chore: add maintainer setup baseline#103
Conversation
|
Codex review: needs changes before merge. Latest ClawSweeper review: 2026-05-22 10:24 UTC / May 22, 2026, 6:24 AM ET. Workflow note: Future ClawSweeper reviews update this same comment in place. How this review workflow works
Summary Reproducibility: yes. for the review finding: the risky runner selection is visible directly in the changed workflow source and the intended fixed labels are visible in the new Crabbox config. There is no separate runtime bug report to reproduce. PR rating Rank-up moves:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. Real behavior proof Risk before merge
Maintainer options:
Copy recommended automerge instructionNext step before merge Security Review findings
Review detailsBest possible solution: Ship the baseline only after the hydrate workflow is constrained to Crabbox-only self-hosted runners and maintainers accept the stale/ownership policy. Do we have a high-confidence way to reproduce the issue? Yes for the review finding: the risky runner selection is visible directly in the changed workflow source and the intended fixed labels are visible in the new Crabbox config. There is no separate runtime bug report to reproduce. Is this the best way to solve the issue? No, not as-is; the baseline direction is reasonable, but the hydrate workflow should enforce static Crabbox runner labels before merge, and stale automation remains a maintainer policy choice. Label changes:
Label justifications:
Full review comments:
Overall correctness: patch is incorrect Security concerns:
Acceptance criteria:
What I checked:
Likely related people:
Codex review notes: model gpt-5.5, reasoning high; reviewed against 2680adb3aaf9. |
|
ClawSweeper PR egg 🔥 Warming up: real-behavior proof passed; findings, security review, or rank-up moves are still in progress. Hatch commandComment Hatchability rules:
What is this egg doing here?
|
|
Closing this in favor of the shared public skill source at https://github.com/openclaw/agent-skills. We do not want to vendor the same maintainer skills into every repo. Repos that need zero-setup guidance should add a small pointer to |
Summary
Verification
Runtime tests were not run; this is setup, policy, and workflow metadata only.