Skip to content

Agentic software factory Part 8: issue-triage skill and board audit - #4906

Merged
cliffhall merged 10 commits into
v2/mainfrom
v2/feat/4868-issue-triage
Sep 29, 2026
Merged

cliffhall merged 10 commits into
v2/mainfrom
v2/feat/4868-issue-triage

Conversation

@cliffhall

@cliffhall cliffhall commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Closes #4868

Important

Stacked on #4904 (Part 9, contribution model), which is itself stacked on #4899 (Part 6, board-ops / issue-create). This PR's base is v2/docs/4869-contribution-model, so the diff shows only this change. Retarget it as those merge: to v2/feat/4866-board-ops-issue-create if #4904 is folded in first, and to v2/main once both have merged.

Description

Part 8 of the agentic software factory (#4858, Wave 3): the issue-triage skill and the board audit, adapted from the MCP Inspector's for one board (#43) and this repo's community inflow, and carrying out the outside-PR plan that #4904 wrote in docs/contribution-model.md ("The plan").

New skill: .claude/skills/issue-triage/

  • Step 0, the class check (new; the Inspector has no public inflow). Each class has an action and a canned response:
    Class Action Response
    Server listing or submission Close, not planned Registry, issue
    New server request Close, not planned Registry, issue
    Archived server (servers-archived) Close, not planned Archived
    SDK or specification Close, not planned Elsewhere
    Duplicate Close as duplicate, delete any card Duplicate
    Spam or empty Close, not planned None
    Security report Stop; a maintainer decides, no details restated Security
    Everything else Pass 1 Score comment
  • Two-pass sweep: pass 1 labels (v2, one type, the server-<name> scope label read off the issue form's dropdown), boards as Incoming, scores Priority and posts the score, leaves the milestone unset (already-milestoned → Todo). Pass 2 (milestone + Todo) is human-only.
  • Priority rubric: the Inspector's two axes, bonuses and bands, with the severity axis reworded for servers ("reports something false about the protocol", "escapes an allowed root", SSRF, injection), and the trust boundary for the public org-level Fields → Priority.
  • Outside PRs, per the plan: snapshot with a truncation check, maintainer detection (admin/maintain role; write access is not enough), a path-based pre-class as a hint, a duplicate-group finder, the classes (listing, new server, archived server, no-op/spam, duplicate, security fix, fix to keep, out of scope), a maintainer reviews the manifest before anything is closed, harvest into Incoming issues with no milestone, a paced close loop that stops on the first failure and skips security fixes, and the verify step.
  • Canned responses in one place: the plan's general and Registry PR comments, plus Registry/Archived/Elsewhere/Duplicate/Security responses for issues. docs/contribution-model.md now points at them instead of holding a second copy.
  • The board audit for Initial GitLab server version #43, read-only, every check meant to print 0. It adds open issue, no card, open, no v2 and closed completed, not Done (single version label here) to the Inspector's set and drops the two-board checks. The issue listing uses --limit 5000, above the repo's 1,250 total issues, and treats a listing that fills the limit as truncated; the board listing is checked against .totalCount.
  • The [GHSA- draft-card carve-out: Agentic software factory Part 10: security-advisory skill; rewrite SECURITY.md #4905 (Part 10) left it to this PR. The exemption is DraftIssue and the [GHSA- title prefix (a [GHSA--titled PR or any other draft is still reported), with the replacement GHSA draft missing Status/Priority check so an advisory card is never invisible to the audit.
  • Eval cases: 6 positives, 2 negatives.

readme-pr-check.yml folded in and retired

Its /i-promise-this-is-not-a-new-server escape invited exactly the outside PR the policy now closes. Its "only README.md changed" test is now the skill's listing pre-class (widened to ADDITIONAL.md), its redirect is the Registry response, and its readme: pending / readme: ready for review labels are treated as hints. The file is deleted on v2/main only: pull_request_target runs from the PR's base branch and issue_comment from the default branch, so the copy on main keeps answering PRs against main until the next milestone merge. Nothing live changes when this merges.

Small edits elsewhere

  • AGENTS.md: the skills-index row, and readme-pr-check.yml dropped from the tree.
  • issue-create: the "rubric replaces this table when Add issue-triage skill and board audit, for community inflow #4868 lands" note now points at the rubric (the short table stays, as its quick form).
  • docs/contribution-model.md: the two canned comments replaced by a pointer to the skill; the readme-pr-check.yml bullet records it as done.

Board audit, current output (read-only)

Run 2026-09-29 from the skill's recipe, before any triage pass:

0	non-Issue on #43	[]
0	GHSA draft missing Status/Priority	[]
217	open issue, no card	[4892,4887,4885,4882,4850,4846,4844,4841,4838,4830]
0	no Status	[]
0	Incoming w/ milestone	[]
0	past Incoming, no ms	[]
217	open, no v2	[4892,4887,4885,4882,4850,4846,4844,4841,4838,4830]
90	open, not exactly 1 type label	[4892,4887,4885,4882,4877,4876,4875,4860,4858,4857]
1	open, no Priority	[4860]
0	closed unshipped, still carded	[]
0	open, but carded Done	[]
0	closed completed, not Done	[]

The non-zero rows are the untriaged backlog (217 unboarded, unlabeled issues) plus a little drift on carded issues: the trackers #4857, #4858, #4860, #4875, #4876 and #4877 carry no type label, and #4860 has no Priority. None were touched.

Outside-PR pre-class on the same day (hints from paths only; 323 open PRs): 4 Dependabot, 13 maintainer (14 counting this PR), 24 listing?, 9 new-server?, 255 server-change?, 18 repo-level?, so 306 outside PRs, matching #4904's snapshot.

Human-gated follow-ups (not done by this PR)

These are the acceptance criteria that are mass outward-facing actions. No issue or PR outside this one was closed, commented on, labeled or boarded. They are tracked by #4875 (#4876 issues, #4877 PRs), and need a maintainer's go-ahead after this merges:

  1. Issue backlog triage pass (Triage the open issue backlog #4876): in a session on v2/main, ask "Triage new issues" (or /issue-triage). It runs step 0 and pass 1 over the 217 unboarded issues and lists any closes for your confirmation first. Then run the audit block from the skill's "The board audit" section; the acceptance is every row 0. The six tracker issues above need a type label and Adopt MCP interface-diff CI for the everything server (decide on PR #3260) #4860 a Priority for their rows to clear.
  2. Outside-PR backlog (Triage the open PR backlog #4877): ask "Triage the PRs" (or /issue-triage → Outside PRs). It stops after writing the manifest; review it, then approve harvest (step 3), the closes (step 4, the paced loop), and run verify (step 5). Tracker: Triage the open issue and PR backlog #4875's conventions (a close label, and a #4875 reference in each close comment) are applied during that sweep.
  3. Optional repo cleanup: the readme: pending / readme: ready for review labels become unused once main receives this change; deleting them is a repo-settings call.

How Has This Been Tested?

Docs and skills only; no server code changed, so there was no LLM-client server test.

  • Every read-only recipe in the skill (the unboarded finder, the PR snapshot and pre-class, the duplicate-group finder, and the audit) was extracted verbatim from SKILL.md and run against the live repo; the outputs are above.
  • npm run validate:guards: pass (verify:skills OK, 3 model-invoked skills, listing 1210/4000 chars; 247 script tests).
  • RUNS=5 npm run skills:eval (whole suite): 22/22 first-move cases pass (all six issue-triage positives at 100% except "After scoring an issue against the rubric, what do I do with the score?" at 80%, the threshold; every negative at 100%, and no regression in board-ops or issue-create), and the issue-create → board-ops hand-off at 100%.

Breaking Changes

None. No server, tool or configuration changed; the retired workflow keeps running on main until the milestone merge.

Types of changes

  • Documentation update

Checklist

  • I have read the MCP Protocol Documentation (no protocol feature touched)
  • My changes follows MCP security best practices
  • I have updated the server's README accordingly (not applicable: no server changed)
  • I have tested this with an LLM client (not applicable: no server-facing change; triggering measured with skills:eval)
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling (not applicable)
  • I have documented all environment variables and configuration options (not applicable)

🤖 Generated with Claude Code

@cliffhall cliffhall added the v2 label Sep 29, 2026
@cliffhall cliffhall linked an issue Sep 29, 2026 that may be closed by this pull request
4 tasks
@cliffhall
cliffhall requested a balanced review from Copilot September 29, 2026 05:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The bulk-close procedure can misparse manifests and accidentally close security fixes or post incorrect issue references.

Review effort: Balanced
Findings: 2 High severity · 2 Medium severity

Open (4)
What changed in this PR

Adds the issue-triage skill for issue/PR classification, board auditing, and backlog handling while retiring the README-only PR workflow.

Changes:

  • Adds triage procedures, canned responses, priority scoring, board audit, and evals.
  • Updates skill documentation and contribution guidance.
  • Removes readme-pr-check.yml.
File Description
.claude/​skills/​issue-triage/​SKILL.md Adds the triage and audit procedures.
.claude/​skills/​issue-triage/​evals/​evals.json Adds skill-triggering eval cases.
.claude/​skills/​issue-create/​SKILL.md Links priority selection to the new rubric.
.github/​workflows/​readme-pr-check.yml Retires the README PR workflow.
AGENTS.md Registers the skill and updates the repository tree.
docs/​contribution-model.md Makes the skill authoritative for canned responses.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .claude/skills/issue-triage/SKILL.md
Comment thread .claude/skills/issue-triage/SKILL.md
Comment thread .claude/skills/issue-triage/SKILL.md
Comment thread .claude/skills/issue-triage/SKILL.md Outdated
cliffhall added a commit that referenced this pull request Sep 29, 2026
…e rule

Copilot round 1 on #4906:
- the manifest uses '-' for 'no issue', because read collapses adjacent tabs
  and an empty field shifted the reason into the issue column
- class slugs are defined in the table; the loop whitelists them, skips
  'security', and stops on anything unknown instead of closing it
- the backlog sweep's close label and #4875 reference (SWEEP_LABEL, SWEEP_REF)
  are part of the loop, and the step 0 issue closes take the same two
- step 0's close rule covers only rows whose Action is Close, never a
  security report

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall

Copy link
Copy Markdown
Member Author

Copilot round 1: 4 findings, all fixed in cf677d6, with a reply in each thread.

  • Manifest parsing (high): an empty issue field collapsed under a tab IFS. Fixed with a - sentinel, and every field is now required.
  • Security class (high): the loop only recognized security. There are now canonical slugs in the class table, and the loop whitelists them and stops on an unknown value.
  • Tracker: Triage the open issue and PR backlog #4875 conventions (medium): SWEEP_LABEL / SWEEP_REF in the close loop add the close label and the Tracker: Triage the open issue and PR backlog #4875 reference, and step 0 issue closes do the same.
  • Step 0 close rule (medium): scoped to rows whose Action is Close. A security report is never closed by triage.

The loop was dry-run with gh replaced by echo. verify:skills passes. No suppressed comments this round. Re-requesting review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The audit and bulk-close recipes have correctness gaps, and the linked issue’s acceptance criteria remain deferred.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (4)
Previously missed (4)

In code that hasn't changed since last review

Medium severity Do not close #4868 with acceptance criteria still deferred

.claude/​skills/​issue-triage/​SKILL.md:34

The linked #4868 acceptance criteria require running the current issue backlog through triage until the audit is all zero and handling the outside-PR backlog, but this change defers those actions to #4876/#4877 while the PR still declares Closes #4868. Those follow-ups are themselves blocked by #4857 and #4858, so merging would mark Part 8 complete with two acceptance criteria outstanding. Keep #4868 open/change the PR relationship, or update the agreed issue scope before approval.

Medium severity Use an exact Dependabot bot identity check

.claude/​skills/​issue-triage/​SKILL.md:314

This substring test exempts any outside author whose login merely contains dependabot (for example, dependabot-helper), even though the policy exempts only the actual Dependabot bot. Such a PR is classified as Dependabot, omitted from human classification, and allowed by verification. Use an anchored predicate for the bot actor instead.

This issue also appears on line 355 of the same file.

Medium severity Detect completed cards that remain outside Done

.claude/​skills/​issue-triage/​SKILL.md:604

A completed closed issue whose card remains in Todo/In Review and has no Priority passes every predicate here: the Priority check is restricted to open issues, closed unshipped excludes COMPLETED, and open, but carded Done only checks the opposite direction. That leaves shipped work outside Done and can hide an unprioritized board item, contrary to the stated invariants. Add the missing closed + COMPLETED + status != Done check and either check Priority for all issue cards or explicitly define a closed-card exemption; update the audit table accordingly.

Low severity Treat README path classification as a hint, not a final decision

docs/​contribution-model.md:179

This makes every README-only PR a final listing classification, but the new skill explicitly says that path result is only a hint and that an existing-entry documentation fix may be keep (.claude/skills/issue-triage/SKILL.md:443-449). As written, the plan can direct maintainers to send the Registry response for legitimate README fixes. Describe this as pre-classification followed by reading the PR.

Comment thread .claude/skills/issue-triage/SKILL.md
cliffhall added a commit that referenced this pull request Sep 29, 2026
…pleted-not-Done audit check

Copilot round 2 on #4906:
- the close loop stops when a response is empty or still holds #ISSUE, so a
  missing file can never become a close without an explanation
- Dependabot is matched as exactly app/dependabot, not by substring
- the audit gains 'closed completed, not Done'; Priority stays open-only,
  now stated
- contribution-model.md: a README-only PR pre-classifies as a listing, and
  reading it decides the class

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall

Copy link
Copy Markdown
Member Author

Copilot round 2: 1 inline finding plus 4 "previously missed" findings, which have no thread, so they are answered here.

Audit and recipes re-run after the changes (all read-only). verify:skills passes. Re-requesting review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several procedures can misclassify or incompletely process triage items, and #4868’s operational acceptance criteria remain unfinished.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)
Previously missed (3)

In code that hasn't changed since last review

Medium severity Align PR closure claim with issue acceptance criteria

.claude/​skills/​issue-triage/​SKILL.md:34

This PR says Closes #4868, but #4868 requires running the current issue backlog to an all-zero audit and handling the outside-PR backlog. Moving those actions to #4875/#4876/#4877 leaves those acceptance criteria explicitly undone. Either complete the human-gated passes before closing #4868 or update the issue relationship/acceptance criteria so this PR does not claim completion.

Medium severity Validate response content before closing issues

.claude/​skills/​issue-triage/​SKILL.md:86

A missing or unreadable response file does not stop this command: command substitution yields an empty string and gh issue close still runs with --comment "", so a canned-response class can be closed silently. Validate a non-empty body before invoking gh; handle the explicitly no-response Spam/empty class through a separate close path.

Medium severity Ensure triage completion after partial item updates

.claude/​skills/​issue-triage/​SKILL.md:146

This is not fully idempotent after item-add: if Priority or the score comment fails afterward, the issue already has a card and disappears from this finder. The audit catches a missing Priority but not a missing score comment, so rerunning as directed can silently leave triage incomplete. Require inspecting/completing the last attempted issue before resuming.

Comment thread .claude/skills/issue-triage/SKILL.md Outdated
cliffhall added a commit that referenced this pull request Sep 29, 2026
…me rule

Copilot round 3 on #4906:
- the listing class is adding or promoting a server entry; a correction to an
  existing entry is read on its merits
- the step 0 issue close stops on an empty response; spam closes separately
- resuming pass 1 finishes the last issue first, since a half-triaged issue
  has already left the finder's list

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall

Copy link
Copy Markdown
Member Author

Copilot round 3: 1 inline finding plus 3 "previously missed" findings (answered here, since they have no thread).

verify:skills passes. Re-requesting review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The bulk-close path can discard tracked work, and the implementation does not fully match its documentation or acceptance criteria.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)
Previously missed (2)

In code that hasn't changed since last review

Medium severity Do not close #4868 before completing its acceptance criteria

.claude/​skills/​issue-triage/​SKILL.md:34

The PR declares Closes #4868, but this delegates the one-time sweeps to #4876/#4877 while #4868's acceptance criteria require the current issue backlog to be triaged to a zero audit and the outside-PR backlog to be handled. The PR description confirms those actions were not performed. Either keep #4868 open/change the closing relationship, or complete its acceptance criteria before merging.

This issue also appears on line 408 of the same file.

Medium severity Reconcile archived-server routing with the documented PR response plan

.claude/​skills/​issue-triage/​SKILL.md:407

This routes archived-server PRs to archived.md, but the updated contribution plan (lines 146–151) and the General response heading (line 469) say every PR class except listings/new servers receives the General PR response. The archived text omits the outside-PR policy and issue flow, so this class will send a different response than the documented plan. Add a PR-specific response combining the policy and archive redirect, or explicitly reconcile the plan and routing.

Comment thread docs/contribution-model.md
cliffhall added a commit that referenced this pull request Sep 29, 2026
…g to the skill

Copilot round 4 on #4906: the plan's Listing row now covers adding or
promoting an entry only, and the canned-response pointer (and the skill's
General heading) name the Archived pointer used for archived-server PRs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall

Copy link
Copy Markdown
Member Author

Copilot round 4: 1 inline finding plus 2 "previously missed" findings.

Re-requesting review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The audit exempts currently forbidden draft cards, a close recipe masks failures, and linked acceptance work remains deferred.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)
Previously missed (2)

In code that hasn't changed since last review

Medium severity PR does not satisfy linked issue acceptance criteria

.claude/​skills/​issue-triage/​SKILL.md:29

The linked #4868 acceptance criteria require running the current issue triage until every audit row is zero and handling the outside-PR backlog, but the PR description reports 217 unboarded issues and explicitly defers both passes to #4876/#4877. As written, this PR therefore cannot satisfy the issue it declares it closes; complete the human-gated actions before merge or revise the linked issue/closing scope.

Medium severity Fallback masks failed issue closure

.claude/​skills/​issue-triage/​SKILL.md:88

This fallback masks a failed gh issue close: because echo succeeds, the compound command returns status 0, so a batch caller can continue despite the stop-on-first-failure rule. Preserve a nonzero status for a missing response or failed close.

Comment thread .claude/skills/issue-triage/SKILL.md
cliffhall added a commit that referenced this pull request Sep 29, 2026
Copilot round 5 on #4906: the fallback echo returned 0, so a batch caller
could carry on past a missing response or a failed close.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall

Copy link
Copy Markdown
Member Author

Copilot round 5: 1 inline finding plus 2 "previously missed" findings.

Re-requesting review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The close loop can lose harvested work, documentation contains contradictory guidance, and linked acceptance criteria remain deferred.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (6)

In code that hasn't changed since last review

Medium severity Complete backlog sweeps or correct completion linkage

.claude/​skills/​issue-triage/​SKILL.md:34

This explicitly defers the one-time sweeps to #4875, but the PR still closes #4868, whose acceptance criteria require the current issue backlog to reach a zero audit and the outside-PR backlog to be handled. The PR description confirms neither action was performed; either complete those criteria before closing #4868 or update the issue/PR linkage so this implementation does not mark the broader work complete.

Medium severity Reject '-' for duplicate and keep classes before writing

.claude/​skills/​issue-triage/​SKILL.md:410

The close loop permits - for duplicate and keep, then selects the untracked response and closes the PR without a harvest issue. That violates the class table and can discard a valuable fix if the reviewed manifest contains a missing issue number; reject - for these two classes before any write.

Medium severity Audit Priority on all board items, including closed cards

.claude/​skills/​issue-triage/​SKILL.md:612

The authoritative rule says every board item has a Priority (AGENTS.md:267), and this audit's invariant says the same, but isopen(.n) excludes closed/Done cards. The audit can therefore print zero while a board item violates the rule; check all issue cards, or explicitly change the rule and audit documentation if closed cards are intended to be exempt.

Low severity Cover labels on both form and non-form issue arrivals

.claude/​skills/​issue-create/​SKILL.md:194

This paragraph still says every UI-created issue arrives without v2 or a type label, but the stacked bug and feature forms apply both labels (.github/ISSUE_TEMPLATE/1-bug_report.yml:14 and 2-feature_request.yml:14). Describe both form and non-form arrivals so the issue-create and triage skills agree.

Low severity Clarify that score details are public issue comments

.claude/​skills/​issue-triage/​SKILL.md:227

This says reporters never see the score, but the Recording the score section posts the Priority and full arithmetic as a public issue comment. Clarify that only the board fields are private so triagers do not mistake the score explanation for private data.

Low severity Add Archived server to the class table

docs/​contribution-model.md:96

The plan requires each PR to be assigned exactly one class, but this table still omits the newly documented Archived server class. A reader following the plan can therefore route archived-server PRs through New server or Out of scope and post the wrong response; add the class here as well as in the skill.

@cliffhall
cliffhall added this pull request to stack #4909 September 29, 2026 12:50
@cliffhall
cliffhall force-pushed the v2/docs/4869-contribution-model branch from 3122de0 to 414ac21 Compare September 29, 2026 13:05
cliffhall added a commit that referenced this pull request Sep 29, 2026
…e rule

Copilot round 1 on #4906:
- the manifest uses '-' for 'no issue', because read collapses adjacent tabs
  and an empty field shifted the reason into the issue column
- class slugs are defined in the table; the loop whitelists them, skips
  'security', and stops on anything unknown instead of closing it
- the backlog sweep's close label and #4875 reference (SWEEP_LABEL, SWEEP_REF)
  are part of the loop, and the step 0 issue closes take the same two
- step 0's close rule covers only rows whose Action is Close, never a
  security report

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
cliffhall added a commit that referenced this pull request Sep 29, 2026
…pleted-not-Done audit check

Copilot round 2 on #4906:
- the close loop stops when a response is empty or still holds #ISSUE, so a
  missing file can never become a close without an explanation
- Dependabot is matched as exactly app/dependabot, not by substring
- the audit gains 'closed completed, not Done'; Priority stays open-only,
  now stated
- contribution-model.md: a README-only PR pre-classifies as a listing, and
  reading it decides the class

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
cliffhall added a commit that referenced this pull request Sep 29, 2026
…me rule

Copilot round 3 on #4906:
- the listing class is adding or promoting a server entry; a correction to an
  existing entry is read on its merits
- the step 0 issue close stops on an empty response; spam closes separately
- resuming pass 1 finishes the last issue first, since a half-triaged issue
  has already left the finder's list

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
cliffhall added a commit that referenced this pull request Sep 29, 2026
…g to the skill

Copilot round 4 on #4906: the plan's Listing row now covers adding or
promoting an entry only, and the canned-response pointer (and the skill's
General heading) name the Archived pointer used for archived-server PRs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
cliffhall added a commit that referenced this pull request Sep 29, 2026
Copilot round 5 on #4906: the fallback echo returned 0, so a batch caller
could carry on past a missing response or a failed close.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall
cliffhall force-pushed the v2/feat/4868-issue-triage branch from 49c6fc1 to 5063bc0 Compare September 29, 2026 13:05
cliffhall added a commit that referenced this pull request Sep 29, 2026
…y public score

Copilot round 6 on #4906 (previously-missed findings):
- the close loop stops on a duplicate or keep row with no harvest issue
- the trust-boundary note says the score comment is public
- issue-create describes form-filed arrivals (v2 + type, no scope label)
- the plan's class table gains the Archived server row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
cliffhall added a commit that referenced this pull request Sep 29, 2026
…n manifest issues

Copilot round 7 on #4906:
- the maintainer list is captured before jq, so a failed page fails the step
- the pre-class count runs only on a successful pre-class
- step 0 creates the run's temp dir and says to materialize the response first
- the close loop accepts '#123' as well as '123' in the issue column

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
cliffhall added a commit that referenced this pull request Sep 29, 2026
Copilot round 8 on #4906: the axes max out at 10, so reaching Urgent with the
reporter's +1 takes the axes plus another bonus, not 11 from the axes alone.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
cliffhall added a commit that referenced this pull request Sep 29, 2026
…recipe

Copilot round 9 on #4906: the generic step 0 close would record a duplicate as
not planned and skip the card deletion; the recipe now sends duplicates
through board-ops' duplicate close and card delete.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall
cliffhall removed this pull request from stack #4909 September 29, 2026 13:31
Base automatically changed from v2/docs/4869-contribution-model to v2/main September 29, 2026 13:32
cliffhall and others added 10 commits September 29, 2026 09:33
Adds .claude/skills/issue-triage, adapted from the MCP Inspector's for one
board (#43) and this repo's community inflow:

- step 0 class check for issues (listings, new servers, archived servers,
  SDK/spec, duplicates, spam, security reports), each with a canned response
- pass 1 onto the board as Incoming (no milestone), pass 2 left to a human
- the priority rubric with its severity axis reworded for servers, and the
  posted score comment
- outside PRs: snapshot, pre-classify, manifest reviewed by a maintainer,
  harvest into Incoming issues, paced close, verify (docs/contribution-model.md)
- the board audit for #43, with the [GHSA- advisory draft carve-out and an
  issue --limit above the repo's total issue count, both truncation-checked
- eval cases (6 positives, 2 negatives)

Retires readme-pr-check.yml on v2/main and folds its behavior into the
listing class. The canned PR comments now live only in the skill;
contribution-model.md points at them. Skills index row added.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…e rule

Copilot round 1 on #4906:
- the manifest uses '-' for 'no issue', because read collapses adjacent tabs
  and an empty field shifted the reason into the issue column
- class slugs are defined in the table; the loop whitelists them, skips
  'security', and stops on anything unknown instead of closing it
- the backlog sweep's close label and #4875 reference (SWEEP_LABEL, SWEEP_REF)
  are part of the loop, and the step 0 issue closes take the same two
- step 0's close rule covers only rows whose Action is Close, never a
  security report

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…pleted-not-Done audit check

Copilot round 2 on #4906:
- the close loop stops when a response is empty or still holds #ISSUE, so a
  missing file can never become a close without an explanation
- Dependabot is matched as exactly app/dependabot, not by substring
- the audit gains 'closed completed, not Done'; Priority stays open-only,
  now stated
- contribution-model.md: a README-only PR pre-classifies as a listing, and
  reading it decides the class

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…me rule

Copilot round 3 on #4906:
- the listing class is adding or promoting a server entry; a correction to an
  existing entry is read on its merits
- the step 0 issue close stops on an empty response; spam closes separately
- resuming pass 1 finishes the last issue first, since a half-triaged issue
  has already left the finder's list

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…g to the skill

Copilot round 4 on #4906: the plan's Listing row now covers adding or
promoting an entry only, and the canned-response pointer (and the skill's
General heading) name the Archived pointer used for archived-server PRs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Copilot round 5 on #4906: the fallback echo returned 0, so a batch caller
could carry on past a missing response or a failed close.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…y public score

Copilot round 6 on #4906 (previously-missed findings):
- the close loop stops on a duplicate or keep row with no harvest issue
- the trust-boundary note says the score comment is public
- issue-create describes form-filed arrivals (v2 + type, no scope label)
- the plan's class table gains the Archived server row

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…n manifest issues

Copilot round 7 on #4906:
- the maintainer list is captured before jq, so a failed page fails the step
- the pre-class count runs only on a successful pre-class
- step 0 creates the run's temp dir and says to materialize the response first
- the close loop accepts '#123' as well as '123' in the issue column

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Copilot round 8 on #4906: the axes max out at 10, so reaching Urgent with the
reporter's +1 takes the axes plus another bonus, not 11 from the axes alone.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…recipe

Copilot round 9 on #4906: the generic step 0 close would record a duplicate as
not planned and skip the card deletion; the recipe now sends duplicates
through board-ops' duplicate close and card delete.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall
cliffhall force-pushed the v2/feat/4868-issue-triage branch from 5063bc0 to ce855b7 Compare September 29, 2026 13:33
@cliffhall
cliffhall merged commit 574cba8 into v2/main Sep 29, 2026
28 checks passed
@cliffhall
cliffhall deleted the v2/feat/4868-issue-triage branch September 29, 2026 13:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add issue-triage skill and board audit, for community inflow

2 participants