Cherry Studio Regression Tests
CherryHQ/cherry-studio
Runs Cherry Studio's critical-path regression suite as deterministic Playwright E2E tests through a GitHub workflow on macOS and Windows runners.
github-pre-push-gates — Pre-push quality gates: immutable verification, privacy scanning, independent closeout review, and clean publication from divergent local history.
$ npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AtlasOmnia/donna-starter github-pre-push-gates --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AtlasOmnia/donna-starter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/github/github-pre-push-gates .claude/skills/github-pre-push-gates && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-pre-push-gates" agent skill from https://github.com/AtlasOmnia/donna-starter/tree/main/skills/github/github-pre-push-gates into .claude/skills/github-pre-push-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-pre-push-gates", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AtlasOmnia/donna-starter/tree/main/skills/github/github-pre-push-gatesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AtlasOmnia/donna-starter github-pre-push-gates --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AtlasOmnia/donna-starter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/github/github-pre-push-gates .agents/skills/github-pre-push-gates && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-pre-push-gates" agent skill from https://github.com/AtlasOmnia/donna-starter/tree/main/skills/github/github-pre-push-gates into .agents/skills/github-pre-push-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-pre-push-gates", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AtlasOmnia/donna-starter github-pre-push-gates --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AtlasOmnia/donna-starter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/github/github-pre-push-gates .cursor/skills/github-pre-push-gates && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-pre-push-gates" agent skill from https://github.com/AtlasOmnia/donna-starter/tree/main/skills/github/github-pre-push-gates into .cursor/skills/github-pre-push-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-pre-push-gates", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AtlasOmnia/donna-starter.git --path skills/github/github-pre-push-gates--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AtlasOmnia/donna-starter github-pre-push-gates --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AtlasOmnia/donna-starter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/github/github-pre-push-gates .gemini/skills/github-pre-push-gates && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-pre-push-gates" agent skill from https://github.com/AtlasOmnia/donna-starter/tree/main/skills/github/github-pre-push-gates into .gemini/skills/github-pre-push-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-pre-push-gates", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AtlasOmnia/donna-starter github-pre-push-gatesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AtlasOmnia/donna-starter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/github/github-pre-push-gates .github/skills/github-pre-push-gates && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-pre-push-gates" agent skill from https://github.com/AtlasOmnia/donna-starter/tree/main/skills/github/github-pre-push-gates into .github/skills/github-pre-push-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-pre-push-gates", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AtlasOmnia/donna-starter github-pre-push-gates --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AtlasOmnia/donna-starter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/github/github-pre-push-gates .opencode/skills/github-pre-push-gates && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-pre-push-gates" agent skill from https://github.com/AtlasOmnia/donna-starter/tree/main/skills/github/github-pre-push-gates into .opencode/skills/github-pre-push-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-pre-push-gates", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-pre-push-gatesgithub-pre-push-gates — Pre-push quality gates: immutable verification, privacy scanning, independent closeout review, and clean publication from divergent local history.
GitHub Pre Push Gates is an agent skill from AtlasOmnia/donna-starter. github-pre-push-gates — Pre-push quality gates: immutable verification, privacy scanning, independent closeout review, and clean publication from divergent local history.
Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/ci-retry-monitor.py`).
It sits in Testing & QA, covering Quality gates. It works with GitHub. The repository describes itself as: Donna — a starter Hermes Agent profile: opinionated persona, 73 curated skills, guided first-run orientation, optional Token Router. MIT. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a3710bd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gitnpmghnpxpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm, gh and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub Pre Push Gates loads about 6.2k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 3,125 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from AtlasOmnia/donna-starter at commit a3710bd, republished under its MIT licence (© AtlasOmnia). 3,125 words, ~6,233 tokens.
.claude/skills/github-pre-push-gates/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Before pushing a branch to a shared remote, run through these gates. They prevent pushing credentials, PII, private history, or a broken tree. The skill covers the pre-PR quality phase — use github-pr-workflow for the PR lifecycle itself.
npm audit --omit=dev --audit-level=high, but a zero result there does not clear a vulnerable developer toolchain. Run the full audit too when the repository ships or executes from source.npm audit --package-lock-only can pass while stale node_modules still reports old versions; use a clean npm ci in CI and then run ordinary npm audit before declaring the dependency fix verified.npm audit fix --force without reviewing proposed major downgrades and behavior changes.[code complete] → [immutable verification] → [privacy scan] → [reviewer] → [push + SHA verify] → [PR]Each gate is optional by severity — skip when the scope doesn't warrant it, but never skip the privacy scan when pushing to a shared/public remote.
Before any final gate or read-only review, verify that no write-capable agent still owns the checkout or can advance the branch from an orchestrator/sibling worktree. A clean status alone is insufficient: interrupted parent agents can leave delegated workers alive, continuation controllers can auto-start the next task, and command | tee log can mask an agent failure unless the shell uses set -o pipefail. Freeze the exact SHA across gates and recheck HEAD/status/writers after every long command. For process checks, shared-ref/worktree freezes, dirty-tree fingerprints, safe interrupted-writer recovery, and synthetic secret-fixture classification,
If later work keeps advancing the live development branch, publish the approved ancestor from a detached non-cloud worktree instead of resetting or force-pushing the moving checkout. Re-run immutable gates, privacy scanning, and exact-SHA review there, then push the immutable SHA with an explicit refspec (see §4 for the full frozen-worktree procedure).
If the checkout is under iCloud Drive, OneDrive, Dropbox, or another placeholder-backed sync root, move recovery to a non-cloud development directory before resuming. Resource deadlock avoided, unreadable Git refs/objects, zero-block placeholders, and conflict copies such as file 2.ts invalidate normal Git evidence. Hydrate placeholders before reading, preserve dirty-tree state, and verify the destination before resuming.
Run the full test suite, then verify the working tree and commit SHA did not change. This catches regenerated lockfiles, build artifacts, or side-effect file writes that could invalidate your pass:
set -e
sha=$(git rev-parse HEAD)
test -z "$(git status --porcelain)"
npm test
npx tsc --noEmit
npm run build
npm run validate
git diff --check
# ... any other project-specific gates ...
npm audit --audit-level=high --omit=dev
test -z "$(git status --porcelain)"
test "$sha" = "$(git rev-parse HEAD)"
printf 'IMMUTABLE_GATE=PASS sha=%s\n' "$sha"Pitfalls:
git status shows a change after the test suite, investigate — the tree is not reproducible..gitignore.PASS marker—or reports zero while an inner gate failed—do not choose the convenient result. Run a minimal standalone reconciliation that verifies the exact SHA, empty porcelain, committed-range diff --check, and lock/writer state, with an explicit final exit code. Record the first run as contradictory transport evidence, not a pass or product failure.When a release changes a website's palette, theme, gradients, or component backgrounds, responsive geometry is not sufficient accessibility evidence.
getComputedStyle() after focus.A useful Playwright pattern is: load the page, press Tab, assert the active element is the expected skip link, parse its computed color and backgroundColor, calculate WCAG relative luminance, and require ratio >= 4.5.
For background-clip: text / -webkit-background-clip: text headings, add a visual glyph-paint gate: DOM containment and scrollWidth can pass while the bottom of a gradient line is visibly shaved off. Prefer a small bottom paint allowance on the gradient span (for example padding-bottom: 0.08em) over globally loosening every heading’s line-height. Verify computed padding, overflow: visible, and screenshot appearance at the exact reported width plus mobile/desktop Chromium and WebKit widths; confirm the allowance does not introduce an uneven gap below the headline.
A background process exit code is not an engineering verdict. An agent can exit 0 after returning HOLD, exhausting turns, leaving a dirty candidate, or failing to commit. Before accepting an agent-produced commit:
PASS, HOLD, and native/runtime gaps.HEAD, porcelain status, staged/unstaged/untracked paths, locks, and every worktree.git cat-file commit <sha> plus explicit %H/%P/%T/%an/%ae/%cn/%ce formatting. Do not rely only on a wrapper-rendered identity line.git diff --check "$parent" "$sha". Do not build a revision expression with control characters or a visually ambiguous separator.For producer/consumer changes across repositories, acceptance also requires field-by-field reconciliation using the producer's minimal exact payload. See specification-compliance-review and ; green convenience fixtures do not prove interoperability.
Scan the committed tree for credentials, local paths, private artifacts, and whitespace issues. Run after the immutable gate so the tree is final.
Check for API keys, tokens, private keys in the tracked tree:
PAT='AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{30,}|sk-[A-Za-z0-9_-]{20,}|-----BEGIN (RSA |EC |OPENSSH )?PRIVATE KEY-----|xox[baprs]-[A-Za-z0-9-]{20,}'
test -z "$(git grep -IlE "$PAT" HEAD -- . || true)"Check for machine-specific paths, private IP addresses, employer email addresses, and internal assistant/agent/profile persona names:
test -z "$(git grep -IlE '<user-home>/[^/]|10\.0\.0\.[0-9]|@[a-zA-Z]+\.com' HEAD -- . || true)"
test -z "$(git grep -IlEi '<profile-name-1>|<profile-name-2>|<internal-worker-name>' HEAD -- . || true)"Build the profile/persona inventory from the user's actual private environment; generic terms such as router-test, test-profile, alpha, and beta are safe fixture names. Scan the whole candidate tree, current public default branch, every active PR head, and PR metadata—not only added lines. Profile names can be inherited from main or remain exposed on sibling draft branches even when the current diff is clean.
Keep legitimate public author attribution separate from profile-name privacy. A copyright holder or package author is not automatically an internal profile identifier. Also distinguish current-tree cleanup from history purge: removing a name in a new commit does not erase it from reachable Git history, and history rewriting requires separate explicit authorization.
Adjust patterns for the user's environment.
Check for tracked internal artifact directories:
test -z "$(git ls-tree -r --name-only HEAD .hermes .vscode __pycache__ .DS_Store 2>/dev/null || true)"Only lines added by this branch (not inherited from main). This avoids false positives from pre-existing public values:
git diff --check origin/main..HEAD
python3 -c '
import subprocess, re, sys
raw = subprocess.check_output(["git","diff","--unified=0","origin/main..HEAD"])
patterns = {
"credential": re.compile(rb"AKIA[0-9A-Z]{16}|gh[pousr]_[A-Za-z0-9_]{30,}|sk-[A-Za-z0-9_-]{20,}|-----BEGIN.*PRIVATE KEY-----"),
"local_path": re.compile(rb"<user-home>/[^/]|10\.0\.0\.[0-9]"),
}
hits = []
for line in raw.splitlines():
if line.startswith(b"+") and not line.startswith(b"+++"):
for kind, pat in patterns.items():
if pat.search(line):
hits.append((kind, line[:120].decode(errors="replace")))
if hits:
for kind, text in hits:
print(kind, text)
sys.exit(9)
'For a new public repository or a branch whose existing history will become reachable, scanning HEAD is insufficient. Inspect every reachable commit and ref—not only the current tree:
git rev-list --all and scan the blobs reachable from each revision;git log --all --format=...;git fsck --full;A clean current tree does not erase private data from prior commits. If reachable history is unsafe, publish from a new clean history rather than merely deleting the file in a later commit.
For significant branches (new feature, cross-repo work, security hardening), run a separate read-only agent as a second opinion:
hermes --profile <name> --yolo chat --provider <provider> --model <model> --max-turns <N> \
-q 'READ-ONLY final binary check of exact clean commit <SHA> in <path>. ...'Rules:
hermes --profile <target> ... or provide verified target-profile output as authoritative context.file:line for every HOLD. A bare line number or unexplained verdict is not actionable; retrieve the review transcript or rerun with a tighter prompt.For Electron/filesystem features, a passing bridge test does not prove product completeness: trace the production UI route through preload, privileged IPC, and the service, and treat an unreachable user-facing feature as blocking. Review canonical-path, symlink, and TOCTOU behavior across write, rollback, extraction, reveal, and deletion—not only the nominal import call.
For packaged Electron release manifests and scanners, follow the release checklist. It covers built-vs-packaged proof, macOS framework symlinks without dereferencing, regular-entry type checks before hashing, canonical manifest paths, global caps, binary allowlists, literal-backslash spoofing, and idempotent manifest regeneration.
For large branches, partition evidence by risk surface rather than asking one bounded reviewer to ingest the entire diff. Context exhaustion is an incomplete review, never approval. An evidence-backed BLOCKER/HIGH from specification or security review overrides a generic quality PASS until repaired, and every replacement SHA must be re-reviewed.
For multi-skill/tool collection repositories, see for layout, raw-install URL, companion-asset, CI-path, and first-release checks.
When local history diverged significantly from origin/main (dozens of commits of internal/campaign/prototype work), do not push the raw history. Expose a clean single commit.
git branch local/archive/<topic>-$(date +%Y%m%d)git reset --hard origin/main
git merge --squash local/archive/<topic>-$(date +%Y%m%d)Remove private artifacts, campaign docs, and generated files from staging:
git rm --cached -r .hermes docs/autoresearch-*.md .vscode 2>/dev/null || true
rm -f docs/autoresearch-*.mdReal three-way conflicts mean remote main accumulated changes during your local work. Resolve with care:
package-lock.json): regenerate via npm install and stage the resultgit rm --cached them rather than forcing incompatible tests into the publication commitnpm test
npx tsc --noEmit
npm run build
npm run validate
git diff --check origin/main..HEAD
test "$(git rev-list --count origin/main..HEAD)" = 1
test -z "$(git status --porcelain)"This reset-and-squash pattern is for publication only — it rewrites commit metadata. Do not use it on a branch others are collaborating on.
An ordinary shallow clone cannot always be pushed to a brand-new empty repository. Its boundary commit still names a parent object that the clone does not have, so GitHub may reject both normal and --no-thin pushes with remote unpack failed / did not receive expected object <sha>.
Do not unshallow a multi-gigabyte upstream repository merely to publish one private feature branch. Build a complete, self-contained two-commit graph instead:
git commit-tree using the shallow boundary commit's tree but no parent.git rev-list --count HEAD is 2, git fsck --full is clean, the feature's stable patch ID matches the reviewed commit, and the tree is clean.git push --no-thin, then compare local, git ls-remote, and GitHub API SHAs.Keep the original development checkout untouched. Use this only for a new empty publication repository where preserving all upstream ancestry is unnecessary; do not rewrite a shared branch or conceal contributor history.
git push -u origin <branch>
remote_sha=$(git ls-remote --heads origin "refs/heads/<branch>" | cut -f1)
test "$remote_sha" = "$(git rev-parse HEAD)"
printf 'PUSH_VERIFIED branch=%s sha=%s\n' "<branch>" "$remote_sha"Before retrying a failed exact-SHA run, distinguish a product failure from GitHub infrastructure and billing limits. Inspect every job's timestamps and step count: failures in seconds with steps: [] did not execute repository code. Check GitHub Status, gh api rate_limit, and—especially for private repositories—Billing → Usage → Actions. Exhausted hosted-runner minutes with no paid budget is separate from REST API limits. Do not launch repeated reruns while usage is exhausted or Actions/API service is degraded; wait for the cause to clear, then rerun the same SHA once.
For a new public repository, the push is only the transport step. Verify public visibility and the repository API SHA, fetch the public page and raw install URL, test a fresh HTTPS clone, and wait for the exact commit's CI run with gh run watch <run-id> --exit-status. Inspect annotations even when CI succeeds; if a supported dependency or GitHub Action is deprecated, update it and repeat every affected gate on the replacement commit.
For packaging or matrix workflows, top-level success is insufficient evidence: inspect every required job and critical step, then enumerate uploaded artifacts through the Actions API and record each artifact's name, size, and expiry state. Confirm both build and packaged-smoke steps passed on every promised platform.
When a matrix run fails, diagnose the exact current-SHA job log rather than the checks-table summary. Normalize policy-scan paths across Windows/POSIX, release database/file handles on constructor failure, avoid experimental built-in module mocks when real fixtures or injected seams suffice, synchronize timing tests on request-start signals, and explicitly provision locked desktop runtimes when their packages have no lifecycle installer.
If every independent job fails almost immediately with steps: [], verify the provider status before changing code. That pattern is CI infrastructure evidence, especially when Actions and API services are degraded. Rerun the same exact-SHA workflow after recovery and inspect attempt-specific jobs; any job with substantive executed steps is a real candidate failure until diagnosed. Prefer a bounded exact-SHA retry monitor that exits on substantive failure over no-op commits made only to retrigger CI.
Treat a public repository rename as a coordinated migration rather than a GitHub setting change:
gh repo rename <new-slug> --repo <owner>/<old-slug> --yes.origin to the new URL and update the GitHub description; do not rely on GitHub's redirect as the permanent configuration.git ls-remote, and GitHub API SHAs match.For mixed public collections, choose a broad class-level name that is distinct from any existing product or website. A label such as “Custom Pack” can cover skills, plugins, integrations, scripts, and utilities without implying they are all one formal tool type.
For static sites whose production host uses manual/direct upload rather than Git-connected builds, a verified Git push is not deployment evidence. Build a minimal archive from the exact committed public assets—excluding .git, local artifacts, and unrelated repository files—and include every runtime dependency introduced by the release, including client JavaScript, JSON/data files, and nested assets. Inspect the archive manifest while counting files separately from directory entries, upload it as a production deployment, and require the host UI to confirm the expected expanded file count before submission.
After host-side success, compare live bytes or hashes against the committed files and probe at least one new release sentinel—a newly added script, JSON endpoint, or distinctive marker—on both the custom and provider domains with cache-busting queries. A missing data path that returns the old index.html through SPA fallback is evidence that the new archive is absent, not a successful JSON response. Run a bounded propagation poll before declaring the deployment stale, but trust public readback over a dashboard that merely looks published. Then rerun the reported visual defect at the exact viewport plus the normal browser matrix.
When browser automation must populate a hidden file input, prefer CDP DOM.setFileInputFiles over the native chooser. If ordinary node IDs are invalid across stateless CDP calls, obtain the input's stable backendDOMNodeId from a full DOM or accessibility snapshot and address it by backend ID. Read back the archive name, expanded file list/count, and enabled deploy button before clicking. If the controllable dashboard reaches a login/Turnstile gate, test for an already-authorized CLI/API session without exposing tokens; otherwise stop at the human authentication gate rather than claiming publication or asking the user to perform the upload manually.
When publishing the same pattern across multiple repositories (e.g., porting a library component):
| Skill | Coverage |
|---|---|
github-pr-workflow | PR creation, CI monitoring, merging |
github-auth | GitHub token setup, SSH key config |
github-code-review | PR code review workflow |
scripts/ci-retry-monitor.py© AtlasOmnia, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in skills/github/github-pre-push-gates of AtlasOmnia/donna-starter.
Open the folder on GitHubat commit a3710bd
GitHub Pre Push Gates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub Pre Push Gates this skillAtlasOmnia/donna-starter | 125 | — | ~6.2k | Automated safety check: Pass | MIT | |
| Cherry Studio Regression TestsCherryHQ/cherry-studio | 52k | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | |
| lo2cin4bt Acceptance Reviewlo2cin4/lo2cin4bt | 288 | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| Dev ReviewFHIR/fhir-codegen | 154 | — | ~5k | Automated safety check: Pass | MIT | |
| Michel Packmind Engineer ReviewPackmindHub/packmind | 317 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| cmux Testing Rulesdisler/learning-cmux-with-agents | 115 | — | ~1.2k | Automated safety check: Pass | MIT |
CherryHQ/cherry-studio
Runs Cherry Studio's critical-path regression suite as deterministic Playwright E2E tests through a GitHub workflow on macOS and Windows runners.
lo2cin4/lo2cin4bt
Runs a pass, revise or block acceptance review on lo2cin4bt work, checking a deliverable against the request, repo contracts, tests, docs and the public GitHub boundary.
FHIR/fhir-codegen
Performs a two-track code-quality and QA review in the roles of a staff-level Engineering Lead and QA Lead, then synthesizes both critiques into a single analysis.md.
PackmindHub/packmind
Review an implemented GitHub issue the way a senior Packmind engineer would — the human-judgment checks that ESLint, the TypeScript compiler, and e2e tests cannot catch (authorization scoping…
disler/learning-cmux-with-agents
Testing rules for the cmux Swift codebase: Swift Testing as the default framework, a two-commit regression policy, and tests that check runtime behavior, not source text.
sickn33/agentic-awesome-skills
Orchestrate autonomous AI development pipelines through your Kanban board (Asana, GitHub Projects, Linear).
AtlasOmnia/donna-starter
macos-storage-management — Use when freeing Mac storage or moving files to SSDs.
AtlasOmnia/donna-starter
marketing-collateral-design — Use when designing, recreating, critiquing, or exporting static marketing collateral such as flyers, social graphics, postcards, brochures, business cards, print ads…
AtlasOmnia/donna-starter
hermes-self-evaluation — Use when the user asks to evaluate, audit, or optimize Hermes itself — analyzing session history, skill library, costs, and architecture to identify improvements, automation…
AtlasOmnia/donna-starter
skill-auditor — Use when auditing, reviewing, or grading Hermes skills for quality.
AtlasOmnia/donna-starter
local-discovery — Find local events, venues, and activities — ad-hoc web discovery when the user asks 'what's happening' or 'what should I do this weekend'.
AtlasOmnia/donna-starter
cross-browser-typography-qa — Diagnose and verify web typography rendering defects across Chromium, WebKit, and native Safari, including clipped glyphs, broken descenders, wrapping, font metrics…
Works with
Categories
github-pre-push-gates — Pre-push quality gates: immutable verification, privacy scanning, independent closeout review, and clean publication from divergent local history. GitHub Pre Push Gates is an agent skill from AtlasOmnia/donna-starter. github-pre-push-gates — Pre-push quality gates: immutable verification, privacy scanning, independent closeout review, and clean publication from divergent local history.
GitHub Pre Push Gates fits situations like: tasks that involve Quality gates.
Run `npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a claude-code`. Or copy the skill folder (skills/github/github-pre-push-gates in AtlasOmnia/donna-starter) into .claude/skills/github-pre-push-gates in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a codex`. Or copy the skill folder (skills/github/github-pre-push-gates in AtlasOmnia/donna-starter) into .agents/skills/github-pre-push-gates in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AtlasOmnia/donna-starter --skill github-pre-push-gates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-pre-push-gates, .gemini/skills/github-pre-push-gates, .github/skills/github-pre-push-gates and .opencode/skills/github-pre-push-gates in your project.
Going by SKILL.md and its folder, GitHub Pre Push Gates needs Python for the scripts in its folder and the command-line tools its instructions call (git, npm, gh, npx and python3). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use git, npm, gh and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
GitHub Pre Push Gates is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with GitHub Pre Push Gates: Cherry Studio Regression Tests (CherryHQ/cherry-studio, 52k stars), lo2cin4bt Acceptance Review (lo2cin4/lo2cin4bt, 288 stars), Dev Review (FHIR/fhir-codegen, 154 stars) and Michel Packmind Engineer Review (PackmindHub/packmind, 317 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AtlasOmnia (a GitHub user) maintains it in AtlasOmnia/donna-starter, which has 125 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on September 19, 2026.
Source: AtlasOmnia/donna-starter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.