6 Commits

Author SHA1 Message Date
temeddix d7f57e3522 Model input
Check / deno (pull_request) Successful in 34s
2026-09-14 01:47:09 +09:00
temeddix 75d3593376 Author replies (#5)
The reviewer drops a finding the author has answered in the PR comments as intended or a false alarm, once the code or docs make that clear. Pairs with memona's merge-branch gate loop.

Reviewed-on: #5
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 15:35:17 +00:00
temeddix 439f2b4e77 Checked-out head (#4)
Checked-out head (#4)

Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 15:06:27 +00:00
temeddix f0506adfea Fail-closed verdict (#3)
Fail-closed verdict (#3)

Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 14:57:01 +00:00
temeddix b8d0093ef2 Superpowers review (#2)
Superpowers review (#2)

Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 14:30:29 +00:00
temeddix 8c2041bbc5 Split tokens (#1)
The agent and the bot are now two accounts, and the runner is one Deno script.

- `author-token` (was `gitea-token`): commits, pushes, and opens pull requests; the agent sees it as `GITEA_TOKEN`, and commits use that account's login and email.
- `reviewer-token`: posts comments and reviews as the bot; withheld from the agent's environment so it can never approve as the bot.
- A `pull_request` run posts a review instead of a comment: `REQUEST_CHANGES` when the response mentions `@bot`, `COMMENT` when the run failed, `APPROVED` otherwise. Gitea refuses self-approval, so the two accounts must differ.
- The reviewer checks the whole repository against `commons/code-rules`, which is fetched and embedded in the prompt, and requests changes for violations even when the diff did not cause them.
- `run.ts` replaces the three shell scripts plus `jq`, `envsubst`, and `ansifilter`; only `deno` is added to the install step, per the rules' Deno-over-Node policy. A `.gitea` workflow runs `deno fmt`, `lint`, and `check`.

Callers must rename `gitea-token` and add `reviewer-token` (`write:issue` and `write:repository` scopes). A rejection stays until the bot reviews again, so callers that want it lifted after a fix should trigger on `pull_request: [opened, synchronize]`.

Verified with a fake `claude` binary against this PR in an isolated `HOME`: git author configured from the token, prompt rendered with rules and comment history, events streamed, reviewer token absent from the agent's environment, review posted (then deleted).

Reviewed-on: #1
Co-authored-by: Danny Kim <temeddix@gmail.com>
Co-committed-by: Danny Kim <temeddix@gmail.com>
2026-09-13 14:15:23 +00:00
3 changed files with 103 additions and 36 deletions
+11
View File
@@ -20,10 +20,20 @@ inputs:
bot-token: bot-token:
description: API key or token for the selected bot description: API key or token for the selected bot
required: false required: false
model:
description: >-
Model for the selected bot. Defaults to `claude-sonnet-5` or
`gpt-5.6-terra`, the mid tiers, which cover reviews and fixes.
required: false
runs: runs:
using: composite using: composite
steps: steps:
# The agent works on the event's commit with full history, as the author.
- uses: actions/checkout@v4
with:
fetch-depth: 0
token: ${{ inputs.author-token }}
# This step assumes this is `node:24-bookworm` container. # This step assumes this is `node:24-bookworm` container.
- name: Install dependencies - name: Install dependencies
shell: bash shell: bash
@@ -35,6 +45,7 @@ runs:
ACTION_PATH: ${{ gitea.action_path }} ACTION_PATH: ${{ gitea.action_path }}
BOT_TYPE: ${{ inputs.bot-type }} BOT_TYPE: ${{ inputs.bot-type }}
BOT_TOKEN: ${{ inputs.bot-token }} BOT_TOKEN: ${{ inputs.bot-token }}
MODEL: ${{ inputs.model }}
GITEA_API_URL: ${{ gitea.api_url }} GITEA_API_URL: ${{ gitea.api_url }}
GITEA_REPOSITORY: ${{ gitea.repository }} GITEA_REPOSITORY: ${{ gitea.repository }}
GITEA_TOKEN: ${{ inputs.author-token }} GITEA_TOKEN: ${{ inputs.author-token }}
+33 -9
View File
@@ -13,15 +13,39 @@ response ends, so background monitors, scheduled wake-ups, and queued tasks
never resume. Never promise future action and never claim to be waiting on a never resume. Never promise future action and never claim to be waiting on a
notification. notification.
For a `pull_request` event, review the PR without changing code. Your final The repository is checked out in the working directory at the event's commit,
response is posted as a pull request review from the bot account: it requests the head of the pull request when there is one, with full history and the
changes when it mentions `@bot` and approves otherwise. So include `@bot` with author's push credentials. Read the code there, run its checks and tests when
instructions to fix the findings exactly when changes are needed, and never they bear on the task, and push from there.
mention `@bot` when the PR is ready. For UI changes, check that the result is
aligned, clean, and pixel-perfect, and that included screenshots prove the For a `pull_request` event, review the PR without changing code, using the
intended result was achieved. Also check the whole repository, not only the `requesting-code-review` skill from superpowers: run its code reviewer template
diff, against the code rules at the end of this prompt, and request changes for against the PR's base and head, and make its complete output your final response
every violation you find even when the diff did not cause it. instead of the short comment style above. Run the project's checks on the head
and treat a failure as at least Important. Check the whole repository against
the code rules at the end of this prompt, not only the diff; a violation is at
least Important even when the diff did not cause it. Your final response is
posted verbatim as a pull request review from the bot account, so it is the
review text and nothing else: no narration about what you did, verified, or are
about to post, whether you reviewed yourself or relayed a reviewer subagent. Its
first line must be exactly the template's verdict and nothing else: `Yes`, `No`,
or `With fixes`. `Yes` approves and the other two request changes; any other
first line is posted as a plain comment, which wastes the run. Minor issues
alone never block, and neither does a finding the author has answered in the
comment history below as intended or a false alarm, once the code or docs make
that clear. When the verdict is not `Yes`, the second line names what must
change in one line, addressed to the author; the author's own agent picks the
fixes up, so never ask `@bot` to make them. For UI changes, check that the
result is aligned, clean, and pixel-perfect, and that included screenshots prove
the intended result was achieved.
The review must read at a glance: everything outside `<details>` blocks totals
under 512 bytes. Only core information stays visible: the verdict, the summary
line, and the section headings. Anything verbose goes into a `<details>` block
whose `<summary>` is a few words, such as the `file:line` and title of an issue
with the what, why, and how inside; the same for each strength, each
recommendation, the reasoning, and any compliance notes. Details blocks are
top-level, never inside a list item, because Gitea breaks them there.
For an `issue_comment` or `pull_request_review_comment` event, treat the `body` For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
in the triggering comment payload below as the user's exact instruction. in the triggering comment payload below as the user's exact instruction.
+53 -21
View File
@@ -20,6 +20,13 @@ const EVENT = env("EVENT_NAME");
const AUTHOR_TOKEN = env("GITEA_TOKEN"); const AUTHOR_TOKEN = env("GITEA_TOKEN");
const REVIEWER_TOKEN = env("REVIEWER_TOKEN"); const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
const RULES_PATH = "repos/commons/code-rules/raw/README.md"; const RULES_PATH = "repos/commons/code-rules/raw/README.md";
// The mid tiers: a run follows a fixed template and the project's checks.
const DEFAULT_MODELS: Record<string, string> = {
claude: "claude-sonnet-5",
codex: "gpt-5.6-terra",
};
const model = (bot: string): string =>
Deno.env.get("MODEL") || DEFAULT_MODELS[bot];
// The reviewer token is withheld so the agent cannot approve as the bot. // The reviewer token is withheld so the agent cannot approve as the bot.
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject(); const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
@@ -52,32 +59,50 @@ async function postComment(body: string): Promise<void> {
}); });
} }
// A pull request event is a review request, so the response becomes a review: // A pull request event is a review request, so the response becomes a review.
// changes are requested when the agent asked @bot to fix something, a failed // Its first line is the verdict; anything unexpected only comments, never
// run only comments, and anything else approves. // approves.
const VERDICTS: Record<string, string> = {
Yes: "APPROVED",
No: "REQUEST_CHANGES",
"With fixes": "REQUEST_CHANGES",
};
async function postResult(body: string): Promise<void> { async function postResult(body: string): Promise<void> {
if (EVENT !== "pull_request") return postComment(body); if (EVENT !== "pull_request") return postComment(body);
const event = body.includes("@bot") const [verdict] = body.split("\n", 1);
? "REQUEST_CHANGES"
: body.startsWith("Bot failed:")
? "COMMENT"
: "APPROVED";
await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, { await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
body: stripAnsi(body), body: stripAnsi(body),
event, event: VERDICTS[verdict.trim()] ?? "COMMENT",
}); });
} }
async function run(command: string, args: string[]): Promise<void> {
const { success, code } = await new Deno.Command(command, { args }).output();
if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`);
}
// Commits belong to the same account as the pull request they end up in. // Commits belong to the same account as the pull request they end up in.
async function configureGitAuthor(): Promise<void> { async function configureGitAuthor(): Promise<void> {
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json(); const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
for (const [key, value] of [["name", user.login], ["email", user.email]]) { for (const [key, value] of [["name", user.login], ["email", user.email]]) {
await new Deno.Command("git", { await run("git", ["config", "--global", `user.${key}`, value]);
args: ["config", "--global", `user.${key}`, value],
}).output();
} }
} }
// The superpowers plugin gives the agent its skills, including the code review
// one that the prompt asks for. Both installs are idempotent on the persisted
// home.
async function installSuperpowers(bot: string): Promise<void> {
const commands = bot === "claude"
? [
["plugin", "marketplace", "add", "obra/superpowers-marketplace"],
["plugin", "install", "-y", "superpowers@superpowers-marketplace"],
]
: [["plugin", "add", "superpowers@openai-curated-remote"]];
for (const args of commands) await run(bot, args);
}
async function renderPrompt(): Promise<string> { async function renderPrompt(): Promise<string> {
const comments: GiteaComment[] = await (await gitea( const comments: GiteaComment[] = await (await gitea(
REVIEWER_TOKEN, REVIEWER_TOKEN,
@@ -106,17 +131,17 @@ async function renderPrompt(): Promise<string> {
async function runClaude(prompt: string): Promise<string> { async function runClaude(prompt: string): Promise<string> {
const token = Deno.env.get("BOT_TOKEN"); const token = Deno.env.get("BOT_TOKEN");
if (!token) { if (!token) {
await postComment( throw new Error(
"Run `claude setup-token` locally and set the `bot-token` action input.", "Run `claude setup-token` locally and set the `bot-token` action input.",
); );
Deno.exit(1);
} }
await installSuperpowers("claude");
const claude = new Deno.Command("claude", { const claude = new Deno.Command("claude", {
args: [ args: [
"--print", "--print",
"--dangerously-skip-permissions", "--dangerously-skip-permissions",
"--model", "--model",
"claude-fable-5", model("claude"),
"--output-format", "--output-format",
"stream-json", "stream-json",
"--verbose", "--verbose",
@@ -127,7 +152,7 @@ async function runClaude(prompt: string): Promise<string> {
clearEnv: true, clearEnv: true,
stdout: "piped", stdout: "piped",
}).spawn(); }).spawn();
let result = "Bot failed: no result"; let result: { result?: string; subtype: string } | undefined;
// Print events as they stream so the runner does not kill the job as a zombie. // Print events as they stream so the runner does not kill the job as a zombie.
const lines = claude.stdout const lines = claude.stdout
.pipeThrough(new TextDecoderStream()) .pipeThrough(new TextDecoderStream())
@@ -139,12 +164,13 @@ async function runClaude(prompt: string): Promise<string> {
const text = part.thinking ?? part.text ?? part.name; const text = part.thinking ?? part.text ?? part.name;
if (text) console.log(text); if (text) console.log(text);
} }
if (event.type === "result") { if (event.type === "result") result = event;
result = event.result ?? `Bot failed: ${event.subtype}`;
}
} }
await claude.status; await claude.status;
return result; if (result?.result === undefined) {
throw new Error(`claude ended with ${result?.subtype ?? "no result"}`);
}
return result.result;
} }
// Posts the device code so a human can finish the login on the persisted home. // Posts the device code so a human can finish the login on the persisted home.
@@ -174,12 +200,13 @@ async function runCodex(prompt: string): Promise<string> {
}) })
.output(); .output();
if (!loggedIn.success) await codexDeviceLogin(); if (!loggedIn.success) await codexDeviceLogin();
await installSuperpowers("codex");
const file = await Deno.makeTempFile(); const file = await Deno.makeTempFile();
const status = await new Deno.Command("codex", { const status = await new Deno.Command("codex", {
args: [ args: [
"exec", "exec",
"--model", "--model",
"gpt-5.5", model("codex"),
"--dangerously-bypass-approvals-and-sandbox", "--dangerously-bypass-approvals-and-sandbox",
"--output-last-message", "--output-last-message",
file, file,
@@ -194,9 +221,14 @@ async function runCodex(prompt: string): Promise<string> {
return await Deno.readTextFile(file); return await Deno.readTextFile(file);
} }
try {
await configureGitAuthor(); await configureGitAuthor();
const prompt = await renderPrompt(); const prompt = await renderPrompt();
const result = env("BOT_TYPE") === "claude" const result = env("BOT_TYPE") === "claude"
? await runClaude(prompt) ? await runClaude(prompt)
: await runCodex(prompt); : await runCodex(prompt);
await postResult(result); await postResult(result);
} catch (error) {
await postComment(`Bot failed: ${error}`);
throw error;
}