Summary
When teamai is used with a Git host whose provider cannot open a PR/MR (a plain ssh:// remote, for
example), teamai push leaves new resources on teamai/push/<user>/<timestamp> with no signal about
whether they are usable. I would like a read-only check that tells the reviewer what is wrong before
the branch is merged by hand.
This is the "Add Skill health checks" / "validation" pair from the roadmap (#647), and it complements
#663 (pushed branches end up with no PR and no visible signal).
What I propose (read-only, no writes)
teamai review <branch> — or a flag on an existing command, see "Open questions" — reporting findings
per branch with three levels: fail (must fix), warn (needs a human decision), info (context):
- structure —
SKILL.md at the first level (skills/<ns>/<name>/SKILL.md); resource declared on
the axis that namespaces it; namespace declared by some role/project on that axis
- naming — invalid characters; frontmatter
name vs directory name
- duplicates — the same resource name in two namespaces that can be active together; this makes
pull fail, so it is worth catching before merge
- format — frontmatter present,
description explains when to use the skill
- leaks — credential shapes and internal addresses, reusing
utils/redact
A machine-readable mode (--json) matters to me so CI can consume the same result.
Non-goals
- No auto-merge. I am not proposing a
--direct-style path to the default branch; merging stays a
human decision. A "publish" step can be a separate discussion if it is wanted at all.
- No second implementation of existing logic. The checks should import
loadRolesManifest /
loadProjectsManifest, NAMESPACE_AXIS, parseAgentYaml, scanTeamForPull and utils/redact.
I am happy to export what is currently module-private (e.g. the secret pattern list) rather than
duplicating it.
- Conventions stay off by default. A namespace-prefix rule or a denylist of names would be opt-in
configuration, not default behaviour.
Open questions
- Entry point: extend
teamai review, or add a flag to push / status?
- Which checks belong in the default
fail set? My suggestion: missing SKILL.md, frontmatter
missing or name mismatch, cross-namespace duplicate names, namespace not declared anywhere, and a
credential hit. Everything else warn.
- Is a merge / "publish" step for these branches in scope for the CLI, now or later?
I already have a working local implementation and can send a PR in whatever shape you prefer, including
a real-CLI end-to-end record with it.
Summary
When teamai is used with a Git host whose provider cannot open a PR/MR (a plain
ssh://remote, forexample),
teamai pushleaves new resources onteamai/push/<user>/<timestamp>with no signal aboutwhether they are usable. I would like a read-only check that tells the reviewer what is wrong before
the branch is merged by hand.
This is the "Add Skill health checks" / "validation" pair from the roadmap (#647), and it complements
#663 (pushed branches end up with no PR and no visible signal).
What I propose (read-only, no writes)
teamai review <branch>— or a flag on an existing command, see "Open questions" — reporting findingsper branch with three levels:
fail(must fix),warn(needs a human decision),info(context):SKILL.mdat the first level (skills/<ns>/<name>/SKILL.md); resource declared onthe axis that namespaces it; namespace declared by some role/project on that axis
namevs directory namepullfail, so it is worth catching before mergedescriptionexplains when to use the skillutils/redactA machine-readable mode (
--json) matters to me so CI can consume the same result.Non-goals
--direct-style path to the default branch; merging stays ahuman decision. A "publish" step can be a separate discussion if it is wanted at all.
loadRolesManifest/loadProjectsManifest,NAMESPACE_AXIS,parseAgentYaml,scanTeamForPullandutils/redact.I am happy to export what is currently module-private (e.g. the secret pattern list) rather than
duplicating it.
configuration, not default behaviour.
Open questions
teamai review, or add a flag topush/status?failset? My suggestion: missingSKILL.md, frontmattermissing or
namemismatch, cross-namespace duplicate names, namespace not declared anywhere, and acredential hit. Everything else
warn.I already have a working local implementation and can send a PR in whatever shape you prefer, including
a real-CLI end-to-end record with it.