Skip to content

Sync files from themoment-ai-harness-sync - #2

Open
themoment-ai-harness-sync[bot] wants to merge 1 commit into
mainfrom
harness-sync/main
Open

themoment-ai-harness-sync[bot] wants to merge 1 commit into
mainfrom
harness-sync/main

Conversation

@themoment-ai-harness-sync

Copy link
Copy Markdown

synced local file(s) with themoment-team/themoment-ai-harness-sync.

Automated file sync from themoment-ai-harness-sync.


This PR was created automatically by the repo-file-sync-action workflow run #34731813242

Copilot AI balanced review requested due to automatic review settings September 13, 2026 02:00
@themoment-ai-harness-sync themoment-ai-harness-sync Bot changed the title chore synced file(s) with themoment-team/themoment-ai-harness-sync Sync files from themoment-ai-harness-sync Sep 13, 2026
@code-companion-ai

Copy link
Copy Markdown

Processing PR updates...

@superagent-security superagent-security Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Superagent found 1 security concern(s).

Comment thread .codex/config.toml
hooks = true
[mcp_servers.context7]
command = "npx"
args = ["-y", "@upstash/context7-mcp"]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: The Codex configuration enables execution of an unpinned package fetched from the network.

npx -y executes an unpinned MCP package fetched from the network at runtime.

Pin and audit the MCP server or vendor it; do not run an unpinned package via npx -y.

AI prompt
Check if this security scanner issue is valid. If so, understand the root cause and fix it. If appropriate, update or add tests. Keep the change focused and preserve intended behavior.

<file name=".codex/config.toml">
<violation number="1" location=".codex/config.toml:12">
<priority>P1</priority>
<title>The Codex configuration enables execution of an unpinned package fetched from the network.</title>
<evidence>The new MCP server is configured as `command = "npx"` with `args = ["-y", "@upstash/context7-mcp"]`. `npx -y` can download and execute the package without a lockfile, integrity pin, or version constraint; the same configuration also enables sandbox network access, so this code can be fetched at runtime.</evidence>
<recommendation>Do not execute an unpinned package through npx. Pin an audited package version and integrity/source revision, preferably vendor or lock the MCP server in a controlled environment, and require explicit approval before enabling network-fetched MCP code. Review whether the network_access setting is necessary.</recommendation>
</violation>
</file>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Several synced workflows are incompatible with this repository, contain broken scripts, or introduce unsafe unpinned execution.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Synchronizes AI-agent configuration, reusable skills, workflow scripts, and framework guidance from the shared harness repository.

Changes:

  • Adds Gemini, Codex, and Claude agent configuration.
  • Adds development, review, testing, security, and framework skills.
  • Adds PR automation, debugging utilities, and FSD validation scripts.
File summaries
File Description
.gemini/settings.json Configures Gemini context and approvals.
.codex/config.toml Configures Codex networking and MCP.
.codex/agents/web-researcher.toml Adds web-research agent.
.codex/agents/prompt-polisher.toml Adds prompt-review agent.
.codex/agents/kotlin-test-fixer.toml Adds Kotlin test repair agent.
.codex/agents/kotlin-convention-validator.toml Adds Kotlin convention agent.
.codex/agents/frontend-convention-validator.toml Adds frontend convention agent.
.codex/agents/doc-polisher.toml Adds documentation agent.
.codex/agents/contradiction-finder.toml Adds consistency-audit agent.
.claude/skills/write-pr/SKILL.md Defines Claude PR workflow.
.claude/skills/write-pr/scripts/create-pr.sh Implements PR creation.
.claude/skills/write-pr/references/labels.md Documents PR labels.
.claude/skills/write-pr/references/commit-conventions.md Documents commit conventions.
.claude/skills/the-sdk/SKILL.md Documents shared SDK usage.
.claude/skills/test/SKILL.md Defines test workflow.
.claude/skills/tanstack-query-zod/SKILL.md Adds TanStack/Zod guidance.
.claude/skills/tailwind-shadcn/SKILL.md Adds Tailwind/shadcn guidance.
.claude/skills/systematic-debugging/test-pressure-3.md Adds authority-pressure fixture.
.claude/skills/systematic-debugging/test-pressure-2.md Adds exhaustion-pressure fixture.
.claude/skills/systematic-debugging/test-pressure-1.md Adds incident-pressure fixture.
.claude/skills/systematic-debugging/test-academic.md Adds debugging knowledge fixture.
.claude/skills/systematic-debugging/scripts/find-polluter.sh Adds test-pollution utility.
.claude/skills/systematic-debugging/root-cause-tracing.md Documents root-cause tracing.
.claude/skills/systematic-debugging/defense-in-depth.md Documents layered validation.
.claude/skills/systematic-debugging/CREATION-LOG.md Records skill provenance.
.claude/skills/systematic-debugging/condition-based-waiting.md Documents condition-based waiting.
.claude/skills/systematic-debugging/condition-based-waiting-example.ts Adds waiting utilities example.
.claude/skills/security-checklist/SKILL.md Adds security checklist.
.claude/skills/resolve-reviews/SKILL.md Defines review-resolution workflow.
.claude/skills/resolve-reviews/scripts/get-pr-data.sh Collects PR review data.
.claude/skills/resolve-reviews/references/reply-formats.md Defines review reply templates.
.claude/skills/planning/SKILL.md Adds planning interview skill.
.claude/skills/nextjs-turborepo-fsd/SKILL.md Adds Turborepo FSD guidance.
.claude/skills/nextjs-package-boundaries/SKILL.md Adds package-boundary guidance.
.claude/skills/nextjs-fsd-architecture/SKILL.md Adds Next.js FSD guidance.
.claude/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.test.mjs Tests FSD checker.
.claude/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.mjs Implements FSD checker.
.claude/skills/nextjs-fsd-architecture/references/steiger.config.mjs Provides Steiger configuration.
.claude/skills/migration-guide/SKILL.md Adds migration guidance.
.claude/skills/kotlin-spring-arch/SKILL.md Adds Kotlin architecture guidance.
.claude/skills/kotest-guide/SKILL.md Adds Kotest guidance.
.claude/skills/java-spring-arch/SKILL.md Adds Java architecture guidance.
.claude/skills/humanizer/LICENSE Adds humanizer license.
.claude/skills/git-commit/SKILL.md Defines commit workflow.
.claude/skills/git-commit/references/scope-guide.md Documents commit scopes.
.claude/skills/git-commit/references/commit-conventions.md Documents commit format.
.claude/skills/docker/SKILL.md Adds Docker guidance.
.claude/skills/database-schema/SKILL.md Adds schema guidance.
.claude/skills/api-design/SKILL.md Adds REST API guidance.
.claude/agents/web-researcher.md Adds Claude web-research agent.
.claude/agents/prompt-polisher.md Adds Claude prompt agent.
.claude/agents/kotlin-test-fixer.md Adds Claude Kotlin test agent.
.claude/agents/kotlin-convention-validator.md Adds Claude Kotlin convention agent.
.claude/agents/frontend-convention-validator.md Adds Claude frontend convention agent.
.claude/agents/doc-polisher.md Adds Claude documentation agent.
.claude/agents/contradiction-finder.md Adds Claude consistency agent.
.agents/skills/write-pr/SKILL.md Defines portable PR workflow.
.agents/skills/write-pr/scripts/create-pr.sh Implements portable PR creation.
.agents/skills/write-pr/references/labels.md Documents portable PR labels.
.agents/skills/write-pr/references/commit-conventions.md Documents portable commit conventions.
.agents/skills/the-sdk/SKILL.md Documents shared SDK usage.
.agents/skills/test/SKILL.md Defines portable test workflow.
.agents/skills/tanstack-query-zod/SKILL.md Adds portable TanStack/Zod guidance.
.agents/skills/tailwind-shadcn/SKILL.md Adds portable UI guidance.
.agents/skills/systematic-debugging/scripts/find-polluter.sh Adds portable pollution utility.
.agents/skills/systematic-debugging/references/root-cause-tracing.md Adds root-cause reference.
.agents/skills/systematic-debugging/references/defense-in-depth.md Adds validation reference.
.agents/skills/systematic-debugging/references/condition-based-waiting.md Adds waiting reference.
.agents/skills/security-checklist/SKILL.md Adds portable security checklist.
.agents/skills/resolve-reviews/SKILL.md Defines portable review workflow.
.agents/skills/resolve-reviews/scripts/get-pr-data.sh Collects PR data.
.agents/skills/resolve-reviews/references/reply-formats.md Defines review replies.
.agents/skills/planning/SKILL.md Adds portable planning skill.
.agents/skills/nextjs-turborepo-fsd/SKILL.md Adds portable Turborepo guidance.
.agents/skills/nextjs-package-boundaries/SKILL.md Adds portable package guidance.
.agents/skills/nextjs-fsd-architecture/SKILL.md Adds portable FSD guidance.
.agents/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.test.mjs Tests portable FSD checker.
.agents/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.mjs Implements portable FSD checker.
.agents/skills/nextjs-fsd-architecture/references/steiger.config.mjs Provides portable Steiger config.
.agents/skills/migration-guide/SKILL.md Adds portable migration guidance.
.agents/skills/kotlin-spring-arch/SKILL.md Adds portable Kotlin guidance.
.agents/skills/kotest-guide/SKILL.md Adds portable Kotest guidance.
.agents/skills/java-spring-arch/SKILL.md Adds portable Java guidance.
.agents/skills/humanizer/LICENSE Adds portable humanizer license.
.agents/skills/git-commit/SKILL.md Defines portable commit workflow.
.agents/skills/git-commit/references/scope-guide.md Documents portable scopes.
.agents/skills/git-commit/references/commit-conventions.md Documents portable commit format.
.agents/skills/docker/SKILL.md Adds portable Docker guidance.
.agents/skills/database-schema/SKILL.md Adds portable schema guidance.
.agents/skills/api-design/SKILL.md Adds portable API guidance.
Review details

Suppressed comments (3)

.claude/skills/systematic-debugging/scripts/find-polluter.sh:42

  • The repository root has no package.json, so this command fails for every test here; || true suppresses that failure and the script ultimately reports the suite as clean. Run the test from the owning package or accept a runner command, and treat runner failures separately from pollution detection.
    .agents/skills/resolve-reviews/SKILL.md:36
  • This repository has no CLAUDE.md, so the primary convention source named here is absent, while the actual repository instructions are in .github/copilot-instructions.md. Because this skill auto-edits, commits, and pushes based on its verdicts, it must load the real instruction file before assessing comments.
1. **Project conventions** (primary): cross-reference CLAUDE.md and CONTRIBUTING.md
   - DTO annotation rules, commit scope, logging style, exception message format, etc.
2. **Language/framework best practices** (secondary): Kotlin official guide, Spring Boot recommendations
   - Apply only when no matching project rule exists

.claude/skills/resolve-reviews/SKILL.md:37

  • The discovery command finds no files in this repository because .claude/rules is absent, and the listed CLAUDE.md/styleguide sources are also absent; the actual project rules live in .github/copilot-instructions.md. Since this skill auto-edits, commits, and pushes, explicitly load that file before assessing comments.
  • Files reviewed: 94/94 changed files
  • Comments generated: 22
  • Review effort level: Balanced

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

echo ""

# Get list of test files
TEST_FILES=$(find . -path "$TEST_PATTERN" | sort)
Comment on lines +33 to +37
if [ -e "$POLLUTION_CHECK" ]; then
echo "⚠️ Pollution already exists before test $COUNT/$TOTAL"
echo " Skipping: $TEST_FILE"
continue
fi
echo "[$COUNT/$TOTAL] Testing: $TEST_FILE"

# Run the test
npm test "$TEST_FILE" > /dev/null 2>&1 || true
echo ""

# Get list of test files
TEST_FILES=$(find . -path "$TEST_PATTERN" | sort)
Comment on lines +33 to +37
if [ -e "$POLLUTION_CHECK" ]; then
echo "⚠️ Pollution already exists before test $COUNT/$TOTAL"
echo " Skipping: $TEST_FILE"
continue
fi
---
name: write-pr
description: Generate a PR title, body, and a single label from commits since the base branch, then create the PR on GitHub. Handles base branch detection, label selection, and PR creation end-to-end.
allowed-tools: Bash(git *:*), Bash(bash *create-pr.sh:*), Bash(cat *:*), Read, Write
Comment thread .gemini/settings.json
"defaultApprovalMode": "auto_edit"
},
"context": {
"fileName": ["AGENTS.md"]

## Response Format

- Success: `CommonApiResponse(data = ...)`
Comment on lines +9 to +12
| `enhancement:개선작업` | New feature, improvement to existing feature, refactoring |
| `bug:버그` | Bug fix |
| `documentation:문서화` | Docs-only changes (README, CONTRIBUTING, comments) |
| `release:릴리즈` | Release preparation or version bump |
Comment on lines +9 to +12
| `enhancement:개선작업` | New feature, improvement to existing feature, refactoring |
| `bug:버그` | Bug fix |
| `documentation:문서화` | Docs-only changes (README, CONTRIBUTING, comments) |
| `release:릴리즈` | Release preparation or version bump |
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant