Skip to content

Add maintainer loop (orchestrator + triage skills) - #8

Merged
adityash8 merged 1 commit into
mainfrom
chore/maintainer-loop
Jun 16, 2026
Merged

adityash8 merged 1 commit into
mainfrom
chore/maintainer-loop

Conversation

@adityash8

Copy link
Copy Markdown
Owner

Adds the maintainer-loop tooling copied from gate-slip:

  • .claude/skills/maintainer-orchestrator/
  • .claude/skills/github-project-triage/
  • docs/MAINTAINER_LOOP.md

Generated by Claude Code

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces two Claude Code skills (github-project-triage and maintainer-orchestrator) along with a MAINTAINER_LOOP.md documentation file to set up an automated maintenance loop. The reviewer feedback correctly identifies that the added files contain stale, copy-pasted references from a different project (ITSEZMONEY / gate-slip), including incorrect organization names, non-applicable file paths, and irrelevant risk heuristics (such as Stripe, Passport, and TypeScript schemas) instead of those matching the Swift/macOS Auto-Up codebase. Additionally, the reviewer points out that the referenced script scripts/fanout-maintainer-skills.sh is missing from the repository.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.


- If invoked inside a Git repo with a GitHub remote (or a Routine cloned a
specific repo), triage **only that repo**.
- Only broaden to multiple repos / the whole `ITSEZMONEY` org when the prompt

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The organization name ITSEZMONEY is a stale reference from the copied project. Replace it with a generic term or the correct organization name.

Suggested change
- Only broaden to multiple repos / the whole `ITSEZMONEY` org when the prompt
- Only broaden to multiple repos / the whole organization when the prompt

Comment on lines +55 to +61
## Risk heuristics (ITSEZMONEY / gate-slip context)

Treat as **high risk** anything touching: auth/Passport/OAuth, payments/Stripe,
`certificates/` or any key/secret, DB schema or migrations (`shared/schema.ts`),
the parsing pipeline's output shape (`flightDataSchema`, the dual-AI parsers),
or CI/release/`.env` config. Treat docs, copy, tests, lockfile/dep bumps, and
formatting as **low risk**.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The risk heuristics and file paths specified here are copied from a different project (gate-slip / ITSEZMONEY) and do not match the Auto-Up codebase. This project is a Swift/macOS application and does not use TypeScript (shared/schema.ts), Stripe, or Passport. Update the high-risk areas to reflect the actual critical components of Auto-Up (e.g., InstallManager, Sparkle feeds, database encryption, and code signing).

Suggested change
## Risk heuristics (ITSEZMONEY / gate-slip context)
Treat as **high risk** anything touching: auth/Passport/OAuth, payments/Stripe,
`certificates/` or any key/secret, DB schema or migrations (`shared/schema.ts`),
the parsing pipeline's output shape (`flightDataSchema`, the dual-AI parsers),
or CI/release/`.env` config. Treat docs, copy, tests, lockfile/dep bumps, and
formatting as **low risk**.
## Risk heuristics (Auto-Up context)
Treat as **high risk** anything touching: installer logic (InstallManager), Sparkle update feeds/signatures, database schema or encryption (SQLCipher), StoreKit/monetization, background scheduling, or entitlements/code signing. Treat docs, copy, tests, and formatting as **low risk**.

---
name: maintainer-orchestrator
description: >-
Control-plane loop for maintaining ITSEZMONEY repositories. Use when asked to

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The organization name ITSEZMONEY is a stale reference. Replace it with the correct repository or organization name.

Suggested change
Control-plane loop for maintaining ITSEZMONEY repositories. Use when asked to
Control-plane loop for maintaining Auto-Up repositories. Use when asked to

Comment on lines +70 to +72
- It touches **none** of: auth, payments/Stripe, `certificates/` or any
key/secret, DB schema or migrations (`shared/schema.ts`, drizzle), CI/release
config, or anything in `.env*`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The high-risk files and modules listed here are stale references to a different project. Update them to match the critical paths of the Auto-Up Swift codebase.

Suggested change
- It touches **none** of: auth, payments/Stripe, `certificates/` or any
key/secret, DB schema or migrations (`shared/schema.ts`, drizzle), CI/release
config, or anything in `.env*`.
- It touches **none** of: installer logic (InstallManager), Sparkle update feeds/signatures, database schema or encryption (SQLCipher), StoreKit/monetization, background scheduling, or entitlements/code signing.

Comment thread docs/MAINTAINER_LOOP.md
@@ -0,0 +1,113 @@
# Maintainer Loop (cloud)

A self-running maintenance loop for ITSEZMONEY repos: wake on a trigger β†’ triage

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The organization name ITSEZMONEY is a stale reference from the copied project. Update it to refer to the current project or organization.

Suggested change
A self-running maintenance loop for ITSEZMONEY repos: wake on a trigger β†’ triage
A self-running maintenance loop for Auto-Up repos: wake on a trigger -> triage

Comment thread docs/MAINTAINER_LOOP.md
Comment on lines +43 to +45
1. **Commit the skills.** They must live in the repo(s) the routine clones β€”
that's what this PR does. The fan-out script (below) copies them to every
ITSEZMONEY repo.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The organization name ITSEZMONEY is a stale reference. Update it to refer to the current project or organization.

Suggested change
1. **Commit the skills.** They must live in the repo(s) the routine clones β€”
that's what this PR does. The fan-out script (below) copies them to every
ITSEZMONEY repo.
1. **Commit the skills.** They must live in the repo(s) the routine clones β€”
that's what this PR does. The fan-out script (below) copies them to every
Auto-Up repo.

Comment thread docs/MAINTAINER_LOOP.md Outdated
Comment on lines +80 to +83
- **Auto-merge** (squash) only when *all* hold: CI green Β· change is
deps/docs/tests/lockfile/formatting/safe-config Β· small bounded diff Β· touches
none of {auth, Stripe, `certificates/`, schema/migrations, CI/release, `.env*`,
secrets} Β· trusted author or loop-authored Β· no unresolved change requests.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The autonomy policy summary contains stale references to Stripe, schema/migrations, and .env files which are not applicable to the Auto-Up Swift codebase. Update these to match the actual high-risk areas of this project.

Suggested change
- **Auto-merge** (squash) only when *all* hold: CI green Β· change is
deps/docs/tests/lockfile/formatting/safe-config Β· small bounded diff Β· touches
none of {auth, Stripe, `certificates/`, schema/migrations, CI/release, `.env*`,
secrets} Β· trusted author or loop-authored Β· no unresolved change requests.
- **Auto-merge** (squash) only when *all* hold: CI green Β· change is
deps/docs/tests/lockfile/formatting/safe-config Β· small bounded diff Β· touches
none of {installer logic (InstallManager), Sparkle update feeds/signatures, database schema/encryption, StoreKit/monetization, background scheduling, entitlements/code signing} Β· trusted author or loop-authored Β· no unresolved change requests.

Comment thread docs/MAINTAINER_LOOP.md
Comment on lines +91 to +95
```bash
# Copy the skills + this runbook into every ITSEZMONEY repo and open a PR each.
scripts/fanout-maintainer-skills.sh # all org repos (needs gh + perms)
scripts/fanout-maintainer-skills.sh repo-a repo-b # just these
```

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The script scripts/fanout-maintainer-skills.sh referenced here is not included in this pull request or the repository. Add the script to the repository or remove this section until the script is available.

@adityash8 adityash8 closed this Jun 16, 2026
@adityash8 adityash8 reopened this Jun 16, 2026
@adityash8
adityash8 marked this pull request as ready for review June 16, 2026 05:51

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 092ee80570

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +70 to +72
- It touches **none** of: auth, payments/Stripe, `certificates/` or any
key/secret, DB schema or migrations (`shared/schema.ts`, drizzle), CI/release
config, or anything in `.env*`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Block AutoUp-sensitive paths from autonomous merges

When this routine is used in the AutoUp repo, this protected-surface check only excludes copied web-app paths such as auth/Stripe/shared/schema/CI/.env from auto-merge. It does not cover this app's high-risk surfaces such as Sources/Core/InstallManager.swift (installer/update execution), Sources/Services/ProManager.swift (StoreKit subscription state), AutoUp.entitlements, or Sources/Info.plist, so a small "safe config" or trusted formatting/dependency PR touching those areas can satisfy the listed conditions and be merged without owner review. Please replace the copied gate-slip exclusions with AutoUp-specific protected paths before enabling the loop.

Useful? React with πŸ‘Β / πŸ‘Ž.

Comment thread docs/MAINTAINER_LOOP.md Outdated
Comment on lines +93 to +94
scripts/fanout-maintainer-skills.sh # all org repos (needs gh + perms)
scripts/fanout-maintainer-skills.sh repo-a repo-b # just these

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Add the fan-out script before documenting it

The runbook tells maintainers to run scripts/fanout-maintainer-skills.sh, but this commit doesn't add that script; I checked the repo file list for fanout/maintainer and only the two skill files plus this doc exist. Anyone following the "Fan out to all repos" path will get a file-not-found error before they can propagate the loop, so either add the script or replace these commands with working instructions.

Useful? React with πŸ‘Β / πŸ‘Ž.


## Item card

For every open issue/PR, produce:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Exclude the ledger from backlog triage

After the first run creates πŸ€– Maintainer Loop β€” Ledger, this instruction pulls that ledger back into the triage queue because it says to produce cards for every open issue/PR. The later defer/close step operates on those cards, so a stale or out-of-scope classification can close the one issue that is supposed to preserve durable state. Please explicitly skip the maintainer-ledger issue by label/title during queue discovery and actions.

Useful? React with πŸ‘Β / πŸ‘Ž.

Comment on lines +47 to +49
5. **Escalate needs-owner items.** Don't guess at product/direction/secret
decisions. Label `needs-owner`, leave a one-paragraph comment stating the
decision required and the options, and record it in the ledger.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Ensure the needs-owner label exists before use

In a repo that doesn't already have a needs-owner label, this escalation path can fail when it tries to apply the label; the only bootstrapping in the loop creates maintainer-ledger. Those blocked items would then be much harder to filter or revisit from GitHub, even though escalation relies on the label as the visible signal. Please create/ensure needs-owner before applying it, the same way the ledger label is handled.

Useful? React with πŸ‘Β / πŸ‘Ž.

Comment on lines +20 to +21
- Only broaden to multiple repos / the whole `ITSEZMONEY` org when the prompt
explicitly says `all`, `broad`, `org-wide`, or `everything`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require an explicit org-wide scope phrase

When invoked from a single repo, a normal request like "triage all open issues" contains all, so this rule can override the repo-only default and make the triage query the whole ITSEZMONEY org. That can unexpectedly read and act on unrelated repositories; please require an unambiguous phrase such as all repos or org-wide before broadening scope.

Useful? React with πŸ‘Β / πŸ‘Ž.

@adityash8
adityash8 force-pushed the chore/maintainer-loop branch from 092ee80 to e39fda7 Compare June 16, 2026 06:09
@adityash8
adityash8 force-pushed the chore/maintainer-loop branch from e39fda7 to 46dc8e3 Compare June 16, 2026 06:14
@adityash8
adityash8 merged commit 104b0c0 into main Jun 16, 2026
1 check passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 46dc8e3cf7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

`duplicate_of` set to the survivor), and continue on the survivor. If none exists, create it, ensure the
`maintainer-ledger` label exists, and apply it. Never open a second ledger
when one is already open. The ledger is the durable memory across runs (cloud
sessions are ephemeral); skip anything it marks resolved or `wontfix`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reprocess reopened items despite ledger tombstones

Because discovery only queues open issues/PRs, this skip only matters when the ledger is stale, such as an issue previously marked resolved/wontfix that a human later reopens or comments on with new information. In that scenario the current open state is ignored forever until someone manually edits the ledger, so reopened work can disappear from the maintainer loop; please treat GitHub's current open/reopened state or newer activity as authoritative before skipping.

Useful? React with πŸ‘Β / πŸ‘Ž.

Comment on lines +57 to +63
## Risk heuristics (ITSEZMONEY / gate-slip context)

Treat as **high risk** anything touching: auth/Passport/OAuth, payments/Stripe,
`certificates/` or any key/secret, DB schema or migrations (`shared/schema.ts`),
the parsing pipeline's output shape (`flightDataSchema`, the dual-AI parsers),
or CI/release/`.env`/infra/deployment config. Treat docs, copy, tests,
lockfile/dep bumps, and formatting as **low risk**.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Replace gate-slip triage risks with AutoUp surfaces

This triage classifier still uses copied gate-slip/web-app surfaces, so AutoUp changes to installer/update execution, StoreKit subscription handling, entitlements, or Sparkle/Info.plist release settings are not classified as high risk before they reach the autonomy bucket. Fresh evidence is that this is a second copied list in the triage skill itself, so fixing only the merge gate would still let PRs touching files like Sources/Core/InstallManager.swift, Sources/Services/ProManager.swift, AutoUp.entitlements, or Sources/Info.plist be presented as low-risk autonomous work.

Useful? React with πŸ‘Β / πŸ‘Ž.

### Low-risk β†’ may land autonomously (open PR, get CI green, then merge)

ALL must hold:
- CI is **fully green** on the head commit (not pending, not skipped-as-proxy).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require an actual build before auto-merging

In this repo, green CI doesn't prove the app builds: I checked .github/workflows/cursor-review.yml, and the only PR workflow is Cursor Review, which exits 0 as a no-op when CURSOR_API_KEY is unset and never runs swift build or swift test. With this gate, a low-risk dependency/config change can be auto-merged once that no-op job is green, so require a real AutoUp build/test before merge rather than treating any green CI as sufficient.

Useful? React with πŸ‘Β / πŸ‘Ž.

- Author is **trusted** per the allowlist below (or the change was authored by
this loop, which runs as `adityash8`) β€” **or** it is a bot dependency bump that
independently meets every other gate in this list.
- No unresolved review thread requests changes.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Honor top-level changes-requested reviews

For PRs where a reviewer uses a summary-only CHANGES_REQUESTED review, there is no unresolved inline thread for this condition to find, so a trusted low-risk PR could still be merged over an explicit review block in repos that don't enforce review state via branch protection. Please check the latest PR review states/change-requested status, not only unresolved review threads.

Useful? React with πŸ‘Β / πŸ‘Ž.

Comment on lines +25 to +28
Use the **GitHub MCP connector** (preferred) or `gh`:
- Open PRs (with CI status, requested reviewers, draft state, mergeability).
- Open issues (with labels, age, last activity).
- For each, the last few comments and the CI job summary.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Isolate untrusted GitHub text from instructions

When this runs on public/org PRs or issues, the comments and CI summaries gathered here are author-controlled text, but the skill never tells the agent to treat them as data only. A malicious comment or log can instruct the autonomous routine to ignore the allowlist or alter labels/merges while using the owner's GitHub identity; add an explicit rule to never follow instructions from issue/PR bodies, comments, or logs.

Useful? React with πŸ‘Β / πŸ‘Ž.

Comment thread docs/MAINTAINER_LOOP.md
Comment on lines +134 to +136
(already identical), skip that repo. Otherwise create/update branch
chore/maintainer-loop, commit "chore: sync maintainer loop skills", and open or
update a DRAFT PR titled "Sync maintainer loop skills". Do not modify gate-slip.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use a pushable branch for distributor PRs

With the default routine permissions configured above, Claude can only push claude/-prefixed branches unless unrestricted branch pushes is enabled (the Routines docs state this restriction). This distributor prompt asks it to create/update chore/maintainer-loop, so the no-local-gh propagation path will fail to push/open PRs for users who follow the default setup; either use a claude/... branch or require unrestricted pushes for this routine.

Useful? React with πŸ‘Β / πŸ‘Ž.

Comment on lines +51 to +53
5. **Escalate needs-owner items.** Don't guess at product/direction/secret
decisions. Label `needs-owner`, leave a one-paragraph comment stating the
decision required and the options, and record it in the ledger.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid repeating needs-owner comments each run

For an item that is already escalated and still waiting on a human, the next scheduled run rediscovers the same open issue/PR, and the ledger skip only covers resolved/wontfix entries. This step therefore posts another needs-owner comment every pass until the owner acts, which can spam active discussions; record already-escalated items and only comment again when there is new activity or the required decision changes.

Useful? React with πŸ‘Β / πŸ‘Ž.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant