Analyze GitHub Action Logs
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
在目标仓库 harness.yaml 的 settings.gates 里声明与定制任务完成门:local-command 本地命令见证、manual-attest 人工签字、github-actions CI 见证、none 显式免除,治理字段 mandatorySignoff(双控签注)与 allowOverride(owner 特批),以及…
$ npx skills add FairladyZ625/harness-anything --skill gate-customization -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install FairladyZ625/harness-anything gate-customization --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/FairladyZ625/harness-anything.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gate-customization .claude/skills/gate-customization && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gate-customization" agent skill from https://github.com/FairladyZ625/harness-anything/tree/main/skills/gate-customization into .claude/skills/gate-customization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gate-customization", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/FairladyZ625/harness-anything/tree/main/skills/gate-customizationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add FairladyZ625/harness-anything --skill gate-customization -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install FairladyZ625/harness-anything gate-customization --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FairladyZ625/harness-anything.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/gate-customization .agents/skills/gate-customization && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gate-customization" agent skill from https://github.com/FairladyZ625/harness-anything/tree/main/skills/gate-customization into .agents/skills/gate-customization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gate-customization", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FairladyZ625/harness-anything --skill gate-customization -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install FairladyZ625/harness-anything gate-customization --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FairladyZ625/harness-anything.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/gate-customization .cursor/skills/gate-customization && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gate-customization" agent skill from https://github.com/FairladyZ625/harness-anything/tree/main/skills/gate-customization into .cursor/skills/gate-customization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gate-customization", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/FairladyZ625/harness-anything.git --path skills/gate-customization--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add FairladyZ625/harness-anything --skill gate-customization -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install FairladyZ625/harness-anything gate-customization --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FairladyZ625/harness-anything.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/gate-customization .gemini/skills/gate-customization && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gate-customization" agent skill from https://github.com/FairladyZ625/harness-anything/tree/main/skills/gate-customization into .gemini/skills/gate-customization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gate-customization", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install FairladyZ625/harness-anything gate-customizationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add FairladyZ625/harness-anything --skill gate-customization -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/FairladyZ625/harness-anything.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/gate-customization .github/skills/gate-customization && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gate-customization" agent skill from https://github.com/FairladyZ625/harness-anything/tree/main/skills/gate-customization into .github/skills/gate-customization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gate-customization", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FairladyZ625/harness-anything --skill gate-customization -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install FairladyZ625/harness-anything gate-customization --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FairladyZ625/harness-anything.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/gate-customization .opencode/skills/gate-customization && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gate-customization" agent skill from https://github.com/FairladyZ625/harness-anything/tree/main/skills/gate-customization into .opencode/skills/gate-customization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gate-customization", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gate-customization在目标仓库 harness.yaml 的 settings.gates 里声明与定制任务完成门:local-command 本地命令见证、manual-attest 人工签字、github-actions CI 见证、none 显式免除,治理字段 mandatorySignoff(双控签注)与 allowOverride(owner 特批),以及…
Gate Customization is an agent skill from FairladyZ625/harness-anything. 在目标仓库 harness.yaml 的 settings.gates 里声明与定制任务完成门:local-command 本地命令见证、manual-attest 人工签字、github-actions CI 见证、none 显式免除,治理字段 mandatorySignoff(双控签注)与 allowOverride(owner 特批),以及 appliesTo(submission/code/artifacts)适用范围与 merged-to 合并门。Use when 为新接入或既有仓库配置完成门、把内置 ci 门改用本地见证、配置人工签注或 break-glass 特批、或排查 gatemappinginvalid、witnessunavailable、invalidproof、signoffmissing、gate missing 类收口阻塞。
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `examples/harness-docs-only.yaml`, `examples/harness-go.yaml` and `examples/harness-governance.yaml`).
It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: Clean-room Harness rewrite monorepo. The licence is AGPL-3.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1426d98. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmshpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gate Customization loads about 3.4k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 1,057 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from FairladyZ625/harness-anything at commit 1426d98, republished under its AGPL-3.0 licence (© FairladyZ625). 1,057 words, ~3,430 tokens.
.claude/skills/gate-customization/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.本技能教你在目标仓库的 harness.yaml 里声明任务完成门:挂本地测试、设人工签字卡点、配双控与特批、免除内置门。所有字段与行为以当前源码为准——契约在 packages/kernel/src/domain/completion-contract.ts,YAML 读写与校验在 packages/kernel/src/domain/settings.ts,逐门判定在 packages/kernel/src/domain/closeout-readiness.ts(judgeGateWitnesses),适配器执行与人工见证准入在 packages/daemon/src/repo-cell-witness-adapters.ts。改配置前先读这几个文件里你要用的部分,不凭记忆写。
完成门是三层拼起来的,缺一层都不工作:
| 层 | 谁声明 | 在哪里 |
|---|---|---|
| 任务声明 gate id | 任务所用 preset 的 profile completionGates | preset 包(内置见 packages/preset/assets/software-coding/presets/*/preset.json) |
| 仓库映射 witness | settings.gates.<gateId> → 适配器 | 本仓 harness.yaml |
| 提交时冻结 | submit 把解析结果连同 adapterOptions 冻进 completionContract | 随提交 cut 走,改 YAML 不影响在审 cut |
判定规则(fail-closed):
settings.gates 没有它的映射 → submit 报 gate_mapping_invalid,不是静默跳过。none → 该需求被移除,不铸造虚假 pass。内置 preset 只声明两个 gate id:ci 与 code-doc-reconciliation。要用自定义 id(如 lint、signoff、merged-to.main),任务侧必须有一个声明了它的 preset:按 preset-creator 打包(profile 的 completionGates 写入自定义 id),ha preset install --source <包目录> 安装,ha task create --preset <id> 使用。只改 settings.gates 不换 preset,自定义 gate 不会被任何任务要求。
两个编译期剔除规则(在任务创建时就生效,先于任何映射):
settings.ci.workflows 为空数组(或缺整个 ci: 段)→ preset 解析把 ci 从任务的 completionGateIds 里剔除(packages/preset/src/preset-runtime.ts profile.completionGateIds 处)。无 GitHub CI 的仓想让测试在本地见证,用自定义 gate id 配 preset,不要指望 ci 映射。workKind: docs 的任务 → ci 与 code-doc-reconciliation 都被剔除(packages/preset/src/preset-bootstrap.ts withoutCodeDeliveryGates)。写在 harness.yaml 的 settings: 下。缩进敏感:gates: 两空格、gate id 四空格、字段六空格;字段行顺序任意;值后可跟注释。
settings:
ci:
workflows: [rewrite-ci] # github-actions 适配器共用的 workflow 注册表
gates:
ci: # 块形式:下面六空格字段
adapter: github-actions
appliesTo: code
branch: main
event: push
coverage: descendant
selection: newest
lint: # 自定义 id(需 preset 声明)
appliesTo: code
adapter: local-command
command: npm ci && npm run lint
signoff:
appliesTo: submission
adapter: manual-attest
code-doc-reconciliation: none # none 只能内联,后面不许再跟字段解析规则(settings.ts readGateSettings/gateSettingsSchema/gateWitnessMappingIssues):
^[A-Za-z0-9][A-Za-z0-9/_.@-]*$:不含空格和冒号。合并门写 merged-to.main,不写 merged-to:main。none;ci: github-actions 这种行内写法直接报 settings.gates cannot read line。must declare exactly:| adapter | 必填字段(恰好这些) | 可选治理字段 |
|---|---|---|
github-actions | appliesTo branch event coverage selection | mandatorySignoff allowOverride |
local-command | appliesTo command | mandatorySignoff allowOverride |
manual-attest | appliesTo | 无(见下) |
none | 无(只能内联) | 无 |
mandatorySignoff / allowOverride 是治理修饰字段,不计入上面的精确集:只许写在 github-actions 与 local-command 上,写在 manual-attest 或 none 上会报 cannot declare mandatorySignoff or allowOverride(人工见证的门不再需要这两个修饰)。值必须是 YAML 布尔 true/false,其他写法(如 yes)被 schema 拒;只有 true 会进入冻结契约,写 false 等价于不写。
github-actions 的 workflow 清单不写在 gate 映射里,统一来自 settings.ci.workflows(内联数组 [a, b],名字不带 .yml);映射了 github-actions 而 workflows 为空 → 解析报错。
branch/event 值受 ^[A-Za-z0-9][A-Za-z0-9/_.@-]*$ 限制;coverage 只认 exact(run 的 head SHA 必须就是提交 SHA)或 descendant(run 的 head SHA 以提交 SHA 为祖先);selection 只认 newest。
同一 gate 内字段重复、六空格字段出现在 gate 行之前、未知行 → cannot read line。
# 在任何行内都起注释作用并被剥离——命令值里不能出现 #(command: echo a#b 会变成 echo a)。
code-doc-reconciliation 是 Harness 内部检查器,只能映射 none,映射任何适配器都报错。
gates 是 repository-owned 设置;ha settings update 的输入字段不含 gates,手工编辑 harness.yaml 是正式通道,重写其他设置不会动 gates 段。改完用 ha settings show 回读校验。
枚举就三个(completion-contract.ts gateAppliesTo),按提交 cut 的形状生效:
| 值 | 何时适用 | 典型用途 |
|---|---|---|
submission | 每个提交 cut 都适用 | 人工签字、交付物本身的检查 |
code | cut 带交付 commit(commitSha 非空) | 测试、lint、构建、CI、合并门 |
artifacts | cut 带至少一个已接受 artifact 锚 | 产物签字、报告审阅 |
判定语义:不适用的 gate 在该 cut 上记 not_applicable,不阻塞也不需要证据。混合交付(commit + artifact)同时承载两类 gate。
实践规则:
local-command 需要 commit cut(它要把提交物化成沙箱);artifact-only 交付上它会报 witness_unavailable。纯文档/产物型交付用 manual-attest。appliesTo: code,文档任务不会被卡死;交付级卡点(如 owner 签字)用 submission。把一条 shell 命令当作 gate 的见证人。执行语义(repo-cell-witness-adapters.ts collectLocalCommand):
task-submit 与 task-complete 的写队列之前自动采集;每次都重新采集,直到该 gate 已有绑定当前 cut 的 accepted pass 见证(或已被 owner 特批为 waived——waived 门不再重采)。上次的 fail 不会被冻结成终局——修好后重跑 task complete 会采到新的 pass。git archive 解到全新临时目录再运行命令。命令看到的是提交时的内容,不是工作树;目录里没有 .git。临时目录用后即删,两次运行之间不保留任何状态(依赖装了什么都不会留下)。sh -c "<command> 2>&1",stdout 与 stderr 合并。PATH 加下面三个,父进程其余环境(HOME、node/npm 配置等)一概不传:| 变量 | 值 |
|---|---|
HARNESS_WITNESS_CUT | 被见证的提交 SHA |
HARNESS_WITNESS_GATE | gate id |
HARNESS_WITNESS_REPO | 源仓库根(含 .git),供仓库级观察(如合并祖先检查)使用 |
0 = pass;非零 = fail(complete 时以 invalid_proof 阻塞完成;门声明了 allowOverride 时 fail 先作为正式回执落库,blocker 改给特批命令);启动失败、被信号杀死或超过 10 分钟 = witness_unavailable(证据不可得,不是 pass 也不是 fail,任务停在 gate 未满足上)。commitSha + submissionDigest;提交被 amend 或契约变化后,旧观测作废、需要重采。witness_unavailable。exit N; output sha256:…; tail "…"(输出摘要 + 最后约 500 字符),不存全量输出。写命令的守则:
npm ci && npm test、python3 -m venv .venv && …。export GOCACHE="$PWD/.gocache",否则报 GOCACHE is not defined and $HOME is not defined;Rust 建议显式 export CARGO_HOME="$PWD/.cargo-home"(有依赖时注册表也走它)。git -C "$HARNESS_WITNESS_REPO",不要指望工作目录里有 .git。合并门示例(决策 dec_59FA45A407F850E2B167A192D7 的 merged-to 形态,用自定义 gate id 配 preset 声明后生效):
gates:
merged-to.main:
appliesTo: code
adapter: local-command
command: git -C "$HARNESS_WITNESS_REPO" merge-base --is-ancestor "$HARNESS_WITNESS_CUT" refs/heads/main行为:提交时 main 还没包含该 cut → 采到 fail(不阻塞 submit,verdict 在 complete 时判);合并进 main 后重跑 task complete → pass。
适配器本身不采集任何观测:见证由人通过 CLI 写入。
ha task attest <task-id> --gate <gate-id> --result pass --note "审阅意见"--result 只认 pass 或 fail;--note 可选,会进证据的 rawResult;--mode 缺省为 approve。manual-attest(给声明为 github-actions 且无 mandatorySignoff 的门 attesting 会以 invalid_command 拒绝——人工 pass 不能顶替声明的见证来源);appliesTo 与该 cut 匹配(code 门不能在 artifact-only cut 上签字)。source: human,绑定当时的执行身份。带 executor 的 runtime 会话永远不能以人工身份签注(actor_unauthorized)——签注只认人类 principal。它不替代 Review/Consent 流程,只是 gate 见证。适合:无自动化环境的签字卡点、artifact-only 交付的人工审阅、上线前 owner 批准。
在 github-actions 或 local-command 门上加 mandatorySignoff: true:
gates:
ci:
adapter: github-actions
appliesTo: code
branch: main
event: push
coverage: descendant
selection: newest
mandatorySignoff: true行为(judgeGateWitnesses):自动见证 pass 后门状态是 signoff_missing 而不是 passed——complete 的 blocker 直接给出签注命令:
ha task attest <task-id> --gate ci --result passtask attest 入口,--mode 缺省 approve;它要求本 cut 已有被接受的自动 pass,否则拒 invalid_transition(先跑 ha task complete 让见证落库)。approve 不能带 --rationale(那是 override 的字段,invalid_field),可用 --note。manual-attest 与 none 门不能声明此字段。在 github-actions 或 local-command 门上加 allowOverride: true,给任务 owner 留一条「记录的失败可以豁免」的紧急通道:
gates:
e2e:
adapter: local-command
appliesTo: code
command: npm run e2e
allowOverride: true特批命令(complete 的 blocker 与采集失败时的拒绝信息都会给出它):
ha task attest <task-id> --gate e2e --result pass --mode override --rationale "<为什么豁免,trim 后至少 10 字符>"准入与语义(attestGateWitness / judgeGateWitnesses,逐条与源码核对):
allowOverride——提交后才补到 YAML 不影响在审 cut(invalid_command)。createdBy 对应的 principal)能特批,其他人 actor_unauthorized;runtime executor 不能特批。waivedReceiptId: <receipt id>);本 cut 没有任何自动回执(runner 不可达、采集超时等,从未产生见证)→ waivedReceiptId 显式记 null,表示「豁免缺席的自动见证」。本 cut 已有自动 pass 或其他见证时 override 拒收 invalid_transition——真实通过不需要特批。failed,需对新回执重新特批;新 pass → passed(若门同时是 mandatorySignoff 则回 signoff_missing,需独立 approve)。已 waived 的门不再重新采集(local-command 不重跑、CI 不重拉),但已记录观测照常重判、新回执照常落库。waived(满足态,不显示为 passed),不再需要单独签注。commitSha + submissionDigest:cut 被 amend 或契约变化后需重新取证。allowOverride 门的自动 fail 会先作为正式回执落库(给 owner 留下可豁免的 receipt),再由 complete 的 blocker 给出特批命令;采集本身失败(gh 不可达、命令超时)时拒绝信息同样附 override 提示。GUI 对应入口:daemon 注册了 task.attest GUI action(repo.task.attest / bridge 方法 taskAttest / POST /api/tasks/:taskId/attest),payload 为闭形状 { taskId, gateId, result, mode?, note?, rationale? }——override 的理由必须放 rationale(放 note 会因缺 rationale 被拒);renderer 按钮的显隐规则(仅 failed/missing 且冻结契约 allowOverride 的门出现特批,waived 展示为特批放行而非通过)由 GUI 侧实现。
gates:
ci: none
code-doc-reconciliation: nonenone 把任务声明的该 gate 需求移除:不运行任何东西、不铸造 pass、完成判定里不再出现。它是显式声明——「没写映射」和「写了 none」是两回事:前者对已声明的 gate 是配置错误,后者是仓库的裁决。code-doc-reconciliation 只能用 none 移除。
常见组合:内部工具仓不想被代码-文档对账卡住 → code-doc-reconciliation: none;无 GitHub CI 的仓 → ci.workflows: [](preset 侧会直接不给任务声明 ci,无需再写 none)。
ci 是唯一内置声明且默认走 GitHub Actions 的 gate。映射写法见上文语法节;要点:
settings.ci.workflows,映射里没有 workflows 字段。coverage: descendant 接受以提交 SHA 为祖先的后续 run(提合并 PR 后 CI 在 merge commit 上跑的场景);exact 要求 run 就挂在提交 SHA 上。selection: newest 是当前唯一选取策略(最高 run/attempt 优先)。ci → github-actions + rewrite-ci,可作对照。examples/ 下是完整可解析的 harness.yaml(均通过 readSettingsFacet 校验;命令配方在最小环境 PATH-only 下实测):
| 文件 | 场景 |
|---|---|
examples/harness-node.yaml | Node 仓:GitHub CI 见证 ci + 本地命令见证 lint + 合并门 |
examples/harness-python.yaml | Python 仓:无 GitHub CI,测试全本地命令见证 |
examples/harness-go.yaml | Go 仓:本地 vet+test(显式 GOCACHE) |
examples/harness-rust.yaml | Rust 仓:本地 cargo test --locked(显式 CARGO_HOME) |
examples/harness-manual-only.yaml | 无自动化环境:免除内置门 + 人工签字卡点 |
examples/harness-docs-only.yaml | 纯文档仓:artifact 交付 + 人工审阅签字 |
examples/harness-governance.yaml | 治理字段:CI 双控签注(mandatorySignoff)+ e2e 特批(allowOverride) |
除 Node 示例的 ci 外,示例中的自定义 gate id 都需要配套 preset 声明才会被任务要求(见「模型」节)。
| 症状 | 含义 | 处置 |
|---|---|---|
Task declares completion gate X, but harness.yaml settings.gates maps no witness for it | 任务声明了 gate、仓库没映射 | 补映射或写 X: none |
settings.gates.X with adapter Y must declare exactly: … | 字段集不精确 | 按字段表补齐/删多余字段 |
settings.gates cannot read line: … | 缩进错、行内值非 none、字段重复 | 对照语法节修 YAML |
Gate X is witnessed by github-actions, but settings.ci.workflows is empty | workflows 注册表为空 | 填 settings.ci.workflows 或换适配器 |
witness_unavailable(local-command) | 提交不可达 / artifact-only cut / 命令超时或启动失败 | 确认 commit 在 daemon 可读的仓库里;artifact 交付改 manual-attest;检查命令是否卡死;allowOverride 门下可按提示特批 |
Gate X receipt … reported fail(invalid_proof,complete 时) | 命令非零退出或见证观测为 fail(门未声明 allowOverride) | 修到退出码 0(或合并/attest 后)重跑 task complete |
gate 状态 signoff_missing | 自动见证已 pass,mandatorySignoff 门缺人工签注 | ha task attest <task> --gate <g> --result pass |
gate 状态 waived | owner 已特批(满足态,不是 passed) | 无需动作;注意新自动回执会使其失效 |
invalid_command(attest) | 门不在冻结契约 / 门未声明 allowOverride / 自动化门未声明 mandatorySignoff 却来 approve | 核对冻结契约(ha task show);改治理字段需重新 submit 才生效 |
invalid_transition(attest) | 无已提交 execution / appliesTo 不匹配 / approve 时无自动 pass / override 时已有自动见证 | 先 submit/complete 让见证落库;真实通过不需要特批 |
actor_unauthorized(attest) | 带 executor 的会话签注 / 非 owner 尝试 override | 由人类 principal 执行;override 必须是任务创建者 |
invalid_field(attest) | override 缺 --result pass 或 rationale 不足 10 字符 / approve 误带 --rationale | 按命令形态修正 |
任务停在 incomplete、blocker 是 gate | 该 gate 没有绑定当前 cut 的 pass 见证 | 跑 ha task show 看 gate 状态;按适配器补证据 |
| 映射了自定义 gate 却从不生效 | 没有任务声明它 | 给 preset 的 completionGates 加该 id |
harness.yaml 只影响之后的 submit;在审 cut 按冻结契约判定。cut 被 amend 后 commitSha + submissionDigest 变化,旧观测(含人工签注与特批)作废重取。manual-attest 纯人工、mandatorySignoff 自动+签注双控、allowOverride 自动失败可特批。两个治理字段可同挂一门(双控+特批);被特批的门记 waived 满足态。© FairladyZ625, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files in skills/gate-customization of FairladyZ625/harness-anything.
Open the folder on GitHubat commit 1426d98
Gate Customization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gate Customization this skillFairladyZ625/harness-anything | 225 | — | ~3.4k | Automated safety check: Pass | AGPL-3.0 | |
| Analyze GitHub Action Logswithastro/astro | 63k | 1 repos | ~1.3k | Automated safety check: Pass | Custom licence | |
| GitHub Actions Templatesbartstc/vite-ts-react-template | 122 | 14 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Nushellccusage/ccusage | 19k | — | ~938 | Automated safety check: Pass | Custom licence | |
| Repo Hygiene Scan and FixQwenLM/qwen-code | 28k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence |
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
bartstc/vite-ts-react-template
Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.
ccusage/ccusage
Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.
QwenLM/qwen-code
Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Chachamaru127/claude-code-harness
Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.
FairladyZ625/harness-anything
Contribute a public change to Harness Anything from a GitHub issue through an isolated worktree, scoped tests, manifest-selected gates, a complete bilingual PR body, review triage, and maintainer…
FairladyZ625/harness-anything
Create, review, or update Harness Anything preset-manifest/v3 packages, including profiles, completion gates, template selections, output shapes, script entrypoints, capability declarations, package…
FairladyZ625/harness-anything
Start Harness Anything task creation by choosing a software/coding preset first.
FairladyZ625/harness-anything
产出与增量维护任务包中的活解释页 artifacts/explainer.html;按物化模板中的唯一权威注释编写,并消费派工注入的 <task-context 因果上下文。Use when a task-bound dispatch requires creating, updating, or freezing the task's living explainer page, or…
FairladyZ625/harness-anything
Create, review, or update Harness Anything verticals. An agent skill from FairladyZ625/harness-anything.
FairladyZ625/harness-anything
Run and interpret a read-only retrospective over Harness ledger projections, then prepare evidence-backed mechanism fixes, deletion candidates, or time-bounded rule proposals for human adjudication.
Works with
Categories
在目标仓库 harness.yaml 的 settings.gates 里声明与定制任务完成门:local-command 本地命令见证、manual-attest 人工签字、github-actions CI 见证、none 显式免除,治理字段 mandatorySignoff(双控签注)与 allowOverride(owner 特批),以及…. Gate Customization is an agent skill from FairladyZ625/harness-anything.
Gate Customization fits situations like: tasks that involve CI/CD.
Run `npx skills add FairladyZ625/harness-anything --skill gate-customization -a claude-code`. Or copy the skill folder (skills/gate-customization in FairladyZ625/harness-anything) into .claude/skills/gate-customization in your project. Claude Code loads it when a task matches its description.
Run `npx skills add FairladyZ625/harness-anything --skill gate-customization -a codex`. Or copy the skill folder (skills/gate-customization in FairladyZ625/harness-anything) into .agents/skills/gate-customization in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FairladyZ625/harness-anything --skill gate-customization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gate-customization, .gemini/skills/gate-customization, .github/skills/gate-customization and .opencode/skills/gate-customization in your project.
Going by SKILL.md and its folder, Gate Customization needs the command-line tools its instructions call (git, npm, sh and python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gate Customization is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gate Customization: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
FairladyZ625 (a GitHub user) maintains it in FairladyZ625/harness-anything, which has 225 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.
Source: FairladyZ625/harness-anything on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.