Skip to content

docs(skills): 新增三技能閉環自動化 14-step workflow skills - #36

Merged
monkey1sai merged 2 commits into
mainfrom
claude/competent-cartwright-83f7c8
May 13, 2026
Merged

monkey1sai merged 2 commits into
mainfrom
claude/competent-cartwright-83f7c8

Conversation

@monkey1sai

@monkey1sai monkey1sai commented May 13, 2026 •

Copy link
Copy Markdown
Owner

變更摘要

依「三技能閉環自動化工作流設計研究報告」PDF 結論,落地 7 個 Claude Code skills,把 AI-BIM-governance agent / OpenSpec / GitNexus 三技能排成可審查的分層閉環,覆蓋 OpenSpec change lifecycle 完整 14 步驟(起點判定 → explore → 風險判讀 → apply → review → archive → closeout)。

⚠️ 本 PR 並非 OpenSpec change 實作,因此 branch 命名沿用 worktree-default 的 claude/competent-cartwright-83f7c8 而非 codex/openspec/<change-id>。僅新增 .claude/skills/ 下 tooling artifacts,不動產品程式碼、specs、roadmap。

修改原因

PDF 報告(Anthropic conversation context)核心結論:

  1. 三技能不能平行使用,必須分層:AI-BIM-governance agent(外層 policy)→ OpenSpec(規格收斂)→ GitNexus(風險診斷)
  2. 缺乏 NoSuccessorWhilePredecessorOpen gate,造成 PR fix(worker): 補 canonical batch timeout 診斷 #33 / PR 歸檔 canonical batch 並新增 enumeration 優化切片 #35 並存時的治理歧義
  3. 兩段式 PR(implementation + archive)必須強制分開
  4. Phase 4(11 item)/ Phase 5(18 item)必須單一 change-id 流,禁止 mega-change

把上述規則寫成可重複呼叫的 Claude Code skills,是讓閉環從「文件建議」變成「機制」的最小落地。

主要變更

驗證方式

  • `.gitignore` 例外驗證:`git add -n .claude/skills/` 只列出 7 個目標 SKILL.md,其餘 `.claude/skills/generated/` 等仍正確被忽略
  • 7 個 SKILL.md 都符合 Anthropic 官方 skill 結構:YAML frontmatter(name / description / allowed-tools)+ markdown body
  • 不可逆操作的 skills(`closed-loop-orchestrator` / `pr-review-gate` / `archive-and-closeout`)設定 `disable-model-invocation: true`,避免 Claude 自動觸發
  • Claude Code live change detection 已即時偵測 7 個 skills(系統 reminder 三度刷新 skill 清單)
  • runtime smoke:實際跑一次 `/closed-loop-orchestrator` 完整 dry-run(待 reviewer 同意 merge 後在 follow-up 進行)

風險與影響

  • risk_level: LOW
  • 受影響面:僅 `.claude/skills/` tooling,不動 `_bim-control` / `_worker` / `bim-review-coordinator` / `bim-streaming-server` / `web-viewer-sample` 任一服務
  • 不違反 AGENTS.md repo 邊界(這些 skills 是 workflow helper,不取代邊界規則本身)
  • `.claude/` 既有 ignored 規則維持,只碰出 7 個明確命名的目錄

回滾方式

若決定不採用:

  • `gh pr revert ` 開 revert PR
  • 或直接 `git rm -r .claude/skills/{closed-loop-orchestrator,change-id-resolve,...}` 並還原 `.gitignore`

後續建議

  1. R3(NoSuccessorWhilePredecessorOpen)與 R7(CI gates)優先落地:PDF Executive Summary 提出的 7 條規則中,這兩條風險最高,建議單獨開 OpenSpec change `setup-ci-merge-gates` 跑完整閉環來驗證 skills
  2. 第二輪迭代:實際跑一次完整閉環後,依使用者回饋調整 skill description 與 trigger phrases
  3. AGENTS.md / CLAUDE.md 同步更新:把 R1-R7 七條規則正式寫進 source-of-truth(需另開 OpenSpec change)

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation

    • Added comprehensive workflow skill specifications: closed-loop orchestration, two‑round spec exploration, apply‑and‑verify implementation, pre/post blast‑radius analysis, PR review gate, change‑id resolution, and archive/closeout procedures.
  • Chores

    • Updated ignore rules to include and track the new workflow skill definition files.

Review Change Stack

依「三技能閉環自動化工作流設計研究報告」PDF,落地 7 個 Claude Code skills
(1 orchestrator + 6 worker),覆蓋 OpenSpec change lifecycle 完整 14 步驟:

- closed-loop-orchestrator:串接 Phase A-F,merge/archive 前停下等使用者同意
- change-id-resolve:解析下一個 active change-id,套用 NoSuccessorWhilePredecessorOpen gate
- openspec-explore-twice:強制兩輪 explore,open questions 不可遺留
- gitnexus-blast-radius:pre-change impact + post-change detect_changes
- apply-and-verify:apply + 四層驗證 (openspec / focused tests / git diff / detect_changes)
- pr-review-gate:CI checks + reviewer comments + GitNexus debug loop + 人工 merge gate
- archive-and-closeout:archive branch + spec sync + roadmap sync + cleanup

.gitignore 同步調整:碰出這 7 個 skill 目錄為 tracked,其餘 .claude/ 維持 ignored。
Copilot AI review requested due to automatic review settings May 13, 2026 06:21
@coderabbitai

coderabbitai Bot commented May 13, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

This PR introduces a complete multi-phase workflow system for managing OpenSpec-driven changes. Seven new Claude skills define the specification exploration, risk analysis, implementation verification, PR review gating, archive/closeout, and change resolution phases. The .gitignore is updated to track these skills in version control, enabling the closed-loop orchestration that ties all phases together through standardized gates, verification layers, and rollback rules.

Changes

OpenSpec Workflow Orchestration

Layer / File(s) Summary
Specification exploration with two-round convergence
.claude/skills/openspec-explore-twice/SKILL.md
Defines the openspec-explore-twice skill: two rounds of structured exploration converging on goals/scope, minimal reversible verification tasks, and finalized design decisions with explicit open-question closure gates before proceeding.
GitNexus blast-radius impact and scope verification
.claude/skills/gitnexus-blast-radius/SKILL.md
Defines the gitnexus-blast-radius skill with pre-change impact analysis (symbols → risk_level) and post-change scope verification (detected vs expected scope comparison), including a multi-step detect-changes fallback and reviewer-comment-driven debug targeting.
Implementation with bounded-service constraints and 4-layer verification
.claude/skills/apply-and-verify/SKILL.md
Defines the apply-and-verify skill: bounded code implementation per tasks.md within service repo boundaries, mandatory linked-file updates, four-layer verification (strict OpenSpec validation, focused unit/E2E tests, git diff hygiene, GitNexus scope-drift detection), commit with Conventional Commits, and PR creation with standardized body/report templates.
PR review gating with conditional debug loop
.claude/skills/pr-review-gate/SKILL.md
Defines the pr-review-gate skill: PR validation and mergeability checking, CI waiting, review decision classification, conditional Debug Loop only for blocking REQUEST_CHANGES items (with GitNexus re-analysis and focused test requests), and mandatory explicit human merge confirmation with constraints.
Archive and closeout with specs/roadmap synchronization
.claude/skills/archive-and-closeout/SKILL.md
Defines the archive-and-closeout skill spanning prerequisites (implementation PR merged, clean worktree), archive branch creation, openspec archive execution with file moves and spec updates, roadmap synchronization (Markdown and HTML), four-layer verification, archive PR creation via pr-review-gate, merge-time branch cleanup, and next-change resolution via change-id-resolve.
Change-ID resolution from roadmap with predecessor gating
.claude/skills/change-id-resolve/SKILL.md
Defines the change-id-resolve skill: parses main roadmap as single source of truth, applies NoSuccessorWhilePredecessorOpen gate checking predecessor implementation/archive PR merge status, determines if target change has existing open PR (continue vs plan new branch), outputs structured YAML with change_id, predecessor, branch_plan, and blockers.
Closed-loop orchestration tying all phases with safety rules
.claude/skills/closed-loop-orchestrator/SKILL.md
Defines the closed-loop-orchestrator skill as the master 14-step workflow integrating all phases: starter decision, spec convergence (explore-twice + strict validation), pre-change risk (blast-radius), implementation/verification (apply-and-verify), review gating (pr-review-gate with conditional debug), archive/closeout (archive-and-closeout), and next-change resolution (change-id-resolve). Includes safety clauses (branch isolation, two-PR policy, merge confirmation, roadmap sync), repo-state checks, and phase-specific rollback/failure handling.
Git configuration to version-control skill definitions
.gitignore
Updates .gitignore to stop blanket-ignoring .claude/ directory and instead selectively allows .claude/skills/ and the specific skill subdirectories to be tracked in version control.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • monkey1sai/AI-BIM-governance#27: Adds roadmap HTML generation and synchronization requirements that integrate with the archive-and-closeout skill's spec/roadmap sync pipeline.

Poem

🐰 A workflow so grand, in fourteen fair steps,
Where phases dance onward through specs and their preps,
Two rounds of exploring, then gating with care,
Blast radius singing, and archives laid bare—
At last, safe and sorted, the loop is complete! 🎀

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: adding seven new Claude Code skills to implement a 14-step closed-loop workflow automation. It is concise, specific, and directly related to the primary purpose of this PR.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/competent-cartwright-83f7c8

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@monkey1sai

Copy link
Copy Markdown
Owner Author

Code Review Summary(五軸評估)

Verdict: COMMENT only(無 blocking issue,2 個建議於下次迭代採納)

PR 規模:8 files / +1023 lines / -1 line。7 個 SKILL.md(103–192 lines 之間)+ .gitignore 例外。


✅ Correctness(正確性)

  • 7 個 SKILL.md 均有合規 YAML frontmatter(name / description / allowed-tools)。
  • name 與目錄名稱一致,符合 Claude Code skills 結構。
  • 跨技能呼叫使用 /skill-name slash command 語法,符合官方 invocation pattern。
  • Claude Code live change detection 在 commit 前已三度確認新技能即時被偵測載入。

✅ Readability(可讀性)

✅ Architecture(架構)

  • 1 orchestrator + 6 worker 拆分,與 PDF Executive Summary 三技能分層原則一致。
  • 不可逆操作(merge / archive)由獨立 skill 承接,符合 PDF Step 13 「archive 不得搭便車塞進 implementation PR」規則。
  • gitnexus-blast-radius 用模式參數(pre-change / post-change)共用一個 skill,避免重複 description budget;模式分支明確。
  • 7 個 skill 都有「邊界與限制」段落,明確標出不做什麼,符合 AGENTS.md repo 邊界精神。

✅ Security(安全性)

  • disable-model-invocation: true 正確套用於三個不可逆 skill:
    • closed-loop-orchestrator(會觸發 merge / archive 鏈)
    • pr-review-gate(包含 gh pr merge)
    • archive-and-closeout(包含 archive PR merge)
  • pr-review-gate 明文寫死:「gh pr merge 前必須使用者明確 "merge" 才執行」「絕對不可以自動執行」。
  • allowed-tools 已脫離 Bash(*) 全 wildcard,採命名 glob(例 Bash(git status*)、Bash(gh pr*))。

✅ Performance(效能)

  • 7 skills × 平均 ~145 lines × ~5 tokens/line ≈ 單 skill ~700 tokens;遠低於 Anthropic 官方 500-line / 5k-token 建議上限。
  • description 平均 ~120 字,總 description budget 約 850 chars,遠低於 1,536 char 上限。
  • 只在 invoke 時 full body 才載入 context,符合 progressive disclosure 原則。

💡 建議(非 blocking,下次迭代採納)

  1. apply-and-verify 的 allowed-tools 可再收斂:目前用 Bash(git*) 過於寬鬆,可拆成 Bash(git add*) Bash(git commit*) Bash(git push*) Bash(git diff*),減少誤觸 git reset --hard 等破壞性指令的可能。
  2. Description trigger phrases 缺乏中英文同義詞:例如 change-id-resolve 只觸發於「OpenSpec change」「下一個 change」等中文片語,未涵蓋「new change id」「what's next」等英文同義詞;建議在實際跑一輪後依 mismatch 案例補強。
  3. closed-loop-orchestrator 與其他 6 個 worker 之間的回傳格式目前以 YAML pseudo-schema 描述,未定義嚴格 contract;若未來要做端對端自動化測試,建議改用 JSON schema 並寫進 supporting file(schema.json)。
  4. gitnexus-blast-radius 的 fallback path(git diff --name-only)已明文揭露為「不能永久替代」,但缺少何時應停止 fallback 升級回 GitNexus 修復的條件;建議補上「連續 3 次 detect-changes 失敗就升 issue」這類停損機制。

✅ Looks Good(亮點)

  • NoSuccessorWhilePredecessorOpen gate 在 change-id-resolve Step 5 有具體查詢條件(implementation PR + archive PR 都需 MERGED),直接解決 PR fix(worker): 補 canonical batch timeout 診斷 #33/歸檔 canonical batch 並新增 enumeration 優化切片 #35 並存的歷史治理風險。
  • 兩段式 PR 強制化 在 archive-and-closeout Step 2/8 明文寫死,配合 pr-review-gate 人工 gate,形成不可繞過的閉環。
  • 驗證證據鏈 在 apply-and-verify 四層驗證(openspec validate → focused tests → git diff --check → detect-changes)與 AGENTS.md 驗證順序完全對齊。
  • PR body 已揭露所有 caveat:branch 命名未走 codex/openspec/<change-id>、runtime smoke 尚未跑、後續建議拆 OpenSpec change 落地 R3/R7。透明度高。

結論

本 PR 為 tooling layer 變更(不動產品程式碼、specs、roadmap),risk_level LOW,建議 merge 後立即跑一次 /closed-loop-orchestrator 完整 dry-run 收集 runtime feedback,作為第二輪迭代輸入。

🤖 Review by Claude Code(Opus 4.7)

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 14

🧹 Nitpick comments (2)
.claude/skills/archive-and-closeout/SKILL.md (1)

22-24: 💤 Low value

Consider adding language specifiers to code blocks.

Multiple fenced code blocks lack language specifiers. Adding hints like bash, markdown, or text would improve documentation quality and resolve linting warnings.

Also applies to: 34-36, 42-44, 72-76, 82-89, 93-103, 141-143, 155-160, 175-177

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/archive-and-closeout/SKILL.md around lines 22 - 24, Several
fenced code blocks (e.g., the blocks containing `!`git switch main`` and `!`git
pull origin main --ff-only`` and other blocks noted at ranges 34-36, 42-44,
72-76, 82-89, 93-103, 141-143, 155-160, 175-177) are missing language
specifiers; update each triple-backtick fence to include an appropriate language
hint like ```bash for shell commands or ```text/markdown for plain text so
linters and renderers can parse them correctly, ensuring each fence that
contains shell commands (`git ...`, `az ...`, etc.) uses ```bash and other
examples use a suitable specifier.
.claude/skills/pr-review-gate/SKILL.md (1)

20-22: 💤 Low value

Consider adding language specifiers to code blocks.

Multiple fenced code blocks are missing language specifiers. While these blocks contain command examples rather than executable code, adding language hints (e.g., bash, text, yaml) would improve documentation clarity and satisfy linting tools.

Also applies to: 30-32, 44-46, 61-63, 71-81, 89-91

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/pr-review-gate/SKILL.md around lines 20 - 22, The fenced code
blocks in .claude/skills/pr-review-gate/SKILL.md (e.g., the block containing the
gh pr view command) are missing language specifiers; update each triple-backtick
fence for those examples (including the blocks at the other noted ranges) to
include an appropriate hint such as bash, text, or yaml (for example change ```
to ```bash or ```text) so linters and readers get correct syntax highlighting
and semantics; locate the blocks by the shown example command `gh pr view
<pr-number> --json
number,title,state,mergeable,mergeStateStatus,reviewDecision,statusCheckRollup,labels,reviews`
and apply the same change to the other listed blocks.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.claude/skills/apply-and-verify/SKILL.md:
- Around line 9-10: The verification contract in SKILL.md declares "type check →
lint → affected unit tests → integration / E2E" but does not enforce type-check
and lint in the Step 3 gate; update the document and pipeline notes so that the
Step 3 "OpenSpec validate + tests + diff check + detect-changes" block first
runs and fails on static/type checks (e.g., add explicit commands for Python
services: python -m mypy . and python -m ruff check .; and for frontend: npm run
typecheck and npm run lint) and require those to pass before running
unit/integration tests; ensure the text references the verification order and
that failing type/lint short-circuits the rest of Step 3.
- Around line 37-44: Several fenced code blocks in the SKILL.md doc are
unlabeled (triggering markdownlint MD040); update each unlabeled ``` block to
include the appropriate language tag (e.g., use ```text for directory/listing
blocks like the "openspec/changes/<change-id>/ ..." block and for PR body
templates, and use ```bash for command lines such as `openspec validate
<change-id> --strict`, `cd _worker && python -m pytest ...`, `git diff --check`,
`gitnexus detect-changes --scope staged`, `git push -u origin
codex/openspec/<change-id>`, and the `gh pr create \` block) so every fenced
block is explicitly typed and markdownlint MD040 is resolved.

In @.claude/skills/archive-and-closeout/SKILL.md:
- Around line 70-76: Replace the CLI-style invocation with the project's
function-style call: change the `gitnexus detect-changes --scope staged` line to
the underscore form `gitnexus_detect_changes()` (or the explicit call
`gitnexus_detect_changes(repo="...", scope="staged")`) so it matches the
documented usage patterns and verifies staged changes before commit; update any
surrounding examples/snippets to use the function name `gitnexus_detect_changes`
consistently.

In @.claude/skills/change-id-resolve/SKILL.md:
- Line 4: The allowed-tools list on the SKILL.md header currently lacks
permission for the ls command used later (see Step 4); update the allowed-tools
entry (the line beginning with "allowed-tools:") to include Bash(ls*) so that
Bash can execute ls at runtime and unblock the skill; ensure the same addition
is applied where the header repeats (noted at lines referenced in the review).
- Line 9: Links to AGENTS.md, CLAUDE.md and docs/... in SKILL.md are using
incorrect relative paths and likely broken; update each Markdown link (e.g.,
"AGENTS.md", "CLAUDE.md", any "docs/..." links) to use the correct repo-relative
path from the current document (for example prefix with ../../../ to reach the
repository root) or replace them with absolute repository URLs, and verify all
occurrences in the file are fixed (including other instances of AGENTS.md,
CLAUDE.md, and docs/...).
- Around line 21-23: The markdown fences in SKILL.md are missing language
identifiers which triggers markdownlint MD040; update each fenced code block
(the backtick blocks shown around `git status --porcelain` and the other
occurrences at the ranges called out) to include a language tag (use bash) so
they read as fenced blocks like ```bash; ensure you apply this change to all
listed occurrences (lines referenced in the comment: the block at the example
plus the ones at 29-32, 44-46, 56-58, 68-70) so the linter stops flagging MD040.
- Around line 34-40: Update the step that reads the roadmap so it explicitly
fetches the file from origin/main instead of the worktree: replace the implicit
instruction to "讀 docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md" with a
command that reads the file from the remote branch (e.g., use git show
origin/main:docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md) and then
search that output for the latest "YYYY-MM-DD 更新(... active change)" or keywords
like "active change" / "下一個 worker risk burn-down" to ensure change_id
resolution uses origin/main content.

In @.claude/skills/closed-loop-orchestrator/SKILL.md:
- Line 5: The allowed-tools list does not permit the git commands required by
the "pull rebase" step used by the continue-existing flow; update the
allowed-tools entry (the "allowed-tools:" line) to include git pull* and/or git
rebase* (or a broader git* pattern) so the declared "pull rebase" step and the
continue-existing phase can execute, ensuring the pattern matches the existing
git commands like "git pull --rebase" used in the workflow.
- Around line 25-27: Add language identifiers to the fenced code blocks in
.claude/skills/closed-loop-orchestrator/SKILL.md to satisfy markdownlint MD040:
tag plain skill invocation blocks with "text" (e.g. the blocks containing
"/change-id-resolve", "/openspec-explore-twice <change-id>",
"/gitnexus-blast-radius pre-change <symbol1,symbol2,...>", "/apply-and-verify
<change-id>", "/pr-review-gate <pr-number>", "/archive-and-closeout
<change-id>") and tag the shell command block containing backticked git/gh
commands with "bash"; update each triple-backtick opening fence accordingly for
the occurrences around lines referenced (also at 40-42, 54-56, 66-68, 83-85,
97-99, 123-127).
- Line 3: Update the description in SKILL.md to correct the skill-count wording:
replace 「三技能」 with 「七技能」 (or "七項技能") so the line accurately states that this
orchestrator depends on seven skills in this PR/stack; ensure the rest of the
sentence remains unchanged (the phrase describing the 14-step closed loop and
the pause-before-irreversible phases should be preserved).

In @.claude/skills/gitnexus-blast-radius/SKILL.md:
- Around line 21-23: The markdown contains unlabeled fenced code blocks with
shell commands (e.g., the backticked lines containing gitnexus analyze
--embeddings --skills --skip-agents-md, gitnexus impact --target <symbol>
--direction upstream, gitnexus detect-changes --scope staged, and git diff
--name-only --cached) which triggers MD040; update each fenced code block around
these commands to include the language label "bash" (i.e., replace ``` with
```bash) at every occurrence noted (including the other locations mentioned) so
the code fences are properly labeled for markdownlint.
- Around line 99-103: The fallback wording is inconsistent: the prose mentions
"git diff --name-only" while the actual fallback command uses "git diff
--name-only --cached"; update the SKILL.md fallback text so both references
match by replacing the staged-only reference with "git diff --name-only
--cached" (or vice versa if you intentionally want unstaged files) so the
fallback evidence only includes staged files; adjust the line that currently
reads the unstaged command to the staged-only form to match the command used
later.

In @.claude/skills/openspec-explore-twice/SKILL.md:
- Around line 20-27: The unlabeled fenced code blocks showing the directory tree
(the block containing "openspec/changes/<change-id>/ ├── proposal.md ...") and
the command block containing the command invocation starting with "!`openspec
validate <change-id> --strict`" need explicit languages to satisfy MD040 and
improve readability; change the tree block fence from ``` to ```text and change
the command block fence from ``` to ```bash so the tree uses a plain-text fence
and the command uses a bash shell fence respectively.

In @.claude/skills/pr-review-gate/SKILL.md:
- Around line 28-65: Update the workflow text to separate CI failures from
reviewer-requested changes: change the Step 2 rule for "fail > 0" to route to a
new "CI Failure Resolution Loop" (describe: fix code/tests, re-run CI, then
return to Step 2) and add a clarifying note that CI failures do not enter the
"Debug Loop (Step 4)"; leave Step 4 ("Debug Loop") explicitly scoped to handling
`REQUEST_CHANGES` comments (summarize comment → call `/gitnexus-blast-radius
post-change` → apply-and-verify → re-push → back to Step 2) so readers can
clearly distinguish the two remediation paths.

---

Nitpick comments:
In @.claude/skills/archive-and-closeout/SKILL.md:
- Around line 22-24: Several fenced code blocks (e.g., the blocks containing
`!`git switch main`` and `!`git pull origin main --ff-only`` and other blocks
noted at ranges 34-36, 42-44, 72-76, 82-89, 93-103, 141-143, 155-160, 175-177)
are missing language specifiers; update each triple-backtick fence to include an
appropriate language hint like ```bash for shell commands or ```text/markdown
for plain text so linters and renderers can parse them correctly, ensuring each
fence that contains shell commands (`git ...`, `az ...`, etc.) uses ```bash and
other examples use a suitable specifier.

In @.claude/skills/pr-review-gate/SKILL.md:
- Around line 20-22: The fenced code blocks in
.claude/skills/pr-review-gate/SKILL.md (e.g., the block containing the gh pr
view command) are missing language specifiers; update each triple-backtick fence
for those examples (including the blocks at the other noted ranges) to include
an appropriate hint such as bash, text, or yaml (for example change ``` to
```bash or ```text) so linters and readers get correct syntax highlighting and
semantics; locate the blocks by the shown example command `gh pr view
<pr-number> --json
number,title,state,mergeable,mergeStateStatus,reviewDecision,statusCheckRollup,labels,reviews`
and apply the same change to the other listed blocks.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9a8d5ba7-33dc-4862-8155-f42c7d5c4654

📥 Commits

Reviewing files that changed from the base of the PR and between 0a0ea9e and b05697b.

📒 Files selected for processing (8)
  • .claude/skills/apply-and-verify/SKILL.md
  • .claude/skills/archive-and-closeout/SKILL.md
  • .claude/skills/change-id-resolve/SKILL.md
  • .claude/skills/closed-loop-orchestrator/SKILL.md
  • .claude/skills/gitnexus-blast-radius/SKILL.md
  • .claude/skills/openspec-explore-twice/SKILL.md
  • .claude/skills/pr-review-gate/SKILL.md
  • .gitignore

Comment on lines +9 to +10
依 [CLAUDE.md](CLAUDE.md) 驗證順序規範:type check → lint → affected unit tests → integration / E2E only when needed。

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Verification contract is incomplete: type-check and lint gates are declared but not enforced.

Line 9 states the required order includes type check and lint, but Step 3 only mandates OpenSpec validate + tests + diff check + detect-changes. This can let static/type issues pass despite the stated policy.

Proposed fix
 ### Step 3:四層驗證

+#### Layer 0:type check + lint(依 service)
+
+```bash
+# Python services (example)
+!`cd _worker && python -m mypy .`
+!`cd _worker && python -m ruff check .`
+
+# Frontend service (example)
+!`cd web-viewer-sample && npm run typecheck`
+!`cd web-viewer-sample && npm run lint`
+```
+
+不過 → 先修正型別/靜態檢查問題,再進入後續驗證。
+
 #### Layer 1:OpenSpec strict validate

Also applies to: 49-77

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/apply-and-verify/SKILL.md around lines 9 - 10, The
verification contract in SKILL.md declares "type check → lint → affected unit
tests → integration / E2E" but does not enforce type-check and lint in the Step
3 gate; update the document and pipeline notes so that the Step 3 "OpenSpec
validate + tests + diff check + detect-changes" block first runs and fails on
static/type checks (e.g., add explicit commands for Python services: python -m
mypy . and python -m ruff check .; and for frontend: npm run typecheck and npm
run lint) and require those to pass before running unit/integration tests;
ensure the text references the verification order and that failing type/lint
short-circuits the rest of Step 3.

Comment on lines +37 to +44
```
openspec/changes/<change-id>/ # 規格
proposal.md / design.md / tasks.md
specs/<capability>.delta.md
<bounded-service>/... # 程式碼
<bounded-service>/tests/... # focused tests
docs/verification/<date>-<change-id>.md # verification evidence
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Add fenced-code languages to clear MD040 warnings.

Multiple command/template blocks are unlabeled and will keep failing markdownlint checks.

Proposed fix
-```
+```text
 openspec/changes/<change-id>/                # 規格
   proposal.md / design.md / tasks.md
   specs/<capability>.delta.md
 <bounded-service>/...                        # 程式碼
 <bounded-service>/tests/...                  # focused tests
 docs/verification/<date>-<change-id>.md     # verification evidence

- +bash
!openspec validate <change-id> --strict


-```
+```bash
# _worker
!`cd _worker && python -m pytest tests/ -x`
...

- +bash
!git diff --check


-```
+```bash
!`gitnexus detect-changes --scope staged`

- +text
(): - <一句話摘要>

<可選的多行 body 說明>


-```
+```bash
!`git push -u origin codex/openspec/<change-id>`

- +bash
!gh pr create \ --base main \ --head codex/openspec/<change-id> \ --title "<type>(<bounded-service>): <change-id> - <摘要>" \ --body-file <generated PR body>

Also applies to: 53-55, 63-75, 81-83, 89-91, 101-105, 116-118, 120-126

🧰 Tools
🪛 markdownlint-cli2 (0.22.1)

[warning] 37-37: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/apply-and-verify/SKILL.md around lines 37 - 44, Several
fenced code blocks in the SKILL.md doc are unlabeled (triggering markdownlint
MD040); update each unlabeled ``` block to include the appropriate language tag
(e.g., use ```text for directory/listing blocks like the
"openspec/changes/<change-id>/ ..." block and for PR body templates, and use
```bash for command lines such as `openspec validate <change-id> --strict`, `cd
_worker && python -m pytest ...`, `git diff --check`, `gitnexus detect-changes
--scope staged`, `git push -u origin codex/openspec/<change-id>`, and the `gh pr
create \` block) so every fenced block is explicitly typed and markdownlint
MD040 is resolved.

---
name: change-id-resolve
description: 解析下一個正式 change-id,套用 NoSuccessorWhilePredecessorOpen gate。當使用者要開始新 OpenSpec change、詢問「下一個 change 是什麼」、或要判定 active change 起點時使用。
allowed-tools: Bash(git status*) Bash(git fetch*) Bash(git rev-parse*) Bash(gh pr list*) Bash(gh pr view*) Read Grep Glob

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

allowed-tools does not permit a command used later (ls).

Step 4 runs ls, but Line 4 does not allow Bash(ls*). This can block execution of the skill at runtime.

Suggested fix
-allowed-tools: Bash(git status*) Bash(git fetch*) Bash(git rev-parse*) Bash(gh pr list*) Bash(gh pr view*) Read Grep Glob
+allowed-tools: Bash(git status*) Bash(git fetch*) Bash(git rev-parse*) Bash(gh pr list*) Bash(gh pr view*) Bash(ls*) Read Grep Glob

Also applies to: 45-45

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/change-id-resolve/SKILL.md at line 4, The allowed-tools list
on the SKILL.md header currently lacks permission for the ls command used later
(see Step 4); update the allowed-tools entry (the line beginning with
"allowed-tools:") to include Bash(ls*) so that Bash can execute ls at runtime
and unblock the skill; ensure the same addition is applied where the header
repeats (noted at lines referenced in the review).


# Change ID Resolve

依 [AGENTS.md](AGENTS.md) 規範,找出下一個正式 active change-id。

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Several Markdown links are likely broken due to incorrect relative paths.

This file is under .claude/skills/change-id-resolve/, so AGENTS.md, CLAUDE.md, and docs/... links should be rooted relatively (../../../...) or converted to absolute repo links.

Suggested fix
-依 [AGENTS.md](AGENTS.md) 規範,找出下一個正式 active change-id。
+依 [AGENTS.md](../../../AGENTS.md) 規範,找出下一個正式 active change-id。
...
-讀 [docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md](docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md)。
+讀 [docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md](../../../docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md)。
...
-- [AGENTS.md](AGENTS.md):repo 邊界與 source-of-truth 順序
-- [CLAUDE.md](CLAUDE.md) §0.1:Claude 與 OpenSpec 對齊規則
-- [docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md](docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md):正式 active change 來源
+- [AGENTS.md](../../../AGENTS.md):repo 邊界與 source-of-truth 順序
+- [CLAUDE.md](../../../CLAUDE.md) §0.1:Claude 與 OpenSpec 對齊規則
+- [docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md](../../../docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md):正式 active change 來源

Also applies to: 36-36, 101-103

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/change-id-resolve/SKILL.md at line 9, Links to AGENTS.md,
CLAUDE.md and docs/... in SKILL.md are using incorrect relative paths and likely
broken; update each Markdown link (e.g., "AGENTS.md", "CLAUDE.md", any
"docs/..." links) to use the correct repo-relative path from the current
document (for example prefix with ../../../ to reach the repository root) or
replace them with absolute repository URLs, and verify all occurrences in the
file are fixed (including other instances of AGENTS.md, CLAUDE.md, and
docs/...).

Comment on lines +21 to +23
```
!`git status --porcelain`
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Add fenced code block languages to satisfy markdownlint MD040.

Static analysis flags these fences; adding bash keeps docs lint-clean and avoids avoidable pipeline noise.

Also applies to: 29-32, 44-46, 56-58, 68-70

🧰 Tools
🪛 markdownlint-cli2 (0.22.1)

[warning] 21-21: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/change-id-resolve/SKILL.md around lines 21 - 23, The markdown
fences in SKILL.md are missing language identifiers which triggers markdownlint
MD040; update each fenced code block (the backtick blocks shown around `git
status --porcelain` and the other occurrences at the ranges called out) to
include a language tag (use bash) so they read as fenced blocks like ```bash;
ensure you apply this change to all listed occurrences (lines referenced in the
comment: the block at the example plus the ones at 29-32, 44-46, 56-58, 68-70)
so the linter stops flagging MD040.

Comment on lines +25 to +27
```
/change-id-resolve
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Add language identifiers to fenced code blocks (MD040).

These blocks currently fail markdownlint. Tag them as text (skill invocations) and bash (shell commands) to keep docs lint-clean.

Suggested edit
-```
+```text
 /change-id-resolve

- +text
/openspec-explore-twice


-```
+```text
/gitnexus-blast-radius pre-change <symbol1,symbol2,...>

- +text
/apply-and-verify


-```
+```text
/pr-review-gate <pr-number>

- +text
/archive-and-closeout


-```
+```bash
!`git status --short --branch`
!`git rev-parse origin/main`
!`gh pr list --state open --limit 5 --json number,title,headRefName,state`
</details>
 


Also applies to: 40-42, 54-56, 66-68, 83-85, 97-99, 123-127

<details>
<summary>🧰 Tools</summary>

<details>
<summary>🪛 markdownlint-cli2 (0.22.1)</summary>

[warning] 25-25: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

</details>

</details>

<details>
<summary>🤖 Prompt for AI Agents</summary>

Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/closed-loop-orchestrator/SKILL.md around lines 25 - 27, Add
language identifiers to the fenced code blocks in
.claude/skills/closed-loop-orchestrator/SKILL.md to satisfy markdownlint MD040:
tag plain skill invocation blocks with "text" (e.g. the blocks containing
"/change-id-resolve", "/openspec-explore-twice ",
"/gitnexus-blast-radius pre-change <symbol1,symbol2,...>", "/apply-and-verify
", "/pr-review-gate ", "/archive-and-closeout
") and tag the shell command block containing backticked git/gh
commands with "bash"; update each triple-backtick opening fence accordingly for
the occurrences around lines referenced (also at 40-42, 54-56, 66-68, 83-85,
97-99, 123-127).


</details>

<!-- fingerprinting:phantom:triton:hawk -->

<!-- d98c2f50 -->

<!-- This is an auto-generated comment by CodeRabbit -->

Comment on lines +21 to +23
```
!`gitnexus analyze --embeddings --skills --skip-agents-md`
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Label fenced command blocks with bash to satisfy markdownlint.

These unlabeled fences will keep triggering MD040 and add avoidable CI/doc noise.

Proposed fix
-```
+```bash
 !`gitnexus analyze --embeddings --skills --skip-agents-md`

- +bash
!gitnexus impact --target <symbol> --direction upstream


-```
+```bash
!`gitnexus detect-changes --scope staged`

- +bash
!gitnexus analyze --embeddings --skills --skip-agents-md
!gitnexus detect-changes --scope staged


-```
+```bash
!`git diff --name-only --cached`
</details>


Also applies to: 31-33, 69-71, 94-97, 101-103

<details>
<summary>🧰 Tools</summary>

<details>
<summary>🪛 markdownlint-cli2 (0.22.1)</summary>

[warning] 21-21: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

</details>

</details>

<details>
<summary>🤖 Prompt for AI Agents</summary>

Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/gitnexus-blast-radius/SKILL.md around lines 21 - 23, The
markdown contains unlabeled fenced code blocks with shell commands (e.g., the
backticked lines containing gitnexus analyze --embeddings --skills
--skip-agents-md, gitnexus impact --target --direction upstream,
gitnexus detect-changes --scope staged, and git diff --name-only --cached) which
triggers MD040; update each fenced code block around these commands to include
the language label "bash" (i.e., replace withbash) at every occurrence
noted (including the other locations mentioned) so the code fences are properly
labeled for markdownlint.


</details>

<!-- fingerprinting:phantom:triton:hawk -->

<!-- 4e71b3a2 -->

<!-- This is an auto-generated comment by CodeRabbit -->

Comment thread .claude/skills/gitnexus-blast-radius/SKILL.md
Comment on lines +20 to +27
```
openspec/changes/<change-id>/
├── proposal.md
├── design.md
├── tasks.md
└── specs/
└── <capability>.delta.md
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Add fenced-code languages for command/tree blocks.

Line 20 and Line 68 use unlabeled fenced blocks, which will keep failing MD040 and reduce readability in rendered docs.

Proposed fix
-```
+```text
 openspec/changes/<change-id>/
 ├── proposal.md
 ├── design.md
 ├── tasks.md
 └── specs/
     └── <capability>.delta.md

- +bash
!openspec validate <change-id> --strict

Also applies to: 68-70

🧰 Tools
🪛 markdownlint-cli2 (0.22.1)

[warning] 20-20: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/openspec-explore-twice/SKILL.md around lines 20 - 27, The
unlabeled fenced code blocks showing the directory tree (the block containing
"openspec/changes/<change-id>/ ├── proposal.md ...") and the command block
containing the command invocation starting with "!`openspec validate <change-id>
--strict`" need explicit languages to satisfy MD040 and improve readability;
change the tree block fence from ``` to ```text and change the command block
fence from ``` to ```bash so the tree uses a plain-text fence and the command
uses a bash shell fence respectively.

Comment on lines +28 to +65
### Step 2:等待 CI checks

```
!`gh pr checks <pr-number>`
```

統計:
- `pass` 數
- `fail` 數
- `pending` 數

若 `fail > 0` → 進入 Debug Loop(Step 4)
若 `pending > 0` → 等待,建議使用者過幾分鐘再執行;不自己 sleep。

### Step 3:列出 review comments

```
!`gh pr view <pr-number> --json reviews,comments`
!`gh api repos/{owner}/{repo}/pulls/<pr-number>/comments`
```

分類:
- `APPROVED`
- `REQUEST_CHANGES`(blocking)
- `COMMENTED`(non-blocking)

### Step 4:Debug Loop(有 blocking risk 時)

針對每個 `REQUEST_CHANGES` comment:

1. 把 comment 文字摘要成 debug target(symbol / file / function)
2. 呼叫 `gitnexus-blast-radius post-change` skill:

```
/gitnexus-blast-radius post-change
```

3. 依結果回到 `apply-and-verify` skill 修正、重 push、回 Step 2

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Fix logic inconsistency between CI failure and review comment handling.

There's a logic mismatch in the Debug Loop flow:

  • Line 39 (Step 2): States that if fail > 0 (CI check failures) → go to Debug Loop (Step 4)
  • Lines 54-65 (Step 4): Describes Debug Loop as handling REQUEST_CHANGES comments specifically

These are fundamentally different scenarios:

  • CI failures require fixing code/tests and re-running the pipeline
  • REQUEST_CHANGES comments require analyzing reviewer feedback and targeted debugging with GitNexus

The workflow should distinguish between these cases:

  1. CI failures should trigger a different remediation path (e.g., "CI Failure Resolution Loop")
  2. Debug Loop (Step 4) should remain focused on reviewer-requested changes
🔧 Proposed fix to separate CI failure and review comment handling
 ### Step 2:等待 CI checks
 

!gh pr checks <pr-number>


統計:
- `pass` 數
- `fail` 數
- `pending` 數

-若 `fail > 0` → 進入 Debug Loop(Step 4)
+若 `fail > 0` → CI 失敗,需修正程式碼/測試並重新 push;回到 Step 2 重新檢查
若 `pending > 0` → 等待,建議使用者過幾分鐘再執行;不自己 sleep。
+
+**注意**:CI 失敗與 reviewer REQUEST_CHANGES 是不同情境,CI 失敗時不進入 Debug Loop(Step 4)。
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)

[warning] 30-30: Fenced code blocks should have a language specified

(MD040, fenced-code-language)


[warning] 44-44: Fenced code blocks should have a language specified

(MD040, fenced-code-language)


[warning] 61-61: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/pr-review-gate/SKILL.md around lines 28 - 65, Update the
workflow text to separate CI failures from reviewer-requested changes: change
the Step 2 rule for "fail > 0" to route to a new "CI Failure Resolution Loop"
(describe: fix code/tests, re-run CI, then return to Step 2) and add a
clarifying note that CI failures do not enter the "Debug Loop (Step 4)"; leave
Step 4 ("Debug Loop") explicitly scoped to handling `REQUEST_CHANGES` comments
(summarize comment → call `/gitnexus-blast-radius post-change` →
apply-and-verify → re-push → back to Step 2) so readers can clearly distinguish
the two remediation paths.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a set of 7 Claude Code “skills” documents to codify a 14-step closed-loop workflow (AI-BIM-governance → OpenSpec → GitNexus → PR review → archive/closeout), and updates .gitignore so these specific skill artifacts under .claude/skills/ are tracked while other .claude/ content remains ignored.

Changes:

  • Updated .gitignore to unignore and track 7 specific .claude/skills/<skill>/ directories.
  • Added 7 new SKILL.md workflow artifacts covering change-id resolution, double-explore, GitNexus blast radius checks, apply+verify, PR review gating, and archive+closeout.
  • Added an orchestrator skill that composes the above into a single end-to-end flow with manual confirmation gates.

Reviewed changes

Copilot reviewed 7 out of 8 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
.gitignore Unignores .claude/skills/ and selectively tracks 7 skill directories.
.claude/skills/closed-loop-orchestrator/SKILL.md Defines the end-to-end 14-step orchestration across the other skills.
.claude/skills/change-id-resolve/SKILL.md Specifies how to resolve the next active change-id and apply predecessor gating.
.claude/skills/openspec-explore-twice/SKILL.md Enforces two OpenSpec explore rounds with “no open questions” gates.
.claude/skills/gitnexus-blast-radius/SKILL.md Wraps GitNexus pre-change impact + post-change scope drift checks (with fallback).
.claude/skills/apply-and-verify/SKILL.md Describes apply phase steps plus a 4-layer verification and PR creation workflow.
.claude/skills/pr-review-gate/SKILL.md Defines CI/review gates and a manual merge confirmation step.
.claude/skills/archive-and-closeout/SKILL.md Defines archive PR flow, roadmap/spec sync expectations, and branch closeout.
Comments suppressed due to low confidence (4)

.claude/skills/closed-loop-orchestrator/SKILL.md:92

  • 這裡說 pr-review-gate 會在同意後執行 gh pr merge --squash --auto --delete-branch,但 pr-review-gate 自己的 Step 6 明確寫「不用 --auto(除非使用者特別說)」。兩份 skill 規範互相矛盾會導致實際 gate 行為不一致;建議統一:預設不使用 --auto,並在 orchestrator 描述中移除 --auto 或改成「視使用者指示」。
該 skill 會:
- 跑 `gh pr checks` 等待 CI 結果
- 列出 review comments
- 若有 blocking risk,自動觸發 `gitnexus-blast-radius post-change` 進入 debug loop
- 全綠後**等待使用者明確同意**才 `gh pr merge --squash --auto --delete-branch`

.claude/skills/pr-review-gate/SKILL.md:11

  • 此檔中的 [CLAUDE.md](CLAUDE.md) 等連結以目前相對路徑在 GitHub 會指向 .claude/skills/pr-review-gate/CLAUDE.md 而失效。建議改成 root-relative(例如 /CLAUDE.md)或正確的相對路徑(例如 ../../../CLAUDE.md)。
# PR Review Gate

依 [CLAUDE.md](CLAUDE.md) 與 PDF 規範,merge 是不可逆動作,必須使用者明確同意。

.claude/skills/change-id-resolve/SKILL.md:10

  • 此檔的 [AGENTS.md](AGENTS.md) / [CLAUDE.md](CLAUDE.md) / [docs/plans/...](docs/plans/...) 連結目前會解析成 .claude/skills/change-id-resolve/... 底下的路徑而失效。建議改成 root-relative(例如 /AGENTS.md、/docs/plans/...)或補上正確相對路徑。
# Change ID Resolve

依 [AGENTS.md](AGENTS.md) 規範,找出下一個正式 active change-id。

.claude/skills/archive-and-closeout/SKILL.md:11

  • 此檔的 [AGENTS.md](AGENTS.md)、[docs/plans/...](docs/plans/...) 連結會因為相對路徑而失效(會指向 .claude/skills/archive-and-closeout/...)。建議改成 root-relative(例如 /AGENTS.md、/docs/plans/...)或使用正確相對路徑。
# Archive and Closeout

依 [AGENTS.md](AGENTS.md) closeout flow:implementation PR merge 後另開 archive branch,不得偷塞進 implementation PR。


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.


# Closed-Loop Orchestrator

依 [docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md](docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md) 與 [AGENTS.md](AGENTS.md) 規範,串接完整的 OpenSpec change 閉環。
Comment thread .claude/skills/pr-review-gate/SKILL.md Outdated
name: pr-review-gate
description: implementation PR 開出後的 review gate;等待 CI checks、列出 reviewer comments、若有 blocking risk 自動觸發 GitNexus debug loop、全綠後等使用者明確同意才 merge。Merge 動作絕不自動執行,必須使用者人工同意。
disable-model-invocation: true
allowed-tools: Bash(gh pr*) Bash(git*) Skill Read Grep
---
name: change-id-resolve
description: 解析下一個正式 change-id,套用 NoSuccessorWhilePredecessorOpen gate。當使用者要開始新 OpenSpec change、詢問「下一個 change 是什麼」、或要判定 active change 起點時使用。
allowed-tools: Bash(git status*) Bash(git fetch*) Bash(git rev-parse*) Bash(gh pr list*) Bash(gh pr view*) Read Grep Glob

# GitNexus Blast Radius

依 [CLAUDE.md](CLAUDE.md) GitNexus Always Do 規範,本 skill 把 GitNexus 包成兩個明確 phase:改前的 blast radius、改後的 scope 驗證。
name: archive-and-closeout
description: implementation PR merge 後執行 archive 與 closeout:建 archive branch、跑 openspec archive、同步 specs 與 roadmap markdown/HTML、開 archive PR、等使用者同意後 merge、最後做 branch cleanup。所有 merge 動作絕不自動執行。
disable-model-invocation: true
allowed-tools: Bash(git*) Bash(gh pr*) Bash(openspec archive*) Read Edit Write Grep

# OpenSpec Explore Twice

依 [CLAUDE.md](CLAUDE.md) §0.1 規範,OpenSpec change 必須至少做兩輪 explore,open questions 不可遺留。
Comment on lines +7 to +10
# Apply and Verify

依 [CLAUDE.md](CLAUDE.md) 驗證順序規範:type check → lint → affected unit tests → integration / E2E only when needed。

依 PR #36 code review 建議 1 與 4:

1. 收斂 `Bash(git*)` 全 wildcard 為命名 glob,避免誤觸 git reset --hard / branch -D:
   - apply-and-verify:拆成 git add/commit/push/diff/status/log
   - pr-review-gate:拆成 git push/status/log(read-only + push only)
   - archive-and-closeout:拆成 git switch/pull/status/fetch/branch/add/commit/push/diff
                        並補上 openspec validate / gitnexus detect-changes

2. gitnexus-blast-radius fallback 補強:
   - 加上「連續 3 次失敗就升 issue 並暫停」的停損條件
   - 避免 git-diff-only fallback 變成永久 technical debt

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b05697b5bb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +70 to +74
# bim-review-coordinator
!`cd bim-review-coordinator && python -m pytest tests/ -x`

# web-viewer-sample
!`cd web-viewer-sample && npm test`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use the actual Node service verification commands

For changes touching the Node services, these focused-test commands send agents down failing paths: bim-review-coordinator is a Vitest/TypeScript package with npm test in package.json, not a Python pytest service, and web-viewer-sample has no test script at all. Any apply run scoped to either service will fail before commit even when the code is valid; use the existing service scripts such as coordinator npm test and viewer npm run build/npm run verify instead.

Useful? React with 👍 / 👎.

Comment on lines +73 to +75
!`openspec validate --strict`
!`git diff --check`
!`gitnexus detect-changes --scope staged`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Allow the archive validation commands

When this skill reaches archive verification, the frontmatter only whitelists Bash(openspec archive*), but this step invokes openspec validate --strict; similarly the GitNexus command is only safe if the Bash(git*) glob is intentionally meant to cover gitnexus. In Claude skill execution this makes the mandatory validation step unavailable, so archive PRs can get blocked or skip the checks the workflow requires.

Useful? React with 👍 / 👎.

Comment on lines +45 to +46
!`gh pr view <pr-number> --json reviews,comments`
!`gh api repos/{owner}/{repo}/pulls/<pr-number>/comments`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit the review-comment API call

This review-gate step asks the skill to run gh api .../pulls/<pr>/comments, but the skill only grants Bash(gh pr*), so the command that fetches inline review comments is not allowed. In PRs with blocking line comments, the gate will miss the data needed for the debug loop or require an unexpected permission escalation; add the gh api command to the allowed tools or use an allowed gh pr command that returns the same comments.

Useful? React with 👍 / 👎.

Comment on lines +81 to +83
讀 `openspec/changes/<change-id>/tasks.md`,比對:
- `tasks.md` 預期碰到的 symbols / files
- `detect-changes` 實際碰到的 symbols / files

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit reading tasks during scope checks

In post-change mode this step requires reading openspec/changes/<change-id>/tasks.md, but the skill frontmatter only allows Bash commands and does not grant Read/Grep/Glob. That means the mandatory comparison of actual GitNexus scope against the expected task scope cannot be performed, so scope drift may either block the workflow unexpectedly or be skipped.

Useful? React with 👍 / 👎.

Comment on lines +34 to +36
### Step 3:讀 main 上的 roadmap

讀 [docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md](docs/plans/AI-BIM-governance-saas-roadmap-2026-05.md)。

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Read the roadmap from origin/main

When this resolver is invoked from an existing feature/archive branch, this instruction reads the worktree's roadmap after only fetching origin/main, so it can select a change id from unmerged branch edits even though the rule above says only main counts. Use git show origin/main:docs/plans/... or switch to a clean main before reading, otherwise successor gating can be based on the wrong roadmap.

Useful? React with 👍 / 👎.

Comment on lines +87 to +93
#### Layer 4:GitNexus scope drift 驗證

```
!`gitnexus detect-changes --scope staged`
```

呼叫 `gitnexus-blast-radius post-change` skill,比對 `affected_symbols` 是否 ⊆ tasks.md 預期 scope。

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit the post-change skill call

This verification layer tells the agent to call gitnexus-blast-radius post-change, but the skill frontmatter does not include the Skill tool. When the apply flow reaches this required scope-drift comparison, the nested skill invocation is unavailable, so the workflow either blocks after detect-changes or skips the expected-vs-actual scope check.

Useful? React with 👍 / 👎.

Comment on lines +137 to +143
### Step 9:等待 archive PR review

呼叫 `pr-review-gate`:

```
/pr-review-gate <archive-pr-number>
```

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit invoking the archive review gate

Archive closeout requires handing the archive PR to /pr-review-gate, but this skill's allowed tools do not include Skill. In the archive flow, that makes the mandatory review/merge gate impossible to invoke from the skill, leaving the PR at Step 9 without the promised CI and review checks.

Useful? React with 👍 / 👎.

Comment on lines +155 to +160
```
!`git switch main`
!`git fetch origin --prune`
!`git status --short --branch`
!`git branch --no-merged origin/main`
```

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Restore the required branch closeout inventory

This closeout inventory omits the AGENTS-required git branch -vv --no-abbrev, remote git branch -r --no-merged origin/main, and PR-state checks before deleting merged/superseded branches. In squash-merge or superseded-branch cases, relying only on local --no-merged can misclassify branches and skip remote cleanup evidence, so the skill should perform the full read-only inventory before any deletion.

Useful? React with 👍 / 👎.

- 跑 `gh pr checks` 等待 CI 結果
- 列出 review comments
- 若有 blocking risk,自動觸發 `gitnexus-blast-radius post-change` 進入 debug loop
- 全綠後**等待使用者明確同意**才 `gh pr merge --squash --auto --delete-branch`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Remove auto-merge from the consented merge path

This orchestrator summary tells users the review gate will run gh pr merge --squash --auto --delete-branch, but the actual gate below explicitly avoids --auto, and the official gh pr merge manual defines --auto as merging automatically once requirements are met (https://cli.github.com/manual/gh_pr_merge). In contexts where checks are still pending or merge queues are involved, this contradicts the repository's manual merge-confirmation policy and can schedule a future merge rather than performing only the just-approved action.

Useful? React with 👍 / 👎.

Comment on lines +63 to +68
```
# _worker
!`cd _worker && python -m pytest tests/ -x`

# _bim-control
!`cd _bim-control && python -m pytest tests/ -x`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit the Python test commands actually shown

The Python service test examples are executed as cd ... && python -m pytest, but the skill only allows Bash(pytest*)/Bash(npm*) rather than commands starting with cd or python. For _worker or _bim-control changes, the documented focused-test commands are therefore not allowed by the skill sandbox even though they are the required service-local invocation.

Useful? React with 👍 / 👎.

@monkey1sai

Copy link
Copy Markdown
Owner Author

Follow-up fix(b1550bc)

依本 PR code review 建議 1 與 4 已 push 第二次 commit:

建議 1:收斂 allowed-tools(防 Bash 全 wildcard 誤觸)

Skill 修改前 修改後
apply-and-verify Bash(git*) Bash(git add*) Bash(git commit*) Bash(git push*) Bash(git diff*) Bash(git status*) Bash(git log*)
pr-review-gate Bash(git*) Bash(git push*) Bash(git status*) Bash(git log*) + Bash(gh api*)
archive-and-closeout Bash(git*) Bash(git switch*) Bash(git pull*) Bash(git status*) Bash(git fetch*) Bash(git branch*) Bash(git add*) Bash(git commit*) Bash(git push*) Bash(git diff*)、補上 Bash(openspec validate*) Bash(gitnexus detect-changes*)

效果:移除 git reset --hard、git push -f、git branch -D 等破壞性指令的「免確認權限」。

建議 4:gitnexus-blast-radius fallback 停損

加上明確的失敗計數表:

  • 第 1 次 → analyze 後重試
  • 第 2 次 → 用 git diff --name-only fallback,PR body 標 ⚠️
  • 第 3 次 → 停止 + gh issue create 升 issue + 暫停 commit/merge 流程

防止 fallback 變成永久 technical debt(PR #35 曾出現的真實風險)。

Diff scope

.claude/skills/apply-and-verify/SKILL.md      |  2 +-
.claude/skills/archive-and-closeout/SKILL.md  |  2 +-
.claude/skills/gitnexus-blast-radius/SKILL.md | 12 +++++++++++-
.claude/skills/pr-review-gate/SKILL.md        |  2 +-
4 files changed, 14 insertions(+), 4 deletions(-)

建議 2(trigger phrases 中英文同義詞)與建議 3(skill 間 contract schema)保留為下次迭代採納,因為這兩條需要實際跑一輪 closed-loop 收集 mismatch / interface 使用案例後再優化,現在做容易過度設計。

PR 維持 OPEN 狀態,等待 @monkey1sai 同意 merge。

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.claude/skills/apply-and-verify/SKILL.md:
- Around line 87-91: Layer 4's scope drift check uses "gitnexus detect-changes
--scope staged" but the workflow never stages files (Layer 3 only runs "git diff
--check"), so the staged set can be empty and the check will falsely pass; add
an explicit staging step before Layer 4 (for example call "git add -p" or
per-file "git add <file>") so that changed files are actually in the staged
index before running "gitnexus detect-changes --scope staged", ensuring the
scope drift verification in Layer 4 detects real changes.

In @.claude/skills/archive-and-closeout/SKILL.md:
- Around line 70-76: Add an explicit staging step before running the staged-only
verification: insert a command to stage the modified directories (e.g. run git
add openspec/ docs/plans/) before the series of checks that include openspec
validate, git diff --check and gitnexus detect-changes --scope staged so that
gitnexus actually inspects the intended changes; update the block around the
Step 6 commands (the triple-backtick snippet containing openspec validate, git
diff --check, gitnexus detect-changes) to include this git add command
immediately before gitnexus detect-changes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 3b1861a1-bf95-4101-b84a-e8b034d845f1

📥 Commits

Reviewing files that changed from the base of the PR and between b05697b and b1550bc.

📒 Files selected for processing (4)
  • .claude/skills/apply-and-verify/SKILL.md
  • .claude/skills/archive-and-closeout/SKILL.md
  • .claude/skills/gitnexus-blast-radius/SKILL.md
  • .claude/skills/pr-review-gate/SKILL.md

Comment on lines +87 to +91
#### Layer 4:GitNexus scope drift 驗證

```
!`gitnexus detect-changes --scope staged`
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

cat -n .claude/skills/apply-and-verify/SKILL.md | sed -n '75,105p'

Repository: monkey1sai/AI-BIM-governance

Length of output: 838


🏁 Script executed:

wc -l .claude/skills/apply-and-verify/SKILL.md

Repository: monkey1sai/AI-BIM-governance

Length of output: 117


🏁 Script executed:

cat -n .claude/skills/apply-and-verify/SKILL.md | head -90

Repository: monkey1sai/AI-BIM-governance

Length of output: 3122


🏁 Script executed:

cat -n .claude/skills/apply-and-verify/SKILL.md | sed -n '87,120p'

Repository: monkey1sai/AI-BIM-governance

Length of output: 869


🏁 Script executed:

fd gitnexus

Repository: monkey1sai/AI-BIM-governance

Length of output: 100


🏁 Script executed:

grep -r "git add" .claude/skills/apply-and-verify/ || echo "No git add found in file"

Repository: monkey1sai/AI-BIM-governance

Length of output: 413


🏁 Script executed:

cat -n CLAUDE.md | grep -A5 -B5 "stage\|git add" || echo "No staging references found"

Repository: monkey1sai/AI-BIM-governance

Length of output: 4056


🏁 Script executed:

grep -n "不跑.*git add" .claude/skills/apply-and-verify/SKILL.md

Repository: monkey1sai/AI-BIM-governance

Length of output: 104


🏁 Script executed:

cat -n docs/gitnexus-validation.md

Repository: monkey1sai/AI-BIM-governance

Length of output: 5224


🏁 Script executed:

cat -n .claude/skills/apply-and-verify/SKILL.md | sed -n '175,189p'

Repository: monkey1sai/AI-BIM-governance

Length of output: 521


Layer 4 runs scope drift check against potentially empty staged set.

Layer 4 uses --scope staged to detect scope drift, but the workflow has no explicit staging instruction before it. Layer 3 checks unstaged changes with git diff --check, yet no git add command follows. If files remain unstaged when Layer 4 executes, the staged set is empty and scope verification silently passes without detecting actual changes, defeating the safety check's purpose.

Add a staging step before Layer 4 (e.g., git add -p or explicit per-file staging per the safety guidelines) to ensure changed files are staged before running scope drift verification.

🧰 Tools
🪛 LanguageTool

[grammar] ~87-~87: Ensure spelling is correct
Context: ...whitespace / formatting 問題。 #### Layer 4:GitNexus scope drift 驗證 ``` !`gitnexus detect-c...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🪛 markdownlint-cli2 (0.22.1)

[warning] 89-89: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/apply-and-verify/SKILL.md around lines 87 - 91, Layer 4's
scope drift check uses "gitnexus detect-changes --scope staged" but the workflow
never stages files (Layer 3 only runs "git diff --check"), so the staged set can
be empty and the check will falsely pass; add an explicit staging step before
Layer 4 (for example call "git add -p" or per-file "git add <file>") so that
changed files are actually in the staged index before running "gitnexus
detect-changes --scope staged", ensuring the scope drift verification in Layer 4
detects real changes.

Comment on lines +70 to +76
### Step 6:四層驗證

```
!`openspec validate --strict`
!`git diff --check`
!`gitnexus detect-changes --scope staged`
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

cat -n ".claude/skills/archive-and-closeout/SKILL.md" | head -100

Repository: monkey1sai/AI-BIM-governance

Length of output: 3486


🏁 Script executed:

sed -n '80,120p' ".claude/skills/archive-and-closeout/SKILL.md" | cat -n

Repository: monkey1sai/AI-BIM-governance

Length of output: 1312


🏁 Script executed:

sed -n '100,150p' ".claude/skills/archive-and-closeout/SKILL.md" | cat -n

Repository: monkey1sai/AI-BIM-governance

Length of output: 1636


Add explicit staging before Step 6 verification.

At Line 75, gitnexus detect-changes --scope staged runs without files being staged first, so the verification would find no changes despite modifications in Steps 3–5. Add an explicit staging step before the detect-changes command to verify the correct directories (openspec/ and docs/plans/).

Proposed fix
 ### Step 6:四層驗證
 

+!git add openspec/ docs/plans/
!openspec validate --strict
!git diff --check
!gitnexus detect-changes --scope staged

🧰 Tools
🪛 markdownlint-cli2 (0.22.1)

[warning] 72-72: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/archive-and-closeout/SKILL.md around lines 70 - 76, Add an
explicit staging step before running the staged-only verification: insert a
command to stage the modified directories (e.g. run git add openspec/
docs/plans/) before the series of checks that include openspec validate, git
diff --check and gitnexus detect-changes --scope staged so that gitnexus
actually inspects the intended changes; update the block around the Step 6
commands (the triple-backtick snippet containing openspec validate, git diff
--check, gitnexus detect-changes) to include this git add command immediately
before gitnexus detect-changes.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b1550bc8f4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

|---|---|
| 第 1 次失敗 | 跑 `gitnexus analyze --embeddings --skills --skip-agents-md` 後重試 |
| 第 2 次失敗 | 改用 `git diff --name-only --cached` 作 fallback,但在 PR body 標記 ⚠️ |
| **第 3 次失敗(同一 session)** | **停止**:升為 issue(`gh issue create`),標題格式 `gitnexus: detect-changes repeatedly failing on <branch>`,body 附最近 3 次失敗指令與 stderr,並暫停該 change 的 commit / merge 流程,等修復或 reviewer 明確 sign-off「accept git-diff-only fallback for this PR」後再繼續 |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit the stop-loss issue creation

When detect-changes fails three times in this post-change path, the skill makes gh issue create the required escalation, but this skill's allowed-tools only permits GitNexus, git diff, and git status Bash commands. In that failure scenario the mandatory stop-loss action is unavailable, so the workflow either blocks or skips the issue evidence it says is required; add an allowed Bash(gh issue*)/Bash(gh*) entry or make this an explicit manual step.

Useful? React with 👍 / 👎.

#### Layer 4:GitNexus scope drift 驗證

```
!`gitnexus detect-changes --scope staged`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run scope detection against actual changes

In a normal apply run this verification step happens before the Commit step and there is no prior instruction to git add the worktree, so --scope staged can inspect an empty index and report no affected symbols even when the implementation changed files. That lets the scope-drift gate pass without checking the real diff; either stage the intended files before this layer or use a working-tree/all-changes scope here.

Useful? React with 👍 / 👎.

**Gate**:
- `blockers` 非空 → STOP 並回報
- 若 `branch_plan == "new"` → `git switch -c codex/openspec/<change-id>`
- 若 `branch_plan == "continue-existing"` → `git switch <branch>` 並 pull rebase

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Permit syncing existing change branches

When branch_plan == "continue-existing", this path explicitly requires a pull/rebase after switching to the existing branch, but the skill's allowed-tools only grants git status, fetch, switch, and rev-parse for Git commands. Any run that resumes an already-open change cannot perform the documented sync step, leaving the agent either blocked or continuing from a stale local branch.

Useful? React with 👍 / 👎.

### Step 2:等待 CI checks

```
!`gh pr checks <pr-number>`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Collect check status without tripping on pending CI

For PRs with pending checks, this command can terminate the skill before the documented pending > 0 branch runs: the official gh pr checks manual says pending checks use additional exit code 8, and it also exposes a bucket field only with --json for pass/fail/pending classification. Use gh pr checks --json ... and explicitly handle exit 8, otherwise normal in-progress CI can look like a command failure instead of a wait condition.

Useful? React with 👍 / 👎.

### Step 3:列出 review comments

```
!`gh pr view <pr-number> --json reviews,comments`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use latest review state, not historical reviews

On PRs where a reviewer requested changes and later approved, reviews still contains the old REQUEST_CHANGES entry, so the Step 4 classification can treat an already-resolved review as blocking. The gh pr view JSON fields include latestReviews and this skill already fetches reviewDecision in Step 1, so base the blocking gate on the latest/effective review state rather than the full historical reviews list.

Useful? React with 👍 / 👎.

Comment on lines +67 to +68
讀同名 `.html`(若存在),同步更新 archive 段落、Phase 狀態。
若無 `.html` → 跳過,但在 archive PR body 註明。

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Do not skip the required roadmap HTML sync

If the roadmap HTML is missing, this branch tells the archive flow to skip it, but the workspace closeout rule requires archive sync to actively produce or update the same-name HTML view after the Markdown roadmap is synchronized. In that scenario an archive PR can be opened without the required derived roadmap view, so the skill should generate the HTML or stop for a documented blocker rather than silently skipping it.

Useful? React with 👍 / 👎.

@monkey1sai
monkey1sai merged commit fa96c55 into main May 13, 2026
1 check passed
@monkey1sai
monkey1sai deleted the claude/competent-cartwright-83f7c8 branch May 13, 2026 06:44
monkey1sai added a commit that referenced this pull request Jun 2, 2026
…ig-hygiene

L4 9 items 拆三類,本 design 收第 1 類(可設定防禦 #2 #6 #23 #26,複用 CH-2 strict
pattern 預設 off 不破 demo)+ 第 2 類(repo 治理 #29 #36)共 6 項。使用者拍板:#6
維持 unauth + 文件 + test、#34 不納入。執行權威 = 同名 OpenSpec change。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
monkey1sai added a commit that referenced this pull request Jun 2, 2026
harden-internal-auth-and-config-hygiene: #2 host-native token(已存在)補 test+GET comment / #6 coordinator internal middleware(已存在)comment+test / #36 退役 event 過濾 test / #26 kit-manager CORS 可設定+compose env / #23 deploy env fallback warning+missing throw。#29 evidence 移出(archive immutable,走獨立 PR)。opus 4-lens 全 LGTM + 外部 reviewer fix。
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants