chore: add maintainer setup baseline#3
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
Codex review: found issues before merge. Latest ClawSweeper review: 2026-05-22 14:45 UTC / May 22, 2026, 10:45 AM ET. Workflow note: Future ClawSweeper reviews update this same comment in place. How this review workflow works
Summary Reproducibility: yes. for the review findings from source inspection: the hydrate workflow uses only self-hosted plus input label before npm ci, and the added Crabbox skill references pnpm/crabbox scripts missing from current package.json. PR rating Rank-up moves:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. Real behavior proof Risk before merge
Maintainer options:
Next step before merge Security Review findings
Review detailsBest possible solution: Land a Kova-specific setup baseline after hardening Crabbox runner targeting, aligning skill commands with npm/Kova scenarios, and explicitly approving stale/CODEOWNERS policy. Do we have a high-confidence way to reproduce the issue? Yes for the review findings from source inspection: the hydrate workflow uses only self-hosted plus input label before npm ci, and the added Crabbox skill references pnpm/crabbox scripts missing from current package.json. Is this the best way to solve the issue? No. The baseline should first constrain self-hosted runner selection, make the Crabbox skill Kova-specific, and get maintainer approval for the new stale/CODEOWNERS policy. Label changes:
Label justifications:
Full review comments:
Overall correctness: patch is incorrect Security concerns:
What I checked:
Likely related people:
Codex review notes: model gpt-5.5, reasoning high; reviewed against ac1b15e61afd. |
|
ClawSweeper PR egg 🔥 Warming up: real-behavior proof passed; findings, security review, or rank-up moves are still in progress. Hatch commandComment Hatchability rules:
What is this egg doing here?
|
|
Closing this in favor of the shared public skill source at https://github.com/openclaw/agent-skills. We do not want to vendor the same maintainer skills into every repo. Repos that need zero-setup guidance should add a small pointer to |
Summary
Verification
Runtime tests were not run; this is setup, policy, and workflow metadata only.