chore: add maintainer setup baseline#122
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
Codex review: found issues before merge. Latest ClawSweeper review: 2026-05-22 14:44 UTC / May 22, 2026, 10:44 AM ET. Workflow note: Future ClawSweeper reviews update this same comment in place. How this review workflow works
Summary Reproducibility: no. live runner reproduction was established, but the source path is clear: workflow_dispatch inputs feed both PR rating Rank-up moves:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. Real behavior proof Risk before merge
Maintainer options:
Next step before merge Security Review findings
Review detailsBest possible solution: Land the setup baseline only after maintainer approval of the stale policy and after constraining or explicitly documenting the Crabbox self-hosted runner/ref dispatch boundary for ephemeral Crabbox use. Do we have a high-confidence way to reproduce the issue? No live runner reproduction was established, but the source path is clear: workflow_dispatch inputs feed both Is this the best way to solve the issue? Unclear as proposed: the setup baseline is broadly maintainable, but the self-hosted runner/ref dispatch should be constrained or explicitly approved before merge. The narrowest safe path is to preserve the baseline while tightening that trust boundary or documenting the accepted Crabbox-only model. Label changes:
Label justifications:
Full review comments:
Overall correctness: patch is incorrect Security concerns:
What I checked:
Likely related people:
Codex review notes: model gpt-5.5, reasoning high; reviewed against c7ae79c1b195. |
|
ClawSweeper PR egg 🔥 Warming up: real-behavior proof passed; findings, security review, or rank-up moves are still in progress. Hatch commandComment Hatchability rules:
What is this egg doing here?
|
|
Closing this in favor of the shared public skill source at https://github.com/openclaw/agent-skills. We do not want to vendor the same maintainer skills into every repo. Repos that need zero-setup guidance should add a small pointer to |
Summary
Verification
Runtime tests were not run; this is setup, policy, and workflow metadata only.