Agent skill

CI Watch and Auto-Fix Loop

by modu-ai in modu-ai/moai-adk

Watches a pull request's CI checks after creation, separates required from auxiliary failures, applies limited safe fixes and escalates anything semantic to you.

Apache-2.0Auto-check: notesDevOps & Cloud

Install CI Watch and Auto-Fix Loop

skills CLI
$ npx skills add modu-ai/moai-adk --skill hns-workflow-ci-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install modu-ai/moai-adk hns-workflow-ci-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/modu-ai/moai-adk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/hns-workflow-ci-loop .claude/skills/hns-workflow-ci-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hns-workflow-ci-loop
GitHub stars
1.2k
Token cost
~2.4k tokens
SKILL.md length
932 words
Files
1
Skills in repo
48
Repo updated
First seen
Licence
Apache-2.0

At a glance

Watches a pull request's CI checks after creation, separates required from auxiliary failures, applies limited safe fixes and escalates anything semantic to you.

  • Works in 2 steps: Watch Loop → Auto-Fix Loop
  • Monitoring CI on a pull request that was just opened
  • SKILL.md covers Quick Reference, Implementation Guide, Works Well With and Common Rationalizations, plus 2 more sections
  • Calls gh, sh and git

What it does

After a PR is created through the MoAI sync workflow, the skill polls gh pr checks every 30 seconds, using .github/required-checks.yml to decide which checks are required and which are only auxiliary. Auxiliary failures never block readiness. It exits when required checks pass, when something fails, or after a 30-minute hard timeout, and the exit codes (0 pass, 1 fatal error, 2 required failure, 3 timeout) tell the orchestrator what to do next.

On a required failure it hands off JSON to an auto-fix phase that tries mechanical patches for at most three iterations, then asks you. Semantic failures such as races, deadlocks, panics and assertion failures are never patched automatically. Force-pushing is banned in every form, and files such as .env files, credentials, Claude settings, the required-checks file and the watch script are protected. A state file tracks the active watch, and moai pr watch --abort stops it.

When your agent uses it

  • Monitoring CI on a pull request that was just opened
  • Letting an agent retry safe, mechanical CI fixes with a fixed iteration cap
  • Distinguishing blocking required checks from optional ones
  • Aborting or taking over a stalled CI watch

Example prompts

  • “Watch CI on the PR I just opened and fix anything mechanical that fails.”
  • “Poll the required checks for this branch and tell me when it is ready to merge.”
  • “Stop the running CI watch with moai pr watch --abort.”

Requirements

  • GitHub CLI (gh) authenticated to the repository
  • A .github/required-checks.yml file listing the required checks
  • The MoAI workflow that creates the PR
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Watch Loop
  2. Auto-Fix Loop

What it can do on your machine

Read from SKILL.md and the folder at commit 2aab5f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • sh
    • git
    • bash
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

CI Watch and Auto-Fix Loop loads about 2.4k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 932 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:66
    - Protected files: `.env*`, credentials, `.claude/settings*.json`, `.github/required-checks.yml`,
  • NoteMentions a .env fileSKILL.md:140
    - `**/.env`, `**/.env.*`
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from modu-ai/moai-adk at commit 2aab5f7, republished under its Apache-2.0 licence (© modu-ai). 932 words, ~2,415 tokens.

Download SKILL.mdSave it as .claude/skills/hns-workflow-ci-loop/SKILL.md (or your agent's skills folder).
name
hns-workflow-ci-loop
description
Unified CI watch + auto-fix loop skill. Polls gh pr checks after /moai sync PR creation, classifies required vs auxiliary failures, attempts safe automated patches (max 3 iterations), and escalates semantic failures to the user. Use for CI loop workflow — NOT for general loop iteration patterns (see moai-workflow-loop).
allowed-tools
Bash, Read
compatibility
Designed for Claude Code
when_to_use
Use for the CI watch and auto-fix loop after /moai sync PR creation: polling gh pr checks, classifying required vs auxiliary failures, safe automated patch…
license
Apache-2.0
user-invocable
false
metadata.version
0.1.0
metadata.category
workflow
metadata.status
active
metadata.updated
2026-05-22
metadata.tags
ci, watch, autofix, polling, github-actions, required-checks, force-push-prohibited
progressive_disclosure.enabled
true
progressive_disclosure.level1_tokens
120

CI Loop (hns-workflow-ci-loop)

Unified CI watch + auto-fix loop. The orchestrator invokes this skill after /moai sync Phase 4 (gh pr create) returns a PR number. The skill polls required checks, classifies failures into mechanical vs semantic, attempts safe patches up to 3 iterations, and escalates semantic failures via AskUserQuestion.

Quick Reference

Trigger: /moai sync Phase 4 PR-create returns a PR number, or an existing PR needs CI monitoring.

Two phases, one skill:

  1. Watch — Poll gh pr checks every 30s, classify required vs auxiliary via .github/required-checks.yml SSoT; exit on green/fail/timeout.
  2. Auto-fix — On required-fail (exit 2), receive JSON handoff, run up to 3 patch iterations, escalate semantic failures immediately.

One-liner:

bash
MOAI_CIWATCH_GH=gh sh scripts/ci-watch/run.sh <PR_NUMBER> <BRANCH>

Exit codes:

  • 0 — all required passed → ready-to-merge AskUserQuestion
  • 1 — fatal error → surface remediation
  • 2 — required failure → JSON handoff → auto-fix phase
  • 3 — 30-min hard timeout → blocker message, return control

HARD invariants:

  • AskUserQuestion is orchestrator-only — CLI, shell scripts, and the manager-develop (cycle_type=autofix) subagent MUST NOT call it.
  • Force-push is absolutely prohibited (--force, -f, --force-with-lease all banned).
  • Max 3 auto-fix iterations; iteration 4+ triggers mandatory blocking AskUserQuestion.
  • Semantic failures (race, deadlock, panic, assertion) are never auto-patched.
  • Protected files: .env*, credentials, .claude/settings*.json, .github/required-checks.yml, scripts/ci-watch/run.sh.

Implementation Guide

Phase 1 — Watch Loop

Polling cadence: 30 seconds minimum (GitHub API rate-limit). Override via CIWATCH_POLL_INTERVAL env, never below 30 in production. Test mode uses MOAI_CIWATCH_NO_SLEEP=1 (single-tick exit).

30-minute hard timeout: CIWATCH_TIMEOUT_SECONDS=1800 default. On timeout, exit 3. Do not auto-restart.

Required vs auxiliary: Required checks live in .github/required-checks.yml branches.<pattern>.contexts. Auxiliary checks listed under auxiliary: MUST NOT block ready-to-merge. Hardcoding check names in scripts is prohibited.

State file: .moai/state/ci-watch-active.flag (YAML). Tracks pr_number, started_at, heartbeat_at, required_checks, abort_requested. Heartbeat staleness > 90s allows takeover. Abort: moai pr watch --abort.

Background watch standardization: For long-running PRs (5+ min), use gh pr checks <PR> --watch invoked via run_in_background: true. Sleep + poll loops are prohibited — they block the orchestrator's main session.

Status report format (stderr, state-change ticks only, no ANSI):

[ci-watch] PR #<N>: required 4/6 pass, 2 pending; advisory 0 fail

Handoff schema on exit 2 — JSON with stable fields: prNumber, branch, failedChecks[] (each entry {name, runId, logUrl}), auxiliaryFailCount, totalRequired. Field stability: name, runId, logUrl are stable contract — do not rename. Schema source: the CI-watch handoff struct.

Phase 2 — Auto-Fix Loop

Entry condition: ci-watch exit 2 + valid JSON handoff. State file: .moai/state/ci-autofix-<PR>.json (PR-scoped, 24-hour staleness threshold).

OQ2 cadence matrix (single source of truth for iteration behavior):

  • iter 1, any mechanical sub_class → confirm + apply via AskUserQuestion (1st option = "Apply patch (Recommended)").
  • iter 1, semantic/unknown → escalate (no patch attempt) via AskUserQuestion with diagnosis report.
  • iter 2-3, mechanical + sub_class=trivial → silent apply + log (no AskUserQuestion).
  • iter 2-3, mechanical + sub_class=non-trivial → confirm + apply via AskUserQuestion.
  • iter 2-3, semantic/unknown → escalate (no patch) via AskUserQuestion.
  • iter 4+ → mandatory blocking AskUserQuestion (no timer, options: manual fix / revise SPEC / abandon PR).

"trivial" = whitespace, gofmt/goimports, import-order (matches classify.sh RX_TRIVIAL_*).

Patch commit rule: Every patch = new commit. Format: fix(ci): auto-fix <classification> failure (iter <N>). After push, re-invoke scripts/ci-watch/run.sh to restart the watch loop.

Iteration 4+ escalation (mandatory blocking, no silent timeout):

  1. (Recommended) Manual fix — investigate and fix manually
  2. Revise SPEC — revise the SPEC and restart implementation
  3. Abandon PR — close the PR and abandon this approach

manager-develop (cycle_type=autofix) spawn prompt injects: handoff JSON, classification + sub_class, failed CI log + PR diff, mode directive (mechanical → propose unified-diff patch; semantic/unknown → return diagnosis only, no patch). HARD: no AskUserQuestion call from the subagent — return Markdown only.

Audit log: .moai/logs/ci-autofix/<PR-NNN>-<YYYY-MM-DD>.md. Append-only. Each iteration records classification, sub_class, action, patch_sha, escalation_reason.

Show full SKILL.md (384 more words)Show less
Protected Files (never auto-modified)
  • **/.env, **/.env.*
  • **/credentials*, **/*_key.json, **/*secret*
  • .claude/settings.json, .claude/settings.local.json
  • .github/required-checks.yml (Wave 1 SSoT, read-only for Wave 2/3)
  • scripts/ci-watch/run.sh (Wave 2 invariant)

If the manager-develop (cycle_type=autofix) subagent proposes a patch touching any of these, reject and escalate.

Go Helpers and Shell Scripts

Go helpers: the CI-watch classifier (required-vs-auxiliary), the handoff JSON-schema struct, the watch state file, and the PR-watch report emitters (EmitReadyToMergeReport, EmitFailureHandoff). Shell: scripts/ci-watch/run.sh (main loop, mock via MOAI_CIWATCH_GH); scripts/ci-watch/lib/classify.sh (yq + grep fallback); scripts/ci-autofix/log-fetch.sh (failure log + PR diff); scripts/ci-autofix/classify.sh (mechanical vs semantic).

gh CLI compat: requires gh >= 2.50 for the workflow JSON field. On older gh, classify.sh falls back to name-based heuristics from the required: list.

Works Well With

  • manager-develop (cycle_type=autofix) — failure diagnosis + patch proposal subagent

  • manager-git — commit/push of auto-fix patches

  • .claude/rules/local/ci-watch-protocol.md — HARD watch invocation contract (dev-only; governs scripts/ci-watch/)

  • .claude/rules/local/ci-autofix-protocol.md — HARD autofix invocation contract (dev-only; governs scripts/ci-autofix/)

    Both are the dev-repo twins, not the distributed rules of the same basename. The distributed .claude/rules/moai/workflow/ci-autofix-protocol.md is deliberately script-free and governs the manager-develop autofix cycle instead; it does not describe the scripts this skill runs. ci-watch-protocol.md is not distributed at all.

  • .github/required-checks.yml — Wave 1 SSoT

Common Rationalizations

  • "Skip watch loop for small PRs" — small PRs fail CI too. Loop costs nothing, saves manual polling.
  • "Auxiliary failures should block merge" — advisory by SSoT definition. Edit required-checks.yml to change classification.
  • "Try auto-patching even semantic failures" — semantic failures (race, assertion) cannot be auto-patched without context; wrong patch is worse.
  • "Clean up history with force-push" — force-push destroys reviewer diff visibility. Always a new commit.
  • "Time out after iter 3" — silent timeout prohibited; user must decide explicitly.
  • "Apply trivial fixes without confirming" — iter 1 always confirms; iter 2+ trivial may silent apply.

Red Flags

  • manager-develop (cycle_type=autofix) subagent calls AskUserQuestion (HARD: orchestrator-only)
  • Iteration 4 auto-continues without blocking AskUser
  • git push --force / -f / --force-with-lease anywhere in scripts
  • Semantic classification produces a patch attempt
  • State file missing → iteration counter lost → infinite loop risk
  • Watch polling interval < 30s (rate-limit risk)
  • required-checks.yml modified without moai github init re-run

Verification

  • bash scripts/ci-watch/test/run_test.sh passes all shell tests
  • go test ./internal/ciwatch/... ./internal/cli/pr/... -race passes
  • internal/ciwatch/ coverage >= 85%
  • No ANSI codes in FormatStatusUpdate() output
  • EmitReadyToMergeReport first option carries (Recommended)
  • CLI does NOT call AskUserQuestion
  • grep -r 'push -f\|push --force' scripts/ci-autofix/ scripts/ci-watch/ returns no matches
  • Audit log .moai/logs/ci-autofix/<PR>-<DATE>.md contains every iteration
<!-- absorbed from moai-workflow-ci-watch + moai-workflow-ci-autofix per the skill consolidation policy -->

© modu-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/hns-workflow-ci-loop of modu-ai/moai-adk.

Open the folder on GitHubat commit 2aab5f7

Compare with similar skills

CI Watch and Auto-Fix Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI Watch and Auto-Fix Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI Watch and Auto-Fix Loop this skillmodu-ai/moai-adk1.2k—~2.4kAutomated safety check: NotesApache-2.0
PR BabysitterEveryInc/compound-engineering-plugin25k—~2kAutomated safety check: PassMIT
CIaiblueprinthq/ai-blueprint463—~2.2kAutomated safety check: PassMIT
Gh Actionlive-codes/livecodes1.5k—~1.8kAutomated safety check: PassMIT
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Michel Monitor Pull Request GitHub ActionsPackmindHub/packmind317—~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    EveryInc/compound-engineering-plugin

    Watches an open GitHub pull request over time, routing review comments and CI failures to other skills until the PR is ready to merge.

    25k GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • CI

    aiblueprinthq/ai-blueprint

    Set up or normalize one project Verify command and matching GitHub Actions checks while preserving existing CI, with an optional local pre-push hook.

    463 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Gh Action

    live-codes/livecodes

    Use the "Preview in LiveCodes" GitHub Action to generate preview playground links for pull request code changes.

    1.5k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Diagnose a failed, stuck, or never-triggered CI run on a GitHub PR, apply a local fix if possible, push it, and document the result in a single running PR comment.

    317 GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI

    openJiuwen-ai/sciencediscovery

    Read, diagnose, and change the CI pipeline: GitHub Actions on pull requests, the nightly schedule and the release tag.

    156 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from modu-ai/moai-adk

All 48 skills in this repo
  • Builds hand-editable SVG diagrams from computed layout coordinates, lints the source and renders a 2x PNG, with rules for when mermaid is the better choice.

    1.2k GitHub stars~5.2k tokensUpdated today
    Auto-check: notes
  • MoAI Foundation Core

    modu-ai/moai-adk

    Reference for MoAI-ADK's core development principles: TRUST 5 quality gates, SPEC-first domain-driven workflow, agent delegation and token budgeting.

    1.2k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • MoAI SPEC Workflow

    modu-ai/moai-adk

    Manages SPEC documents for MoAI-ADK development, with GEARS or EARS requirement notation, acceptance criteria and a link into the Plan-Run-Sync workflow.

    1.2k GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • MoAI TDD Workflow

    modu-ai/moai-adk

    Drives test-first development through the RED, GREEN, REFACTOR cycle, with a config switch that selects between TDD and a DDD workflow for existing code.

    1.2k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • MoAI Worktree Management

    modu-ai/moai-adk

    Gives each SPEC its own Git worktree with a registry of active workspaces, base-branch sync and cleanup of merged ones, inside the MoAI-ADK workflow.

    1.2k GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Database guidance for PostgreSQL, MongoDB, Redis and Oracle plus Neon, Supabase and Firestore: schema design, indexing, query tuning and cloud database choice.

    1.2k GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Works with

Questions about CI Watch and Auto-Fix Loop

What does CI Watch and Auto-Fix Loop do?

Watches a pull request's CI checks after creation, separates required from auxiliary failures, applies limited safe fixes and escalates anything semantic to you. yml to decide which checks are required and which are only auxiliary. Auxiliary failures never block readiness.

When should I use CI Watch and Auto-Fix Loop?

CI Watch and Auto-Fix Loop fits situations like: monitoring CI on a pull request that was just opened; letting an agent retry safe, mechanical CI fixes with a fixed iteration cap; distinguishing blocking required checks from optional ones; aborting or taking over a stalled CI watch.

How do I install CI Watch and Auto-Fix Loop in Claude Code?

Run `npx skills add modu-ai/moai-adk --skill hns-workflow-ci-loop -a claude-code`. Or copy the skill folder (.claude/skills/hns-workflow-ci-loop in modu-ai/moai-adk) into .claude/skills/hns-workflow-ci-loop in your project. Claude Code loads it when a task matches its description.

How do I install CI Watch and Auto-Fix Loop in Codex?

Run `npx skills add modu-ai/moai-adk --skill hns-workflow-ci-loop -a codex`. Or copy the skill folder (.claude/skills/hns-workflow-ci-loop in modu-ai/moai-adk) into .agents/skills/hns-workflow-ci-loop in your project. Codex loads it when a task matches its description.

Can I use CI Watch and Auto-Fix Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add modu-ai/moai-adk --skill hns-workflow-ci-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hns-workflow-ci-loop, .gemini/skills/hns-workflow-ci-loop, .github/skills/hns-workflow-ci-loop and .opencode/skills/hns-workflow-ci-loop in your project.

What does CI Watch and Auto-Fix Loop need to run?

Going by SKILL.md and its folder, CI Watch and Auto-Fix Loop needs the command-line tools its instructions call (gh, sh, git, bash and go). Our summary lists: GitHub CLI (gh) authenticated to the repository; A .github/required-checks.yml file listing the required checks; The MoAI workflow that creates the PR. Its frontmatter pre-approves these tools: Bash, Read. Compatibility (from SKILL.md): Designed for Claude Code.

Does CI Watch and Auto-Fix Loop access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is CI Watch and Auto-Fix Loop safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does CI Watch and Auto-Fix Loop use?

CI Watch and Auto-Fix Loop is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI Watch and Auto-Fix Loop use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CI Watch and Auto-Fix Loop?

Skills that share tags, products or a category with CI Watch and Auto-Fix Loop: PR Babysitter (EveryInc/compound-engineering-plugin, 25k stars), CI (aiblueprinthq/ai-blueprint, 463 stars), Gh Action (live-codes/livecodes, 1.5k stars) and GitHub Actions Hardening (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI Watch and Auto-Fix Loop?

modu-ai (a GitHub organization) maintains it in modu-ai/moai-adk, which has 1,232 GitHub stars. The repository holds 48 skills in this directory. The repository was last updated on October 9, 2026.

Source: modu-ai/moai-adk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.