.npmjs.org/@rolldown/pluginutils/-/pluginutils-1.0.1.tgz", @@ -2130,6 +1848,26 @@ "url": "https://opencollective.com/vitest" } }, + "node_modules/@vitest/expect/node_modules/chai": { + "version": "6.2.2", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/chai/-/chai-6.2.2.tgz", + "integrity": "sha1-rkG1LJrKh3NFBTYnF/MlX6zaNg4=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=18" + } + }, + "node_modules/@vitest/expect/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/@vitest/mocker": { "version": "4.1.11", "resolved": "https://registry.npmjs.org/@vitest/mocker/-/mocker-4.1.11.tgz", @@ -2170,6 +1908,16 @@ "url": "https://opencollective.com/vitest" } }, + "node_modules/@vitest/pretty-format/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/@vitest/runner": { "version": "4.1.11", "resolved": "https://registry.npmjs.org/@vitest/runner/-/runner-4.1.11.tgz", @@ -2225,6 +1973,16 @@ "url": "https://opencollective.com/vitest" } }, + "node_modules/@vitest/utils/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/agent-base": { "version": "9.0.0", "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/agent-base/-/agent-base-9.0.0.tgz", @@ -2290,16 +2048,6 @@ "dev": true, "license": "BSD-3-Clause" }, - "node_modules/chai": { - "version": "6.3.0", - "resolved": "https://registry.npmjs.org/chai/-/chai-6.3.0.tgz", - "integrity": "sha512-XWAtwJ6OHO+tj0EKCs0Y2UamnyOxseZWltU4x2U2wh8g4AigdjwvtUjvLP2tqkA/avxHEtzxNaqGq/YGNwckKg==", - "dev": true, - "license": "MIT", - "engines": { - "node": ">=18" - } - }, "node_modules/convert-source-map": { "version": "2.0.0", "resolved": "https://registry.npmjs.org/convert-source-map/-/convert-source-map-2.0.0.tgz", @@ -3016,9 +2764,9 @@ "license": "MIT" }, "node_modules/nanoid": { - "version": "3.3.20", - "resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.20.tgz", - "integrity": "sha512-uKdg2G3GNCKQn9byYOpxbGqrT2fGO5KRt5J/8b3pok8rT6qxGWF6hxMyJiEYtAf+FVyYuD9hRaDqX5uPFYJ4ZQ==", + "version": "3.3.19", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/nanoid/-/nanoid-3.3.19.tgz", + "integrity": "sha512-Y2tUNy4ouw6tq5oDSKeQYGOyhkUBhNOcGV/02KC+6kd9eDGqdZd++mjMiIDilrBYvjEnCYvVtsuHCuP+okSfug==", "dev": true, "funding": [ { @@ -3153,9 +2901,9 @@ } }, "node_modules/postcss": { - "version": "8.5.29", - "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.29.tgz", - "integrity": "sha512-49cGhUbXj8Qenv0iTMxA1cFBzxXoctpC9Ujd77t1WcbJIr6nF/eI7g/8MgxrYldFRuAXvja7xQRwavoW7kgrxQ==", + "version": "8.5.28", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/postcss/-/postcss-8.5.28.tgz", + "integrity": "sha1-2kVjqZoG5i1sHNGsrjYyJLyu1uk=", "dev": true, "funding": [ { @@ -3173,9 +2921,9 @@ ], "license": "MIT", "dependencies": { - "nanoid": "^3.3.19", + "nanoid": "^3.3.18", "picocolors": "^1.1.1", - "source-map-js": "^1.2.2" + "source-map-js": "^1.2.1" }, "engines": { "node": "^10 || ^12 || >=14" @@ -3233,44 +2981,10 @@ "node": ">= 4" } }, - "node_modules/rolldown": { - "version": "1.2.12", - "resolved": "https://registry.npmjs.org/rolldown/-/rolldown-1.2.12.tgz", - "integrity": "sha512-8wafseiaG80xmXSfqidUNqZcylTlhmPZZt+za2m+js2sFZ8dTNlhIOV2WcbIPx2hgwPBJpEUGFAMZ9bgBBLTSQ==", - "dev": true, - "license": "MIT", - "dependencies": { - "@oxc-project/types": "=0.152.0", - "@rolldown/pluginutils": "^1.0.0" - }, - "bin": { - "rolldown": "bin/cli.mjs" - }, - "engines": { - "node": "^20.19.0 || >=22.12.0" - }, - "optionalDependencies": { - "@rolldown/binding-android-arm-eabi": "1.2.12", - "@rolldown/binding-android-arm64": "1.2.12", - "@rolldown/binding-darwin-arm64": "1.2.12", - "@rolldown/binding-darwin-x64": "1.2.12", - "@rolldown/binding-freebsd-x64": "1.2.12", - "@rolldown/binding-linux-arm-gnueabihf": "1.2.12", - "@rolldown/binding-linux-arm64-gnu": "1.2.12", - "@rolldown/binding-linux-arm64-musl": "1.2.12", - "@rolldown/binding-linux-ppc64-gnu": "1.2.12", - "@rolldown/binding-linux-s390x-gnu": "1.2.12", - "@rolldown/binding-linux-x64-gnu": "1.2.12", - "@rolldown/binding-linux-x64-musl": "1.2.12", - "@rolldown/binding-openharmony-arm64": "1.2.12", - "@rolldown/binding-win32-arm64-msvc": "1.2.12", - "@rolldown/binding-win32-x64-msvc": "1.2.12" - } - }, - "node_modules/safe-buffer": { - "version": "5.2.1", - "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/safe-buffer/-/safe-buffer-5.2.1.tgz", - "integrity": "sha1-Hq+fqb2x/dTsdfWPnNtOa3gn7sY=", + "node_modules/safe-buffer": { + "version": "5.2.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/safe-buffer/-/safe-buffer-5.2.1.tgz", + "integrity": "sha1-Hq+fqb2x/dTsdfWPnNtOa3gn7sY=", "dev": true, "funding": [ { @@ -3358,16 +3072,6 @@ "url": "https://github.com/sponsors/SuperchupuDev" } }, - "node_modules/tinyrainbow": { - "version": "3.2.0", - "resolved": "https://registry.npmjs.org/tinyrainbow/-/tinyrainbow-3.2.0.tgz", - "integrity": "sha512-LgO3D9yZJjApUiuUfl9iFAwrtaX4+lok3wJIqttGoKCHlWUqHqbQpnxCf82L8FjgKsh4iGo78hqJwgL8F6To2A==", - "dev": true, - "license": "MIT", - "engines": { - "node": ">=14.0.0" - } - }, "node_modules/ts-algebra": { "version": "2.0.0", "resolved": "https://registry.npmjs.org/ts-algebra/-/ts-algebra-2.0.0.tgz", @@ -3411,16 +3115,16 @@ "license": "MIT" }, "node_modules/vite": { - "version": "8.3.3", - "resolved": "https://registry.npmjs.org/vite/-/vite-8.3.3.tgz", - "integrity": "sha512-cTAldKPImjg6c+gk48U19POPn3GCBzZwpdsN8ZMEEcbpes+6/wvfqUd0C2y3qYY4wsj8PwgFwrZ/1jBPVttMSg==", + "version": "8.3.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/vite/-/vite-8.3.1.tgz", + "integrity": "sha512-/bvH9E9tmCXRGp2uXY3WbOldqpTwFkbha/8ANaEQ6VkxhH60KyqLwgZq6lG2y+4uT55x9+9eUHMpQ7uGnOCKjA==", "dev": true, "license": "MIT", "dependencies": { "lightningcss": "^1.33.0", "picomatch": "^4.0.7", "postcss": "^8.5.28", - "rolldown": "~1.2.11", + "rolldown": "~1.2.9", "tinyglobby": "^0.2.17" }, "bin": { @@ -3488,6 +3192,323 @@ } } }, + "node_modules/vite/node_modules/@oxc-project/types": { + "version": "0.151.0", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@oxc-project/types/-/types-0.151.0.tgz", + "integrity": "sha512-J1yXrIlNDZVzE3ada310xeAw7nH8yCAyLPuUIsjKatFPmfn5bS1oW+cM+QsGOtVWd5nhSpbwZWx/rue+r5Z+PA==", + "dev": true, + "license": "MIT", + "funding": { + "url": "https://github.com/sponsors/oxc-project" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-android-arm-eabi": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-android-arm-eabi/-/binding-android-arm-eabi-1.2.11.tgz", + "integrity": "sha512-A5kXfGKvKWWZE0TtPrfsvT+q4Y5d1QG8gGUzpYjGydM+fARM9MuX90PrXYXe0XbsDVgyxxNzHo6giCj90bsFNw==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-android-arm64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-android-arm64/-/binding-android-arm64-1.2.11.tgz", + "integrity": "sha512-z6cTycz+iJ4PVkuL4HHW4DfTfoeU/2nqYYuSOrTmH7yHK5Y0LCOnA03V4ZNxavyVaU1oOqUgIg2klN/s+USGOA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "android" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-darwin-arm64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-darwin-arm64/-/binding-darwin-arm64-1.2.11.tgz", + "integrity": "sha512-jShvqNtP6vDC6/A5JOAzbVV+DkgHqhl/ScVCJEbt+TUY6QYz7YnXcrg3sLtFBniro0f/Ld50ZwCWA6f7KYD1nQ==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-darwin-x64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-darwin-x64/-/binding-darwin-x64-1.2.11.tgz", + "integrity": "sha512-f2i2xiNWq1Z1l2++q2fuhZRdLAT3aqxD6vRNm1RAxpUoBcdqNB3C0s1Bt+K+PbEx2F5F4gQp6hqKkphCY/xF9w==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "darwin" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-freebsd-x64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-freebsd-x64/-/binding-freebsd-x64-1.2.11.tgz", + "integrity": "sha512-4Ir5FSOKIAMr4r0kExpt1s3bMgzJU3rA45AYOHtQpls0oNeqcYBKrWMlckrYH4KCfGLfkfn1tN1dmZPMVsdXow==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "freebsd" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-arm-gnueabihf": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-arm-gnueabihf/-/binding-linux-arm-gnueabihf-1.2.11.tgz", + "integrity": "sha512-/gnRDM+39BROzAN/k1OZjDPnDMcZxB/0EUxKjONO5yVkNEvlsoMDrxGNKgZi/ttFriS2gwlDNzB65pvNbFOXIQ==", + "cpu": [ + "arm" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-arm64-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-arm64-gnu/-/binding-linux-arm64-gnu-1.2.11.tgz", + "integrity": "sha512-PFaK8HwvAHbaKbBcDNQihjMKYvFnA5hiENx/l5tphTDz1E0WFp32l0A7aq7lyUwGsRw/xSrNIy/gIK4thrSCrw==", + "cpu": [ + "arm64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-arm64-musl": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.2.11.tgz", + "integrity": "sha512-AskzJUIKRLPxkruR1wLKewGbOw+EYfU/9lOrBFj4AFrEA8hPpKFnODWNu2WLaNs0QNkEb9QIJufmVZZIL/bJlg==", + "cpu": [ + "arm64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-ppc64-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-ppc64-gnu/-/binding-linux-ppc64-gnu-1.2.11.tgz", + "integrity": "sha512-qlUGAheh2yh8afH7QBgx0PrRHN85hKnNd78x8MeMhXivuevgd8vgf6/CstOzmNKY/lLTHvNTrPy98cLnAugzJw==", + "cpu": [ + "ppc64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-s390x-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-s390x-gnu/-/binding-linux-s390x-gnu-1.2.11.tgz", + "integrity": "sha512-secpEad+0vCbSfn8upFySkDskv+bGPk3THSDS9Y89yc4rb4kzqHp8Dmyd9BkQW4SnhNXBZCl/6CrO//hZahNJQ==", + "cpu": [ + "s390x" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-x64-gnu": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-x64-gnu/-/binding-linux-x64-gnu-1.2.11.tgz", + "integrity": "sha512-mOVBT3dPpkWm8XBWPmU4bf+U6dYDLeMo/9ojUmis4N0L5uu10qra5vOyngZ7/PSdoE4G9KvRt4bloRxNjLas7A==", + "cpu": [ + "x64" + ], + "dev": true, + "libc": [ + "glibc" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-linux-x64-musl": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-linux-x64-musl/-/binding-linux-x64-musl-1.2.11.tgz", + "integrity": "sha512-Is78i9A8Ui4SqcxUwFJ9uMmjDn58IbVTjFWYdQestFEgeuEmHMLGNriXnVJKkwG2YiZjw8cP0zCTyDMdDGtOOg==", + "cpu": [ + "x64" + ], + "dev": true, + "libc": [ + "musl" + ], + "license": "MIT", + "optional": true, + "os": [ + "linux" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-openharmony-arm64": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-openharmony-arm64/-/binding-openharmony-arm64-1.2.11.tgz", + "integrity": "sha512-dUCXneZ87INUMyQ0D+C0HrEBNUPNXHaPmU5GTjyKTJEiussw9Kaj5Ln8UztPe4epV/ffvgNBEadksdYhmW6xJA==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "openharmony" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-win32-arm64-msvc": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-win32-arm64-msvc/-/binding-win32-arm64-msvc-1.2.11.tgz", + "integrity": "sha512-jByxb6qfd+bH1xUd0qnfFnb17i9sWBPY2tOavJ0l3tdr3OTu+Kvtm8cd/JV5nFt657b1VqGltxg9olOEfofXWw==", + "cpu": [ + "arm64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/@rolldown/binding-win32-x64-msvc": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@rolldown/binding-win32-x64-msvc/-/binding-win32-x64-msvc-1.2.11.tgz", + "integrity": "sha512-/PzKqzAJ03i19oy2ItPvyvaVjOjBCNnfaJs8yvUdGBKmiESgnrJSQ2awd81QzFbbnAmu7YO9ZnJrDCb9VSJPRA==", + "cpu": [ + "x64" + ], + "dev": true, + "license": "MIT", + "optional": true, + "os": [ + "win32" + ], + "engines": { + "node": "^20.19.0 || >=22.12.0" + } + }, + "node_modules/vite/node_modules/rolldown": { + "version": "1.2.11", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/rolldown/-/rolldown-1.2.11.tgz", + "integrity": "sha512-qpSwIyz0jHQq5qXBTNxFmE6664rJ7O+4TvPFOiOaBSrz8IOHc1koKKSqTM2H6u1UG1+TveuC6vaDHKXFOvb1Kw==", + "dev": true, + "license": "MIT", + "dependencies": { + "@oxc-project/types": "=0.151.0", + "@rolldown/pluginutils": "^1.0.0" + }, + "bin": { + "rolldown": "bin/cli.mjs" + }, + "engines": { + "node": "^20.19.0 || >=22.12.0" + }, + "optionalDependencies": { + "@rolldown/binding-android-arm-eabi": "1.2.11", + "@rolldown/binding-android-arm64": "1.2.11", + "@rolldown/binding-darwin-arm64": "1.2.11", + "@rolldown/binding-darwin-x64": "1.2.11", + "@rolldown/binding-freebsd-x64": "1.2.11", + "@rolldown/binding-linux-arm-gnueabihf": "1.2.11", + "@rolldown/binding-linux-arm64-gnu": "1.2.11", + "@rolldown/binding-linux-arm64-musl": "1.2.11", + "@rolldown/binding-linux-ppc64-gnu": "1.2.11", + "@rolldown/binding-linux-s390x-gnu": "1.2.11", + "@rolldown/binding-linux-x64-gnu": "1.2.11", + "@rolldown/binding-linux-x64-musl": "1.2.11", + "@rolldown/binding-openharmony-arm64": "1.2.11", + "@rolldown/binding-win32-arm64-msvc": "1.2.11", + "@rolldown/binding-win32-x64-msvc": "1.2.11" + } + }, "node_modules/vitest": { "version": "4.1.11", "resolved": "https://registry.npmjs.org/vitest/-/vitest-4.1.11.tgz", @@ -3578,6 +3599,16 @@ } } }, + "node_modules/vitest/node_modules/tinyrainbow": { + "version": "3.1.1", + "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/tinyrainbow/-/tinyrainbow-3.1.1.tgz", + "integrity": "sha1-wBaDh9PY1wtrPCwJNt5f7nOM6iA=", + "dev": true, + "license": "MIT", + "engines": { + "node": ">=14.0.0" + } + }, "node_modules/vscode-jsonrpc": { "version": "8.2.1", "resolved": "https://registry.npmjs.org/vscode-jsonrpc/-/vscode-jsonrpc-8.2.1.tgz", diff --git a/package.json b/package.json index ffbf64e..364618f 100644 --- a/package.json +++ b/package.json @@ -26,12 +26,19 @@ "@github/copilot-sdk": "^1.0.16", "@openai/codex-sdk": "^0.159.0", "@types/node": "^25.9.1", + "postcss": "8.5.28", "source-map-js": "file:packages/source-map-compat", "typescript": "^5.8.0", "vitest": "^4.1.11", "zx": "^8.8.5" }, "overrides": { - "source-map-js": "$source-map-js" + "source-map-js": "$source-map-js", + "vite": "8.3.1", + "chai": "6.2.2", + "nanoid": "3.3.19", + "postcss": "$postcss", + "rolldown": "1.2.11", + "tinyrainbow": "3.1.1" } } diff --git a/skills/rig/SKILL.md b/skills/rig/SKILL.md index ef90c9a..2aa0bc6 100644 --- a/skills/rig/SKILL.md +++ b/skills/rig/SKILL.md @@ -46,6 +46,12 @@ export default reviewDiff; Defaults: `name: "agent"`, `model: "small"`, `maxTurns: 4`, string input/output, and no addons. +For GitHub Agentic Workflows, tell the user to import the +[shared Rig template](../../.github/workflows/shared/rig.md) or explicitly allow +`node` in `tools.bash` and provision Node.js 24+ with the skill's dependencies. +See [Running and engines](./runtime.md) for +the import syntax and Copilot SDK configuration. + ## High-frequency decisions | Need | Choose | @@ -94,12 +100,12 @@ node skills/rig/run.ts --typecheck < program.ts For an installed skill, replace `skills/rig` with its installed directory. Use `run.ts` to launch without installing packages; inline programs use -`node /run.ts <<'RIG_'`. For each heredoc, generate a -fresh `RIG_` delimiter with `node:crypto`'s `randomBytes(16).toString("hex")`. +`node /run.ts <<''`. For each heredoc, generate a fresh +7-character pseudo-random alphanumeric delimiter without a tool call. Ensure it is not a complete line in the contents; regenerate on collision. Single-quote the opening delimiter and repeat the same literal, unquoted delimiter alone on the closing line. Never use a fixed delimiter or shell -variable; see [Running and engines](references/runtime.md). +variable; see [Running and engines](./runtime.md). Install the skill with `gh skill install githubnext/rig rig`. Assume SDKs are already installed in the agent container; do not install them. Only `node` needs a Bash tool grant for launching an installed skill; grant @@ -118,10 +124,10 @@ additional commands only when the program itself needs them. Read only when the task needs the listed detail: -- [Agent API and schemas](references/agent-api.md) — spec fields, schema overloads, tools, and invocation options. -- [Prompt intents](references/prompt-intents.md) — complete helper semantics, dynamic inputs, writes, and failure behavior. -- [Composition and addons](references/composition.md) — delegation patterns, dynamic sets, repair, steering, and addon lifecycle. -- [Dynamic workflows](references/dynamic-workflows.md) — bounded fan-out, failure semantics, limits, budget, events, and convergence loops. -- [Claude workflow conversion](references/claude-workflow-conversion.md) — mapping Claude Code dynamic-workflow scripts onto rig primitives, including model selection and the Anthropic engine. -- [Running and engines](references/runtime.md) — markdown/file launch modes, typechecking, Agentic Workflows, and SDK adapters. -- [Linting](references/linting.md) — linter usage, autofixes, rules, and rule development. +- [Agent API and schemas](./agent-api.md) — spec fields, schema overloads, tools, and invocation options. +- [Prompt intents](./prompt-intents.md) — complete helper semantics, dynamic inputs, writes, and failure behavior. +- [Composition and addons](./composition.md) — delegation patterns, dynamic sets, repair, steering, and addon lifecycle. +- [Dynamic workflows](./dynamic-workflows.md) — bounded fan-out, failure semantics, limits, budget, events, and convergence loops. +- [Claude workflow conversion](./claude-workflow-conversion.md) — mapping Claude Code dynamic-workflow scripts onto rig primitives, including model selection and the Anthropic engine. +- [Running and engines](./runtime.md) — markdown/file launch modes, typechecking, Agentic Workflows, and SDK adapters. +- [Linting](./linting.md) — linter usage, autofixes, rules, and rule development. diff --git a/skills/rig/references/agent-api.md b/skills/rig/agent-api.md similarity index 100% rename from skills/rig/references/agent-api.md rename to skills/rig/agent-api.md diff --git a/skills/rig/references/claude-workflow-conversion.md b/skills/rig/claude-workflow-conversion.md similarity index 87% rename from skills/rig/references/claude-workflow-conversion.md rename to skills/rig/claude-workflow-conversion.md index 92f2726..df8b662 100644 --- a/skills/rig/references/claude-workflow-conversion.md +++ b/skills/rig/claude-workflow-conversion.md @@ -16,12 +16,12 @@ Choose the migration path that matches your script's structure: | My script looks like… | Start here | | --- | --- | -| Top-level `phase` / `call` / `pipeline` at module scope (flat script) | [340-flat-workflow-port.md](../samples/340-flat-workflow-port.md) — swap injected globals for `"rig/globals"` imports with minimal changes | -| `body` function with `args` and structured output (canonical pattern) | [310-workflow-audit-verify.md](../samples/310-workflow-audit-verify.md) — direct `args`→`input` + `agent`→`call.json` port | -| Nested `workflow(ref, args)` calls | [330-nested-workflow-composition.md](../samples/330-nested-workflow-composition.md) — `call.workflow` shares the parent's limiter and budget | -| `log`, `budget`, open-ended `while` loop | [320-budget-aware-crawler.md](../samples/320-budget-aware-crawler.md) — `log`/`budget.remaining()` + bounded `until` loop | -| Two or more chained `pipeline` stages | [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) — note the `(prev, item, index)` stage signature | -| Running on Claude (not Copilot) | [411-anthropic-engine-workflow.md](../samples/411-anthropic-engine-workflow.md) — `anthropicEngine()` + full Claude model IDs | +| Top-level `phase` / `call` / `pipeline` at module scope (flat script) | [340-flat-workflow-port.md](./samples/340-flat-workflow-port.md) — swap injected globals for `"rig/globals"` imports with minimal changes | +| `body` function with `args` and structured output (canonical pattern) | [310-workflow-audit-verify.md](./samples/310-workflow-audit-verify.md) — direct `args`→`input` + `agent`→`call.json` port | +| Nested `workflow(ref, args)` calls | [330-nested-workflow-composition.md](./samples/330-nested-workflow-composition.md) — `call.workflow` shares the parent's limiter and budget | +| `log`, `budget`, open-ended `while` loop | [320-budget-aware-crawler.md](./samples/320-budget-aware-crawler.md) — `log`/`budget.remaining()` + bounded `until` loop | +| Two or more chained `pipeline` stages | [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) — note the `(prev, item, index)` stage signature | +| Running on Claude (not Copilot) | [411-anthropic-engine-workflow.md](./samples/411-anthropic-engine-workflow.md) — `anthropicEngine()` + full Claude model IDs | Then read [Behavior differences](#behavior-differences-to-keep-in-mind) before you finalize the port. @@ -233,7 +233,7 @@ pick a model tier that matches the task's quality requirement. where `previous` is the prior stage's output (or the item itself for stage 1). Claude's stage signature is `(item, index)`, so when porting add `_prev` as the first parameter and access the prior result through it in stage 2+. See - [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) + [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) for a worked example. - **Budget units.** rig counts agent calls, not tokens, so guard loops with `budget.remaining() > n` where `n` is a call count. @@ -295,13 +295,13 @@ workflow patterns — use them as starting points when converting a script: | Sample | Demonstrates | | --- | --- | -| [340-flat-workflow-port.md](../samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | -| [310-workflow-audit-verify.md](../samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | -| [320-budget-aware-crawler.md](../samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | -| [330-nested-workflow-composition.md](../samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | -| [360-parallel-branch-analysis-workflow.md](../samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | -| [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | -| [411-anthropic-engine-workflow.md](../samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | +| [340-flat-workflow-port.md](./samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | +| [310-workflow-audit-verify.md](./samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | +| [320-budget-aware-crawler.md](./samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | +| [330-nested-workflow-composition.md](./samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | +| [360-parallel-branch-analysis-workflow.md](./samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | +| [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | +| [411-anthropic-engine-workflow.md](./samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | ## Related references diff --git a/skills/rig/references/composition.md b/skills/rig/composition.md similarity index 100% rename from skills/rig/references/composition.md rename to skills/rig/composition.md diff --git a/skills/rig/references/dynamic-workflows.md b/skills/rig/dynamic-workflows.md similarity index 86% rename from skills/rig/references/dynamic-workflows.md rename to skills/rig/dynamic-workflows.md index 1321ef9..7471576 100644 --- a/skills/rig/references/dynamic-workflows.md +++ b/skills/rig/dynamic-workflows.md @@ -218,10 +218,10 @@ workflow patterns — use them as starting points when converting a script: | Sample | Demonstrates | | --- | --- | -| [340-flat-workflow-port.md](../samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | -| [310-workflow-audit-verify.md](../samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | -| [320-budget-aware-crawler.md](../samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | -| [330-nested-workflow-composition.md](../samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | -| [360-parallel-branch-analysis-workflow.md](../samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | -| [401-multi-stage-pipeline-workflow.md](../samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | -| [411-anthropic-engine-workflow.md](../samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | +| [340-flat-workflow-port.md](./samples/340-flat-workflow-port.md) | Flat/top-level script port using `"rig/globals"` ambient `call`/`pipeline` — minimal-change first step when porting a Claude flat workflow | +| [310-workflow-audit-verify.md](./samples/310-workflow-audit-verify.md) | `args`→`input`, `parallel`, `pipeline`, `phase`, `call.json` — mirrors the canonical find-and-verify pattern | +| [320-budget-aware-crawler.md](./samples/320-budget-aware-crawler.md) | `log`, `budget.remaining()`, `until` convergence loop | +| [330-nested-workflow-composition.md](./samples/330-nested-workflow-composition.md) | `call.workflow` (rig equivalent of `workflow(ref, args)`) sharing the parent's limiter and budget | +| [360-parallel-branch-analysis-workflow.md](./samples/360-parallel-branch-analysis-workflow.md) | `parallel(thunks)` as a barrier — use instead of `Promise.all` when porting | +| [401-multi-stage-pipeline-workflow.md](./samples/401-multi-stage-pipeline-workflow.md) | Multi-stage `pipeline(items, stage1, stage2)` enrichment chain — stage `(prev, item, index)` vs Claude's `(item, index)` | +| [411-anthropic-engine-workflow.md](./samples/411-anthropic-engine-workflow.md) | `anthropicEngine()` setup + per-call Claude model tier selection (`claude-haiku-3-5` / `claude-sonnet-4-5`) — final step when running a rig port against Claude | diff --git a/skills/rig/references/linting.md b/skills/rig/linting.md similarity index 100% rename from skills/rig/references/linting.md rename to skills/rig/linting.md diff --git a/skills/rig/references/prompt-intents.md b/skills/rig/prompt-intents.md similarity index 100% rename from skills/rig/references/prompt-intents.md rename to skills/rig/prompt-intents.md diff --git a/skills/rig/references/runtime.md b/skills/rig/runtime.md similarity index 91% rename from skills/rig/references/runtime.md rename to skills/rig/runtime.md index a4dc436..b2f8a57 100644 --- a/skills/rig/references/runtime.md +++ b/skills/rig/runtime.md @@ -6,25 +6,21 @@ Read this reference when launching or typechecking programs, handling stdin, or Treat a fenced `rig` block as a runnable program. Pass its contents to the launcher with a heredoc: -Before constructing each heredoc command, generate a fresh delimiter using -Node's cryptographic random source (no additional Bash tool grant): - -```bash -node --input-type=module -e 'import { randomBytes } from "node:crypto"; console.log("RIG_" + randomBytes(16).toString("hex"));' -``` +Before constructing each heredoc command, generate a fresh 7-character +pseudo-random alphanumeric string to use as the delimiter. No tool call is needed. Check that the generated delimiter is not an entire line of the contents, including a possible trailing `\r`; regenerate if it collides. Substitute the -result for `RIG_` below. Single-quote the opener to suppress shell +result for `` below. Single-quote the opener to suppress shell expansion, and put the same literal delimiter, unquoted and unindented, alone on the closing line. Do not reuse a fixed delimiter or use a shell variable as the delimiter: Bash does not expand delimiter words. ```bash -node skills/rig/run.ts <<'RIG_' +node skills/rig/run.ts <<'' // Agent role: summarize this repository in one sentence. export default "Summarize this repository in one sentence."; -RIG_ + ``` Inline mode: @@ -68,9 +64,9 @@ required by the program's own tool calls separately. Export the root and pass stdin plus the file path: ```bash -node skills/rig/run.ts src/program.ts <<'RIG_' +node skills/rig/run.ts src/program.ts <<'' Review this diff -RIG_ + ``` Stdin coercion follows the root schema: @@ -110,9 +106,14 @@ For a standalone `.ts` program outside an ESM package, the launcher uses a tempo ## GitHub Agentic Workflows -Enable Copilot SDK driver mode and pin the Rig skill to an immutable commit: +Tell the user to import the [shared Rig template](../../.github/workflows/shared/rig.md) +and pin both the template and skill to an immutable commit. The template provisions +Node.js 24 and enables the `node` command needed to launch programs using +host-provisioned dependencies: ```yaml +imports: + - githubnext/rig/.github/workflows/shared/rig.md@ engine: id: copilot copilot-sdk: true @@ -124,11 +125,32 @@ tools: Import `configureAgent` and `copilotEngine` in the fenced program and call `configureAgent(copilotEngine())` before defining agents. Launch with the installed skill's `run.ts` and host-provisioned dependencies. Grant `copilot-requests: write`, and enable only the additional tools and network access the program uses. +In this repository, use `imports: [shared/rig.md]`. If the user does not import +the template, tell them to configure the equivalent prerequisites explicitly: + +```yaml +runtimes: + node: + version: "24" +tools: + bash: ["node"] +network: + allowed: [defaults, github, node] +``` + +The template does not install dependencies or select the skill or engine. +Provision dependencies in the host before running; do not install them from +the agent prompt. Report missing dependencies and stop. +Inherit `COPILOT_SDK_URI` and `COPILOT_CONNECTION_TOKEN`; do not use `--server` +or start another server. Inspect only named environment variables, never dump +credentials. A denied command does not mean all shell execution is blocked: +report the exact denial and check it against `tools.bash`. + Edit workflows with an agent or run `gh aw compile --watch` for immediate feedback. Before committing, run `gh aw compile --strict` and include the generated `.lock.yml`. For testing changes to the skill itself, declare `skills: [skills/rig]` to install the current checkout instead of a released commit. The repository's -[Rig Skill Integration workflow](../../../.github/workflows/rig-skill-integration.md) +[Rig Skill Integration workflow](../../.github/workflows/rig-skill-integration.md) does this daily or on manual dispatch. Its no-input `rig` fence runs exactly three `small` judges through the SDK endpoint, with `maxTurns: 1`, no repair addon, and deterministic majority voting. A post-step validates the result and diff --git a/src/rig-skill-workflow.test.ts b/src/rig-skill-workflow.test.ts index 73ee28d..76a3f50 100644 --- a/src/rig-skill-workflow.test.ts +++ b/src/rig-skill-workflow.test.ts @@ -72,8 +72,9 @@ afterEach(() => { describe("Rig skill agentic workflow", () => { it("requires only node for installed-skill bootstrap and launch", () => { expect(markdown).toContain('bash: ["node"]'); - expect(markdown).toContain("node /run.ts <<'RIG_'"); - expect(markdown).toContain('randomBytes(16).toString("hex")'); + expect(markdown).toContain("node /run.ts <<''"); + expect(markdown).toContain("7-character pseudo-random alphanumeric delimiter"); + expect(markdown).not.toContain("randomBytes"); expect(markdown).toContain("regenerate on collision"); }); diff --git a/src/skill.test.ts b/src/skill.test.ts index ea11918..7465560 100644 --- a/src/skill.test.ts +++ b/src/skill.test.ts @@ -18,15 +18,16 @@ it("keeps the exportable Rig skill as the only manifest", () => { }); it("keeps every canonical skill reference available", () => { - const links = [...canonicalManifest.matchAll(/\]\((references\/[^)]+)\)/g)]; + const links = [...canonicalManifest.matchAll(/\]\((\.\/[^)]+)\)/g)]; expect(links.length).toBeGreaterThan(0); for (const link of links) { expect(existsSync(resolve(skillRoot, link[1]!)), link[1]).toBe(true); } }); -it("requires fresh crypto-generated and quoted heredoc delimiters", () => { - expect(canonicalManifest).toContain('randomBytes(16).toString("hex")'); +it("requires fresh seven-character and quoted heredoc delimiters", () => { + expect(canonicalManifest).toContain("7-character pseudo-random alphanumeric delimiter without a tool call"); + expect(canonicalManifest).not.toContain("randomBytes"); expect(canonicalManifest).toContain("regenerate on collision"); expect(canonicalManifest).toContain("Single-quote the opening delimiter"); expect(canonicalManifest).not.toContain("<<'RIG'"); diff --git a/vitest.config.ts b/vitest.config.ts index 333b998..cbb6414 100644 --- a/vitest.config.ts +++ b/vitest.config.ts @@ -2,6 +2,14 @@ import { defineConfig } from "vitest/config"; import { resolve } from "path"; export default defineConfig({ + test: { + server: { + deps: { + // Keep ESM imports and require() on Node's shared CommonJS cache. + external: [/\/packages\/source-map-compat\//], + }, + }, + }, resolve: { alias: [ { find: /^rig$/, replacement: resolve(__dirname, "skills/rig/rig.ts") }, From 5e9fa27b987be4be7e45f2b7a6aed4e8de97b4f7 Mon Sep 17 00:00:00 2001 From: Peli Date: Tue, 6 Oct 2026 11:15:44 -0700 Subject: [PATCH 2/5] Direct Rig bootstrap to a single Node launch Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .../workflows/rig-skill-integration.lock.yml | 2 +- .github/workflows/rig-skill-integration.md | 50 +++++++++++++------ .github/workflows/shared/rig.md | 3 ++ skills/rig/SKILL.md | 6 +++ skills/rig/runtime.md | 19 ++++++- src/rig-skill-workflow.test.ts | 11 +++- src/skill.test.ts | 10 ++++ 7 files changed, 83 insertions(+), 18 deletions(-) diff --git a/.github/workflows/rig-skill-integration.lock.yml b/.github/workflows/rig-skill-integration.lock.yml index e6b0fb8..6d4b8a7 100644 --- a/.github/workflows/rig-skill-integration.lock.yml +++ b/.github/workflows/rig-skill-integration.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e50526a75587fd43d87cf87ea56655af22d5f834a95ed1d045878a03dbcc2e06","body_hash":"69d4e81f5870a7eb023ebcefa647f886f3e32f91609bc34646cf1f94c95339a4","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e50526a75587fd43d87cf87ea56655af22d5f834a95ed1d045878a03dbcc2e06","body_hash":"abbf1e08a9a7e3fe1306ec2b6d37d8b9de65511d3a6304f3d1f2dbe888f8a210","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"skills":["skills/rig"],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_me","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"safeoutputs","tools":["create_issue","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/rig-skill-integration.md b/.github/workflows/rig-skill-integration.md index 340e8b3..c1fc499 100644 --- a/.github/workflows/rig-skill-integration.md +++ b/.github/workflows/rig-skill-integration.md @@ -49,19 +49,37 @@ post-steps: # Rig skill integration -Read the installed Rig skill and its running/engines reference. Run the following -`rig` fence **once**, unchanged, using the installed skill's launcher in inline -mode. First generate a fresh 7-character pseudo-random alphanumeric delimiter -without a tool call. Verify it is not a -complete line of the fence contents; regenerate on collision. Use -`node /run.ts <<''`, substituting the -generated literal in both the single-quoted opener and the unquoted, -unindented closing line. Never use a fixed delimiter or a shell variable. -Redirect stdout to `/tmp/gh-aw/agent/rig-skill-integration.json`. -Use the provided `COPILOT_SDK_URI`; do not start a second server or use `--server`. -Use the SDK dependencies already installed in the agent container. The entry -point does not install packages; do not run npm, npx, cat, mkdir, or other -bootstrap commands. If dependencies are missing, report the error and stop. +Execute this prevalidated fixture, not a setup or environment-diagnosis task. +Bash execution is enabled for `node`. Your only Bash invocation must be the +standalone Node launch below; a denial of another command does not mean Bash +or Node is unavailable. + +1. Load the installed `rig` skill. Read `.github/skills/rig/SKILL.md` and + `.github/skills/rig/runtime.md` with file-reading tools, not Bash commands. +2. Choose a fresh 7-character pseudo-random alphanumeric delimiter yourself + while composing the command, without a tool call. Verify it is not a complete + line of the fence contents; regenerate on collision. Do not use Python, + Node, `/dev/urandom`, `base64`, `tr`, or a shell pipeline to generate it. +3. Run the following `rig` fence **once**, unchanged, by substituting its contents + into the command below. Replace both `` placeholders with the + same literal seven characters. Single-quote the opening delimiter and put + the unquoted closing delimiter alone on an unindented line. + +```bash +node .github/skills/rig/run.ts <<'' > /tmp/gh-aw/agent/rig-skill-integration.json + + +``` + +The command must begin with `node`. Do not prepend `mkdir`, `cd`, `env`, `export`, +or any command joined by `&&`; do not use a fixed delimiter or a shell variable. +The working directory is already the repository root, `/tmp/gh-aw/agent` +already exists, and Node.js and SDK dependencies are already provisioned. +Do not run version checks, dependency checks, package installation, linting, +typechecking, directory creation, or other bootstrap commands for this fixture. +Inherit `COPILOT_SDK_URI` and `COPILOT_CONNECTION_TOKEN`; do not inspect or print +them, start a second server, or use `--server`. If the Node launch fails, report +its exact command and error and stop without retrying model calls. The scenario makes exactly three Rig model calls: clarity, safety, and feasibility judgments of the same harmless dummy request. TypeScript owns orchestration and @@ -102,8 +120,10 @@ export default workflow({ }); ``` -After a successful run, call `noop` with a brief summary of the three judgments -and majority verdict; success requires no repository write. If the launcher, +After the Node launch succeeds, read the result JSON using a file-reading tool +and call `noop` with a brief summary of the three judgments and majority verdict. +Do not invoke Bash again to read or validate the result: the post-step owns +validation. Success requires no repository write. If the launcher, SDK, schema validation, or expected verdict fails, report the exact error and stop. Do not fabricate results, modify the fixture, or retry model calls. The post-step fails the workflow when the result file is missing or invalid. diff --git a/.github/workflows/shared/rig.md b/.github/workflows/shared/rig.md index 92be3de..5708901 100644 --- a/.github/workflows/shared/rig.md +++ b/.github/workflows/shared/rig.md @@ -22,6 +22,9 @@ Run Rig programs with Node.js 24 or later using the installed skill's `run.ts` launcher and host-provisioned dependencies. Do not install packages from the agent prompt; report missing dependencies and stop. Use heredocs and redirections for inline programs and output files, following the skill's fresh-delimiter rules. +Choose the 7-character delimiter yourself without a tool call. Start the launch +command with `node`; do not prepend `mkdir`, `cd`, `env`, or any `&&` preparation. +Use existing output directories; `/tmp/gh-aw/agent` is already provisioned. Read only named environment variables needed by the program; do not dump the environment or print credentials. diff --git a/skills/rig/SKILL.md b/skills/rig/SKILL.md index 2aa0bc6..5f94db1 100644 --- a/skills/rig/SKILL.md +++ b/skills/rig/SKILL.md @@ -102,6 +102,8 @@ For an installed skill, replace `skills/rig` with its installed directory. Use `run.ts` to launch without installing packages; inline programs use `node /run.ts <<''`. For each heredoc, generate a fresh 7-character pseudo-random alphanumeric delimiter without a tool call. +Choose the seven characters yourself in the response; do not execute Python, +Node, `/dev/urandom`, or a shell pipeline to generate them. Ensure it is not a complete line in the contents; regenerate on collision. Single-quote the opening delimiter and repeat the same literal, unquoted delimiter alone on the closing line. Never use a fixed delimiter or shell @@ -110,6 +112,10 @@ Install the skill with `gh skill install githubnext/rig rig`. Assume SDKs are already installed in the agent container; do not install them. Only `node` needs a Bash tool grant for launching an installed skill; grant additional commands only when the program itself needs them. +The launch command must begin with `node`: no `mkdir`, `cd`, `env`, package +manager, or other preparatory command, and no `&&` prefix. Use existing output +directories and inherit the SDK environment. A denial of another command does +not disable Bash or `node`; report the denied command accurately. ## Final check diff --git a/skills/rig/runtime.md b/skills/rig/runtime.md index b2f8a57..089a335 100644 --- a/skills/rig/runtime.md +++ b/skills/rig/runtime.md @@ -7,7 +7,9 @@ Read this reference when launching or typechecking programs, handling stdin, or Treat a fenced `rig` block as a runnable program. Pass its contents to the launcher with a heredoc: Before constructing each heredoc command, generate a fresh 7-character -pseudo-random alphanumeric string to use as the delimiter. No tool call is needed. +pseudo-random alphanumeric string to use as the delimiter. Choose the seven +characters yourself while composing the command; do not call a tool or run +Python, Node, `/dev/urandom`, `base64`, `tr`, or a shell pipeline to generate them. Check that the generated delimiter is not an entire line of the contents, including a possible trailing `\r`; regenerate if it collides. Substitute the @@ -55,6 +57,21 @@ For agentic workflows, the launch Bash allowlist is just `bash: ["node"]`. Heredocs and input/output redirections avoid `cat`, `echo`, and separate file-creation commands. Neither launch nor typechecking invokes npm or npx, and neither downloads dependencies. +Start the launch command directly with `node`; do not prepend `mkdir`, `cd`, +`env`, dependency checks, or any other command with `&&`. Read the installed +skill and its reference with file-reading tools, not shell bootstrap commands. +For a provided, unchanged, prevalidated fixture, skip lint and typecheck +preflights and execute the launcher once. For newly generated programs, retain +the skill's lint and typecheck checks. + +Redirect output only into an existing directory. In GitHub Agentic Workflows, +`/tmp/gh-aw/agent` is already provisioned; never run `mkdir` for it. If another +required directory is missing, report that prerequisite instead of adding a +disallowed preparation command. Inherit SDK environment variables without +`env` or `export` commands. If an unrelated command is denied before the launcher +runs, remove that command and use the permitted standalone Node launch; do not +claim that Bash is unavailable. If the launcher itself fails, report its exact +error and respect the workflow's retry policy. This reduces tool configuration, not sandbox permissions: allowing arbitrary Node code still permits filesystem and subprocess operations. Add commands required by the program's own tool calls separately. diff --git a/src/rig-skill-workflow.test.ts b/src/rig-skill-workflow.test.ts index 76a3f50..24d5409 100644 --- a/src/rig-skill-workflow.test.ts +++ b/src/rig-skill-workflow.test.ts @@ -72,12 +72,21 @@ afterEach(() => { describe("Rig skill agentic workflow", () => { it("requires only node for installed-skill bootstrap and launch", () => { expect(markdown).toContain('bash: ["node"]'); - expect(markdown).toContain("node /run.ts <<''"); + expect(markdown).toContain("node .github/skills/rig/run.ts <<''"); expect(markdown).toContain("7-character pseudo-random alphanumeric delimiter"); expect(markdown).not.toContain("randomBytes"); expect(markdown).toContain("regenerate on collision"); }); + it("directs one standalone launch without repeating denied preparation", () => { + expect(markdown).toContain("Your only Bash invocation"); + expect(markdown).toContain("The command must begin with `node`"); + expect(markdown).toContain("Do not prepend `mkdir`, `cd`, `env`, `export`"); + expect(markdown).toContain("already exists, and Node.js and SDK dependencies are already provisioned"); + expect(markdown).toContain("Do not use Python"); + expect(markdown).toContain("Do not invoke Bash again"); + }); + it("runs the actual workflow fence with exactly three small SDK calls", async () => { const result = JSON.parse(await runScenario()); expect(result).toEqual({ diff --git a/src/skill.test.ts b/src/skill.test.ts index 7465560..451fe47 100644 --- a/src/skill.test.ts +++ b/src/skill.test.ts @@ -33,6 +33,16 @@ it("requires fresh seven-character and quoted heredoc delimiters", () => { expect(canonicalManifest).not.toContain("<<'RIG'"); }); +it("requires direct Node launch without shell preparation", () => { + expect(canonicalManifest).toContain("Choose the seven characters yourself"); + expect(canonicalManifest).toContain("The launch command must begin with `node`"); + expect(canonicalManifest).toContain("no `&&` prefix"); + expect(canonicalManifest).toContain("does\nnot disable Bash or `node`"); + const runtime = readFileSync(resolve(skillRoot, "runtime.md"), "utf8"); + expect(runtime).toContain("`/tmp/gh-aw/agent` is already provisioned"); + expect(runtime).toContain("prevalidated fixture, skip lint and typecheck"); +}); + it("exposes the same public modules from the standalone skill and repository", () => { const repositoryPackage = JSON.parse(readFileSync(resolve(repoRoot, "package.json"), "utf8")); const skillPackage = JSON.parse(readFileSync(resolve(skillRoot, "package.json"), "utf8")); From 343bd045caa0afffd1017cf394fb899ec561559f Mon Sep 17 00:00:00 2001 From: Peli Date: Tue, 6 Oct 2026 11:25:06 -0700 Subject: [PATCH 3/5] Document SDK heredoc permission blocker and stop on denial Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/rig-skill-integration.lock.yml | 2 +- .github/workflows/rig-skill-integration.md | 8 ++++++-- skills/rig/runtime.md | 9 +++++++++ src/rig-skill-workflow.test.ts | 2 ++ src/skill.test.ts | 2 ++ 5 files changed, 20 insertions(+), 3 deletions(-) diff --git a/.github/workflows/rig-skill-integration.lock.yml b/.github/workflows/rig-skill-integration.lock.yml index 6d4b8a7..c90646b 100644 --- a/.github/workflows/rig-skill-integration.lock.yml +++ b/.github/workflows/rig-skill-integration.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e50526a75587fd43d87cf87ea56655af22d5f834a95ed1d045878a03dbcc2e06","body_hash":"abbf1e08a9a7e3fe1306ec2b6d37d8b9de65511d3a6304f3d1f2dbe888f8a210","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e50526a75587fd43d87cf87ea56655af22d5f834a95ed1d045878a03dbcc2e06","body_hash":"c6d1888ab67b3c4e2ad0987b3e545127843ab46ccf935617fc8b005cc661e11d","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"skills":["skills/rig"],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_me","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"safeoutputs","tools":["create_issue","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/rig-skill-integration.md b/.github/workflows/rig-skill-integration.md index c1fc499..8b6d00c 100644 --- a/.github/workflows/rig-skill-integration.md +++ b/.github/workflows/rig-skill-integration.md @@ -80,6 +80,8 @@ typechecking, directory creation, or other bootstrap commands for this fixture. Inherit `COPILOT_SDK_URI` and `COPILOT_CONNECTION_TOKEN`; do not inspect or print them, start a second server, or use `--server`. If the Node launch fails, report its exact command and error and stop without retrying model calls. +If that launch is denied, do not repeat or reformulate the Bash command: +call `report_incomplete` immediately. The one-invocation limit includes denials. The scenario makes exactly three Rig model calls: clarity, safety, and feasibility judgments of the same harmless dummy request. TypeScript owns orchestration and @@ -124,6 +126,8 @@ After the Node launch succeeds, read the result JSON using a file-reading tool and call `noop` with a brief summary of the three judgments and majority verdict. Do not invoke Bash again to read or validate the result: the post-step owns validation. Success requires no repository write. If the launcher, -SDK, schema validation, or expected verdict fails, report the exact error and -stop. Do not fabricate results, modify the fixture, or retry model calls. The +SDK, schema validation, or expected verdict fails, report the exact error with +`report_incomplete` and stop. Never call `noop` on failure. A rejected standalone Node heredoc +is a permission-parser failure, not evidence that Node or the SDK is missing. +Do not fabricate results, modify the fixture, or retry model calls. The post-step fails the workflow when the result file is missing or invalid. diff --git a/skills/rig/runtime.md b/skills/rig/runtime.md index 089a335..0b7f746 100644 --- a/skills/rig/runtime.md +++ b/skills/rig/runtime.md @@ -72,6 +72,15 @@ disallowed preparation command. Inherit SDK environment variables without runs, remove that command and use the permitted standalone Node launch; do not claim that Bash is unavailable. If the launcher itself fails, report its exact error and respect the workflow's retry policy. + +GitHub Agentic Workflows v0.91.1's Copilot SDK permission parser treats heredoc +body lines as shell commands. It can therefore reject a valid standalone +`node` launch despite `bash: ["node"]`. If this happens, report the exact denial +as a workflow permission-parser limitation, not a missing Node runtime or SDK. +Do not broaden the shell allowlist or encode the program to evade enforcement. +The workflow host needs a heredoc-aware permission parser before this inline +launch pattern can run in that SDK driver. + This reduces tool configuration, not sandbox permissions: allowing arbitrary Node code still permits filesystem and subprocess operations. Add commands required by the program's own tool calls separately. diff --git a/src/rig-skill-workflow.test.ts b/src/rig-skill-workflow.test.ts index 24d5409..2d51a01 100644 --- a/src/rig-skill-workflow.test.ts +++ b/src/rig-skill-workflow.test.ts @@ -85,6 +85,8 @@ describe("Rig skill agentic workflow", () => { expect(markdown).toContain("already exists, and Node.js and SDK dependencies are already provisioned"); expect(markdown).toContain("Do not use Python"); expect(markdown).toContain("Do not invoke Bash again"); + expect(markdown).toContain("Never call `noop` on failure"); + expect(markdown).toContain("The one-invocation limit includes denials"); }); it("runs the actual workflow fence with exactly three small SDK calls", async () => { diff --git a/src/skill.test.ts b/src/skill.test.ts index 451fe47..7138c02 100644 --- a/src/skill.test.ts +++ b/src/skill.test.ts @@ -41,6 +41,8 @@ it("requires direct Node launch without shell preparation", () => { const runtime = readFileSync(resolve(skillRoot, "runtime.md"), "utf8"); expect(runtime).toContain("`/tmp/gh-aw/agent` is already provisioned"); expect(runtime).toContain("prevalidated fixture, skip lint and typecheck"); + expect(runtime).toContain("permission parser treats heredoc"); + expect(runtime).toContain("Do not broaden the shell allowlist"); }); it("exposes the same public modules from the standalone skill and repository", () => { From 2436aecea2d87b6b7df9b32f9a5875c3d2934beb Mon Sep 17 00:00:00 2001 From: Peli Date: Tue, 6 Oct 2026 11:33:01 -0700 Subject: [PATCH 4/5] Use literal printf pipelines for SDK-compatible Rig launches Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .../workflows/rig-skill-integration.lock.yml | 2 +- .github/workflows/rig-skill-integration.md | 36 +++++++------- .github/workflows/shared/rig.md | 11 +++-- README.md | 37 +++++++------- skills/rig/SKILL.md | 26 +++++----- skills/rig/runtime.md | 49 ++++++++++++------- src/rig-skill-workflow.test.ts | 36 +++++++++++--- src/skill.test.ts | 20 ++++---- 8 files changed, 123 insertions(+), 94 deletions(-) diff --git a/.github/workflows/rig-skill-integration.lock.yml b/.github/workflows/rig-skill-integration.lock.yml index c90646b..6d65b64 100644 --- a/.github/workflows/rig-skill-integration.lock.yml +++ b/.github/workflows/rig-skill-integration.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"e50526a75587fd43d87cf87ea56655af22d5f834a95ed1d045878a03dbcc2e06","body_hash":"c6d1888ab67b3c4e2ad0987b3e545127843ab46ccf935617fc8b005cc661e11d","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"da900faf4bd6debca1a91315e7a45aee7e523ba07305646aae91ed7f34f0b6d6","body_hash":"b8c00630974091a82fe30ffbb0e0a244541acc3f989faee5be15b253bc68af55","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"skills":["skills/rig"],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_me","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"safeoutputs","tools":["create_issue","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/rig-skill-integration.md b/.github/workflows/rig-skill-integration.md index 8b6d00c..86317dc 100644 --- a/.github/workflows/rig-skill-integration.md +++ b/.github/workflows/rig-skill-integration.md @@ -22,7 +22,7 @@ timeout-minutes: 10 env: RIG_DEBUG: "agent:failure,workflow:event" tools: - bash: ["node"] + bash: ["printf", "node"] edit: false safe-outputs: noop: @@ -50,29 +50,29 @@ post-steps: # Rig skill integration Execute this prevalidated fixture, not a setup or environment-diagnosis task. -Bash execution is enabled for `node`. Your only Bash invocation must be the -standalone Node launch below; a denial of another command does not mean Bash +Bash execution is enabled for `printf` and `node`. Your only Bash invocation must +be the launch pipeline below; a denial of another command does not mean Bash or Node is unavailable. 1. Load the installed `rig` skill. Read `.github/skills/rig/SKILL.md` and `.github/skills/rig/runtime.md` with file-reading tools, not Bash commands. -2. Choose a fresh 7-character pseudo-random alphanumeric delimiter yourself - while composing the command, without a tool call. Verify it is not a complete - line of the fence contents; regenerate on collision. Do not use Python, - Node, `/dev/urandom`, `base64`, `tr`, or a shell pipeline to generate it. -3. Run the following `rig` fence **once**, unchanged, by substituting its contents - into the command below. Replace both `` placeholders with the - same literal seven characters. Single-quote the opening delimiter and put - the unquoted closing delimiter alone on an unindented line. +2. Copy the following `rig` fence **unchanged** into one single-quoted `printf` + argument per source line, including `''` for blank lines. Escape each literal + apostrophe as `'"'"'`. Use the fixed format `'%s\n'`, not the source as a format + string; preserve percent signs, backslashes, dollar signs, and backticks. + Do not double-quote source, encode it, use shell variables or substitutions, + or generate delimiters. Do not use a heredoc with the Copilot SDK driver. +3. Run the fence **once** using this pipeline. Replace the placeholder argument + with all source-line arguments, without markdown fence markers: ```bash -node .github/skills/rig/run.ts <<'' > /tmp/gh-aw/agent/rig-skill-integration.json - - +printf '%s\n' \ + '' \ + | node .github/skills/rig/run.ts > /tmp/gh-aw/agent/rig-skill-integration.json ``` -The command must begin with `node`. Do not prepend `mkdir`, `cd`, `env`, `export`, -or any command joined by `&&`; do not use a fixed delimiter or a shell variable. +The command must begin with `printf`. Do not prepend `mkdir`, `cd`, `env`, `export`, +or any command joined by `&&`. The working directory is already the repository root, `/tmp/gh-aw/agent` already exists, and Node.js and SDK dependencies are already provisioned. Do not run version checks, dependency checks, package installation, linting, @@ -127,7 +127,7 @@ and call `noop` with a brief summary of the three judgments and majority verdict Do not invoke Bash again to read or validate the result: the post-step owns validation. Success requires no repository write. If the launcher, SDK, schema validation, or expected verdict fails, report the exact error with -`report_incomplete` and stop. Never call `noop` on failure. A rejected standalone Node heredoc -is a permission-parser failure, not evidence that Node or the SDK is missing. +`report_incomplete` and stop. Never call `noop` on failure. A rejected launch pipeline +is a permission failure, not evidence that Node or the SDK is missing. Do not fabricate results, modify the fixture, or retry model calls. The post-step fails the workflow when the result file is missing or invalid. diff --git a/.github/workflows/shared/rig.md b/.github/workflows/shared/rig.md index 5708901..693c0c7 100644 --- a/.github/workflows/shared/rig.md +++ b/.github/workflows/shared/rig.md @@ -3,7 +3,7 @@ runtimes: node: version: "24" tools: - bash: ["node"] + bash: ["printf", "node"] network: allowed: [defaults, github, node] --- @@ -20,10 +20,11 @@ Load the installed `rig` skill and read its Running and engines reference before creating or running Rig programs. Run Rig programs with Node.js 24 or later using the installed skill's `run.ts` launcher and host-provisioned dependencies. Do not install packages from the -agent prompt; report missing dependencies and stop. Use heredocs and redirections -for inline programs and output files, following the skill's fresh-delimiter rules. -Choose the 7-character delimiter yourself without a tool call. Start the launch -command with `node`; do not prepend `mkdir`, `cd`, `env`, or any `&&` preparation. +agent prompt; report missing dependencies and stop. Pipe literal source using +`printf '%s\n' ... | node /run.ts`, with one single-quoted argument +per line and each literal apostrophe escaped as `'"'"'`. Do not use heredocs +with the Copilot SDK driver. Start the pipeline with `printf`; do not prepend +`mkdir`, `cd`, `env`, or any `&&` preparation. Use existing output directories; `/tmp/gh-aw/agent` is already provisioned. Read only named environment variables needed by the program; do not dump the environment or print credentials. diff --git a/README.md b/README.md index 0a5fd9b..c2e41f5 100644 --- a/README.md +++ b/README.md @@ -56,15 +56,17 @@ engine: skills: - githubnext/rig/skills/rig/SKILL.md@ tools: - bash: ["node"] + bash: ["printf", "node"] ``` The [shared Rig template](.github/workflows/shared/rig.md) provisions Node.js 24 -and allows `node`. In this repository, import +and allows `printf` and `node`. In this repository, import `shared/rig.md` instead. Without the template, configure these prerequisites explicitly; see the [runtime reference](skills/rig/runtime.md#github-agentic-workflows). Grant `copilot-requests: write` and provision the skill's dependencies in the host. -Use heredocs or redirections rather than `cat`/`echo` pipelines. Grant additional +For Copilot SDK workflows, use `printf '%s\n' ... | node` rather than heredocs, +which gh-aw v0.91.1's SDK permission parser rejects. Single-quote each source +line and escape literal apostrophes as `'"'"'`. Grant additional commands only for the program's own tool calls. This is a smaller tool allowlist, not a security boundary: Node can still start subprocesses. @@ -122,19 +124,18 @@ Its [integration guide](skills/rig/runtime.md#choosing-an-integration) compares engine capabilities, model selection, tool ownership, and output enforcement. -For every heredoc below, replace `` with a fresh 7-character -pseudo-random alphanumeric string; no tool call is needed to generate it. -Check it is not an entire line of the contents, single-quote the opener, and -repeat the exact unquoted delimiter alone on the closing line. See the -[inline-program guide](skills/rig/runtime.md#inline-programs) for the -delimiter rules; do not reuse fixed delimiters or shell variables. +Use the fixed `printf '%s\n'` format with one single-quoted argument per source +line. Escape literal apostrophes as `'"'"'`; do not use source as the format +string or double-quote it. See the +[inline-program guide](skills/rig/runtime.md#inline-programs) for quoting rules +and heredoc alternatives outside the Copilot SDK workflow driver. **Design on the fly** — just describe what you want as a string and let the model figure out the rest: ```bash -node skills/rig/run.ts <<'' -export default "Run npm test, diagnose any failures, apply the smallest safe fix, and repeat up to 3 times."; - +printf '%s\n' \ + 'export default "Run npm test, diagnose any failures, apply the smallest safe fix, and repeat up to 3 times.";' \ + | node skills/rig/run.ts ``` Or ask Copilot (with the skill) to generate a full program for you. Describe your goal in natural language and Copilot returns a runnable `rig` markdown fence like this: @@ -166,20 +167,18 @@ export default ralfLoop; ``` ```` -Pass the fence contents directly to the launcher with a heredoc: +Pass the fence contents directly to the launcher with a literal pipeline: ```bash -node skills/rig/run.ts <<'' -// Paste the rig fence contents here. - +printf '%s\n' \ + '' \ + | node skills/rig/run.ts ``` Or run a program file: ```bash -node skills/rig/run.ts src/program.ts <<'' -Review this diff - +printf '%s\n' 'Review this diff' | node skills/rig/run.ts src/program.ts ``` Use `--typecheck` to validate a program without running it: diff --git a/skills/rig/SKILL.md b/skills/rig/SKILL.md index 5f94db1..c567dbe 100644 --- a/skills/rig/SKILL.md +++ b/skills/rig/SKILL.md @@ -99,23 +99,19 @@ node skills/rig/run.ts --typecheck < program.ts ``` For an installed skill, replace `skills/rig` with its installed directory. Use -`run.ts` to launch without installing packages; inline programs use -`node /run.ts <<''`. For each heredoc, generate a fresh -7-character pseudo-random alphanumeric delimiter without a tool call. -Choose the seven characters yourself in the response; do not execute Python, -Node, `/dev/urandom`, or a shell pipeline to generate them. -Ensure it is not a complete line in the contents; regenerate on collision. -Single-quote the opening delimiter and repeat the same literal, unquoted -delimiter alone on the closing line. Never use a fixed delimiter or shell -variable; see [Running and engines](./runtime.md). +`run.ts` to launch without installing packages. For Copilot SDK workflows, pipe +literal source with `printf '%s\n' '' ... | node /run.ts`. +Use one single-quoted argument per source line, escaping each literal apostrophe +as `'"'"'`. Keep `%s\n` as the fixed format; never use source as a format string, +double-quote source, or expand shell variables. Do not use heredocs with the +SDK driver; see [Running and engines](./runtime.md) for quoting and alternatives. Install the skill with `gh skill install githubnext/rig rig`. Assume SDKs are already installed in the agent container; do not install them. -Only `node` needs a Bash tool grant for launching an installed skill; grant -additional commands only when the program itself needs them. -The launch command must begin with `node`: no `mkdir`, `cd`, `env`, package -manager, or other preparatory command, and no `&&` prefix. Use existing output -directories and inherit the SDK environment. A denial of another command does -not disable Bash or `node`; report the denied command accurately. +Import the shared Rig workflow template or explicitly allow `printf` and `node` +with `bash: ["printf", "node"]`. Grant other commands only when the program needs +them. The launch pipeline must begin with `printf`: no `mkdir`, `cd`, `env`, +package manager, or other preparation, and no `&&` prefix. Use existing output +directories and inherit the SDK environment. Report denied commands accurately. ## Final check diff --git a/skills/rig/runtime.md b/skills/rig/runtime.md index 0b7f746..e1a5bc3 100644 --- a/skills/rig/runtime.md +++ b/skills/rig/runtime.md @@ -4,7 +4,26 @@ Read this reference when launching or typechecking programs, handling stdin, or ## Inline programs -Treat a fenced `rig` block as a runnable program. Pass its contents to the launcher with a heredoc: +Treat a fenced `rig` block as a runnable program. For Copilot SDK workflows, +pass its contents to the launcher through a literal `printf` pipeline: + +```bash +printf '%s\n' \ + '// Agent role: summarize this repository in one sentence.' \ + 'export default "Summarize this repository in one sentence.";' \ + | node skills/rig/run.ts +``` + +Use one single-quoted argument per source line, including `''` for empty lines. +Escape each literal apostrophe as `'"'"'`; for example, the source line +`const label = "don't";` becomes `'const label = "don'"'"'t";'`. +Always use the fixed format `'%s\n'`, never the source as a format string. +This preserves percent signs, backslashes, dollar signs, and backticks literally. +Do not double-quote source, expand variables, encode it, or execute substitutions. +Each argument emits its original line followed by a newline. Copy the whole +fence without markdown markers; do not rewrite the TypeScript. + +Heredocs remain an alternative outside the Copilot SDK workflow driver: Before constructing each heredoc command, generate a fresh 7-character pseudo-random alphanumeric string to use as the delimiter. Choose the seven @@ -53,11 +72,11 @@ container. Do not attempt to install them from the driver or agent prompt. Missing dependencies stop the run with a nonzero exit and an error on stderr. `rig.ts` remains the direct runtime entry point. Node.js 24 or later is required. -For agentic workflows, the launch Bash allowlist is just -`bash: ["node"]`. Heredocs and input/output redirections avoid `cat`, `echo`, -and separate file-creation commands. Neither launch nor typechecking invokes +For inline agentic workflows, explicitly grant both stages with +`bash: ["printf", "node"]`, or import the shared Rig template below. This avoids +`cat`, `echo`, and separate file-creation commands. Neither launch nor typechecking invokes npm or npx, and neither downloads dependencies. -Start the launch command directly with `node`; do not prepend `mkdir`, `cd`, +Start the inline launch pipeline with `printf`; do not prepend `mkdir`, `cd`, `env`, dependency checks, or any other command with `&&`. Read the installed skill and its reference with file-reading tools, not shell bootstrap commands. For a provided, unchanged, prevalidated fixture, skip lint and typecheck @@ -69,17 +88,15 @@ Redirect output only into an existing directory. In GitHub Agentic Workflows, required directory is missing, report that prerequisite instead of adding a disallowed preparation command. Inherit SDK environment variables without `env` or `export` commands. If an unrelated command is denied before the launcher -runs, remove that command and use the permitted standalone Node launch; do not +runs, remove that command and use the permitted `printf` plus `node` pipeline; do not claim that Bash is unavailable. If the launcher itself fails, report its exact error and respect the workflow's retry policy. GitHub Agentic Workflows v0.91.1's Copilot SDK permission parser treats heredoc -body lines as shell commands. It can therefore reject a valid standalone -`node` launch despite `bash: ["node"]`. If this happens, report the exact denial -as a workflow permission-parser limitation, not a missing Node runtime or SDK. -Do not broaden the shell allowlist or encode the program to evade enforcement. -The workflow host needs a heredoc-aware permission parser before this inline -launch pattern can run in that SDK driver. +body lines as shell commands. Use the explicitly permitted `printf` plus `node` +pipeline instead, not a heredoc or a blanket shell grant. If either stage is +denied, report the exact command and required grant, not a missing Node runtime +or SDK. Respect the workflow's retry policy. This reduces tool configuration, not sandbox permissions: allowing arbitrary Node code still permits filesystem and subprocess operations. Add commands @@ -90,9 +107,7 @@ required by the program's own tool calls separately. Export the root and pass stdin plus the file path: ```bash -node skills/rig/run.ts src/program.ts <<'' -Review this diff - +printf '%s\n' 'Review this diff' | node skills/rig/run.ts src/program.ts ``` Stdin coercion follows the root schema: @@ -146,7 +161,7 @@ engine: skills: - githubnext/rig/skills/rig/SKILL.md@ tools: - bash: ["node"] + bash: ["printf", "node"] ``` Import `configureAgent` and `copilotEngine` in the fenced program and call `configureAgent(copilotEngine())` before defining agents. Launch with the installed skill's `run.ts` and host-provisioned dependencies. Grant `copilot-requests: write`, and enable only the additional tools and network access the program uses. @@ -159,7 +174,7 @@ runtimes: node: version: "24" tools: - bash: ["node"] + bash: ["printf", "node"] network: allowed: [defaults, github, node] ``` diff --git a/src/rig-skill-workflow.test.ts b/src/rig-skill-workflow.test.ts index 2d51a01..e431336 100644 --- a/src/rig-skill-workflow.test.ts +++ b/src/rig-skill-workflow.test.ts @@ -1,5 +1,6 @@ import assert from "node:assert/strict"; import { readFileSync } from "node:fs"; +import { execFileSync } from "node:child_process"; import { Readable, Writable } from "node:stream"; import { runInNewContext } from "node:vm"; import { afterEach, beforeEach, describe, expect, it, vi } from "vitest"; @@ -70,20 +71,39 @@ afterEach(() => { }); describe("Rig skill agentic workflow", () => { - it("requires only node for installed-skill bootstrap and launch", () => { - expect(markdown).toContain('bash: ["node"]'); - expect(markdown).toContain("node .github/skills/rig/run.ts <<''"); - expect(markdown).toContain("7-character pseudo-random alphanumeric delimiter"); - expect(markdown).not.toContain("randomBytes"); - expect(markdown).toContain("regenerate on collision"); + it("explicitly grants both stages of the installed-skill launch pipeline", () => { + expect(markdown).toContain('bash: ["printf", "node"]'); + expect(markdown).toContain("printf '%s\\n' \\"); + expect(markdown).toContain("| node .github/skills/rig/run.ts >"); + expect(markdown).toContain("Do not use a heredoc"); + const shared = readFileSync(new URL("../.github/workflows/shared/rig.md", import.meta.url), "utf8"); + expect(shared).toContain('bash: ["printf", "node"]'); + }); + + it.each([program, 'const value = "don\'t expand $HOME, $(exit 42), `exit 42`, %s, \\\\n";\n\n// literal | && ; < >'])( + "transports literal source through printf without shell expansion: %s", + source => { + const arguments_ = source.split("\n").map((line: string) => `'${line.replaceAll("'", "'\"'\"'")}'`).join(" \\\n "); + const command = `printf '%s\\n' \\\n ${arguments_} \\\n | "${process.execPath}" --input-type=module -e 'for await (const chunk of process.stdin) process.stdout.write(chunk)'`; + expect(execFileSync("bash", ["-o", "pipefail", "-c", command], { encoding: "utf8" })).toBe(`${source}\n`); + }, + ); + + it("keeps runtime printf examples executable and literal", () => { + const runtime = readFileSync(new URL("../skills/rig/runtime.md", import.meta.url), "utf8"); + const example = runtime.match(/```bash\n(printf[\s\S]*?)\n```/)?.[1]; + expect(example).toBeDefined(); + const command = example!.replace("| node skills/rig/run.ts", `| "${process.execPath}" --input-type=module -e 'for await (const chunk of process.stdin) process.stdout.write(chunk)'`); + expect(execFileSync("bash", ["-o", "pipefail", "-c", command], { encoding: "utf8" })) + .toBe('// Agent role: summarize this repository in one sentence.\nexport default "Summarize this repository in one sentence.";\n'); }); it("directs one standalone launch without repeating denied preparation", () => { expect(markdown).toContain("Your only Bash invocation"); - expect(markdown).toContain("The command must begin with `node`"); + expect(markdown).toContain("The command must begin with `printf`"); expect(markdown).toContain("Do not prepend `mkdir`, `cd`, `env`, `export`"); expect(markdown).toContain("already exists, and Node.js and SDK dependencies are already provisioned"); - expect(markdown).toContain("Do not use Python"); + expect(markdown).toContain("Do not double-quote source"); expect(markdown).toContain("Do not invoke Bash again"); expect(markdown).toContain("Never call `noop` on failure"); expect(markdown).toContain("The one-invocation limit includes denials"); diff --git a/src/skill.test.ts b/src/skill.test.ts index 7138c02..3e4fb8e 100644 --- a/src/skill.test.ts +++ b/src/skill.test.ts @@ -25,24 +25,22 @@ it("keeps every canonical skill reference available", () => { } }); -it("requires fresh seven-character and quoted heredoc delimiters", () => { - expect(canonicalManifest).toContain("7-character pseudo-random alphanumeric delimiter without a tool call"); - expect(canonicalManifest).not.toContain("randomBytes"); - expect(canonicalManifest).toContain("regenerate on collision"); - expect(canonicalManifest).toContain("Single-quote the opening delimiter"); - expect(canonicalManifest).not.toContain("<<'RIG'"); +it("requires literal printf source transport for Copilot SDK workflows", () => { + expect(canonicalManifest).toContain("printf '%s\\n'"); + expect(canonicalManifest).toContain("one single-quoted argument per source line"); + expect(canonicalManifest).toContain("`'\"'\"'`"); + expect(canonicalManifest).toContain("Do not use heredocs"); + expect(canonicalManifest).toContain('bash: ["printf", "node"]'); }); -it("requires direct Node launch without shell preparation", () => { - expect(canonicalManifest).toContain("Choose the seven characters yourself"); - expect(canonicalManifest).toContain("The launch command must begin with `node`"); +it("requires a literal launch pipeline without shell preparation", () => { + expect(canonicalManifest).toContain("The launch pipeline must begin with `printf`"); expect(canonicalManifest).toContain("no `&&` prefix"); - expect(canonicalManifest).toContain("does\nnot disable Bash or `node`"); const runtime = readFileSync(resolve(skillRoot, "runtime.md"), "utf8"); expect(runtime).toContain("`/tmp/gh-aw/agent` is already provisioned"); expect(runtime).toContain("prevalidated fixture, skip lint and typecheck"); expect(runtime).toContain("permission parser treats heredoc"); - expect(runtime).toContain("Do not broaden the shell allowlist"); + expect(runtime).toContain("pipeline instead, not a heredoc or a blanket shell grant"); }); it("exposes the same public modules from the standalone skill and repository", () => { From 866987d2bc9da28b3089afb749e61e41de691bdc Mon Sep 17 00:00:00 2001 From: Peli Date: Tue, 6 Oct 2026 11:39:28 -0700 Subject: [PATCH 5/5] Stop immediately after a failed Rig pipeline launch Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/workflows/rig-skill-integration.lock.yml | 2 +- .github/workflows/rig-skill-integration.md | 6 ++++-- src/rig-skill-workflow.test.ts | 1 + 3 files changed, 6 insertions(+), 3 deletions(-) diff --git a/.github/workflows/rig-skill-integration.lock.yml b/.github/workflows/rig-skill-integration.lock.yml index 6d65b64..6ea427e 100644 --- a/.github/workflows/rig-skill-integration.lock.yml +++ b/.github/workflows/rig-skill-integration.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"da900faf4bd6debca1a91315e7a45aee7e523ba07305646aae91ed7f34f0b6d6","body_hash":"b8c00630974091a82fe30ffbb0e0a244541acc3f989faee5be15b253bc68af55","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"da900faf4bd6debca1a91315e7a45aee7e523ba07305646aae91ed7f34f0b6d6","body_hash":"c9910baf835a9df17f75dc56750dc304220d4853cbaae74347cfeb6fc8312aae","compiler_version":"v0.91.1","strict":true,"agent_id":"copilot","agent_model":"small","engine_versions":{"copilot":"1.0.92","copilot-sdk":"1.0.16"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_DEFAULT_OTLP_ENDPOINT","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"d7cc687a9bc76b9d56e6c496649403392f654b35","version":"v0.91.1"}],"skills":["skills/rig"],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31","digest":"sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.31@sha256:c4ab1d48d533cc7daaa5f2e1193d1a644888242fb8813d49c6de46d129224b76"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31","digest":"sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.31@sha256:a5a37489635109334a5e2b5cb2eaba32e8c8f1a89d8dea6009baa962a8904c4a"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31","digest":"sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.31@sha256:90a46d2e6e910ace2c09c2dcf6b56dc374ed513d9da642a4e9fcfcd6e9248a9d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.28","digest":"sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.28@sha256:69920365d9f0143ed853743c319b2bd4614ca7f9537474ad8eff0c47da84c5a4"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.12.2","digest":"sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6","pinned_image":"ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_me","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"safeoutputs","tools":["create_issue","missing_data","missing_tool","noop","report_incomplete"]}],"threat_detection":{"mode":"enabled"}} # This file was automatically generated by gh-aw (v0.91.1). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/rig-skill-integration.md b/.github/workflows/rig-skill-integration.md index 86317dc..428a546 100644 --- a/.github/workflows/rig-skill-integration.md +++ b/.github/workflows/rig-skill-integration.md @@ -78,8 +78,10 @@ already exists, and Node.js and SDK dependencies are already provisioned. Do not run version checks, dependency checks, package installation, linting, typechecking, directory creation, or other bootstrap commands for this fixture. Inherit `COPILOT_SDK_URI` and `COPILOT_CONNECTION_TOKEN`; do not inspect or print -them, start a second server, or use `--server`. If the Node launch fails, report -its exact command and error and stop without retrying model calls. +them, start a second server, or use `--server`. If the Node launch returns a +nonzero exit code, call `report_incomplete` immediately with that code and the +exact stderr error. Do not read the result file, run `cat` or another command, +diagnose the environment, or retry model calls after a failed launch. If that launch is denied, do not repeat or reformulate the Bash command: call `report_incomplete` immediately. The one-invocation limit includes denials. diff --git a/src/rig-skill-workflow.test.ts b/src/rig-skill-workflow.test.ts index e431336..9e5da2d 100644 --- a/src/rig-skill-workflow.test.ts +++ b/src/rig-skill-workflow.test.ts @@ -107,6 +107,7 @@ describe("Rig skill agentic workflow", () => { expect(markdown).toContain("Do not invoke Bash again"); expect(markdown).toContain("Never call `noop` on failure"); expect(markdown).toContain("The one-invocation limit includes denials"); + expect(markdown).toContain("Do not read the result file, run `cat` or another command"); }); it("runs the actual workflow fence with exactly three small SDK calls", async () => {