# Checklist: the agent in CI

AI Workshop · episode 9: The agent on a team: review and CI
https://mihalkevich.com/en/workshop/team-ci

- [ ] The agent's key is in repository secrets, not in code or the workflow file
- [ ] The CI token has least privilege: read code, comment on PRs, no push to main
- [ ] The agent in CI never merges on its own: the final call is a human's
- [ ] Issue and PR text is treated as untrusted input (prompt injection)
- [ ] Team rules live in CLAUDE.md in the repo, shared skills in .claude/skills
- [ ] Agent review complements human review, it doesn't replace it

## Harness in this episode

CI is the team harness: the same checks you run locally now stand in the way of every change to the repo.

## Official documentation

- [Claude Code — GitHub Actions](https://code.claude.com/docs/en/github-actions)
- [Claude Code — headless mode](https://code.claude.com/docs/en/headless)
- [GitHub Actions — using secrets](https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets)
- [Claude Code — skills](https://code.claude.com/docs/en/skills)
- [OWASP Top 10 for LLM applications](https://genai.owasp.org/llm-top-10/)

— mihalkevich school
