docs(implement): workflowScript embedding gotchas for the review wave #3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "reflex/implement-workflowscript-gotchas"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Skill-improvement reflex patch (triggered by
siafter the karl-marx-bot WP #432 /implement run, 2026-08-30).All three gotchas cost a dead async run or a retry that session:
git diffcontaining bash${…}or backticks parses as JS interpolation inside the workflowScript sandbox. Fix documented: JSON-encode (jq -Rs .) and pass viaworkflowScriptPath.keystone-pi.security-auditorrefused a task titled "Security-audit this diff"; phrasing both tasks explicitly READ-ONLY fixes the classification.runs.hostrequires an explicit integertimeoutMs— optional per docs, required by the validator.Single-line insertion in the CODE REVIEW PHASE of skills/implement/SKILL.md, after the existing "Both analyze that supplied diff." sentence. No code changes.
PR Reviewer Guide 🔍
Here are some key observations to aid the review process:
PR Reviewer Guide 🔍
Here are some key observations to aid the review process:
PR Code Suggestions ✨
No code suggestions found for the PR.
PR Code Suggestions ✨
No code suggestions found for the PR.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.