Safe Push
JetBrains/intellij-community
Push IntelliJ repository changes through the Safe Push workflow.
Preflight a Lego-RL config: answer "is it safe to launch this run right now?".
$ npx skills add LegoX/Lego-RL --skill check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LegoX/Lego-RL check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/check .claude/skills/check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "check" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/check into .claude/skills/check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LegoX/Lego-RL --skill check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LegoX/Lego-RL check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/check .agents/skills/check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "check" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/check into .agents/skills/check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LegoX/Lego-RL --skill check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LegoX/Lego-RL check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/check .cursor/skills/check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "check" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/check into .cursor/skills/check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LegoX/Lego-RL.git --path .claude/plugins/rl-plugin/skills/check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LegoX/Lego-RL --skill check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LegoX/Lego-RL check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/check .gemini/skills/check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "check" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/check into .gemini/skills/check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LegoX/Lego-RL checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LegoX/Lego-RL --skill check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/check .github/skills/check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "check" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/check into .github/skills/check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LegoX/Lego-RL --skill check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LegoX/Lego-RL check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegoX/Lego-RL.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/plugins/rl-plugin/skills/check .opencode/skills/check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "check" agent skill from https://github.com/LegoX/Lego-RL/tree/main/.claude/plugins/rl-plugin/skills/check into .opencode/skills/check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
checkPreflight a Lego-RL config: answer "is it safe to launch this run right now?".
Check is an agent skill from LegoX/Lego-RL. Preflight a Lego-RL config: answer "is it safe to launch this run right now?". Runs every deterministic check through the runner's own PREFLIGHTONLY path (config summary + scripts/lib/preflight.sh), adds the local live checks a config-only script cannot judge (is a run already in flight? is that GPU/port mine or someone else's?), and always ends with one structured report: a SAFE-TO-RUN verdict, a status table, the resolved run parameters, and numbered next steps. Read-only — never edits a config, never launches…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Lego-RL: Harness-Native Reinforcement Learning for Coding Agents. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7c30234. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Check loads about 2.9k tokens when it runs. Until then it costs about 182 tokens; SKILL.md has 1,178 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LegoX/Lego-RL at commit 7c30234, republished under its Apache-2.0 licence (© LegoX). 1,178 words, ~2,893 tokens.
.claude/skills/check/SKILL.md (or your agent's skills folder).Answers one question: is it safe to launch this config right now?
Deterministic checks come from the runner itself (never re-implemented here); this skill adds the local live layer and prints one report ending in a clear YES / NO. Read-only — it never edits a config and never launches.
/rl:check <config>
│
├─ 1. PREFLIGHT_ONLY=1 <kind>.sh <config> ... resolved parameters + OK/WARN/FATAL
│
├─ 2. lib/live_probe.sh <kind> .......... local facts; this skill judges ownership
│
└─ 3. report ............ verdict + status table + run parameters + next stepsEach check lives in exactly one layer:
| Layer | Run by | Covers |
|---|---|---|
| Deterministic | scripts/lib/preflight.sh via the runner | tool_parser × model × scaffold · topology · SP/device-mesh · VRAM · veomni constraints · R3 × model family (MoE/dense) × engine × verl · agent_name × scaffold · image source · kubeconfig · lr_scheduler · val timeout · rollout_is · path existence |
| Live (judgment) | this skill, from scripts/lib/live_probe.sh facts | is a run already in flight? · is that GPU/port mine, stale, or a foreign job's? · venv imports · disk / shm headroom |
Everything is local host only — no SSH to 221/222/240/243, no cluster
mutation. Cluster-side faults (registry down, kyverno crash-looping, a node
missing its insecure-registry config) are out of scope here; they surface as
env_setup_failed once a run is live, which is /rl:status's job.
Repo root is the Lego-RL checkout (contains scripts/lib/preflight.sh).
If the user ran this from elsewhere, locate it; if there is none, abort — but
still print the Step 3 report with a NO verdict whose reason is the abort.
Resolve the config. The argument may be a full path, a bare filename, or absent:
qwen35a3b_4n_mix1582, smoke_sync_cc_qwen35a3b_243.env) → search
scripts/{train,eval,infer}/configs/ then .../templates/;ls scripts/*/configs/*.env) and ask which one. Do not guess.Infer the kind from the resolved path: scripts/train/… → train,
scripts/eval/… → eval, scripts/infer/… → infer. If the path is
ambiguous, read the config: TRAIN_MODE/N_NODES_ROLLOUT → train,
DATASET_PATH/DATASET_NAME → eval, RESULTS_DIR/OUTPUT_INDEX → infer.
Read scripts/README.md for context if you need the axis vocabulary. Do not
echo config or README content into the report.
PREFLIGHT_ONLY=1 bash scripts/train/train.sh <config> 2>&1; echo "EXIT=$?"This one command sources the config and its templates, resolves every derived
value, prints the run configuration block, then runs preflight.sh and exits
without launching. Read its output as-is — never re-run a probe separately and
never overrule an OK.
Only the train runner has PREFLIGHT_ONLY. For an eval or infer config, use
bash scripts/<kind>/<kind>.sh --dry-run <config>: it resolves and prints
everything the same way but does not run preflight.sh, so for those two kinds
the deterministic layer is thinner — say so in the report rather than implying
the config passed rules that never ran.
| Marker | Status | Blocks launch? |
|---|---|---|
✓ OK | pass | — |
⚠ WARN | warning | no |
✗ FATAL | fail | yes |
Two things need follow-up:
run configuration (<kind>) block → copy verbatim into the report; on an
SAO / critic run it carries extra gae:, bypass: and critic lines — quote
them too, they are what rule 10 (SAO / critic) of preflight.sh judged;EXIT with no ✗ FATAL line → the runner died before preflight
(bad config syntax, missing PROJECT_NAME/EXP_TAG, unreadable venv). Treat
as a blocking failure and quote the error.preflight.sh failing is never something to work around. Every ✗ FATAL has
an entry in the Troubleshooting section of the docs site; point the user at it.
bash scripts/lib/live_probe.sh <kind> 2>&1The probe prints facts only (OK / WARN / INFO); deciding whether a
process is ours is this skill's job. Four outcomes block a launch —
job:running, gpu:foreign, port:conflict, import:missing. Everything
else is advisory.
A second run on the same GPUs OOMs or corrupts both.
| Probe lines | Name | Status |
|---|---|---|
any WARN job:trainer or WARN job:runner | job:running | ✗ blocks |
only WARN job:vllm / job:harbor (no trainer/runner) | job:orphan | ⚠ — a leftover server or someone else's serving job; classify in 2b/2c |
OK job:none | job:none | ✓ |
On job:running, record the PID set — call it the run tree; it anchors the
ownership tests below. Report pid + etime, and tell the user to let it finish or
stop it themselves (kill -INT <pid>). Never kill anything.
Input: each WARN gpu:busy pid=<pid> comm=<comm> mem=<mem> line.
| Owner | Name | Status |
|---|---|---|
| in the run tree from 2a | gpu:mine | ⚠ |
| any other pid | gpu:foreign | ✗ blocks |
OK gpu:idle | gpu:idle | ✓ |
Ownership test: walk the parent chain (ps -o ppid= -p <pid>, repeated) and see
whether it reaches a PID in the run tree. A VLLM::Worker_TP* / EngineCore
holding ~130GB with no runner above it is someone else's serving job — block,
report pid + memory + etime, and let the user decide whether to wait or ask its
owner. This box is shared; a foreign vLLM squatting on all 8 GPUs is the
common case, not an anomaly.
If nvidia-smi is absent (INFO gpu:absent), emit gpu:unknown (⚠) and say
the GPU layer could not be judged — do not silently pass it.
Input: each WARN port:<P> line. Only ports this config will bind can
block; the rest are informational.
| kind | ports that matter |
|---|---|
| train | 6379 (ray), 8265 (ray dashboard) |
| eval | the port= in the summary's serving line (default 8000) |
| infer | VLLM_PORT / VLLM_MASTER_PORT / VLLM_DP_RPC_PORT from the summary |
| Owner | Name | Status |
|---|---|---|
| in the run tree | port:mine | ⚠ |
| anything else, on a port this run needs | port:conflict | ✗ blocks |
| busy but irrelevant to this kind (e.g. 8090 webui) | port:other | ✓ note only |
For port:conflict, name the pid and suggest either stopping it or moving this
run's port in the config — never suggest killing a process you cannot attribute.
| Probe line | Name | Status |
|---|---|---|
WARN import:veomni on a train run | import:missing | ✗ blocks — the runner exits on this |
WARN import:<mod> otherwise | import:degraded | ⚠ |
WARN venv | venv:fallback | ⚠ — runner will use a non-.venv python |
WARN shm | shm:dirty | ⚠ — train.sh clears it at bring-up; only worrying if a live run owns it |
WARN disk:<mnt> | disk:low | ⚠ — quote the mount; a full root disk evicts pods and truncates logs |
The report is the deliverable. Print it every time, including on an abort
(then: heading + NO verdict with the abort reason, nothing else). Prose in
Chinese — the field labels and probe names stay as written here.
## harbor check — <kind> · <config basename>
**SAFE TO RUN: <✅ YES | ❌ NO>** — <R> blocking · <W> warnings
| Layer | Check | Status | Detail |
|-------|-------|:------:|--------|
| det | preflight (tool_parser · topology · device-mesh · VRAM · veomni · R3 · agent · image · paths) | <✓/✗> | ok=<N> warn=<N> fatal=<N> |
| det | <one row per ✗ FATAL or ⚠ WARN> | <✗/⚠> | <verbatim text> |
| live | job | <✓/⚠/✗> | <job:none / job:running pid=<P> etime=<T> / job:orphan> |
| live | gpu | <✓/⚠/✗> | <gpu:idle / gpu:mine / gpu:foreign pid=<P> mem=<M>> |
| live | ports | <✓/⚠/✗> | <port:free / port:mine / port:conflict:<P>> |
| live | env | <✓/⚠/✗> | <imports ok / import:missing:<mod> / venv:fallback> |
| live | disk | <✓/⚠> | <shm=<pct> root=<pct> / disk:low:<mnt>> |
**Key parameters for this run**
```
<paste the whole "run configuration (<kind>)" block from PREFLIGHT_ONLY, verbatim>
```
**Log destination / dashboard visibility**
```
train log <TRAIN_LOG, taken from the runner's "train log:" line — never assembled by hand>
dashboard <pid=<P> port=<P> serving <log-dir> → visible / not visible / no instance running>
```
Not a pass/fail check, but it belongs in the report because it is invisible
otherwise: `scripts/templates/verl/common.env` puts `TRAIN_LOG` under
`${HARBOR_LOG_DIR}`, and a real config overrides that to a per-experiment
directory under the shared trials root — **not** `<repo>/logs`. The webui globs
its `--log-dir` one level with no recursion (`webui/server.py`), so such a run
trains normally and never appears on the board. Read the served dirs from
`pgrep -af 'server\.py.*--log-dir'` and say which way it falls. `/rl:run` turns
this line into a question before launching; `/rl:check` only has to report it.
**Next steps**
1. <one line per blocker, blockers before warnings; quote kubectl/curl/git errors verbatim>
2. ...
Re-run `/rl:check <config>` once they are fixed.The four invariants:
✅ YES iff R == 0, where R = ✗ FATAL count + any
job:running + any gpu:foreign + any port:conflict + any
import:missing. Warnings never change the verdict.✓ pass · ✗ blocks · ⚠ advisory · · skipped.✗ or ⚠.Add one italic line under the table when it applies:
NNODES > 1 → (multi-node: this check covers the head node only —
run /rl:check once on every worker node too)VLLM_NNODES > 1 → same, keyed on node_rank.lib/site.env, or anything under src/ to make a check passDRY_RUN that starts vLLM or raypreflight.sh check — add only the live layerkill a process, ray stop, clear /dev/shm, or delete a log — surface it,
let the user decide© LegoX, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/plugins/rl-plugin/skills/check of LegoX/Lego-RL.
Open the folder on GitHubat commit 7c30234
Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Check this skillLegoX/Lego-RL | 108 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Safe PushJetBrains/intellij-community | 21k | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Safe RefactorJuliusBrussee/caveman | 110k | 1 repos | ~177 | Automated safety check: Pass | Apache-2.0 | |
| Logseq Answer Machinelogseq/logseq | 45k | — | ~1.2k | Automated safety check: Warn | AGPL-3.0 | |
| Running CI PreflightPostHog/posthog | 40k | — | ~1.5k | Automated safety check: Pass | Custom licence | |
| Azure Deployment Preflightgithub/awesome-copilot | 40k | 1 repos | ~1.9k | Automated safety check: Pass | MIT |
JetBrains/intellij-community
Push IntelliJ repository changes through the Safe Push workflow.
JuliusBrussee/caveman
Restructure code while preserving behavior. Use for extraction, consolidation, ownership moves, or cleanup where verification must bracket structural edits.
logseq/logseq
Answer user questions about the Logseq repository by researching source code, docs, tests, runtime behavior, and local tools.
PostHog/posthog
Catch the deterministic CI failures reachable from your diff before pushing, with hogli ci:preflight.
github/awesome-copilot
Performs comprehensive preflight validation of Bicep deployments to Azure, including template syntax validation, what-if analysis, and permission checks.
openwpm/OpenWPM
Use BEFORE implementing code in a crosslink-tracked project — loads .crosslink/rules/global.md, the language rules for detected manifests, the project rules, and the active tracking-<mode.md.
LegoX/Lego-RL
Compose, edit, refactor, and validate Lego-RL train/eval/infer .env configs and reusable scripts/templates modules.
LegoX/Lego-RL
Bring up the Lego-RL training dashboard (webui/) on whatever machine you are on, adapting to that box's layout instead of assuming this repo's paths.
LegoX/Lego-RL
Preflight and launch a Lego-RL run (train, eval or infer). An agent skill from LegoX/Lego-RL.
LegoX/Lego-RL
Diagnose a Lego-RL run that is already in flight (or just finished): which run is alive, how far it has got, and whether its numbers are healthy.
LegoX/Lego-RL
Guided install / scale-out of a sandbox Kubernetes cluster for the Lego-RL k8s backend (kubeadm 1.32 + containerd + flannel + ImageVolume, optionally nydus / a shared registry / an isolated dockerd).
LegoX/Lego-RL
One-to-one Codex counterpart for Claude /rl:check. An agent skill from LegoX/Lego-RL.
Preflight a Lego-RL config: answer "is it safe to launch this run right now?". Check is an agent skill from LegoX/Lego-RL.".
Check fits situations like: check this config; preflight this run; can I launch this run; pre-launch check.
Run `npx skills add LegoX/Lego-RL --skill check -a claude-code`. Or copy the skill folder (.claude/plugins/rl-plugin/skills/check in LegoX/Lego-RL) into .claude/skills/check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LegoX/Lego-RL --skill check -a codex`. Or copy the skill folder (.claude/plugins/rl-plugin/skills/check in LegoX/Lego-RL) into .agents/skills/check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LegoX/Lego-RL --skill check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/check, .gemini/skills/check, .github/skills/check and .opencode/skills/check in your project.
Going by SKILL.md and its folder, Check needs the command-line tools its instructions call (bash). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Check is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Check: Safe Push (JetBrains/intellij-community, 21k stars), Safe Refactor (JuliusBrussee/caveman, 110k stars), Logseq Answer Machine (logseq/logseq, 45k stars) and Running CI Preflight (PostHog/posthog, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LegoX (a GitHub organization) maintains it in LegoX/Lego-RL, which has 108 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.
Source: LegoX/Lego-RL on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.