Repository navigation
Sync files from themoment-ai-harness-sync - #2
themoment-ai-harness-sync[bot] wants to merge 1 commit into
Conversation
|
Processing PR updates... |
| hooks = true | ||
| [mcp_servers.context7] | ||
| command = "npx" | ||
| args = ["-y", "@upstash/context7-mcp"] |
There was a problem hiding this comment.
P1: The Codex configuration enables execution of an unpinned package fetched from the network.
npx -y executes an unpinned MCP package fetched from the network at runtime.
Pin and audit the MCP server or vendor it; do not run an unpinned package via npx -y.
AI prompt
Check if this security scanner issue is valid. If so, understand the root cause and fix it. If appropriate, update or add tests. Keep the change focused and preserve intended behavior.
<file name=".codex/config.toml">
<violation number="1" location=".codex/config.toml:12">
<priority>P1</priority>
<title>The Codex configuration enables execution of an unpinned package fetched from the network.</title>
<evidence>The new MCP server is configured as `command = "npx"` with `args = ["-y", "@upstash/context7-mcp"]`. `npx -y` can download and execute the package without a lockfile, integrity pin, or version constraint; the same configuration also enables sandbox network access, so this code can be fetched at runtime.</evidence>
<recommendation>Do not execute an unpinned package through npx. Pin an audited package version and integrity/source revision, preferably vendor or lock the MCP server in a controlled environment, and require explicit approval before enabling network-fetched MCP code. Review whether the network_access setting is necessary.</recommendation>
</violation>
</file>
There was a problem hiding this comment.
🟡 Changes recommended
Several synced workflows are incompatible with this repository, contain broken scripts, or introduce unsafe unpinned execution.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Synchronizes AI-agent configuration, reusable skills, workflow scripts, and framework guidance from the shared harness repository.
Changes:
- Adds Gemini, Codex, and Claude agent configuration.
- Adds development, review, testing, security, and framework skills.
- Adds PR automation, debugging utilities, and FSD validation scripts.
File summaries
| File | Description |
|---|---|
.gemini/settings.json |
Configures Gemini context and approvals. |
.codex/config.toml |
Configures Codex networking and MCP. |
.codex/agents/web-researcher.toml |
Adds web-research agent. |
.codex/agents/prompt-polisher.toml |
Adds prompt-review agent. |
.codex/agents/kotlin-test-fixer.toml |
Adds Kotlin test repair agent. |
.codex/agents/kotlin-convention-validator.toml |
Adds Kotlin convention agent. |
.codex/agents/frontend-convention-validator.toml |
Adds frontend convention agent. |
.codex/agents/doc-polisher.toml |
Adds documentation agent. |
.codex/agents/contradiction-finder.toml |
Adds consistency-audit agent. |
.claude/skills/write-pr/SKILL.md |
Defines Claude PR workflow. |
.claude/skills/write-pr/scripts/create-pr.sh |
Implements PR creation. |
.claude/skills/write-pr/references/labels.md |
Documents PR labels. |
.claude/skills/write-pr/references/commit-conventions.md |
Documents commit conventions. |
.claude/skills/the-sdk/SKILL.md |
Documents shared SDK usage. |
.claude/skills/test/SKILL.md |
Defines test workflow. |
.claude/skills/tanstack-query-zod/SKILL.md |
Adds TanStack/Zod guidance. |
.claude/skills/tailwind-shadcn/SKILL.md |
Adds Tailwind/shadcn guidance. |
.claude/skills/systematic-debugging/test-pressure-3.md |
Adds authority-pressure fixture. |
.claude/skills/systematic-debugging/test-pressure-2.md |
Adds exhaustion-pressure fixture. |
.claude/skills/systematic-debugging/test-pressure-1.md |
Adds incident-pressure fixture. |
.claude/skills/systematic-debugging/test-academic.md |
Adds debugging knowledge fixture. |
.claude/skills/systematic-debugging/scripts/find-polluter.sh |
Adds test-pollution utility. |
.claude/skills/systematic-debugging/root-cause-tracing.md |
Documents root-cause tracing. |
.claude/skills/systematic-debugging/defense-in-depth.md |
Documents layered validation. |
.claude/skills/systematic-debugging/CREATION-LOG.md |
Records skill provenance. |
.claude/skills/systematic-debugging/condition-based-waiting.md |
Documents condition-based waiting. |
.claude/skills/systematic-debugging/condition-based-waiting-example.ts |
Adds waiting utilities example. |
.claude/skills/security-checklist/SKILL.md |
Adds security checklist. |
.claude/skills/resolve-reviews/SKILL.md |
Defines review-resolution workflow. |
.claude/skills/resolve-reviews/scripts/get-pr-data.sh |
Collects PR review data. |
.claude/skills/resolve-reviews/references/reply-formats.md |
Defines review reply templates. |
.claude/skills/planning/SKILL.md |
Adds planning interview skill. |
.claude/skills/nextjs-turborepo-fsd/SKILL.md |
Adds Turborepo FSD guidance. |
.claude/skills/nextjs-package-boundaries/SKILL.md |
Adds package-boundary guidance. |
.claude/skills/nextjs-fsd-architecture/SKILL.md |
Adds Next.js FSD guidance. |
.claude/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.test.mjs |
Tests FSD checker. |
.claude/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.mjs |
Implements FSD checker. |
.claude/skills/nextjs-fsd-architecture/references/steiger.config.mjs |
Provides Steiger configuration. |
.claude/skills/migration-guide/SKILL.md |
Adds migration guidance. |
.claude/skills/kotlin-spring-arch/SKILL.md |
Adds Kotlin architecture guidance. |
.claude/skills/kotest-guide/SKILL.md |
Adds Kotest guidance. |
.claude/skills/java-spring-arch/SKILL.md |
Adds Java architecture guidance. |
.claude/skills/humanizer/LICENSE |
Adds humanizer license. |
.claude/skills/git-commit/SKILL.md |
Defines commit workflow. |
.claude/skills/git-commit/references/scope-guide.md |
Documents commit scopes. |
.claude/skills/git-commit/references/commit-conventions.md |
Documents commit format. |
.claude/skills/docker/SKILL.md |
Adds Docker guidance. |
.claude/skills/database-schema/SKILL.md |
Adds schema guidance. |
.claude/skills/api-design/SKILL.md |
Adds REST API guidance. |
.claude/agents/web-researcher.md |
Adds Claude web-research agent. |
.claude/agents/prompt-polisher.md |
Adds Claude prompt agent. |
.claude/agents/kotlin-test-fixer.md |
Adds Claude Kotlin test agent. |
.claude/agents/kotlin-convention-validator.md |
Adds Claude Kotlin convention agent. |
.claude/agents/frontend-convention-validator.md |
Adds Claude frontend convention agent. |
.claude/agents/doc-polisher.md |
Adds Claude documentation agent. |
.claude/agents/contradiction-finder.md |
Adds Claude consistency agent. |
.agents/skills/write-pr/SKILL.md |
Defines portable PR workflow. |
.agents/skills/write-pr/scripts/create-pr.sh |
Implements portable PR creation. |
.agents/skills/write-pr/references/labels.md |
Documents portable PR labels. |
.agents/skills/write-pr/references/commit-conventions.md |
Documents portable commit conventions. |
.agents/skills/the-sdk/SKILL.md |
Documents shared SDK usage. |
.agents/skills/test/SKILL.md |
Defines portable test workflow. |
.agents/skills/tanstack-query-zod/SKILL.md |
Adds portable TanStack/Zod guidance. |
.agents/skills/tailwind-shadcn/SKILL.md |
Adds portable UI guidance. |
.agents/skills/systematic-debugging/scripts/find-polluter.sh |
Adds portable pollution utility. |
.agents/skills/systematic-debugging/references/root-cause-tracing.md |
Adds root-cause reference. |
.agents/skills/systematic-debugging/references/defense-in-depth.md |
Adds validation reference. |
.agents/skills/systematic-debugging/references/condition-based-waiting.md |
Adds waiting reference. |
.agents/skills/security-checklist/SKILL.md |
Adds portable security checklist. |
.agents/skills/resolve-reviews/SKILL.md |
Defines portable review workflow. |
.agents/skills/resolve-reviews/scripts/get-pr-data.sh |
Collects PR data. |
.agents/skills/resolve-reviews/references/reply-formats.md |
Defines review replies. |
.agents/skills/planning/SKILL.md |
Adds portable planning skill. |
.agents/skills/nextjs-turborepo-fsd/SKILL.md |
Adds portable Turborepo guidance. |
.agents/skills/nextjs-package-boundaries/SKILL.md |
Adds portable package guidance. |
.agents/skills/nextjs-fsd-architecture/SKILL.md |
Adds portable FSD guidance. |
.agents/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.test.mjs |
Tests portable FSD checker. |
.agents/skills/nextjs-fsd-architecture/scripts/check-fsd-dependencies.mjs |
Implements portable FSD checker. |
.agents/skills/nextjs-fsd-architecture/references/steiger.config.mjs |
Provides portable Steiger config. |
.agents/skills/migration-guide/SKILL.md |
Adds portable migration guidance. |
.agents/skills/kotlin-spring-arch/SKILL.md |
Adds portable Kotlin guidance. |
.agents/skills/kotest-guide/SKILL.md |
Adds portable Kotest guidance. |
.agents/skills/java-spring-arch/SKILL.md |
Adds portable Java guidance. |
.agents/skills/humanizer/LICENSE |
Adds portable humanizer license. |
.agents/skills/git-commit/SKILL.md |
Defines portable commit workflow. |
.agents/skills/git-commit/references/scope-guide.md |
Documents portable scopes. |
.agents/skills/git-commit/references/commit-conventions.md |
Documents portable commit format. |
.agents/skills/docker/SKILL.md |
Adds portable Docker guidance. |
.agents/skills/database-schema/SKILL.md |
Adds portable schema guidance. |
.agents/skills/api-design/SKILL.md |
Adds portable API guidance. |
Review details
Suppressed comments (3)
.claude/skills/systematic-debugging/scripts/find-polluter.sh:42
- The repository root has no
package.json, so this command fails for every test here;|| truesuppresses that failure and the script ultimately reports the suite as clean. Run the test from the owning package or accept a runner command, and treat runner failures separately from pollution detection.
.agents/skills/resolve-reviews/SKILL.md:36 - This repository has no
CLAUDE.md, so the primary convention source named here is absent, while the actual repository instructions are in.github/copilot-instructions.md. Because this skill auto-edits, commits, and pushes based on its verdicts, it must load the real instruction file before assessing comments.
1. **Project conventions** (primary): cross-reference CLAUDE.md and CONTRIBUTING.md
- DTO annotation rules, commit scope, logging style, exception message format, etc.
2. **Language/framework best practices** (secondary): Kotlin official guide, Spring Boot recommendations
- Apply only when no matching project rule exists
.claude/skills/resolve-reviews/SKILL.md:37
- The discovery command finds no files in this repository because
.claude/rulesis absent, and the listedCLAUDE.md/styleguide sources are also absent; the actual project rules live in.github/copilot-instructions.md. Since this skill auto-edits, commits, and pushes, explicitly load that file before assessing comments.
- Files reviewed: 94/94 changed files
- Comments generated: 22
- Review effort level: Balanced
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| echo "" | ||
|
|
||
| # Get list of test files | ||
| TEST_FILES=$(find . -path "$TEST_PATTERN" | sort) |
| if [ -e "$POLLUTION_CHECK" ]; then | ||
| echo "⚠️ Pollution already exists before test $COUNT/$TOTAL" | ||
| echo " Skipping: $TEST_FILE" | ||
| continue | ||
| fi |
| echo "[$COUNT/$TOTAL] Testing: $TEST_FILE" | ||
|
|
||
| # Run the test | ||
| npm test "$TEST_FILE" > /dev/null 2>&1 || true |
| echo "" | ||
|
|
||
| # Get list of test files | ||
| TEST_FILES=$(find . -path "$TEST_PATTERN" | sort) |
| if [ -e "$POLLUTION_CHECK" ]; then | ||
| echo "⚠️ Pollution already exists before test $COUNT/$TOTAL" | ||
| echo " Skipping: $TEST_FILE" | ||
| continue | ||
| fi |
| --- | ||
| name: write-pr | ||
| description: Generate a PR title, body, and a single label from commits since the base branch, then create the PR on GitHub. Handles base branch detection, label selection, and PR creation end-to-end. | ||
| allowed-tools: Bash(git *:*), Bash(bash *create-pr.sh:*), Bash(cat *:*), Read, Write |
| "defaultApprovalMode": "auto_edit" | ||
| }, | ||
| "context": { | ||
| "fileName": ["AGENTS.md"] |
|
|
||
| ## Response Format | ||
|
|
||
| - Success: `CommonApiResponse(data = ...)` |
| | `enhancement:개선작업` | New feature, improvement to existing feature, refactoring | | ||
| | `bug:버그` | Bug fix | | ||
| | `documentation:문서화` | Docs-only changes (README, CONTRIBUTING, comments) | | ||
| | `release:릴리즈` | Release preparation or version bump | |
| | `enhancement:개선작업` | New feature, improvement to existing feature, refactoring | | ||
| | `bug:버그` | Bug fix | | ||
| | `documentation:문서화` | Docs-only changes (README, CONTRIBUTING, comments) | | ||
| | `release:릴리즈` | Release preparation or version bump | |
|



synced local file(s) with themoment-team/themoment-ai-harness-sync.
Automated file sync from themoment-ai-harness-sync.
This PR was created automatically by the repo-file-sync-action workflow run #34731813242