{"_id":"@an-lee/owf","_rev":"3-5047d7ee2f487cd559928ac550668d10","name":"@an-lee/owf","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@an-lee/owf","version":"0.1.0","keywords":["open-workflow","agentic","github-actions","cli","ai","workflows"],"author":{"name":"open-workflow contributors"},"license":"MIT","_id":"@an-lee/owf@0.1.0","maintainers":[{"name":"an-lee","email":"an.lee.work@gmail.com"}],"homepage":"https://github.com/open-workflow/open-workflow","bugs":{"url":"https://github.com/open-workflow/open-workflow/issues"},"bin":{"owf":"bin/owf.js"},"dist":{"shasum":"d691a0817a1378bdfbf493e1a1b6b765aac3de72","tarball":"https://registry.npmjs.org/@an-lee/owf/-/owf-0.1.0.tgz","fileCount":66,"integrity":"sha512-mCp3SAAapqs3RgqcKmyEsuolc94iQWsybJUxc0vz9Im1kjNfe8DX9EfNGQjqQYOW8gQVjeRcQS1NsD2TMbbTVw==","signatures":[{"sig":"MEUCICs+eqDhRT5sjlEojvr7fMUSY2SQAm+CZw2jIeRhIwxvAiEA5dVMyWJtoKHbTZk3XufjUFpvptUFCbYhLxFauf/o3pg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108135},"type":"module","engines":{"node":">=20.19.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"7a81ecef07f01165f2acd5487bd4da184312fcd8","scripts":{"dev":"tsc --watch","lint":"eslint src/","test":"vitest run","build":"node build.js","dev:cli":"npm run build && node bin/owf.js","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"an-lee","email":"an.lee.work@gmail.com"},"repository":{"url":"git+https://github.com/open-workflow/open-workflow.git","type":"git"},"_npmVersion":"11.11.1","description":"Lightweight agentic workflow framework for GitHub Actions — skills, recipes, and two composite actions","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.0.0","chalk":"^5.0.0","commander":"^14.0.0","fast-glob":"^3.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.0.0","vitest":"^3.0.0","typescript":"^5.0.0","@types/node":"^24.0.0","typescript-eslint":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/owf_0.1.0_1779107470972_0.14164046353557724","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@an-lee/owf","version":"0.2.0","keywords":["open-workflow","agentic","github-actions","cli","ai","workflows"],"author":{"name":"open-workflow contributors"},"license":"MIT","_id":"@an-lee/owf@0.2.0","maintainers":[{"name":"an-lee","email":"an.lee.work@gmail.com"}],"homepage":"https://github.com/an-lee/open-workflow","bugs":{"url":"https://github.com/an-lee/open-workflow/issues"},"bin":{"owf":"bin/owf.js"},"dist":{"shasum":"f183f710894834d5998d673bcc4dc9bff39db4b8","tarball":"https://registry.npmjs.org/@an-lee/owf/-/owf-0.2.0.tgz","fileCount":152,"integrity":"sha512-nOX65gaqPDWU+evu3EZNhUkFx+Tufm/qLzBCxDDrWjyTkCe5JyjFLG3qe0qmBcU7LFMkXT0kL+OU79eoV3bxIA==","signatures":[{"sig":"MEUCIQCq5IxJ8mvewlf3tu/AqXChQqGshLwfdEAQ+oIBxSLgxQIgagRCL3LTHKT2+BnuH/BNYkA0cR5P8MvrhUHk0Qsxnnc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":329569},"type":"module","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"7c1df947b77d244462aca703d2a9937fb3b40cff","scripts":{"dev":"tsc --watch","lint":"eslint src/","test":"vitest run","build":"node build.js","dev:cli":"npm run build && node bin/owf.js","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"an-lee","email":"an.lee.work@gmail.com"},"repository":{"url":"git+https://github.com/an-lee/open-workflow.git","type":"git"},"_npmVersion":"11.11.1","description":"Lightweight agentic workflow framework for GitHub Actions — skills, recipes, and gate-by-role","directories":{},"_nodeVersion":"24.12.0","dependencies":{"yaml":"^2.0.0","chalk":"^5.0.0","commander":"^14.0.0","fast-glob":"^3.3.0","@inquirer/core":"^10.3.2","@inquirer/prompts":"^7.10.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.0.0","vitest":"^3.0.0","typescript":"^5.0.0","@types/node":"^24.0.0","typescript-eslint":"^8.0.0","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/owf_0.2.0_1779256338833_0.16679242892825963","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@an-lee/owf","version":"0.2.1","description":"Lightweight agentic workflow framework for GitHub Actions — skills, recipes, and gate-by-role","keywords":["open-workflow","agentic","github-actions","cli","ai","workflows"],"homepage":"https://github.com/an-lee/open-workflow","repository":{"type":"git","url":"git+https://github.com/an-lee/open-workflow.git"},"license":"MIT","author":{"name":"open-workflow contributors"},"type":"module","publishConfig":{"access":"public"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"bin":{"owf":"bin/owf.js"},"scripts":{"lint":"eslint src/","build":"node build.js","dev":"tsc --watch","dev:cli":"npm run build && node bin/owf.js","test":"vitest run","test:watch":"vitest","test:coverage":"vitest --coverage","prepare":"npm run build","prepublishOnly":"npm run build"},"engines":{"node":">=22.0.0"},"devDependencies":{"@types/node":"^24.0.0","@vitest/coverage-v8":"^3.2.4","eslint":"^9.0.0","typescript":"^5.0.0","typescript-eslint":"^8.0.0","vitest":"^3.0.0"},"dependencies":{"@inquirer/core":"^10.3.2","@inquirer/prompts":"^7.10.1","chalk":"^5.0.0","commander":"^14.0.0","fast-glob":"^3.3.0","yaml":"^2.0.0"},"gitHead":"71f600e0fae2404b8eab6d6f45180b0a6179b43f","_id":"@an-lee/owf@0.2.1","bugs":{"url":"https://github.com/an-lee/open-workflow/issues"},"_nodeVersion":"24.12.0","_npmVersion":"11.11.1","dist":{"integrity":"sha512-LU7OtRnhjqpeI6c1qBsK++FUG9NaXG/fLR4U0No2clcqYUB6sMN3QpiJMLnNNxJJB0TP6gJ5unhGcIYX3Ytp6Q==","shasum":"206a5ab5263510990d00d74cc7d248957daee99e","tarball":"https://registry.npmjs.org/@an-lee/owf/-/owf-0.2.1.tgz","fileCount":152,"unpackedSize":332596,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICPsSTyRGfc+51nstbDE4Tm5RYfqv1+jRLKYWf3EABVyAiEA1iN+npCNlK9n70RIuFGN4EZm1FaOA3UYd6eggq1isBs="}]},"_npmUser":{"name":"an-lee","email":"an.lee.work@gmail.com"},"directories":{},"maintainers":[{"name":"an-lee","email":"an.lee.work@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/owf_0.2.1_1779260344989_0.8476733989409388"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-18T12:31:10.838Z","modified":"2026-05-20T06:59:05.223Z","0.1.0":"2026-05-18T12:31:11.132Z","0.2.0":"2026-05-20T05:52:18.984Z","0.2.1":"2026-05-20T06:59:05.130Z"},"bugs":{"url":"https://github.com/an-lee/open-workflow/issues"},"author":{"name":"open-workflow contributors"},"license":"MIT","homepage":"https://github.com/an-lee/open-workflow","keywords":["open-workflow","agentic","github-actions","cli","ai","workflows"],"repository":{"type":"git","url":"git+https://github.com/an-lee/open-workflow.git"},"description":"Lightweight agentic workflow framework for GitHub Actions — skills, recipes, and gate-by-role","maintainers":[{"name":"an-lee","email":"an.lee.work@gmail.com"}],"readme":"# open-workflow\n\n[![CI](https://github.com/an-lee/open-workflow/actions/workflows/ci.yml/badge.svg)](https://github.com/an-lee/open-workflow/actions/workflows/ci.yml)\n[![npm](https://img.shields.io/npm/v/@an-lee/owf.svg)](https://www.npmjs.com/package/@an-lee/owf)\n[![GitHub release](https://img.shields.io/github/v/release/an-lee/open-workflow?sort=semver)](https://github.com/an-lee/open-workflow/releases)\n\nA lightweight agentic workflow framework for GitHub Actions.\n\nThe agent does real engineering work — edits files, runs tests, fixes the build — on a branch. It opens a PR. You merge when you're happy. That's the entire safety model.\n\n```text\nYou:   /agent fix the failing integration test\nAI:    [runs on GitHub Actions]\n       [checks out repo, runs agent CLI, pushes to branch agent/42-issue-fix]\n       [opens PR #43: \"[agent] Fix failing integration test\"]\nYou:   [reviews diff, merges]\n```\n\nNo compiler. No lock files. No proprietary frontmatter. Just plain GitHub Actions YAML that you can read, edit, and own.\n\n**v0.1.1** — [Releases](https://github.com/an-lee/open-workflow/releases) · [Feedback thread](https://github.com/an-lee/open-workflow/issues/2)\n\n---\n\n## Get started in three commands\n\n**1. Install the CLI**\n\n```bash\nnpm install -g @an-lee/owf\n```\n\n**2. Initialise your repo** — installs skills and slash commands into your AI tool(s)\n\n```bash\ncd your-repo\nowf init                    # interactive tool picker\n# owf init --tools cursor   # CI / non-interactive\n```\n\n**3. Bootstrap a maintenance suite** — scan the repo and install fitted workflows\n\n```bash\n/owf:bootstrap\n```\n\nThat's it. Your repo now has agentic workflows that work 24/7.\n\n---\n\n## What it ships\n\n### One composite action (the security primitive we ship)\n\n| Action                                                         | What it does                                                                                      |\n| -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- |\n| `an-lee/open-workflow/actions/gate-by-role@v0.1.0`            | Gates workflow execution by GitHub author role and bot identity. The one security primitive.      |\n\n**Write path (v0.2):** the agent runs `git` and `gh` on the runner with `GITHUB_TOKEN` / `GH_TOKEN`. Recipes pass `env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` on the agent step. Branch protection on the default branch and token scope limits are the platform safety boundary.\n\nAgent jobs also use a per-repo **`setup-agent-runtime`** file (written by `/owf:bootstrap` under `.github/actions/setup-agent-runtime/`) to run `npm ci` — it is not a published composite from this repo.\n\n### Agent runbook (framework-side agent guidance)\n\nWorkflow agents receive a short reference in each assembled `TASK` pointing at `.<engine>/skills/agent-runbook/SKILL.md` (installed by `owf init` / `owf update` from the canonical `skills/agent-runbook/SKILL.md`). The runbook covers environment setup, duplicate-PR preflight, branch/PR conventions, `gh` write patterns, self-verification, and communication style — so prompts stay focused on the recipe while conventions stay in one place.\n\n### Five slash commands (the coaching layer)\n\n| Command          | What it does                                                   |\n| ---------------- | -------------------------------------------------------------- |\n| `/owf:bootstrap` | Scan repo, install a fitted starter suite of agentic workflows |\n| `/owf:new`       | Design a fresh agentic workflow from a description             |\n| `/owf:audit`     | Review existing workflows against open-workflow conventions    |\n| `/owf:improve`   | Refactor an existing workflow                                  |\n| `/owf:explore`   | Think about what work to automate (read-only)                  |\n\n### ~15 recipes (the catalog)\n\nReady-to-install workflow files covering:\n\n- **Daily work** — `/agent <task>`, `/fix` on a failing PR, `/ask` for repo Q&A, `/nit` for style nitpicks, AI code review\n- **Scheduled maintenance** — CI doctor, Dependabot bundler, test improver, docs updater, sub-issue closer\n- **Quality & insight** — code simplifier, perf improver, daily repo status, duplicate-code detector\n- **Triage** — issue labeler + triage comment\n\nSee [`recipes/`](./recipes/) or run `owf list` for the full catalog. To refactor a workflow file locally, use `/owf:improve` (not a CI recipe — `GITHUB_TOKEN` cannot push `.github/workflows/*`).\n\n---\n\n## How it works\n\n### The safety story\n\n```\nAgent runs on GitHub Actions runner\n          │\n          ▼\nReads repo context (AGENTS.md, open PRs, recent commits)\n          │\n          ▼\nDoes work (edits files, runs tests, etc.)\n          │\n          ▼\nAgent runs git + gh (GH_TOKEN on agent step)\n  → commits to branch agent/<run-id>-<slug>\n  → opens or updates PR via gh pr create\n  → NEVER touches main\n          │\n          ▼\nHuman reviews and merges\n```\n\nBranch protection on `main` is your backstop. `GITHUB_TOKEN` (the only credential any recipe uses) cannot push to `.github/workflows/*`. The worst-case outcome of a misbehaving agent is a weird PR you don't merge.\n\n### Conversation continuation\n\n```\nIssue #100: \"Add a dark-mode toggle\"\n  └─ /agent let's build this\n       → creates branch agent/42-issue-100\n       → opens PR #101\n\nPR #101 comments:\n  └─ /agent rename the button to Submit\n       → pushes new commit to agent/42-issue-100\n       → PR #101 updated, no new PR opened\n  └─ /agent fix the failing test\n       → same branch, new commit, PR #101 updated\n  └─ You merge → done\n```\n\n### Working memory\n\nAgents use auditable repository state by default: `AGENTS.md` (standing instructions), open issues and pull requests, recent commits, CI failures, and per-run summary artifacts. Scheduled maintenance workflows gather bounded repo context before each run and skip work when an open PR already covers the same change. An optional `.agent-memory/` scratchpad (cache-only, opt-in via `AGENT_MEMORY_SCRATCHPAD=1`) is not required.\n\n---\n\n## Docs\n\n- [Getting started](docs/getting-started.md) — end-to-end walkthrough\n- [Recipes](docs/recipes.md) — catalog reference with copy-paste examples\n- [Skills](docs/skills.md) — what each `/owf:*` command does\n- [Actions](docs/actions.md) — `gate-by-role` reference and v0.2 write path\n- [Conventions](docs/conventions.md) — branch naming, memory layout, safety story\n- [Positioning](docs/positioning.md) — permissive workflow, strict platform; setup checklist\n- [Migrating v0.1 → v0.2](docs/migrating-v0.1-to-v0.2.md) — drop `agent-pr` and github-script writes\n- [Comparison](docs/comparison.md) — vs gh-aw, Copilot Coding Agent, Cursor Background Agents\n- [Releasing](docs/releasing.md) — npm, action tags, and GitHub Releases\n- [Dogfooding](docs/dogfooding.md) — validate workflows and smoke-test this repo\n\n---\n\n## Design philosophy\n\n**Permissive workflow, strict platform** — thin YAML and a capable agent on the runner; branch protection, token scope, and PR review do the safety work. [docs/positioning.md](docs/positioning.md) explains the principle, comparison to alternatives, and the GitHub setup checklist.\n\nInspired by [OpenSpec](https://github.com/Fission-AI/OpenSpec)'s distribution model and [githubnext/agentics](https://github.com/githubnext/agentics)'s workflow taxonomy, built for indie maintainers and small teams.\n\n---\n\n## License\n\nMIT\n","readmeFilename":"README.md"}