diff --git a/.github/copilot-instructions.md b/.github/copilot-instructions.md index 8b8d2ee..956f854 100644 --- a/.github/copilot-instructions.md +++ b/.github/copilot-instructions.md @@ -4,7 +4,7 @@ You are an expert GitHub Agentic Workflow generator. You help users create produ ## Your Knowledge -Use the committed pattern library as the source of truth: `patterns/manifest.json` plus `patterns/archetypes/*.json` generated on 2026-09-28 from 563 source repos, 345 active workflows, and 929 total workflows scanned. The current wizard manifest lists 33 user-facing archetypes; the `custom` archetype exists as a supporting pattern file and is intentionally not exposed as a HOW-step archetype. +Use the committed pattern library as the source of truth: `patterns/manifest.json` plus `patterns/archetypes/*.json` generated on 2026-09-28 from 563 source repos, 345 active workflows, and 929 total workflows scanned. The current wizard manifest lists 34 user-facing archetypes; the `custom` archetype exists as a supporting pattern file and is intentionally not exposed as a HOW-step archetype. ### Key Data Points @@ -24,7 +24,7 @@ Use the committed pattern library as the source of truth: `patterns/manifest.jso - `custom` is hidden from the wizard archetype cards but retained for matching and profile data. Best observed custom profiles are schedule + create-pull-request + noop at 95.2% (n=21), schedule + create-issue + noop + threat-detection at 83.9%, and schedule + create-issue + noop at 80.0%. **Curated archetypes without empirical runs yet (`count: 0`):** -- accessibility-expert, agent-cost-tracker, backlog-drip, batched-ci-doctor, ci-failure-triage, code-health-auditor, community-digest, contribution-guidelines-checker, issue-hierarchy-manager, link-checker, linter-applier, linter-miner, linter-refiner, linter-workflows, nitpick-reviewer, performance-nut, pr-fix-assistant, pr-iteration-loop, repo-qa-assistant, responsive-docs-tester, security-scanner, user-simulator, vex-statement-generator. +- accessibility-expert, agent-cost-tracker, backlog-drip, batched-ci-doctor, ci-failure-triage, code-health-auditor, community-digest, contribution-guidelines-checker, cross-repo-monitor, issue-hierarchy-manager, link-checker, linter-applier, linter-miner, linter-refiner, linter-workflows, nitpick-reviewer, performance-nut, pr-fix-assistant, pr-iteration-loop, repo-qa-assistant, responsive-docs-tester, security-scanner, user-simulator, vex-statement-generator. - Keep these archetypes available. They are newer curated patterns and should not be removed simply because they have no measured success rate. **Trigger combo risk:** diff --git a/patterns/archetypes/cross-repo-monitor.json b/patterns/archetypes/cross-repo-monitor.json new file mode 100644 index 0000000..2600c0a --- /dev/null +++ b/patterns/archetypes/cross-repo-monitor.json @@ -0,0 +1,39 @@ +{ + "id": "cross-repo-monitor", + "label": "Cross-Repository Monitor", + "description": "Read and evaluate activity in a different target repository on a schedule, dispatch per-item evaluation, and write a consolidated report plus labels/comments back to the target repo", + "success_rate": null, + "count": 0, + "recommended_triggers": [ + { + "type": "schedule", + "config": {} + } + ], + "recommended_safe_outputs": [ + "issues", + "add-labels", + "add-comment" + ], + "recommended_tools": [ + "create-issue", + "add-labels", + "add-comment" + ], + "timeout_minutes": 20, + "prompt_style": "role-steps", + "size_range_bytes": [ + 3000, + 8000 + ], + "top_repos": [], + "tips": [ + "Set target-repo (an env var or repository variable, not a hardcoded string) on every safe output that writes to the external repository, and read from that same repository via GitHub toolsets", + "Pre-filter and fetch the target repository's items in a steps: block before the agent starts, so the agent only evaluates a bounded, pre-computed list", + "Act as an orchestrator: dispatch each item to a stateless, self-contained evaluation (inline sub-agent or per-item prompt) and compile the results into one report rather than evaluating everything inline", + "Publish the consolidated report as an issue in the home repository, and use close-older-issues: true so each run replaces the previous report instead of accumulating", + "Use add-labels and add-comment with target-repo to apply verdicts and feedback directly on items in the target repository, each capped with max: to bound write volume", + "Document the required token scopes (contents, issues, pull-requests, or actions:write for cross-repo dispatch) in the prompt since the default GITHUB_TOKEN cannot write to another repository" + ], + "anti_patterns": [] +} diff --git a/patterns/archetypes/issue-hierarchy-manager.json b/patterns/archetypes/issue-hierarchy-manager.json index fccad33..f73172c 100644 --- a/patterns/archetypes/issue-hierarchy-manager.json +++ b/patterns/archetypes/issue-hierarchy-manager.json @@ -27,7 +27,8 @@ "Pre-fetch open issues in a steps: block before reasoning about relationships", "Use link-sub-issue with parent/sub label or title-prefix filters to bound which issues can be linked", "Recursively close parent issues only after confirming every sub-issue is complete", - "Read-only issues permission is enough \u2014 rely on safe-outputs like link-sub-issue and update-issue for writes" + "Read-only issues permission is enough \u2014 rely on safe-outputs like link-sub-issue and update-issue for writes", + "When this run needs to create several new findings as a set, use create-issue's group: true so they land as linked sub-issues under one parent instead of unrelated top-level issues" ], "anti_patterns": [] } diff --git a/patterns/manifest.json b/patterns/manifest.json index dfab156..b0033b3 100644 --- a/patterns/manifest.json +++ b/patterns/manifest.json @@ -38,7 +38,8 @@ "pr-fix-assistant", "backlog-drip", "responsive-docs-tester", - "vex-statement-generator" + "vex-statement-generator", + "cross-repo-monitor" ], "workflow_generation": "workflow-generation.json", "anti_patterns": [ diff --git a/patterns/workflow-generation.json b/patterns/workflow-generation.json index 7bbe854..14eb6cd 100644 --- a/patterns/workflow-generation.json +++ b/patterns/workflow-generation.json @@ -544,6 +544,41 @@ "- **DO NOT** report a finding already covered by an existing open issue from this workflow." ] }, + "cross-repo-monitor": { + "icon": "repo", + "capabilities": { + "pre_steps": true, + "bash": true, + "github_toolsets": true + }, + "permissions": [ + "contents", + "issues", + "pull-requests" + ], + "instructions": [ + "workflow-patterns.md" + ], + "body": [ + "# {{label}}", + "", + "You are an **orchestrator** that monitors a different target repository and reports findings back to this repository.", + "", + "{{pre_steps}}", + "## Process", + "", + "1. Read the pre-filtered list of items from the target repository produced in the steps above", + "2. Dispatch each item to a stateless, self-contained evaluation and collect its verdict", + "3. Compile all verdicts into a single consolidated report issue in THIS repository", + "4. Apply labels and post comments on the evaluated items in the target repository using the pre-configured `target-repo` safe outputs", + "", + "## Constraints", + "", + "- **DO NOT** write to the target repository with anything other than the configured safe-output tools \u2014 never use `gh` or the GitHub API directly for target-repo writes.", + "- **DO NOT** evaluate more items than the pre-filtered list provides.", + "- **DO NOT** merge, approve, or close items in the target repository." + ] + }, "vex-statement-generator": { "icon": "shield", "capabilities": {