diff --git a/.agents/skills/cpn-commit/SKILL.md b/.agents/skills/cpn-commit/SKILL.md index ea7e8ef622..b9f9d1cfe2 100644 --- a/.agents/skills/cpn-commit/SKILL.md +++ b/.agents/skills/cpn-commit/SKILL.md @@ -3,7 +3,7 @@ name: cpn-commit description: "Use when committing in this repo: conventional commit shape enforced by commitlint." -version: 1.0.0 +version: 1.1.0 license: Apache-2.0 --- @@ -37,6 +37,16 @@ Never bypass hooks with `--no-verify`. Reference safety: a bare `#N` resolves to a console issue/PR. Cross-repo references use a full URL or `owner/repo#N`. +Keep the subject ≤ 72 chars — GitHub truncates `messageHeadline` at 72 +bytes with `…`, breaking downstream title-parity checks. + +## Squash-merge message + +When landing (`cpn-merge`), pass the squash message as ONE clean block: +subject via `-t`, body + trailers via `-b`. `-m` is the `--merge` strategy +boolean — a second `-m "text"` fails with "accepts at most 1 arg(s)". +Never trust GitHub's auto-concatenated body. + ## Procedure Single-line message: diff --git a/.agents/skills/cpn-create-skill/references/agentskills-cpn.md b/.agents/skills/cpn-create-skill/references/agentskills-cpn.md index 1f449654fd..deb46e1c9c 100644 --- a/.agents/skills/cpn-create-skill/references/agentskills-cpn.md +++ b/.agents/skills/cpn-create-skill/references/agentskills-cpn.md @@ -14,6 +14,14 @@ La description commence par `Use when`, couvre la capacité et ses déclencheurs Le corps utilise l’impératif, définit entrées, sorties, décisions, erreurs et vérifications. Garder les instructions courantes dans `SKILL.md`; placer les scripts déterministes dans `scripts/`, les références lourdes dans `references/` et les modèles dans `assets/`. Référencer ces fichiers depuis `SKILL.md` par un chemin relatif direct, sans chaîne de références profonde. +## Pratiques de rédaction + +- Ancrer chaque skill dans une exécution réelle : les étapes qui ont fonctionné, les corrections faites, les formats d’entrée et de sortie — jamais un template générique. +- Divulgation progressive : garder `SKILL.md` sous ~500 lignes ; pousser le détail dans `references/` avec une condition de chargement explicite. +- Défauts, pas menus : un outil ou une approche par décision ; ne mentionner une alternative que comme échappatoire. +- Procédures plutôt que déclarations : enseigner comment aborder une classe de problèmes. +- La section `## Pitfalls` recueille les corrections qui contredisent une intuition ; chaque erreur corrigée par l’agent y est ajoutée. + ## Contrôle Utiliser `skills-ref validate .agents/skills/` lorsque la commande existe. Sinon, documenter le contrôle manuel : répertoire égal à `name`, nom conforme, frontmatter YAML lisible, `name` et `description` non vides, ressources référencées présentes et chemins relatifs directs. diff --git a/.agents/skills/cpn-merge/SKILL.md b/.agents/skills/cpn-merge/SKILL.md index bdbf1099d6..ff2a39c707 100644 --- a/.agents/skills/cpn-merge/SKILL.md +++ b/.agents/skills/cpn-merge/SKILL.md @@ -3,7 +3,7 @@ name: cpn-merge description: "Use when merging a reviewed PR in this repo: DoD ledger, threads, CI, and human approval gates, then squash-merge." -version: 1.0.0 +version: 1.1.0 license: Apache-2.0 --- @@ -86,6 +86,8 @@ base first, one squash each. Never force-push. - Merge after a new push without re-approval — approval binds to a head commit. +- `gh pr merge -m "text"` to set a message — `-m` is the `--merge` boolean; + the message flags are `-t ` / `-b `. - `Closes #N` in the squash body — auto-close fires before the ledger is verified; issues close deliberately. - Watch and merge joined with `&&` — the merge fires on stale gates. diff --git a/.agents/skills/cpn-pr/SKILL.md b/.agents/skills/cpn-pr/SKILL.md index 8778e00d57..d865d0c606 100644 --- a/.agents/skills/cpn-pr/SKILL.md +++ b/.agents/skills/cpn-pr/SKILL.md @@ -3,7 +3,7 @@ name: cpn-pr description: "Use when opening or triaging a PR in this repo: French body from the template, draft-first, origin-only, review-gated." -version: 1.0.0 +version: 1.1.0 license: Apache-2.0 --- @@ -58,6 +58,8 @@ gh pr create --repo cloud-pi-native/console --draft --base main \ formatter over it. - A literal `@` in prose triggers a user/team mention — wrap it in a code span. +- Reference issues as `#N` when the reference stands alone — it renders as + a rich link. Cross-repo references carry `owner/repo#N` or a full URL. ## Triage after creation diff --git a/.agents/skills/cpn-review/SKILL.md b/.agents/skills/cpn-review/SKILL.md index 20f4b28f28..df8b6547a8 100644 --- a/.agents/skills/cpn-review/SKILL.md +++ b/.agents/skills/cpn-review/SKILL.md @@ -3,7 +3,7 @@ name: cpn-review description: "Use when reviewing a PR or reconciling its review threads in this repo: severity-tagged French inline findings, DoD ledger, never merge." -version: 1.0.0 +version: 1.1.0 license: Apache-2.0 --- @@ -31,7 +31,10 @@ An unmet requirement is a reported blocker, never a silent scope change. 2. **High-level** — architecture fit: `apps/server-nestjs` is the only modifiable backend target, `apps/server` frozen; API contracts in `packages/shared`; hook lifecycle `pre → main → post` with `revert` on - failure; permission checks at the router via BigInt bitmasks. + failure; permission checks at the router via BigInt bitmasks. Cross-check + the diff against related issues/PRs (changed paths, symbols, subject + keyphrase) before the verdict: do not re-flag a tradeoff a closed issue + already accepted; cite an open issue covering the same change. 3. **Line-by-line** — YAGNI first: anything deletable or replaceable by the stdlib is a finding. A deliberate corner-cut carries a `ponytail:` comment naming the ceiling and the upgrade path. @@ -45,6 +48,15 @@ gh pr review --repo cloud-pi-native/console \ gh pr review --repo cloud-pi-native/console --approve --body "…" # otherwise ``` +A `blocking`/`important` finding qualifies only when it is discrete, +actionable, introduced by this change, and has a demonstrable call path — +never pre-existing code or an intentional behavior change. Nothing +qualifies → state `No findings.`; never invent one. Scan added lines for +hard-coded secrets, injection, `eval`/`exec`, unsafe deserialization, path +traversal, XSS — any match is `blocking` regardless of call path. Cite +evidence as the exact `- old` → `+ new` diff lines or command output in a +fenced block, never a prose summary of what the output "shows". + Commitlint violations → suggest the corrected conventional message; the author amends.