{"_id":"@autosk/gh-review","name":"@autosk/gh-review","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@autosk/gh-review","version":"0.1.0","description":"gh-review — review a GitHub issue or PR (URL in the task title) with a pi agent in a per-task dockerSandbox and a READ-ONLY gh; review → accept (human) → cleanup → done.","license":"MIT","author":{"name":"wierdbytes"},"homepage":"https://github.com/wierdbytes/autosk#readme","repository":{"type":"git","url":"git+https://github.com/wierdbytes/autosk.git","directory":"daemon/extensions/gh-review"},"bugs":{"url":"https://github.com/wierdbytes/autosk/issues"},"keywords":["autosk","autosk-extension","autosk-workflow","docker","github","review"],"type":"module","publishConfig":{"access":"public"},"exports":{".":"./index.ts"},"types":"./index.ts","autosk":{"extensions":["./index.ts"]},"dependencies":{"@autosk/pi-agent":"^0.1.0","@autosk/sandbox":"^0.1.0","@autosk/sdk":"^0.1.0"},"scripts":{"typecheck":"tsc --noEmit -p tsconfig.json"},"gitHead":"b5d78f7763df0ff90569610fbdc17ad54cc40674","_id":"@autosk/gh-review@0.1.0","_nodeVersion":"25.6.1","_npmVersion":"11.9.0","dist":{"integrity":"sha512-STARuB7kHD6RdzZ5smWgOWK1Fa43gNr+rpYwu1MuUH21aePEeh73mUj0A8y+wbnxG3AmowXEpW0LwbyNLiUx/w==","shasum":"8d006e7cd9c30fa6ce0886f0b6f419fa27b0fba5","tarball":"https://registry.npmjs.org/@autosk/gh-review/-/gh-review-0.1.0.tgz","fileCount":7,"unpackedSize":23502,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFuIgVFVk+Ygi81ts5K7FjSYr/vv74DibICWG8Kx/FbjAiEA2Nqqm/DCa8S7nTffQiQPzrWM9f1oPIvWZRf6NHL3Mn0="}]},"_npmUser":{"name":"wierdbytes","email":"wb@xff.pw"},"directories":{},"maintainers":[{"name":"wierdbytes","email":"wb@xff.pw"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gh-review_0.1.0_1785176001091_0.6436789306527408"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-27T18:13:20.889Z","0.1.0":"2026-07-27T18:13:21.244Z","modified":"2026-07-27T18:13:21.506Z"},"maintainers":[{"name":"wierdbytes","email":"wb@xff.pw"}],"description":"gh-review — review a GitHub issue or PR (URL in the task title) with a pi agent in a per-task dockerSandbox and a READ-ONLY gh; review → accept (human) → cleanup → done.","homepage":"https://github.com/wierdbytes/autosk#readme","keywords":["autosk","autosk-extension","autosk-workflow","docker","github","review"],"repository":{"type":"git","url":"git+https://github.com/wierdbytes/autosk.git","directory":"daemon/extensions/gh-review"},"author":{"name":"wierdbytes"},"bugs":{"url":"https://github.com/wierdbytes/autosk/issues"},"license":"MIT","readme":"# @autosk/gh-review\n\nReview a GitHub issue or pull request from a task: enroll a task whose **title\ncarries a GitHub issue/PR URL** (`https://github.com/<owner>/<repo>/issues/9`\nor `…/pull/12`), and a pi agent reviews it inside a **per-task\n`docker run -i --rm` container** with a **READ-ONLY `gh`** — the verdict lands\nas a structured comment on the autosk task. Nothing is ever written to GitHub\n(the token's scopes reject every write with 403, and the prompt never tries).\n\nIt registers ONE workflow, **`gh-review`**:\n\n```text\nreview ──▶ accept (human) ──▶ cleanup ──▶ done\n```\n\n- `review` — `piAgent` (xhigh) in a per-task `dockerSandbox` container\n  (`ghcr.io/wierdbytes/pi-runtime`, which ships `gh`); it reads the issue/PR\n  with `gh` (+ a clone when the diff is not enough), reviews it, posts the\n  review as one task comment, and transits to `accept`.\n- `accept` — `statusStep(\"human\")`; the task parks for you to read the review.\n- `cleanup` — `sandboxCleanupStep`: removes the per-task worktree/container,\n  then transits to `done` (`autosk resume <id> --to cleanup`).\n\nThe enroll is **validated before any agent runs** (`onTransit`): a task with no\nparsable GitHub URL — or a daemon with no gh config — is rejected with an\nexplanatory comment and stays `new`.\n\n## Setup: read-only gh\n\n1. On GitHub, create a **fine-grained personal access token**:\n   - *Repository access*: only the repositories you want reviewed.\n   - *Permissions* (all **Read-only**): `Contents`, `Issues`, `Pull requests`,\n     `Metadata`. (`Contents: Read` is what allows `gh repo clone` for a deeper\n     PR review; drop it for a diff-only token.)\n2. Store it in `~/.autosk/github/ro-token.json` (override the dir with\n   `AUTOSK_GH_DIR`):\n\n   ```json\n   { \"token\": \"github_pat_…\" }\n   ```\n\n   ```bash\n   chmod 600 ~/.autosk/github/ro-token.json\n   ```\n\n3. Done. The extension reads the file at container-start and passes the token\n   as the `GH_TOKEN` env — gh's native token mechanism: no gh config file\n   exists in the container, so gh never tries to rewrite one (gh ≥2.40 rewrites\n   `hosts.yml` on most invocations — a read-only config mount does not work),\n   and `GH_NO_UPDATE_NOTIFIER=1` / `CHECKPOINT_DISABLE=1` keep gh from writing\n   anything else. The token is visible in `docker inspect` while the per-task\n   container lives (minutes); read-only *access* is enforced by the token's\n   scopes on GitHub's side (a write → 403). Rotating the token in the file\n   takes effect on the next run — no daemon restart.\n\n## Use it\n\n```bash\n# 1. build (or pull) the pi-runtime image (ships gh)\ndaemon/extensions/pi-agent/docker/build.sh\n\n# 2. install this extension (hot-applies to open projects, no restart)\nautosk ext add npm:@autosk/gh-review      # or: autosk ext add /path/to/gh-review\n\n# 3. enroll a task whose title carries the URL\nid=$(autosk create \"https://github.com/wierdbytes/autosk/pull/12\" --workflow gh-review --json | jq -r .id)\n\n# the daemon runs the review and parks the task at `accept`;\n# read the review comment, then route it through cleanup:\nautosk resume \"$id\" --to cleanup          # → done (worktree/container removed)\n```\n\nThe host project must be a git repo (the sandbox is a per-task worktree, same\nas `feature-dev`). If the URL points at a *different* repository, the agent\nclones it inside the container (gone when the container exits).\n\nEnv knobs (all optional):\n\n| var | default | what |\n|-----|---------|------|\n| `AUTOSK_GH_REVIEW_IMAGE` | `ghcr.io/wierdbytes/pi-runtime:latest` | image to run (must ship `gh`) |\n| `AUTOSK_GH_DIR` | `~/.autosk/github` | dir holding `ro-token.json` (read fresh per run) |\n| `AUTOSK_PI_DIR` | `~/.pi` | host pi config (auth + models) bind-mounted into the container |\n\n## Exports\n\n- default — the extension factory (registers `gh-review`).\n- `ghReviewWorkflow(opts)` / `ghReviewSandbox()` — compose your own workflow\n  over the same docker sandbox.\n- `ghReviewGuard` — the `onTransit` enroll validator (URL + gh token).\n- `parseGhTarget(text)` — the title/description URL parser.\n- `defaultDockerImage()` / `ghConfigDir()` / `ghTokenFile()` / `readGhToken()` / `checkGhToken()`.\n","readmeFilename":"README.md","_rev":"1-1c52fc02c7ed99c98c4205bb56543d41"}