plugins/lisa-cursor/skills/lisa-setup-github-repo/SKILL.md
Apply Lisa's GitHub repository governance baseline to the current project's repo: repository settings (merge-only, auto-merge, delete-branch-on-merge, update-branch suggestions, wiki off, secret scanning where available), branch + tag rulesets from Lisa templates (base PR gate with CodeRabbit/GitGuardian/Quality Checks, prevent delete, protect tags, stack overlays), a write-access deploy key + DEPLOY_KEY secret so release workflows can push version bumps through the rulesets' DeployKey bypass, and optional deployment environments with human-approval gates (required reviewers) from the github.environments block in .lisa.config.json. Idempotent — re-running updates settings, rulesets, and environments in place and skips an already-configured deploy key.
npx skillsauth add codyswanngt/lisa lisa-setup-github-repoInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Apply the fleet-standard GitHub repository configuration to this project's repo. The settings, rulesets, and deploy key that used to be clicked together by hand for every new repo are applied here as one scripted flow.
scripts/lisa-github-repo-settings.sh)
MERGE_MESSAGE / PR_TITLE).lisa.config.json:
{ "github": { "settings": { "allow_auto_merge": false } } }
(any key under github.settings overrides the baseline)deletion rule means GitHub refuses to delete them)github.settings.default_branchwiki/)scripts/lisa-github-rulesets.sh) — one generated from config, the rest from Lisa's <type>/github-rulesets/ templates matched by project type:
base — generated from .lisa.config.json, not shipped as a template. Deletion/force-push protection from policy.protect, the branch list from policy.ruleset.include_refs, bypass actors from policy.ruleset.bypass_actors, approvals from policy.review, merge methods from policy.merge, and required checks from whatever gates the project awaits. A project that declares nothing gets exactly the ruleset the retired all/github-rulesets/base.json described, minus its two vendor checks — those are now await declarations a project can choose not to makequality checks — the stack's CI checks (TypeScript emoji names or Rails names)prevent delete, protect tags (v*), plus stack overlays (cdk validation, staging-only playwright).github/workflows/ get only app-based required checks — an Actions check that can never report would block every PR forever+ now required: <context>, and a ruleset that already satisfies its template reports nothing to do and is not sent at all, so a second run is visibly a no-opbase, which gets no exemption: removing a protection by default, on a script invoked with --yes, is not something an operator ever opted into. Name a ruleset in github.rulesets.requiredChecks and the live list stops being unioned in, so removing an entry actually stops requiring it — printed as - no longer required: <context>. Dropping an await without that opt-in leaves the live context in place; lisa-reconcile-policy.mjs then reports it as EXTRA, and --prune is where the removal is asked for. The retired addRequiredChecks is still read and could only ever addscripts/setup-deploy-key.sh --yes) — write-access deploy key + DEPLOY_KEY secret, skipped when already configured. The base ruleset's DeployKey: always bypass is what lets CI version-bump pushes through protected branches.scripts/lisa-github-environments.sh) — entirely optional; only runs when .lisa.config.json declares environments:
{
"github": {
"environments": {
"production": {
"branch": "main",
"require_approval": true,
"reviewers": ["some-user", "some-org/some-team"],
"prevent_self_review": false,
"wait_timer": 0
},
"staging": { "branch": "staging" }
}
}
}
production), mapped to branches. Branch resolution order: explicit branch → deploy.branches[<name>] → the name itself.require_approval: true provisions required reviewers (usernames or org/team-slug, max 6) — GitHub pauses any workflow job bound to the environment until a listed reviewer approves it in the Actions UI. Reviewers are mandatory when require_approval is true; the script refuses a gate nobody can approve.deploy.yml templates read this same config at runtime and pass require_approval/approval_environment to release.yml, whose release_approval job is where the run pauses. Requires a public repo or a paid plan for private repos (the script skips gracefully otherwise).scripts/lisa-reconcile-policy.mjs, also npm run policy:reconcile) — compares the DECLARED gates and policy block against what GitHub actually has, and converges it when policy.on_drift is repair. It runs here rather than only from a skill file, because a declaration nothing applies is not governance.
scripts/lisa-reconcile-policy.mjs is preferred; the shipped template is the fallback; finding neither is a hard failure, not a skip.2 is UNPROVEN — gh refused, is missing, or answered something unparseable. A private repository on a plan without rulesets answers 403. Setup warns and continues: failing for a plan limitation punishes a repository that has done nothing wrong. The warning names the state, because a blind gate that says nothing is indistinguishable from a clean one.In the Lisa repo itself, use scripts/ directly. In a downstream project, use the installed package:
LISA_SCRIPTS=$(ls -d node_modules/@codyswann/lisa/scripts 2>/dev/null || echo scripts)
bash "$LISA_SCRIPTS/lisa-github-repo-setup.sh" --dry-run .
Present what would change. If the repo already matches the baseline, say so and stop.
bash "$LISA_SCRIPTS/lisa-github-repo-setup.sh" .
Requires gh authenticated with admin permission on the repo. A 403 on rulesets means the plan doesn't support them (private repo on a free personal plan) — settings and deploy key still apply; the script skips rulesets gracefully.
Only when .lisa.config.json has a github.environments entry with require_approval: true AND .github/workflows/deploy.yml exists but does not reference approval_environment:
[ -f .github/workflows/deploy.yml ] \
&& jq -e '[.github.environments // {} | .[] | select(.require_approval == true)] | length > 0' .lisa.config.json > /dev/null 2>&1 \
&& ! grep -q 'approval_environment' .github/workflows/deploy.yml \
&& echo "deploy.yml needs approval wiring"
A grep hit is only a first pass — before skipping the edit, read the release job's with: block and confirm it actually passes both require_approval and approval_environment from the determine_environment outputs (a commented-out or unrelated occurrence doesn't count as wired).
deploy.yml is create-only — the project owns it, so Lisa never patches it automatically. Show the user the two changes from the current stack template (<stack>/create-only/.github/workflows/deploy.yml in the Lisa repo) and offer to apply them via Edit:
determine_environment, add a checkout step plus the 🚦 Resolve approval gate from .lisa.config.json step, and expose the approval_environment / require_approval outputs.release job's with: block, replace require_approval: false with:
require_approval: ${{ needs.determine_environment.outputs.require_approval == 'true' }}
approval_environment: ${{ needs.determine_environment.outputs.approval_environment }}
Skip this step (and say why) if the project's deploy.yml doesn't call Lisa's release.yml (rails uses release-rails.yml and harper-fabric has no release call — approval gating for those stacks is not wired yet).
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)" \
--jq '{allow_squash_merge, allow_auto_merge, delete_branch_on_merge, allow_update_branch}'
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)/rulesets" --jq '[.[].name]'
When environments were configured, also confirm each one carries its protection rules and branch policy:
gh api "repos/$(gh repo view --json nameWithOwner -q .nameWithOwner)/environments" \
--jq '.environments[] | {name, protection_rules, deployment_branch_policy}'
For every environment declared in github.environments, treat a missing deployment_branch_policy — or, when require_approval is true, an empty protection_rules — as a failure: the environment exists but is unprotected, so an approval gate bound to it would block nothing.
Report the applied settings, ruleset names, and environments. If any step failed, surface the error — do not mark the setup complete.
development
Prepare a machine — a fresh laptop or a throwaway container — to run coding agents, before any repository exists. Detects which of Lisa's supported agents (Claude Code, Codex, Cursor, OpenCode, Antigravity, Copilot) are already installed, asks which credential manager the machine uses (Bitwarden, 1Password, Doppler, Vault, AWS, or none), and installs only what is missing, each by its vendor's own preferred method. Idempotent, headless by default, and emits a Dockerfile for a spin-up/spin-down environment. Run it on a new machine, in a container, or before cloning anything.
tools
Provision and verify a remote execution environment for a host project — Codex Cloud today, other remote surfaces as they are added. Generates a repository-owned setup script that installs the declared toolchain, materializes secrets through lisa-secrets-access, and runs the project's own hook. Provisions by API where one exists, by driving the vendor console where one does not, and by emitting exact config otherwise — then proves the result with the same read-back regardless of which tier did the work. Use before dispatching any work with executionEnv.
tools
Bring a developer's machine in line with the toolchain the project declares. Reports every tool in remoteEnv.tools that is missing, outdated, or unpinned for this platform, and installs the missing ones into ~/.local/bin from the same pinned, checksummed entries the remote surfaces use — but only when asked. Same manifest, same pins, same installers as lisa-setup-remote-env; what differs is consent and that the pin is a floor rather than an equality. Run it on a fresh checkout, after a manifest change, or when a tool fails at the moment of use.
tools
Route one unit of work to a remote execution surface. Reads the executionEnv parameter (local by default, codex-cloud or claude-web today), verifies the environment is provisioned and bound to this repository, submits a thin skill invocation, records the task identifier to .lisa/remote-dispatch.json, and exits without polling. Routing only — the remote runs the identical skill from the identical repository. Composable and inline: other skills invoke it via the Skill tool rather than users calling it directly.