Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CodySwannGT/nestjsstarter --skill lisa-setup-github-repo명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
This skill provides strategies and patterns for reducing cognitive complexity in React components. It should be used when ESLint reports sonarjs/cognitive-complexity violations, when refactoring complex View components, or when planning how to break down large components. The skill enforces this project's Container/View pattern requirements when extracting components.
Make a brownfield project…
Read-only operator surface for…
SKILL.md 표시 중
| name | lisa-setup-github-repo |
| description | Apply Lisa's GitHub repository… |
| allowed-tools | ["Bash","Read","Edit","AskUserQuestion"] |
Apply the fleet-standard GitHub repository configuration to this project's repo. The settings, rulesets, and deploy key that used to be clicked together by hand for every new repo are applied here as one scripted flow.
scripts/lisa-github-repo-settings.sh)
MERGE_MESSAGE / PR_TITLE).lisa.config.json:
{ "github": { "settings": { "allow_auto_merge": false } } }
(any key under github.settings overrides the baseline)deletion rule means GitHub refuses to delete them)github.settings.default_branchwiki/)scripts/lisa-github-rulesets.sh) from Lisa's <type>/github-rulesets/ templates, matched by project type:
base — deletion/force-push protection on main/dev/staging + default, PRs required (0 approvals, review-thread resolution required, merge method = merge only), required checks: CodeRabbit + GitGuardianquality checks — the stack's CI checks (TypeScript emoji names or Rails names)prevent delete, protect tags (v*), plus stack overlays (cdk validation, staging-only playwright).github/workflows/ get only app-based required checks — an Actions check that can never report would block every PR foreverscripts/setup-deploy-key.sh --yes) — write-access deploy key + DEPLOY_KEY secret, skipped when already configured. The base ruleset's DeployKey: always bypass is what lets CI version-bump pushes through protected branches.scripts/lisa-github-environments.sh) — entirely optional; only runs when .lisa.config.json declares environments:
{
"github": {
"environments": {
"production": {
"branch": "main",
"require_approval": true,
"reviewers": ["some-user", "some-org/some-team"],
"prevent_self_review": false,
"wait_timer": 0
},
"staging": { "branch": "staging" }
}
}
}
production), mapped to branches. Branch resolution order: explicit branch → deploy.branches[<name>] → the name itself.In the Lisa repo itself, use scripts/ directly. In a downstream project, use the installed package:
LISA_SCRIPTS=$(ls -d node_modules/@codyswann/lisa/scripts 2>/dev/null || echo scripts)
bash "$LISA_SCRIPTS/lisa-github-repo-setup.sh" --dry-run .
Present what would change. If the repo already matches the baseline, say so and stop.
bash "$LISA_SCRIPTS/lisa-github-repo-setup.sh" .
Requires gh authenticated with admin permission on the repo. A 403 on rulesets means the plan doesn't support them (private repo on a free personal plan) — settings and deploy key still apply; the script skips rulesets gracefully.
Only when .lisa.config.json has a github.environments entry with require_approval: true AND .github/workflows/deploy.yml exists but does not reference approval_environment:
[ -f .github/workflows/deploy.yml ] \
&& jq -e '[.github.environments // {} | .[] | select(.require_approval == true)] | length > 0' .lisa.config.json > /dev/null 2>&1 \
&& ! grep -q 'approval_environment' .github/workflows/deploy.yml \
&& echo "deploy.yml needs approval wiring"
A grep hit is only a first pass — before skipping the edit, read the release job's with: block and confirm it actually passes both require_approval and approval_environment from the determine_environment outputs (a commented-out or unrelated occurrence doesn't count as wired).
deploy.yml is create-only — the project owns it, so Lisa never patches it automatically. Show the user the two changes from the current stack template (<stack>/create-only/.github/workflows/deploy.yml in the Lisa repo) and offer to apply them via Edit:
determine_environment, add a checkout step plus the 🚦 Resolve approval gate from .lisa.config.json step, and expose the approval_environment / require_approval outputs.release job's with: block, replace require_approval: false with:
require_approval: ${{ needs.determine_environment.outputs.require_approval == 'true' }}
approval_environment: ${{ needs.determine_environment.outputs.approval_environment }}
Skip this step (and say why) if the project's deploy.yml doesn't call Lisa's release.yml (rails uses release-rails.yml and harper-fabric has no release call — approval gating for those stacks is not wired yet).
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)" \
--jq '{allow_squash_merge, allow_auto_merge, delete_branch_on_merge, allow_update_branch}'
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)/rulesets" --jq '[.[].name]'
When environments were configured, also confirm each one carries its protection rules and branch policy:
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)/environments" \
--jq '.environments[] | {name, protection_rules, deployment_branch_policy}'
For every environment declared in github.environments, treat a missing deployment_branch_policy — or, when require_approval is true, an empty protection_rules — as a failure: the environment exists but is unprotected, so an approval gate bound to it would block nothing.
Report the applied settings, ruleset names, and environments. If any step failed, surface the error — do not mark the setup complete.
require_approval: trueorg/team-slugrequire_approvaldeploy.yml templates read this same config at runtime and pass require_approval/approval_environment to release.yml, whose release_approval job is where the run pauses. Requires a public repo or a paid plan for private repos (the script skips gracefully otherwise).