feat(claude-lanes): add the intake-triage reusable lane - #659
Conversation
A read-only Claude run (dontAsk, read-only gh queries, JSON schema output whose label enum is the caller allowlist intersected with live repository labels) proposes labels and a comment for a newly opened issue. A step with no model applies only allowlisted, existing labels, breaks @mentions, withholds a comment that looks like a credential, and applies the escalation label on a permission denial, a max-turns stop or a request for a person. The lane installs the newest Claude Code CLI at run time through path_to_claude_code_executable, with a cli-version input and a CLAUDE_LANE_CLI_VERSION variable to fall back to stable or bundled. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 4m 43s —— View job Security review complete
Reviewed only the two changed files ( 1 IMPORTANT finding, posted inline at The "Apply the triage" step's Everything else held up under review: the label allowlist is double-enforced (schema enum + re-check against live repo labels), the Bash tool is restricted to read-only |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e222faf5b0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
claude-security-review has reviewed this pull request through 35c4eb7; a later push is reviewed from there. |
No related issue: main has been red since c11c7ec (#650); this restores it. ## Summary #650 deleted `docs/topics/` while #656 added two AGENTS.md links into it, and two tests still read files there. `lychee-offline` and `selector-contract` fail on `main` and on every open PR. ## Fix - AGENTS.md: the two Code Review Rules lines that linked into `docs/topics/` now state their rule inline. - `.github/scripts/ci-fanout-consolidation.test.cjs`: drop the ADR read and the test that asserted the ADR's text. - `.github/scripts/claude-review-plugin-path.test.cjs`: drop the test that asserted the V2 architecture doc's text. ## Verification - `node --test .github/scripts/*.test.cjs`: 192 pass, 0 fail. - `git grep docs/topics` finds only the standards-managed `.github/actionlint.yaml` comment that #650 already noted. ## Related - Unblocks #659. - Cause: #650 and #656 merged in parallel. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 5m 54s —— View job Code review complete
This is the code-review lane: scoped to correctness, design, error handling, and maintainability. Security findings (the escalation/comment-gating issue already flagged inline by the security review and Codex's empty-enum catch) belong to the security lane and Codex respectively, and are intentionally omitted here to avoid duplicate reporting across lanes. 2 findings posted inline, both independently verified:
Everything else held up: the label resolution, schema composition, CLI version handling, and job-status wiring are internally consistent, and the README addition accurately describes the current behavior. |
|
claude-review has reviewed this pull request through 35c4eb7; a later push is reviewed from there. |
…tes retry-safe An escalated run (permission denial, max turns, unusable output, a credential-like comment, or needs_human) now applies only the escalation label and a fixed note instead of the model's labels and text, and a finished run with unusable output escalates instead of leaving the issue untouched. An empty allowlist yields labels maxItems 0 rather than an invalid empty enum. The comment is written before the labels, a rerun edits the lane's marker comment, and a write failure still records the summary. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 4m 36s —— View job Code review complete (incremental: 007a944…3041dd3)
This push is a fix-up: it addresses all four previously-flagged findings on this PR.
1 finding posted inline (Suggestion, README.md:815): the rewritten Everything else in the diff held up: the |
|
Claude finished @kyle-sexton's task in 2m 2s —— View job Security review complete
No security issues found in this increment. Scope: only what changed since This commit closes the trust-boundary gap flagged in the prior round:
No new trust-boundary, injection, or credential-handling issues were introduced by this diff. The canned escalation message is static text with no model- or issue-controlled interpolation, so it carries no injection surface. Nothing else in scope changed. Instruction-surface lens: this diff touches only the workflow file and README — no |
…calation Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 26s —— View job Code review complete (incremental:
|

No related issue: first CI lane of the automation-lanes effort, planned in a local decision brief.
Hold: a human merges this. It adds a lane that holds a secret and
issues: write, so it is a lane-power change; the babysit lane must not merge it.Summary
Adds
.github/workflows/claude-intake-triage.yml, a reusable workflow that triages a newly opened issue: a read-only Claude run proposes labels and a comment, and a step with no model validates and applies them. README gains its entry.Fix
--permission-mode dontAsk, toolsRead,Grep,Glob,Bash, Bash approved only forgh issue view/list,gh search issues,gh label list, and--json-schemaoutput whose label enum is the caller'sallowed-labelsintersected with the repository's live labels.allowed_non_write_users: "*"with the jobGITHUB_TOKEN, so outside reporters are triaged (the action then scrubs subprocess secrets and keeps.git/configtoken-free).addLabelswould otherwise create unknown ones), breaks @mentions, withholds a comment matching a credential pattern, and appliesescalation-label(defaultneeds-human) on any permission denial, a max-turns stop, orneeds_human: true.path_to_claude_code_executable(cli-versioninput, else theCLAUDE_LANE_CLI_VERSIONvariable, elselatest;bundledkeeps the action's own). The step summary records the installed version and the npm-published latest.claude-intake-triage-statusgoes red on a failed run; it is advisory and must never be required.Verification
actionlintandzizmor --offline: no findings.node --test .github/scripts/*.test.cjs: 183 pass, 2 fail; both failures (ci-fanout-consolidation,V2 architecture doc exists) read files underdocs/topics/, which chore: remove docs/topics #650 removed, and fail onmaintoo. The outcome-wiring test now covers this lane.dontAskdenied Read of/etc/hostnameand/proc/self/statusand recorded both inpermission_denialswhile reading a file in the working directory;--toolsrestricted toRead,Grep,Glob,Bashplus--json-schemawith a label enum returned validstructured_output.Related
claude-review.yml(outcome composite, status job).issue-triage-label.yml(deterministicneeds-triagefloor).runner-policycontract and caller component, then the claude-code-plugins pilot.🤖 Generated with Claude Code