AI Workshop
Episode 9 of 10Upcoming
The agent on a team: review and CI
Agents in pull requests and CI: automated review, repo rules and shared team skills.
The link arrives by email an hour before the stream
Sign up — a day before we'll send a reminder with the episode plan, and an hour before the start the stream link. The player appears on this page 15 minutes before the start.
What we'll show
- The agent in GitHub Actions: reviewing a pull request and answering a mention in an issue
- Headless mode: the agent as a pipeline step, not a chat
- Shared team rules: CLAUDE.md in the repo, skills and commands for everyone
- Secrets in CI and what the agent may and may not do in a pipeline
- Typical risks: prompt injection via issues and PRs, leaks, over-privileged tokens
What you take away
A working workflow: the agent reviews PRs and answers mentions in issues.
Checklist: the agent in CI
- The agent's key is in repository secrets, not in code or the workflow file
- The CI token has least privilege: read code, comment on PRs, no push to main
- The agent in CI never merges on its own: the final call is a human's
- Issue and PR text is treated as untrusted input (prompt injection)
- Team rules live in CLAUDE.md in the repo, shared skills in .claude/skills
- Agent review complements human review, it doesn't replace it
Harness in this episode
CI is the team harness: the same checks you run locally now stand in the way of every change to the repo.
The full harness episodeWhat to have ready
- A GitHub repository where you have admin rights
