Repository navigation
feat(ai): vendor reviewed community skills, agents, and rules with attribution - #6792
caseyisonit wants to merge 1 commit into
Conversation
|
📚 Branch Preview Links🔍 Gen1 Visual Regression Test ResultsWhen a visual regression test fails (or has previously failed while working on this branch), its results can be found in the following URLs:
Deployed to Azure Blob Storage: If the changes are expected, update the |
08a66a4 to
dadd63f
Compare
10575dd to
fa2db34
Compare
fa2db34 to
c7898b9
Compare
67aabe7 to
01a40e5
Compare
64f7d02 to
c8efb74
Compare
c8efb74 to
11d6715
Compare
…tribution Add the community resources selected in the awesome-copilot and superpowers review, adapted to this repository and pinned to the upstream commit they were copied from. - skills: github-actions-hardening, docs-sync-audit, test-gap-audit, bug-reproduction-brief, systematic-debugging, verification-before-completion, and receiving-code-review - test-driven-development: add provenance, the full-suite verification gate, and writing-good-tests.md from upstream, and fix code-fence drift - custom agents: trojan-skill-hunter and accessibility-runtime-tester in .ai/agents/, generated to .github/agents/ for Copilot - rules: markdown-accessibility (narrowed to docs paths) and a new github-actions pointer rule derived from the upstream CI guidance - provenance metadata, license texts in .ai/licenses/, and a generated .ai/THIRD-PARTY-NOTICES.md - lint:ai gains provenance, skill-asset, and agent frontmatter checks - README documents custom agents, vendoring, and optional personal installs; AGENTS.md states that changes integrate through pull requests; docs/superpowers/ is gitignored
11d6715 to
1c598c1
Compare
Description
Vendors the community resources selected in the review of github/awesome-copilot and obra/superpowers: 7 new skills, 2 custom agents, and 2 rules, plus an attribution update to the existing
test-driven-developmentskill. Every vendored file is adapted to this repository, pinned to the upstream commit it came from, and attributed.yarn lint:ainow checks that attribution.Vendored content
Upstream commits:
d7e4ad98ed8fd72e4744ee604e6277eb36748fe25bf4e78011075bcfc0dc295f0724994cd123ee71.ai/agents/trojan-skill-hunter.agent.mdagents/trojan-skill-hunter.agent.mdtools: [read, search](dropped edit and repo tools), removedmodel, added where AI config lives in this repo; static-only review kept.ai/agents/accessibility-runtime-tester.agent.mdagents/accessibility-runtime-tester.agent.mdtools: [read, search, execute], removedmodel, replaced the Chrome DevTools MCP requirement with Storybook, the Playwright a11y specs, axe, and WCAG 2.2; component-focused examples; cross-linksaccessibility-complianceandmigration-a11y.ai/rules/markdown-accessibility.mdinstructions/markdown-accessibility.instructions.md**/*.mdto 5 docs globs; heading roots followcomponent-readmeandstories-documentation; case and punctuation defer totext-formatting; dropped the external-article preamble.ai/rules/github-actions.md(new, 1.9 KB)instructions/github-actions-ci-cd-best-practices.instructions.mdandskills/github-actions-hardening.github/workflows/**and.github/actions/**: explicitpermissions, no untrusted${{ }}inrun:, no privileged fork execution,./.github/actions/setup-job,concurrency, and pinning by maintainer policy.ai/skills/github-actions-hardening/(+5 references)skills/github-actions-hardeningsetup-job, theworkflow_runguard inpublish-gen2-docs.yml); full-SHA pinning framed as a maintainer decision; references copied with Prettier formatting only.ai/skills/docs-sync-audit/(+scripts/docs_drift.py)skills/docs-sync-audit.ai/); generated docs excluded with their generators named; hand-offs tocontributor-docs-nav,yarn lint:ai, andyarn lint:docs-pages; script unchanged.ai/skills/test-gap-audit/(+scripts/coverage_map.py)skills/test-gap-auditmigration-testingandvrt-authoring; script unchanged.ai/skills/bug-reproduction-brief/skills/bug-reproduction-brief(itself from MIT skyestrela/ai-agent-skill-preview)systematic-debugging; records the upstream-of-upstream.ai/skills/systematic-debugging/(+3 techniques)skills/systematic-debuggingsuperpowers:cross-references; SWC multi-layer example (toolchain, lockfile, build, test); droppedfind-polluter.sh,CREATION-LOG.md, and pressure-test files; neutral wording for "your human partner".ai/skills/verification-before-completion/skills/verification-before-completionyarn lint:ai, targeted Vitest,yarn type-check, a11y specs, VRT, builds); pre-existing failure reporting; cross-linksconsistency-passandmigration-review.ai/skills/receiving-code-review/skills/receiving-code-review.ai/rules/as the tie-breaker; SWC examples; tool-agnostic thread-reply guidance.ai/skills/test-driven-development/(existing)skills/test-driven-developmentwriting-good-tests.md; kepttesting-anti-patterns.md; fixed the code-fence drift Prettier introduced;vi.fn()andyarncommandsTooling
yarn ai:syncgenerates.ai/agents/*.agent.mdinto.github/agents/(provenance metadata stripped). Claude Code and Cursor get no copies.yarn ai:syncgenerates.ai/THIRD-PARTY-NOTICES.mdfrom provenance metadata; license texts live in.ai/licenses/<owner>-<repo>.<license>.txt.yarn lint:aichecks: provenance (source, 40-character SHA, license, license file), skill bundled files (links resolve, 5 MB cap, a warning for unreferenced files), and agent frontmatter (descriptionrequired, Copilot tool aliases, nomodel, 30,000-character prompt cap).validate.jsnow runs 9 checks..github/agents/and the notices file along with the other generated files, skipping any that don't exist yet. It also skips the sync when.ai/agents/or.ai/licenses/has unstaged changes. Pre-push regenerates.github/agents/and the notices file too, and blocks the push if either is out of date.Docs
.ai/README.md: custom agents, how to vendor content, and a curated list of 36 optional personal installs with risk notes and Superpowers caveats.AGENTS.md: custom agents row, and "integrate changes only through pull requests.".gitignore:docs/superpowers/, where the optional Superpowers plugin writes plans.Static safety review
A trojan-skill-hunter-style static review of every vendored file found no hidden instructions:
example.com.gitcommands (ls-files,log -1, andrev-parse), and never write files or use the network.curlandwgetappear only as threat descriptions introjan-skill-hunter.Motivation and context
Final layer of the
.ai/Copilot migration stack. The review scored 1,099 community resources against a shared rubric; these 11, plus 1 derived rule, cover gaps no existing skill fills: CI threat modeling for a public repo that accepts fork PRs, docs drift, behavior-level test gaps, bug reproduction, root-cause debugging, verification gates, review triage, and isolated reviewers for AI config and runtime accessibility.Related issue(s)
Screenshots (if appropriate)
N/A (no UI changes).
Author's checklist
No changeset: nothing published changes.
Reviewer's checklist
patch,minor, ormajorfeaturesManual review test cases
Validation passes
yarn installyarn lint:aiCopilot discovers the new skills without duplicates
copilot skill list --jsonCopilot loads the new rules for matching files
copilot instruction listgithub-actions.instructions.mdandmarkdown-accessibility.instructions.mdCustom agents are available
copilotinteractively in the repository and run/agenttrojan-skill-hunterandaccessibility-runtime-testerin the listtrojan-skill-hunterand ask it to review.ai/skills/docs-sync-audit/; expect a read-only reportAttribution is complete
.ai/THIRD-PARTY-NOTICES.md.ai/licenses/Device review
Accessibility testing checklist
Keyboard (required — document steps below)
.ai/README.mdand.ai/THIRD-PARTY-NOTICES.mdon GitHub and Tab through the links.Screen reader (required — document steps below)
.ai/README.mdon GitHub with a screen reader.