Skip to content

feat(ai): vendor reviewed community skills, agents, and rules with attribution - #6792

Draft
caseyisonit wants to merge 1 commit into
ceickhoff-adobe-docs-ai-claude-memory-lessonsfrom
caseyisonit/feat-ai-community-resources
Draft

caseyisonit wants to merge 1 commit into
ceickhoff-adobe-docs-ai-claude-memory-lessonsfrom
caseyisonit/feat-ai-community-resources

Conversation

@caseyisonit

@caseyisonit caseyisonit commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Description

Vendors the community resources selected in the review of github/awesome-copilot and obra/superpowers: 7 new skills, 2 custom agents, and 2 rules, plus an attribution update to the existing test-driven-development skill. Every vendored file is adapted to this repository, pinned to the upstream commit it came from, and attributed. yarn lint:ai now checks that attribution.

Draft: blocked on Adobe open-source review. SWC is Apache-2.0 and this adds MIT-licensed third-party content. Adobe OSS review should confirm the notice format and location (.ai/THIRD-PARTY-NOTICES.md and .ai/licenses/) before this merges.

Vendored content

Upstream commits:

  • github/awesome-copilot at d7e4ad98ed8fd72e4744ee604e6277eb36748fe2
  • obra/superpowers at 5bf4e78011075bcfc0dc295f0724994cd123ee71
Destination Upstream path Adaptations
.ai/agents/trojan-skill-hunter.agent.md awesome-copilot agents/trojan-skill-hunter.agent.md tools: [read, search] (dropped edit and repo tools), removed model, added where AI config lives in this repo; static-only review kept
.ai/agents/accessibility-runtime-tester.agent.md awesome-copilot agents/accessibility-runtime-tester.agent.md tools: [read, search, execute], removed model, replaced the Chrome DevTools MCP requirement with Storybook, the Playwright a11y specs, axe, and WCAG 2.2; component-focused examples; cross-links accessibility-compliance and migration-a11y
.ai/rules/markdown-accessibility.md awesome-copilot instructions/markdown-accessibility.instructions.md Narrowed from **/*.md to 5 docs globs; heading roots follow component-readme and stories-documentation; case and punctuation defer to text-formatting; dropped the external-article preamble
.ai/rules/github-actions.md (new, 1.9 KB) Derived from awesome-copilot instructions/github-actions-ci-cd-best-practices.instructions.md and skills/github-actions-hardening Hand-written pointer rule for .github/workflows/** and .github/actions/**: explicit permissions, no untrusted ${{ }} in run:, no privileged fork execution, ./.github/actions/setup-job, concurrency, and pinning by maintainer policy
.ai/skills/github-actions-hardening/ (+5 references) awesome-copilot skills/github-actions-hardening "In This Repository" section (fork PRs, setup-job, the workflow_run guard in publish-gen2-docs.yml); full-SHA pinning framed as a maintainer decision; references copied with Prettier formatting only
.ai/skills/docs-sync-audit/ (+scripts/docs_drift.py) awesome-copilot skills/docs-sync-audit SWC docs surfaces (READMEs, MDX pages, migration guides, CONTRIBUTOR-DOCS, changesets, .ai/); generated docs excluded with their generators named; hand-offs to contributor-docs-nav, yarn lint:ai, and yarn lint:docs-pages; script unchanged
.ai/skills/test-gap-audit/ (+scripts/coverage_map.py) awesome-copilot skills/test-gap-audit Test levels mapped to Vitest browser tests, Storybook play functions, Playwright a11y specs, Chromatic VRT, and 1st-gen web-test-runner; hands off to migration-testing and vrt-authoring; script unchanged
.ai/skills/bug-reproduction-brief/ awesome-copilot skills/bug-reproduction-brief (itself from MIT skyestrela/ai-agent-skill-preview) SWC evidence (element tag, package version, browser, framework, Storybook story); Americanized spelling; cross-links systematic-debugging; records the upstream-of-upstream
.ai/skills/systematic-debugging/ (+3 techniques) superpowers skills/systematic-debugging Replaced the 2 superpowers: cross-references; SWC multi-layer example (toolchain, lockfile, build, test); dropped find-polluter.sh, CREATION-LOG.md, and pressure-test files; neutral wording for "your human partner"
.ai/skills/verification-before-completion/ superpowers skills/verification-before-completion Claim-to-command table for this repo (yarn lint:ai, targeted Vitest, yarn type-check, a11y specs, VRT, builds); pre-existing failure reporting; cross-links consistency-pass and migration-review
.ai/skills/receiving-code-review/ superpowers skills/receiving-code-review Softer, courteous tone (brief thanks allowed); style guides and .ai/rules/ as the tie-breaker; SWC examples; tool-agnostic thread-reply guidance
.ai/skills/test-driven-development/ (existing) superpowers skills/test-driven-development Provenance and MIT attribution; merged the upstream full-suite gate and writing-good-tests.md; kept testing-anti-patterns.md; fixed the code-fence drift Prettier introduced; vi.fn() and yarn commands

Tooling

  • Custom agents pipeline: yarn ai:sync generates .ai/agents/*.agent.md into .github/agents/ (provenance metadata stripped). Claude Code and Cursor get no copies.
  • Notices: yarn ai:sync generates .ai/THIRD-PARTY-NOTICES.md from provenance metadata; license texts live in .ai/licenses/<owner>-<repo>.<license>.txt.
  • New yarn lint:ai checks: provenance (source, 40-character SHA, license, license file), skill bundled files (links resolve, 5 MB cap, a warning for unreferenced files), and agent frontmatter (description required, Copilot tool aliases, no model, 30,000-character prompt cap). validate.js now runs 9 checks.
  • Git hooks: pre-commit stages .github/agents/ and the notices file along with the other generated files, skipping any that don't exist yet. It also skips the sync when .ai/agents/ or .ai/licenses/ has unstaged changes. Pre-push regenerates .github/agents/ and the notices file too, and blocks the push if either is out of date.

Docs

  • .ai/README.md: custom agents, how to vendor content, and a curated list of 36 optional personal installs with risk notes and Superpowers caveats.
  • AGENTS.md: custom agents row, and "integrate changes only through pull requests."
  • .gitignore: docs/superpowers/, where the optional Superpowers plugin writes plans.

Static safety review

A trojan-skill-hunter-style static review of every vendored file found no hidden instructions:

  • No zero-width, bidirectional-control, or tag Unicode characters.
  • No encoded blobs, and no HTML comments except an example in the agent's own threat list.
  • URLs only point to the upstream repositories, the OWASP LLM Top 10, and example.com.
  • The two Python scripts use only the standard library, run only read-only git commands (ls-files, log -1, and rev-parse), and never write files or use the network.
  • curl and wget appear only as threat descriptions in trojan-skill-hunter.

Motivation and context

Final layer of the .ai/ Copilot migration stack. The review scored 1,099 community resources against a shared rubric; these 11, plus 1 derived rule, cover gaps no existing skill fills: CI threat modeling for a public repo that accepts fork PRs, docs drift, behavior-level test gaps, bug reproduction, root-cause debugging, verification gates, review triage, and isolated reviewers for AI config and runtime accessibility.

Related issue(s)

Screenshots (if appropriate)

N/A (no UI changes).


Author's checklist

  • I have read the CONTRIBUTING and PULL_REQUESTS documents.
  • I have reviewed at the Accessibility Practices for this feature, see: Aria Practices
  • I have added automated tests to cover my changes.
  • I have included a well-written changeset if my change needs to be published.
  • I have included updated documentation if my change required it.

No changeset: nothing published changes.


Reviewer's checklist

  • Includes a Github Issue with appropriate flag or Jira ticket number without a link
  • Includes thoughtfully written changeset if changes suggested include patch, minor, or major features
  • Automated tests cover all use cases and follow best practices for writing
  • Validated on all supported browsers
  • All VRTs are approved before the author can update Golden Hash

Manual review test cases

  • Validation passes

    1. Check out this branch and run yarn install
    2. Run yarn lint:ai
    3. Expect "All checks passed" with 12 vendored files in the provenance check
  • Copilot discovers the new skills without duplicates

    1. From the repository root, run copilot skill list --json
    2. Expect 42 project skills, including the 7 new ones, and no duplicate names
  • Copilot loads the new rules for matching files

    1. Run copilot instruction list
    2. Expect github-actions.instructions.md and markdown-accessibility.instructions.md
  • Custom agents are available

    1. Start copilot interactively in the repository and run /agent
    2. Expect trojan-skill-hunter and accessibility-runtime-tester in the list
    3. Select trojan-skill-hunter and ask it to review .ai/skills/docs-sync-audit/; expect a read-only report
  • Attribution is complete

    1. Open .ai/THIRD-PARTY-NOTICES.md
    2. Expect every vendored file with its upstream path, commit, and license, and the license texts in .ai/licenses/

Device review

  • Did it pass in Desktop?
  • Did it pass in (emulated) Mobile?
  • Did it pass in (emulated) iPad?

Accessibility testing checklist

  • Keyboard (required — document steps below)

    1. No component, story, or UI changes; nothing is focusable in this PR.
    2. Open .ai/README.md and .ai/THIRD-PARTY-NOTICES.md on GitHub and Tab through the links.
    3. Expect every link to be reachable and to have descriptive text.
  • Screen reader (required — document steps below)

    1. Open .ai/README.md on GitHub with a screen reader.
    2. Navigate by headings through "Community resources for personal install".
    3. Expect a logical H3 → H4 order with no skipped levels, and list items announced as lists.

@changeset-bot

changeset-bot Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 1c598c1

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@caseyisonit caseyisonit added Component:Tooling Issue or PR dealing with scripts, workflows, automation, etc. Component prefix is for Jira Status:Blocked PR is blocked for some reason labels Sep 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

📚 Branch Preview Links

🔍 Gen1 Visual Regression Test Results

When a visual regression test fails (or has previously failed while working on this branch), its results can be found in the following URLs:

Deployed to Azure Blob Storage: pr-6792

If the changes are expected, update the current_golden_images_cache hash in the circleci config to accept the new images. Instructions are included in that file.
If the changes are unexpected, you can investigate the cause of the differences and update the code accordingly.

@caseyisonit
caseyisonit added this pull request to stack #6800 September 24, 2026 15:23
@caseyisonit
caseyisonit force-pushed the caseyisonit/feat-ai-community-resources branch 2 times, most recently from 08a66a4 to dadd63f Compare September 25, 2026 20:31
@caseyisonit
caseyisonit removed this pull request from stack #6800 September 25, 2026 20:33
@caseyisonit
caseyisonit changed the base branch from caseyisonit/docs-ai-readme-catalog to ceickhoff-adobe-docs-ai-claude-memory-lessons September 25, 2026 20:33
@caseyisonit
caseyisonit added this pull request to stack #6807 September 25, 2026 20:33
@caseyisonit
caseyisonit force-pushed the caseyisonit/feat-ai-community-resources branch 2 times, most recently from 10575dd to fa2db34 Compare September 28, 2026 16:51
@rubencarvalho
rubencarvalho force-pushed the caseyisonit/feat-ai-community-resources branch from fa2db34 to c7898b9 Compare September 28, 2026 20:09
@caseyisonit
caseyisonit force-pushed the caseyisonit/feat-ai-community-resources branch 2 times, most recently from 67aabe7 to 01a40e5 Compare October 5, 2026 15:12
@caseyisonit
caseyisonit force-pushed the caseyisonit/feat-ai-community-resources branch 2 times, most recently from 64f7d02 to c8efb74 Compare October 5, 2026 19:35
@caseyisonit
caseyisonit force-pushed the caseyisonit/feat-ai-community-resources branch from c8efb74 to 11d6715 Compare October 6, 2026 17:27
…tribution

Add the community resources selected in the awesome-copilot and
superpowers review, adapted to this repository and pinned to the upstream
commit they were copied from.

- skills: github-actions-hardening, docs-sync-audit, test-gap-audit,
  bug-reproduction-brief, systematic-debugging,
  verification-before-completion, and receiving-code-review
- test-driven-development: add provenance, the full-suite verification
  gate, and writing-good-tests.md from upstream, and fix code-fence drift
- custom agents: trojan-skill-hunter and accessibility-runtime-tester in
  .ai/agents/, generated to .github/agents/ for Copilot
- rules: markdown-accessibility (narrowed to docs paths) and a new
  github-actions pointer rule derived from the upstream CI guidance
- provenance metadata, license texts in .ai/licenses/, and a generated
  .ai/THIRD-PARTY-NOTICES.md
- lint:ai gains provenance, skill-asset, and agent frontmatter checks
- README documents custom agents, vendoring, and optional personal
  installs; AGENTS.md states that changes integrate through pull requests;
  docs/superpowers/ is gitignored
@caseyisonit
caseyisonit force-pushed the caseyisonit/feat-ai-community-resources branch from 11d6715 to 1c598c1 Compare October 6, 2026 18:32

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI tooling Component:Tooling Issue or PR dealing with scripts, workflows, automation, etc. Component prefix is for Jira Status:Blocked PR is blocked for some reason

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant