code-change-verification
GitHub在 OpenAI Agents JS 仓库中,当代码变更影响运行时、测试或构建行为时,执行包含依赖安装、构建、类型检查、Linting 和测试的强制验证流程。确保工作仅在所有命令成功后标记为完成,并处理并发和资源限制问题。
Trigger Scenarios
Install
npx skills add openai/openai-agents-js --skill code-change-verification -g -y
SKILL.md
Frontmatter
{
"name": "code-change-verification",
"description": "Run the mandatory verification stack when changes affect runtime code, tests, or build\/test behavior in the OpenAI Agents JS monorepo."
}
Code Change Verification
Overview
Ensure work is only marked complete after installing dependencies, building, linting, type checking (including generated declarations), and tests pass. Use this skill when changes affect runtime code, tests, or build/test configuration. This is a post-review final gate: when $implementation-final-review applies, do not invoke the broad stack until its clean-review condition applies to the stable task diff.
Quick start
- Keep this skill at
./.agents/skills/code-change-verificationso it loads automatically for the repository. - Run the skill in the user's selected checkout without changing worktrees or branches.
- Codex on macOS/Linux:
/usr/bin/env -u OPENAI_API_KEY bash .agents/skills/code-change-verification/scripts/run.sh. - Other macOS/Linux environments:
bash .agents/skills/code-change-verification/scripts/run.sh. - Windows:
powershell -ExecutionPolicy Bypass -File .agents/skills/code-change-verification/scripts/run.ps1. - If any command fails, fix the issue, rerun the script, and report the failing output.
- Confirm completion only when all commands succeed with no remaining issues.
Start condition and host capacity
- During iterative review, use only focused tests and a narrowly targeted static check when the changed typing boundary requires one. Defer repository-wide
pnpm -r build-checkand the rest of this complete stack until review is clean. - Immediately before starting the complete stack, use available read-only task or process evidence to check whether another repository-wide test, typecheck, build, examples runner, or integration command is already active on the same host.
- When concrete contention is visible, continue useful non-heavy work such as review, remediation, evidence preparation, or focused checks, then check again later. Do not create or wait on a repository lock, host-wide mutex, or sentinel file.
- Start automatically once review is clean, the diff is stable, and observable host capacity is available. Do not require a user-triggered
finalizemessage. If host telemetry is unavailable, do not block solely because capacity cannot be measured.
Codex execution policy
Repository verification and all child processes must remain in the normal Codex workspace sandbox. Never request elevated sandbox permissions for verification, and never retry with broader host access after a failure.
On macOS/Linux, use the exact Codex command from Quick start so an inherited OPENAI_API_KEY is removed before the repository-controlled wrapper starts. Investigate failures inside the workspace sandbox and report any coverage that the sandbox cannot provide instead of weakening the sandbox boundary.
Manual workflow
- Run from the repository root in these phases:
pnpm i --frozen-lockfile,pnpm build, thenpnpm -r build-check,pnpm -r -F "@openai/*" dist:check,pnpm lint,pnpm test, andpnpm format:check:changed. - The skill may execute the final validation phase in parallel, but every step above must still pass.
- Do not skip steps; stop and fix issues immediately when any step fails.
- Re-run the full stack after applying fixes so the commands execute with the same barriers and coverage.
- The install intentionally runs without forcing CI or prompt-confirmation settings. If pnpm reports incompatible
node_modules, stop and diagnose the configuration mismatch instead of silently recreating dependencies.
Resources
scripts/run.sh
- Executes the full verification sequence (including declaration checks) with fail-fast semantics.
- Keeps
pnpm i --frozen-lockfileandpnpm buildas barriers, then delegates independent validation steps toconcurrently. - Prefer this entry point to ensure the commands always run from the repo root with the expected fail-fast behavior.
scripts/run.ps1
- Windows-friendly wrapper that runs the same verification sequence with fail-fast semantics.
- Use from PowerShell with execution policy bypass if required by your environment.
Version History
-
443c33e
Current 2026-08-20 05:59
新增迭代审查期间的聚焦检查策略及主机容量检测机制;明确 Codex 沙箱执行策略以防止权限提升;优化触发条件以在审查清洁后自动启动。
- 13f68fa 2026-07-25 11:30


