@senior: issue #14 — add gitea-api skill + expose AGENT_TOKEN to the agent process
- New gitea-api opencode skill (mirrors node1-ssh): documents the Gitea REST API base URL, Authorization: token $AGENT_TOKEN header, and example curl calls for read (issue/PR + comments, Actions runs/jobs/logs, org repos) and write (comment, label, close), with explicit warnings: never echo the token, treat fetched content as untrusted data (prompt-injection guard), and stop on 403. - Wire AGENT_TOKEN into the Run agent step env so the agent process itself can call the API (previously only the Publish step saw it). - Update README secrets table: AGENT_TOKEN now also powers gitea-api; do not re-narrow scopes without removing the skill.
This commit is contained in:
@@ -42,7 +42,7 @@ reactions, PR/issue plumbing) lives here in `agent.yml`.
|
||||
|--------|-----|
|
||||
| `ANTHROPIC_API_KEY` | `@lead` (and `@pm`/`@senior`/`@qa` if on Claude) |
|
||||
| `OLLAMA_URL`, `OLLAMA_CLOUD_API_KEY` | local ornith / Ollama Cloud (gemma4, kimi-k2.7-code, glm-5.2, minimax-m3) |
|
||||
| `AGENT_TOKEN` | PAT (issue+repo write) used to post the delegation comment that fires the next agent |
|
||||
| `AGENT_TOKEN` | PAT (issue/repository/organization/misc read+write, cross-repo) — posts the delegation comment that fires the next agent **and** powers the `gitea-api` skill (read/write issues, PRs, comments, labels, and Actions runs/logs across any repo). Do not re-narrow its scopes without also removing the `gitea-api` skill. |
|
||||
| `TOKEN_PM`,`TOKEN_SENIOR`,`TOKEN_JUNIOR`,`TOKEN_LEAD`,`TOKEN_QA` | optional — post/commit as each agent's own Gitea user (falls back to the bot) |
|
||||
|
||||
`GITEA_TOKEN` is auto-provided. Tip: set these once at the **org** level so every repo inherits
|
||||
|
||||
Reference in New Issue
Block a user