ONNX Opset Bump Checklist
microsoft/onnxruntime
A checklist for upgrading the pinned ONNX version and opset in ONNX Runtime, covering the files to change, archive hashes, patch rebasing and release-candidate handling.
The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…
$ npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-automation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cb-automation .claude/skills/cb-automation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cb-automation" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-automation into .claude/skills/cb-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-automation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-automationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-automation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/cb-automation .agents/skills/cb-automation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cb-automation" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-automation into .agents/skills/cb-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-automation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-automation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/cb-automation .cursor/skills/cb-automation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cb-automation" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-automation into .cursor/skills/cb-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-automation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/BlkLeg/CircuitBreaker.git --path .claude/skills/cb-automation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-automation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/cb-automation .gemini/skills/cb-automation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cb-automation" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-automation into .gemini/skills/cb-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-automation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install BlkLeg/CircuitBreaker cb-automationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/cb-automation .github/skills/cb-automation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cb-automation" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-automation into .github/skills/cb-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-automation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install BlkLeg/CircuitBreaker cb-automation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/cb-automation .opencode/skills/cb-automation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cb-automation" agent skill from https://github.com/BlkLeg/CircuitBreaker/tree/main/.claude/skills/cb-automation into .opencode/skills/cb-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cb-automation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cb-automationThe maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…
Cb Automation is an agent skill from BlkLeg/CircuitBreaker. The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks dispatcher, the post-release follow-up), the GITHUBTOKEN rules they are built around, how to add a new one safely, and the guardrails for AI agents (Copilot cloud agent, Agentic Workflows, Copilot CLI on the headless box). Use this whenever adding or changing a scheduled or bot workflow, anything under scripts/ci/, a…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. It works with Discord and GitHub. The repository describes itself as: Bring your homelab to life. A self-hosted IPAM and service mapper that visualizes complex hardware, compute, and network relationships in real-time. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit fc44f2e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makeghbashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENCOPILOT_GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cb Automation loads about 2.4k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 1,167 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from BlkLeg/CircuitBreaker at commit fc44f2e, republished under its MIT licence (© BlkLeg). 1,167 words, ~2,406 tokens.
.claude/skills/cb-automation/SKILL.md (or your agent's skills folder).One maintainer, no budget: automation exists to remove toil, and must never become toil itself (a noisy alert, a red check nobody owns, a bot that needs babysitting). Everything that needs a human reaches them through Discord.
| Workflow | When | Does | Talks to Discord |
|---|---|---|---|
notify.yml | Every watched workflow completes | scripts/ci/workflow_alert.py decides; posts failures (with ping) and recoveries | Yes — it is the pager |
release.yml | make release-candidate | See cb-release | "draft staged, waiting for you" (ping), "vX is published" |
release-followup.yml | Dispatched by release post-publish | Next-patch PR into dev, stale draft cleanup | Via notify.yml on failure |
ledger-watch.yml | Nightly 06:23 UTC | scripts/ci/ledger_watch.py: one release-control issue listing ledger rows expiring within 30 days and risks past next_review; closes it when clear | When a new issue opens (ping) |
branch-cleanup.yml | Sundays 05:00 UTC; manual dispatch defaults to dry run | scripts/ci/branch_cleanup.py: deletes branches fully contained in main/dev, idle > 14 days, not the head or base of an open PR | Via notify.yml on failure |
dependabot-lockfile-sync.yml | Dependabot pip PR into dev/main | Regenerates requirements.txt from poetry.lock with the base branch's generator, pushes, then dispatches required checks | Via notify.yml on failure |
dependabot-automerge.yml | Dependabot PR opened/updated | Queues gh pr merge --auto for patch/minor updates into dev (the ruleset's 21 checks still decide); labels majors major-update and comments; never touches PRs into main | — |
security.yml, codeql.yml | Weekly + push/PR + dispatch | Scanners | Via notify.yml on failure |
e2e.yml | RC tag, agent-path PR, nightly | Calls composed-e2e.yml, quarantined (quarantined: true, QUAR-001, issue #162) — reports the register row instead of running | Via notify.yml on failure |
Squash-merged branches are never cleaned up (their commits are not contained in main), by design of the containment rule.
push,
pull_request, release, or push: tags run follows a bot's commit, PR,
release or tag. The one exception is workflow_dispatch (and
repository_dispatch). So:bash scripts/ci/dispatch_required_checks.sh <branch> [dev|main], which
dispatches dev-ci.yml/ci.yml, security.yml and codeql.yml so all
21 required checks land on the head SHA. Without it the PR can never
merge. The list of 21 lives only in tests/build/required_checks.py.contents: write even if it only reads.workflow_run and schedule only fire from the default branch's copy
of the workflow file. A new watcher or cron does nothing until it reaches
main. Scheduled workflows carry # scheduled-ref: default-branch-intentional
or pin a ref (test_scheduled_workflows_pin_their_ref).pull_request_target hands out a writable token. Never check out and
execute the PR head in it: restore scripts from the base SHA (see
dependabot-lockfile-sync.yml) and guard on the actor.scripts/ci/notify_discord.py (--level info|success|warning|failure --title … [--body|--body-file] [--url] [--field k=v] [--mention]). Never curl the webhook.DISCORD_WEBHOOK_URL (required for anything to send) and
DISCORD_MENTION_USER_ID (the numeric user id — Developer Mode, right-click
your name, Copy User ID — never the username; used only with --mention,
and a bad value costs only the ping, not the message). Both must be
repository secrets: environment secrets are invisible to every job
without that environment:. Pass them
through step env:, never interpolated into run: — a test enforces it.allowed_mentions is always explicit: text can never ping @everyone,
whatever a branch or commit is named. Only --mention pings, and only the
configured user.name: to
notify.yml's workflows: list. test_every_watched_name_is_a_workflow_that_exists
fails if a listed name stops matching.scripts/ci/ with
unit tests in tests/build/ (fixtures, no network). Nothing to register:
make lint and scripts/ci/tier0-static.sh both glob
scripts/*.py scripts/ci/*.py, so a new script is linted and
type-checked the moment it lands. The enumeration these replaced had
quietly lost 14 files, and only make lint — never CI — ran it.actions/setup-python step, the script
must run on Python 3.10 — ubuntu-22.04's system python3. The dev
venv's 3.12 hides the difference, which is how datetime.UTC reached
quarantine_notice.py.
tests/build/test_ci_scripts_match_runner_python.py fails the build on a
newer stdlib name (an ast scan plus vermin), and ruff.toml pins the
lint target to py310 so ruff cannot ask for a 3.11+ alias back. Either
stay portable, or add actions/setup-python.permissions: {} or read-only; grant per job, minimum needed.${{ }} through env: and quoted; actions pinned by tag like the
rest of the repo (actions/checkout@v5), persist-credentials: false
unless the job pushes.# checkov:skip=CKV_GHA_7 with a reason; run
checkov -f <file> --framework github_actions locally.dispatch_required_checks.sh.notify.yml); successes usually don't.continue-on-error to make it green, never auto-merge to main.Issue and PR text on this public repo is untrusted input. An agent that reads it must not also hold write access.
gh agent-task create): for
bounded code changes that come back as a PR for review. Good first tasks:
QUAR-001 (#162), major Dependabot migrations, a shared sanitiser for the
py/log-injection alerts. It reads CLAUDE.md and these skills
(.claude/skills/ is a supported skills path), so the verification rules
apply to it too.gh aw, Copilot engine): for judgement over
untrusted text — issue triage, CI failure analysis, release-note drafts,
security digests. Keep them read-only; writes go through safe outputs.--allow-tool lists, never --allow-all/--yolo; always
--deny-tool 'shell(git push)', --secret-env-vars, --max-ai-credits,
--no-ask-user. Auth via a fine-grained PAT with Copilot Requests in
COPILOT_GITHUB_TOKEN (classic PATs are not supported). Report through
notify_discord.py.main without a PR, the 21 required
checks and a human merge. No agent approves or promotes a release.Runs only what hosted runners cannot: the release soak (install the draft
tarball, boot, probe /readyz, uninstall), a nightly make e2e-local
against main, the Tier 3 QEMU fleet runner (fleet.yml,
[self-hosted, qemu], needs KVM) and Copilot CLI report jobs.
Self-hosted runners on a public repo will run fork code unless
restricted: register the box in a runner group limited to named workflows
(fleet.yml and the soak/nightly ones), make jobs ephemeral (fresh container
or VM per job), and never attach it to a pull_request trigger. Installer
journeys there use rootless podman with --security-opt label=disable.
© BlkLeg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/cb-automation of BlkLeg/CircuitBreaker.
Open the folder on GitHubat commit fc44f2e
Cb Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cb Automation this skillBlkLeg/CircuitBreaker | 201 | — | ~2.4k | Automated safety check: Pass | MIT | |
| ONNX Opset Bump Checklistmicrosoft/onnxruntime | 22k | — | ~12k | Automated safety check: Pass | MIT | |
| Merge Dependabot PRsonyx-dot-app/onyx | 32k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Update .NET OS Packagesdotnet/core | 22k | — | ~2.3k | Automated safety check: Pass | MIT | |
| OBS Plugin Dependency Upgradesorayuki/obs-multi-rtmp | 5.1k | — | ~609 | Automated safety check: Pass | GPL-2.0 | |
| Renovate Actions PR Reviewbacknotprop/plannotator | 9.2k | — | ~640 | Automated safety check: Pass | Apache-2.0 |
microsoft/onnxruntime
A checklist for upgrading the pinned ONNX version and opset in ONNX Runtime, covering the files to change, archive hashes, patch rebasing and release-candidate handling.
onyx-dot-app/onyx
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…
dotnet/core
Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.
sorayuki/obs-multi-rtmp
Updates the obs-multi-rtmp plugin repo to the latest upstream plugin template and OBS Studio version, including dependency metadata, then rebuilds it with CMake.
backnotprop/plannotator
Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
BlkLeg/CircuitBreaker
How Circuit Breaker is built, tested, packaged, and kept secret-safe — the make dev/verify/test targets, the PostgreSQL integration test database and its fixtures, the mono Docker image and native…
BlkLeg/CircuitBreaker
Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.
BlkLeg/CircuitBreaker
How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…
BlkLeg/CircuitBreaker
How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…
BlkLeg/CircuitBreaker
Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.
Categories
The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…. Cb Automation is an agent skill from BlkLeg/CircuitBreaker. The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks dispatcher, the post-release follow-up), the GITHUBTOKEN rules they are built around, how to add a new one safely, and the guardrails for AI agents (Copilot cloud agent, Agentic Workflows, Copilot CLI on the headless box).
Cb Automation fits situations like: tasks that involve Dependency management.
Run `npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a claude-code`. Or copy the skill folder (.claude/skills/cb-automation in BlkLeg/CircuitBreaker) into .claude/skills/cb-automation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a codex`. Or copy the skill folder (.claude/skills/cb-automation in BlkLeg/CircuitBreaker) into .agents/skills/cb-automation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BlkLeg/CircuitBreaker --skill cb-automation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cb-automation, .gemini/skills/cb-automation, .github/skills/cb-automation and .opencode/skills/cb-automation in your project.
Going by SKILL.md and its folder, Cb Automation needs the command-line tools its instructions call (make, gh and bash) and credentials named GITHUB_TOKEN and COPILOT_GITHUB_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN; A credential in COPILOT_GITHUB_TOKEN.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cb Automation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cb Automation: ONNX Opset Bump Checklist (microsoft/onnxruntime, 22k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars), Update .NET OS Packages (dotnet/core, 22k stars) and OBS Plugin Dependency Upgrade (sorayuki/obs-multi-rtmp, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
BlkLeg (a GitHub user) maintains it in BlkLeg/CircuitBreaker, which has 201 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.
Source: BlkLeg/CircuitBreaker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.