{"id":"f39c30a4-c096-462d-b3ae-3e58d2eed4a2","entityType":"agent","slug":"clawhub-jacksync-pullstar-1on1","name":"Engineering manager 1-on-1 meeting brief generator","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jacksync-pullstar-1on1","canonicalPath":"/agent/clawhub-jacksync-pullstar-1on1","generatedAt":"2026-10-11T17:41:20.514Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T15:08:33.828Z","emptyReason":null},"description":"Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns. Skill: Engineering manager 1-on-1 meeting brief generator Owner: jacksync Summary: Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns. Tags: latest:1.0.3 Version history: v1.0.3 | 2026-08-24T00:02:35.036Z | user - Improved pipeline: 1-on-1 brief is now generated deterministically in a single agent session with exactly five tool calls (no sub-agents spawned","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17797mbhv0wkbd3wj9d1mynr185px38:pullstar-1on1","sourceUrl":"https://clawhub.ai/jacksync/pullstar-1on1","homepage":"https://clawhub.ai/jacksync/skills/pullstar-1on1","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jacksync/pullstar-1on1","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jacksync/skills/pullstar-1on1","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns. Skill: Engineering manager 1-on-1 meeting brie"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:08:33.828Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:08:33.828Z","emptyReason":null},"stars":null,"forks":null,"downloads":1043,"packageName":null,"latestVersion":"1.0.3","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:08:33.813Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T15:08:33.828Z","lastCrawledAt":"2026-10-11T15:08:33.813Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T15:08:33.813Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.3","createdAt":"2026-08-24T00:02:35.036Z","changelog":"- Improved pipeline: 1-on-1 brief is now generated deterministically in a single agent session with exactly five tool calls (no sub-agents spawned). - Updated documentation to clarify the new inline LLM inference flow—agents must not use sub-agents. - Removed the agent best practices section about sub-agent polling and management. - Added a \"quality gate\" step: agents must check for empty or non-meaningful briefs before presenting results. - Removed the sample skill-card.md file.","fileCount":11,"zipByteSize":37786},{"version":"1.0.2","createdAt":"2026-06-01T20:44:16.712Z","changelog":"pullstar-1on1 v1.0.2 - Switched to a new entry point: added run_brief.py for unified brief generation. - Added GitHub GraphQL mode as default, with REST fallback and --api-mode flag - Expanded documentation: added README.md with updated usage, config, and privacy details. - Clarified agent and LLM inference instructions for output workflow. - Updated dependencies list (requires 'requests'). - Removed skill-card.md; see README.md and SKILL.md for all reference details. -skills/scripts/ingest.py now default to GitHub GraphQL API when a token is present, reducing API call count from ~200+ REST calls per user to 2-4 GraphQL queries total. REST remains the automatic fallback when no GITHUB_TOKEN is found, preserving full backwards compatibility including unauthenticated access.","fileCount":11,"zipByteSize":37179},{"version":"1.0.1","createdAt":"2026-05-05T20:45:25.878Z","changelog":"**pullstar-1on1 v1.0.1 Changelog** - Updated documentation for greater clarity, security best practices, and user guidance. - Added detailed privacy, security, and token usage sections, including specific guidance for fine-grained and classic GitHub PATs. - Improved description of data flow and artifact responsibilities—clearly separated local and external steps. - Expanded PR insights mode explanation, including privacy warnings and safety limits. - Provided troubleshooting tips for token and rate-limit issues. - No code changes in this version; documentation and user guidance only.","fileCount":10,"zipByteSize":32095},{"version":"1.0.0","createdAt":"2026-05-05T20:20:29.552Z","changelog":"pullstar 1.0.0 — First release of the Pullstar 1-on-1 brief generator. - Generates structured 1-on-1 prep briefs for engineers based on GitHub activity. - Detects output patterns, review activity, batching, and cross-repo collaboration. - Uses a deterministic scoring engine across five dimensions for each engineer. - Supports secure, local data processing — all data stays on your machine. - Provides detailed, clear requirements for JSON output contracts and workflow. - Optional PR insights enrichment available via a command-line flag.","fileCount":9,"zipByteSize":29978}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17797mbhv0wkbd3wj9d1mynr185px38:pullstar-1on1","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T17:41:20.513Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jacksync-pullstar-1on1/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T15:08:33.828Z","emptyReason":null},"readme":"Skill: Engineering manager 1-on-1 meeting brief generator\n\nOwner: jacksync\n\nSummary: Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns.\n\nTags: latest:1.0.3\n\nVersion history:\n\nv1.0.3 | 2026-08-24T00:02:35.036Z | user\n\n- Improved pipeline: 1-on-1 brief is now generated deterministically in a single agent session with exactly five tool calls (no sub-agents spawned).\n- Updated documentation to clarify the new inline LLM inference flow—agents must not use sub-agents.\n- Removed the agent best practices section about sub-agent polling and management.\n- Added a \"quality gate\" step: agents must check for empty or non-meaningful briefs before presenting results.\n- Removed the sample skill-card.md file.\n\nv1.0.2 | 2026-06-01T20:44:16.712Z | user\n\npullstar-1on1 v1.0.2\n\n- Switched to a new entry point: added run_brief.py for unified brief generation.\n- Added GitHub GraphQL mode as default, with REST fallback and --api-mode flag\n- Expanded documentation: added README.md with updated usage, config, and privacy details.\n- Clarified agent and LLM inference instructions for output workflow.\n- Updated dependencies list (requires 'requests').\n- Removed skill-card.md; see README.md and SKILL.md for all reference details.\n-skills/scripts/ingest.py now default to GitHub\nGraphQL API when a token is present, reducing API call count from ~200+ REST\ncalls per user to 2-4 GraphQL queries total. REST remains the automatic\nfallback when no GITHUB_TOKEN is found, preserving full backwards compatibility\nincluding unauthenticated access.\n\nv1.0.1 | 2026-05-05T20:45:25.878Z | user\n\n**pullstar-1on1 v1.0.1 Changelog**\n\n- Updated documentation for greater clarity, security best practices, and user guidance.\n- Added detailed privacy, security, and token usage sections, including specific guidance for fine-grained and classic GitHub PATs.\n- Improved description of data flow and artifact responsibilities—clearly separated local and external steps.\n- Expanded PR insights mode explanation, including privacy warnings and safety limits.\n- Provided troubleshooting tips for token and rate-limit issues.\n- No code changes in this version; documentation and user guidance only.\n\nv1.0.0 | 2026-05-05T20:20:29.552Z | user\n\npullstar 1.0.0 — First release of the Pullstar 1-on-1 brief generator.\n\n- Generates structured 1-on-1 prep briefs for engineers based on GitHub activity.\n- Detects output patterns, review activity, batching, and cross-repo collaboration.\n- Uses a deterministic scoring engine across five dimensions for each engineer.\n- Supports secure, local data processing — all data stays on your machine.\n- Provides detailed, clear requirements for JSON output contracts and workflow.\n- Optional PR insights enrichment available via a command-line flag.\n\nArchive index:\n\nArchive v1.0.3: 11 files, 37786 bytes\n\nFiles: brief_v1.txt (4911b), models.py (4027b), prompt_builder.py (14373b), run_brief.py (5404b), scripts/agent_finalize_1on1.py (6734b), scripts/agent_prepare_1on1.py (4160b), scripts/ingest.py (36086b), scripts/score.py (30453b), skill-card.md (2534b), SKILL.md (8906b), _meta.json (132b)\n\nFile v1.0.3:SKILL.md\n\n---\r\nname: skills\r\ndescription: Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns.\r\nlicense: MIT\r\n---\r\n\r\n## Overview\r\n\r\nPullStar fetches GitHub activity for one engineer (PRs authored, reviews given), runs a **deterministic local scoring engine** across five dimensions, and prepares an LLM input payload. The **agent** then performs LLM inference and finalizes the brief.\r\n\r\n\r\n**Quickstart:** \r\n\r\n    run_brief.py --login steipete --pr-insights --days 7\r\n    Read llm_input_steipete.json, do the LLM inference, present the brief\r\n\r\n\r\n\r\n**Data Flow Summary:**\r\n\r\n| Step | What runs | External calls |\r\n|------|-----------|----------------|\r\n| Ingest | `run_brief.py` → `ingest.py` | GitHub API |\r\n| Score | `run_brief.py` → `score.py` | None |\r\n| Prepare | `run_brief.py` → `agent_prepare_1on1.py` | None |\r\n| **Agent inference** | **Agent calls LLM** | **LLM provider** |\r\n| Finalize | Agent runs `agent_finalize_1on1.py` | None |\r\n\r\n**⚠️ Important:** Steps 1–3 run locally. Only the LLM inference step (step 4) sends data to your AI provider.\r\n\r\n---\r\n\r\n## Requirements\r\n\r\n- Python 3.11+\r\n- Install dependencies: `pip install PyGithub python-dotenv requests`\r\n- A GitHub personal access token (see Security section below)\r\n\r\n---\r\n\r\n## Security & Privacy\r\n\r\n### Token Scope\r\n\r\n| Option | Where to create | Best for |\r\n|--------|----------------|----------|\r\n| Classic PAT (`repo` scope) | https://github.com/settings/tokens | Cross-user search, org-wide ingestion |\r\n| Fine-grained PAT | https://github.com/settings/personal-access-tokens | Your own repos only |\r\n\r\n> Fine-grained PATs cannot search across arbitrary users. Use a classic PAT for org-wide briefs.\r\n\r\nSet `GITHUB_ORG` to narrow search to one organization.\r\n\r\n### Token Resolution Order\r\n\r\nSecrets are resolved using layered lookup — first match wins:\r\n\r\n1. `--github-token` CLI flag (override/debug only — never logged)\r\n2. `GITHUB_TOKEN` environment variable\r\n3. `~/.pullstar/credentials` (key=value format)\r\n4. `.env` in the skill directory\r\n\r\n### Data Privacy by Mode\r\n\r\n**Default (no `--pr-insights`):**\r\n- Only aggregated statistics and scores sent to LLM\r\n- No raw PR text, comments, or review bodies included\r\n\r\n**PR Insights (`--pr-insights`):**\r\n- Bounded raw PR discussion text packaged into the LLM prompt\r\n- Bounded to 5 PRs, 3 reviews/comments each, 600 char limit per item\r\n- Review `llm_input_{login}.json` before inference if you have privacy concerns\r\n\r\n---\r\n\r\n## Configuration\r\n\r\n### `.env`\r\n\r\n| Variable | Required | Description |\r\n|----------|----------|-------------|\r\n| `GITHUB_TOKEN` | Recommended | Classic PAT with `repo` scope. Omit for unauthenticated access (60 req/hr). |\r\n| `GITHUB_ORG` | No | Scope ingestion to one org. |\r\n\r\n---\r\n\r\n## Usage\r\n\r\n### Standard run\r\n\r\n```bash\r\npython run_brief.py --login jsmith\r\n```\r\n\r\n### With PR insights\r\n\r\n```bash\r\npython run_brief.py --login jsmith --pr-insights\r\n```\r\n\r\n### Common options\r\n\r\n```bash\r\npython run_brief.py --login jsmith --days 14          # wider lookback (default: 5)\r\npython run_brief.py --login jsmith --max-results 10   # faster on high-activity users (default: 20)\r\npython run_brief.py --login jsmith --api-mode rest    # force REST API (default: graphql)\r\n```\r\n\r\n### All options\r\n\r\n| Flag | Default | Description |\r\n|------|---------|-------------|\r\n| `--login` | required | Engineer GitHub login |\r\n| `--days` | `5` | Lookback window in days |\r\n| `--pr-insights` | off | Include PR review/comment context in LLM prompt |\r\n| `--max-results` | `20` | Max search results to iterate (lower = faster) |\r\n| `--api-mode` | `graphql` | `graphql` or `rest` |\r\n| `--output-dir` | `.pullstar` | Directory for all artifacts |\r\n| `--github-token` | — | Override/debug only. Prefer `.env`. |\r\n\r\n---\r\n\r\n## Agent Flow (Deterministic — No Sub-Agents)\r\n\r\n**The entire pipeline runs in the agent's main session.** Use `exec` for Python scripts and do the LLM inference inline — the agent itself is the LLM. Never spawn sub-agents.\r\n\r\n```\r\n1. exec:    python run_brief.py --login <login> [flags]\r\n2. read:    .pullstar/llm_input_<login>.json\r\n3. write:   .pullstar/llm_output_<login>.json  (produce the brief inline as the LLM)\r\n4. exec:    python scripts/agent_finalize_1on1.py --login <login>\r\n5. read:    .pullstar/output_<login>.json       (quality gate: verify meaningful data)\r\n6. (done — present the brief)\r\n```\r\n\r\n### Why Inline\r\n\r\n- **Zero sub-agent overhead.** No spawn latency, no polling, no completion-event complexity.\r\n- **Deterministic tool count.** Exactly 5 tool calls: exec → read → write → exec → read.\r\n- **Faster end-to-end.** All steps run sequentially in one session with no context-fork tax.\r\n- **The agent IS the LLM.** Creating a sub-agent to call the same model for inference adds nothing.\r\n\r\n### Quality Gate\r\n\r\nAfter step 4, read `output_<login>.json` and verify the brief has meaningful data. If `total_score` is 0 or the brief contains phrases like \"no activity\" / \"no contributions\" / \"no PRs merged\" / \"insufficient data\", respond with a graceful fallback message instead of presenting an empty brief.\r\n\r\n---\r\n\r\n## Agent JSON Contract\r\n\r\n### Input (from `run_brief.py`)\r\n\r\nFile: `.pullstar/llm_input_{login}.json`\r\n\r\n| Field | Type | Description |\r\n|-------|------|-------------|\r\n| `system` | string | System prompt with instructions |\r\n| `user` | string | User message with engineer data and scores |\r\n| `metadata` | object | Version, timestamps, total score, confidence |\r\n\r\n### Output (from agent)\r\n\r\nFile: `.pullstar/llm_output_{login}.json`\r\n\r\n```json\r\n{\r\n  \"version\":        \"1.0\",\r\n  \"engineer_login\": \"jsmith\",\r\n  \"brief\":          \"## Quick Summary\\n...\"\r\n}\r\n```\r\n\r\n**Requirements:**\r\n- Valid JSON\r\n- `brief` must be a non-empty markdown string\r\n- Plain text is also accepted — the full file content will be used as the brief\r\n\r\n---\r\n\r\n## Brief Output Format\r\n\r\nThe final brief (`output_{login}.json`) contains a markdown document with six sections:\r\n\r\n| Section | Content |\r\n|---------|---------|\r\n| **Quick Summary** | 2–3 sentences, lead with concrete numbers |\r\n| **Highlights** | 2–4 bullets, one data point each |\r\n| **Areas to Explore** | 2–3 open-ended questions for the 1-on-1 |\r\n| **Patterns Worth Noting** | 1–3 factual behavioral observations |\r\n| **Score Summary** | Markdown table — Dimension / Score / Confidence / Signal. Emoji encouraged in Confidence column. |\r\n| **Suggested Focus** | One paragraph on the most useful 1-on-1 theme |\r\n\r\nExample Score Summary table:\r\n\r\n| Dimension | Score | Confidence | Signal |\r\n|-----------|-------|------------|--------|\r\n| Velocity | 16/20 | ✅ High | 10 PRs merged, 3 active weeks |\r\n| PR Quality | 14/20 | ✅ High | Avg 320 lines, 2 large PRs flagged |\r\n| Review Participation | 8/20 | ⚠️ Medium | 3 reviews given in window |\r\n| Collaboration | 12/20 | ✅ High | 4 repos, 3 reviewers per PR avg |\r\n| Consistency | 10/20 | 🔴 Low | 1 of 3 weeks inactive |\r\n\r\n---\r\n\r\n## Artifacts\r\n\r\nAll artifacts are written to `.pullstar/` (gitignored, never committed).\r\n\r\n| File | Written by | Sent to AI? |\r\n|------|------------|-------------|\r\n| `ingest_{login}.json` | `ingest.py` | ❌ No |\r\n| `score_{login}.json` | `score.py` | ❌ No |\r\n| `llm_input_{login}.json` | `agent_prepare_1on1.py` | ✅ Yes |\r\n| `llm_output_{login}.json` | Agent | ❌ No |\r\n| `output_{login}.json` | `agent_finalize_1on1.py` | ❌ No |\r\n\r\n---\r\n\r\n## Troubleshooting\r\n\r\n**\"GitHub rejected the PR search query (422)\"**\r\nUse a classic PAT — fine-grained PATs cannot search across arbitrary users.\r\n\r\n**\"GitHub rate limit hit\"**\r\nAuthenticated: 5000 req/hr. Unauthenticated: 60 req/hr. Set `GITHUB_TOKEN`.\r\n\r\n**Slow ingestion on high-activity users**\r\nUse `--max-results 10` to cap iteration. Default is 20.\r\n\r\n**GraphQL errors**\r\nUse `--api-mode rest` to fall back to the legacy REST API.\r\n\r\n---\r\n\r\n## For Agent Developers\r\n\r\n### Deterministic Pattern (Mandatory)\r\n\r\nThe brief pipeline is fully deterministic. There is exactly one correct execution path:\r\n\r\n```\r\nexec(run_brief.py) → read(llm_input) → write(llm_output) → exec(agent_finalize) → read(output/quality gate)\r\n```\r\n\r\n**❌ Never spawn sub-agents for this pipeline.** The agent itself performs the LLM inference step — delegating to a sub-agent is redundant, adds latency, and creates thrash. The pipeline completes in 5 tool calls. If you're tempted to spawn a sub-agent, ask yourself: \"Am I running a Python script or doing LLM inference?\" If the answer is \"Python script,\" use `exec`. If the answer is \"LLM inference,\" do it inline.\r\n\r\n**Recovery:** If `run_brief.py` exits non-zero, the GitHub user likely doesn't exist or the token is invalid. Respond with the graceful fallback message; do not retry or spawn alternative paths.\r\n\r\n---\r\n\r\n## License\r\n\r\nMIT — See source repository for full license text.\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn74sjz5m0z36x7fz1vcsh3xrs85phv2\",\n  \"slug\": \"pullstar-1on1\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1787529755036\n}\n\nFile v1.0.3:skill-card.md\n\n## Description:\n\nGenerate a 1-on-1 brief from GitHub activity using a deterministic five-step agent pipeline.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jacksync](https://clawhub.ai/user/jacksync)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nEngineering managers and team leads use this skill to turn an engineer's GitHub pull request and review activity into a concise preparation brief for a 1-on-1. It supports data-backed conversation preparation without presenting the result as a performance review.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill handles GitHub tokens and can read repositories visible to the configured token.\n\nMitigation: Use a fine-grained token where possible, or a narrowly scoped classic token with GITHUB_ORG set to limit ingestion scope.\n\nRisk: PR insights mode may send private pull request discussion text to the configured LLM provider.\n\nMitigation: Leave PR insights disabled unless raw PR discussions are appropriate for the provider, and review llm_input_<login>.json before inference.\n\nRisk: Local .pullstar artifacts may contain private engineering activity data.\n\nMitigation: Review and delete generated .pullstar artifacts when they may contain private data.\n\nRisk: Runtime dependencies may change behavior if installed without version pinning.\n\nMitigation: Use an isolated Python environment with pinned dependencies where possible.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jacksync/skills/pullstar-1on1)\n- [Publisher profile](https://clawhub.ai/user/jacksync)\n- [GitHub classic personal access tokens](https://github.com/settings/tokens)\n- [GitHub fine-grained personal access tokens](https://github.com/settings/personal-access-tokens)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, JSON, Shell commands, Guidance]\n\n**Output Format:** [Markdown brief embedded in JSON artifacts, with command guidance for the agent workflow]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Writes local .pullstar artifacts for ingest, scoring, LLM input, LLM output, and final output; PR insights mode may include bounded raw PR discussion excerpts.]\n\n## Skill Version(s):\n\n1.0.3 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.0.3:brief_v1.txt\n\nYou are an engineering leadership intelligence tool. Your output is read by an engineering manager immediately before a 1-on-1 with a direct report. The manager is technically competent and time-pressed.\n\nYour job: convert GitHub activity scores and signals into a preparation brief the manager can scan in under 2 minutes. Every sentence must be usable — either as context the manager didn't have, a question worth asking, or a pattern worth noticing.\n\n---\n\nWHAT MAKES A BRIEF USEFUL:\n\n1. Specificity. Reference actual numbers: \"14 PRs merged\" not \"active contributor.\"\n\n2. At least one non-obvious observation. Don't just restate the dimension scores. Look for combinations — a dimension that contradicts another, a signal that's unusual given the other signals, or a pattern that only appears when you look across the full picture. If the data doesn't support a non-obvious insight, skip it rather than inventing one.\n\n3. Calibrated uncertainty. If confidence is low or data volume is small, say so clearly in one sentence and move on. Don't pad the brief to compensate for thin data.\n\n4. No inferred context. You don't know: sprint goals, team norms, on-call rotations, personal circumstances, what the manager already knows, or why any number is what it is. Don't guess.\n\n---\n\nTONE:\n\n- Practical, not corporate. Write like a sharp colleague briefing a peer, not a performance review.\n- Neutral, not cheerful. \"3 of 12 PRs had descriptions\" is better than \"shows room for growth in documentation.\"\n- Direct, not hedging. One precise sentence beats three careful ones.\n- Highlights must contain only positive or clearly constructive strengths.\n- Reserve concerns, asymmetries, and coaching topics for Areas to Explore or Patterns Worth Noting.\n- Do not over-index on a single metric unless it is clearly dominant and unusual.\n- When identifying a possible concern, acknowledge plausible contextual explanations when appropriate.\n\n---\n\nANTI-PATTERNS — never do these:\n\n- Open any section with \"In this period...\" or \"Over the past X days...\"\n- Write generic bullets: \"Consistent contributor,\" \"Active team member,\" \"Good reviewer\"\n- Repeat the same data point across multiple sections\n- Turn Areas to Explore into leading questions that imply a specific problem (\"Have you considered improving your PR descriptions?\")\n- Expand the Score Summary beyond a compact reference table\n- Tell the engineer what they \"should\" do, even indirectly\n- Invent patterns the data doesn't support\n\n---\n\nOUTPUT — produce exactly these six sections in this order, in markdown. Do not add extra sections.\n\n## Quick Summary\n2-3 sentences. Lead with the most concrete number. Answer: what did this engineer ship and how engaged were they? If there is a non-obvious combination in the data worth flagging, include it here.\n\n## Highlights\n2-4 bullets. One specific data point per bullet. Draw signals from at least two different dimensions — don't cluster around one.\n\n## Areas to Explore\n2-3 open-ended questions. Derive from flags, low-confidence dimensions, or dimension combinations that raise a genuine question. Each question should be one the manager is glad to have — not one that makes the engineer feel accused of something. The engineer may have a completely valid reason; the question is what matters, not a presumed answer.\n\n## Patterns Worth Noting\n1-3 short factual observations. These should be things a manager might not notice from a single number alone — a behavioral tendency, a contrast between dimensions, or something stable across the window. Neutral tone. No judgment.\n\n## Score Summary\nA compact markdown table only. Columns: Dimension | Score | Confidence | Signal. One row per dimension. Nothing else in this section.\n\n## Suggested Focus for This 1-on-1\nOne paragraph, 3-5 sentences. Given everything in the data, what theme would make this 1-on-1 most useful? Be specific about the topic, not the script. Do not prescribe what the manager should say, ask, or conclude.\n\n---\n\nLENGTH: 500-1500 words total. Shorter is better if the data supports it.\n\n---\n\nWHEN PR CONTEXT IS PROVIDED (=== PR CONTEXT (OPT-IN) === section):\n\nThis section contains raw review and comment excerpts from a bounded sample of the engineer's recent PRs.\nUse it to inform observations about collaboration style, review dynamics, and feedback patterns.\n\nRules:\n- Do NOT quote review or comment text directly in the brief\n- Do NOT turn the brief into a code review summary or technical analysis\n- Do NOT highlight specific technical suggestions from reviewers\n- Bot reviews and comments are labeled as (bot) — use them only to understand the review environment, not to assess the engineer's work quality\n- Focus on: how feedback flows, reviewer engagement patterns, communication dynamics, iteration behavior\n- If PR context adds nothing beyond what the dimension scores already show, omit it from the brief entirely\n\nArchive v1.0.2: 11 files, 37179 bytes\n\nFiles: brief_v1.txt (4911b), models.py (4027b), prompt_builder.py (14373b), run_brief.py (4943b), scripts/agent_finalize_1on1.py (6734b), scripts/agent_prepare_1on1.py (3668b), scripts/ingest.py (36086b), scripts/score.py (30453b), skill-card.md (2111b), SKILL.md (8103b), _meta.json (132b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: skills\ndescription: Generate a ready-to-use 1-on-1 brief for any engineer on your team — from their GitHub activity, in seconds. Spots patterns like high output but low review participation, large PR sizes suggesting batching, and cross-repo collaboration signals.\nlicense: MIT\n---\n\n## Overview\n\nPullStar fetches GitHub activity for one engineer (PRs authored, reviews given), runs a **deterministic local scoring engine** across five dimensions, and prepares an LLM input payload. The **agent** then performs LLM inference and finalizes the brief.\n\n\n**Quickstart:** \n\n    run_brief.py --login steipete --pr-insights --days 7\n    Read llm_input_steipete.json, do the LLM inference, present the brief\n\n\n\n**Data Flow Summary:**\n\n| Step | What runs | External calls |\n|------|-----------|----------------|\n| Ingest | `run_brief.py` → `ingest.py` | GitHub API |\n| Score | `run_brief.py` → `score.py` | None |\n| Prepare | `run_brief.py` → `agent_prepare_1on1.py` | None |\n| **Agent inference** | **Agent calls LLM** | **LLM provider** |\n| Finalize | Agent runs `agent_finalize_1on1.py` | None |\n\n**⚠️ Important:** Steps 1–3 run locally. Only the LLM inference step (step 4) sends data to your AI provider.\n\n---\n\n## Requirements\n\n- Python 3.11+\n- Install dependencies: `pip install PyGithub python-dotenv requests`\n- A GitHub personal access token (see Security section below)\n\n---\n\n## Security & Privacy\n\n### Token Scope\n\n| Option | Where to create | Best for |\n|--------|----------------|----------|\n| Classic PAT (`repo` scope) | https://github.com/settings/tokens | Cross-user search, org-wide ingestion |\n| Fine-grained PAT | https://github.com/settings/personal-access-tokens | Your own repos only |\n\n> Fine-grained PATs cannot search across arbitrary users. Use a classic PAT for org-wide briefs.\n\nSet `GITHUB_ORG` to narrow search to one organization.\n\n### Token Resolution Order\n\nSecrets are resolved using layered lookup — first match wins:\n\n1. `--github-token` CLI flag (override/debug only — never logged)\n2. `GITHUB_TOKEN` environment variable\n3. `~/.pullstar/credentials` (key=value format)\n4. `.env` in the skill directory\n\n### Data Privacy by Mode\n\n**Default (no `--pr-insights`):**\n- Only aggregated statistics and scores sent to LLM\n- No raw PR text, comments, or review bodies included\n\n**PR Insights (`--pr-insights`):**\n- Bounded raw PR discussion text packaged into the LLM prompt\n- Bounded to 5 PRs, 3 reviews/comments each, 600 char limit per item\n- Review `llm_input_{login}.json` before inference if you have privacy concerns\n\n---\n\n## Configuration\n\n### `.env`\n\n| Variable | Required | Description |\n|----------|----------|-------------|\n| `GITHUB_TOKEN` | Recommended | Classic PAT with `repo` scope. Omit for unauthenticated access (60 req/hr). |\n| `GITHUB_ORG` | No | Scope ingestion to one org. |\n\n---\n\n## Usage\n\n### Standard run\n\n```bash\npython run_brief.py --login jsmith\n```\n\n### With PR insights\n\n```bash\npython run_brief.py --login jsmith --pr-insights\n```\n\n### Common options\n\n```bash\npython run_brief.py --login jsmith --days 14          # wider lookback (default: 5)\npython run_brief.py --login jsmith --max-results 10   # faster on high-activity users (default: 20)\npython run_brief.py --login jsmith --api-mode rest    # force REST API (default: graphql)\n```\n\n### All options\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--login` | required | Engineer GitHub login |\n| `--days` | `5` | Lookback window in days |\n| `--pr-insights` | off | Include PR review/comment context in LLM prompt |\n| `--max-results` | `20` | Max search results to iterate (lower = faster) |\n| `--api-mode` | `graphql` | `graphql` or `rest` |\n| `--output-dir` | `.pullstar` | Directory for all artifacts |\n| `--github-token` | — | Override/debug only. Prefer `.env`. |\n\n---\n\n## Agent Flow\n\n`run_brief.py` runs the deterministic pipeline (ingest → score → prepare) and then prints an explicit instruction block. The agent must complete the final two steps:\n\n```\n============================================================\nPIPELINE COMPLETE — AGENT ACTION REQUIRED\n============================================================\n\n  1. Read:   .pullstar/llm_input_jsmith.json\n  2. Extract the \"system\" and \"user\" fields\n  3. Call your LLM with those as the system prompt and user message\n  4. Write the response to .pullstar/llm_output_jsmith.json\n  5. Run:    python scripts/agent_finalize_1on1.py --login jsmith\n```\n\n---\n\n## Agent JSON Contract\n\n### Input (from `run_brief.py`)\n\nFile: `.pullstar/llm_input_{login}.json`\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `system` | string | System prompt with instructions |\n| `user` | string | User message with engineer data and scores |\n| `metadata` | object | Version, timestamps, total score, confidence |\n\n### Output (from agent)\n\nFile: `.pullstar/llm_output_{login}.json`\n\n```json\n{\n  \"version\":        \"1.0\",\n  \"engineer_login\": \"jsmith\",\n  \"brief\":          \"## Quick Summary\\n...\"\n}\n```\n\n**Requirements:**\n- Valid JSON\n- `brief` must be a non-empty markdown string\n- Plain text is also accepted — the full file content will be used as the brief\n\n---\n\n## Brief Output Format\n\nThe final brief (`output_{login}.json`) contains a markdown document with six sections:\n\n| Section | Content |\n|---------|---------|\n| **Quick Summary** | 2–3 sentences, lead with concrete numbers |\n| **Highlights** | 2–4 bullets, one data point each |\n| **Areas to Explore** | 2–3 open-ended questions for the 1-on-1 |\n| **Patterns Worth Noting** | 1–3 factual behavioral observations |\n| **Score Summary** | Markdown table — Dimension / Score / Confidence / Signal. Emoji encouraged in Confidence column. |\n| **Suggested Focus** | One paragraph on the most useful 1-on-1 theme |\n\nExample Score Summary table:\n\n| Dimension | Score | Confidence | Signal |\n|-----------|-------|------------|--------|\n| Velocity | 16/20 | ✅ High | 10 PRs merged, 3 active weeks |\n| PR Quality | 14/20 | ✅ High | Avg 320 lines, 2 large PRs flagged |\n| Review Participation | 8/20 | ⚠️ Medium | 3 reviews given in window |\n| Collaboration | 12/20 | ✅ High | 4 repos, 3 reviewers per PR avg |\n| Consistency | 10/20 | 🔴 Low | 1 of 3 weeks inactive |\n\n---\n\n## Artifacts\n\nAll artifacts are written to `.pullstar/` (gitignored, never committed).\n\n| File | Written by | Sent to AI? |\n|------|------------|-------------|\n| `ingest_{login}.json` | `ingest.py` | ❌ No |\n| `score_{login}.json` | `score.py` | ❌ No |\n| `llm_input_{login}.json` | `agent_prepare_1on1.py` | ✅ Yes |\n| `llm_output_{login}.json` | Agent | ❌ No |\n| `output_{login}.json` | `agent_finalize_1on1.py` | ❌ No |\n\n---\n\n## Troubleshooting\n\n**\"GitHub rejected the PR search query (422)\"**\nUse a classic PAT — fine-grained PATs cannot search across arbitrary users.\n\n**\"GitHub rate limit hit\"**\nAuthenticated: 5000 req/hr. Unauthenticated: 60 req/hr. Set `GITHUB_TOKEN`.\n\n**Slow ingestion on high-activity users**\nUse `--max-results 10` to cap iteration. Default is 20.\n\n**GraphQL errors**\nUse `--api-mode rest` to fall back to the legacy REST API.\n\n---\n\n## For Agent Developers\n\n### Subagent Best Practices (Don't Be a Nervous Parent)\n\nWhen using `sessions_spawn` for the LLM inference step:\n\n**✅ Do:**\n- Spawn once with the task to read `llm_input_{login}.json` and write `llm_output_{login}.json`\n- Trust the \"auto-announces on completion\" behavior — you'll get a completion event\n- Handle the result when the event arrives\n\n**❌ Don't:**\n- Poll `subagents list` in a tight loop waiting for completion\n- Spawn multiple subagents for the same task\n- Check status every few seconds — it's wasteful\n\n**Why:** Subagents are lightweight (no full OpenClaw context, isolated environment), but polling defeats the purpose of push-based completion. The system will tell you when it's done.\n\n**Recovery:** If a subagent fails, you can always generate the brief directly in the main session — the JSON contract is simple and documented above.\n\n---\n\n## License\n\nMIT — See source repository for full license text.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn74sjz5m0z36x7fz1vcsh3xrs85phv2\",\n  \"slug\": \"pullstar-1on1\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1780346656712\n}\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nGenerate a ready-to-use 1-on-1 brief for any engineer on your team from their GitHub activity, including patterns such as high output with low review participation, large PR sizes, and cross-repo collaboration signals. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jacksync](https://clawhub.ai/user/jacksync) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nEngineering managers use this skill to prepare for 1-on-1 meetings by turning a direct report's GitHub activity into a concise, scan-ready brief. The workflow gathers scoped GitHub activity, scores contribution patterns locally, prepares an LLM input, and finalizes a markdown brief. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill requires a GitHub token and may access private repository activity depending on token scope. <br>\nMitigation: Use the narrowest GitHub token scope that still works and set GITHUB_ORG where possible to limit ingestion scope. <br>\nRisk: Generated .pullstar artifacts may contain private repository activity and PR discussion excerpts. <br>\nMitigation: Treat .pullstar artifacts as sensitive local files and review llm_input before sending it to an AI provider, especially when PR insights are enabled. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill release page](https://clawhub.ai/jacksync/pullstar-1on1) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [markdown, json, shell commands, guidance] <br>\n**Output Format:** [Markdown brief and JSON artifacts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Writes local .pullstar artifacts, including LLM input, LLM output, and final brief JSON.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.2:brief_v1.txt\n\nYou are an engineering leadership intelligence tool. Your output is read by an engineering manager immediately before a 1-on-1 with a direct report. The manager is technically competent and time-pressed.\n\nYour job: convert GitHub activity scores and signals into a preparation brief the manager can scan in under 2 minutes. Every sentence must be usable — either as context the manager didn't have, a question worth asking, or a pattern worth noticing.\n\n---\n\nWHAT MAKES A BRIEF USEFUL:\n\n1. Specificity. Reference actual numbers: \"14 PRs merged\" not \"active contributor.\"\n\n2. At least one non-obvious observation. Don't just restate the dimension scores. Look for combinations — a dimension that contradicts another, a signal that's unusual given the other signals, or a pattern that only appears when you look across the full picture. If the data doesn't support a non-obvious insight, skip it rather than inventing one.\n\n3. Calibrated uncertainty. If confidence is low or data volume is small, say so clearly in one sentence and move on. Don't pad the brief to compensate for thin data.\n\n4. No inferred context. You don't know: sprint goals, team norms, on-call rotations, personal circumstances, what the manager already knows, or why any number is what it is. Don't guess.\n\n---\n\nTONE:\n\n- Practical, not corporate. Write like a sharp colleague briefing a peer, not a performance review.\n- Neutral, not cheerful. \"3 of 12 PRs had descriptions\" is better than \"shows room for growth in documentation.\"\n- Direct, not hedging. One precise sentence beats three careful ones.\n- Highlights must contain only positive or clearly constructive strengths.\n- Reserve concerns, asymmetries, and coaching topics for Areas to Explore or Patterns Worth Noting.\n- Do not over-index on a single metric unless it is clearly dominant and unusual.\n- When identifying a possible concern, acknowledge plausible contextual explanations when appropriate.\n\n---\n\nANTI-PATTERNS — never do these:\n\n- Open any section with \"In this period...\" or \"Over the past X days...\"\n- Write generic bullets: \"Consistent contributor,\" \"Active team member,\" \"Good reviewer\"\n- Repeat the same data point across multiple sections\n- Turn Areas to Explore into leading questions that imply a specific problem (\"Have you considered improving your PR descriptions?\")\n- Expand the Score Summary beyond a compact reference table\n- Tell the engineer what they \"should\" do, even indirectly\n- Invent patterns the data doesn't support\n\n---\n\nOUTPUT — produce exactly these six sections in this order, in markdown. Do not add extra sections.\n\n## Quick Summary\n2-3 sentences. Lead with the most concrete number. Answer: what did this engineer ship and how engaged were they? If there is a non-obvious combination in the data worth flagging, include it here.\n\n## Highlights\n2-4 bullets. One specific data point per bullet. Draw signals from at least two different dimensions — don't cluster around one.\n\n## Areas to Explore\n2-3 open-ended questions. Derive from flags, low-confidence dimensions, or dimension combinations that raise a genuine question. Each question should be one the manager is glad to have — not one that makes the engineer feel accused of something. The engineer may have a completely valid reason; the question is what matters, not a presumed answer.\n\n## Patterns Worth Noting\n1-3 short factual observations. These should be things a manager might not notice from a single number alone — a behavioral tendency, a contrast between dimensions, or something stable across the window. Neutral tone. No judgment.\n\n## Score Summary\nA compact markdown table only. Columns: Dimension | Score | Confidence | Signal. One row per dimension. Nothing else in this section.\n\n## Suggested Focus for This 1-on-1\nOne paragraph, 3-5 sentences. Given everything in the data, what theme would make this 1-on-1 most useful? Be specific about the topic, not the script. Do not prescribe what the manager should say, ask, or conclude.\n\n---\n\nLENGTH: 500-1500 words total. Shorter is better if the data supports it.\n\n---\n\nWHEN PR CONTEXT IS PROVIDED (=== PR CONTEXT (OPT-IN) === section):\n\nThis section contains raw review and comment excerpts from a bounded sample of the engineer's recent PRs.\nUse it to inform observations about collaboration style, review dynamics, and feedback patterns.\n\nRules:\n- Do NOT quote review or comment text directly in the brief\n- Do NOT turn the brief into a code review summary or technical analysis\n- Do NOT highlight specific technical suggestions from reviewers\n- Bot reviews and comments are labeled as (bot) — use them only to understand the review environment, not to assess the engineer's work quality\n- Focus on: how feedback flows, reviewer engagement patterns, communication dynamics, iteration behavior\n- If PR context adds nothing beyond what the dimension scores already show, omit it from the brief entirely\n\nArchive v1.0.1: 10 files, 32095 bytes\n\nFiles: brief_v1.txt (4911b), models.py (4027b), prompt_builder.py (14373b), scripts/agent_finalize_1on1.py (6734b), scripts/agent_prepare_1on1.py (3668b), scripts/ingest.py (21766b), scripts/score.py (30453b), skill-card.md (2501b), SKILL.md (7063b), _meta.json (132b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: pullstar-1on1\ndescription: Generate a ready-to-use 1-on-1 brief for any engineer on your team — from their GitHub activity, in seconds. Spots patterns like high output but low review participation, large PR sizes suggesting batching, and cross-repo collaboration signals.\nsource: https://github.com/pullstar-ai/pullstar\nhomepage: https://github.com/pullstar-ai/pullstar\n---\n\n## Overview\n\nPullStar fetches GitHub activity for one engineer (PRs authored, reviews given), runs a **deterministic local scoring engine** across five dimensions, and prepares an LLM input payload. An **external agent** (your configured AI provider) generates the final structured brief.\n\n**Data Flow Summary:**\n| Step | Location | Data Sent |\n|------|----------|-----------|\n| Ingest | Local | GitHub API only |\n| Score | Local | No external calls |\n| Prepare | Local | No external calls |\n| **Agent inference** | **External** | **LLM input payload sent to your AI provider** |\n| Finalize | Local | No external calls |\n\n**⚠️ Important:** The final brief generation step sends data to your configured AI provider. All other steps run locally on your machine.\n\n---\n\n## Requirements\n\n- Python 3.11+\n- Install dependencies: `pip install PyGithub python-dotenv`\n- A GitHub personal access token (see Security section below)\n\n---\n\n## Security & Privacy\n\n### Token Scope (Important)\n\nThis skill requires a GitHub token to read repository activity. You have two options:\n\n**Option A: Fine-grained PAT (Recommended)**\n- Create at: https://github.com/settings/personal-access-tokens\n- Repository permissions: Read access to code, issues, and pull requests\n- Limit to specific repositories or organizations\n- **Note:** Fine-grained PATs cannot search across arbitrary users — use only for your own repos\n\n**Option B: Classic PAT (Broader access)**\n- Create at: https://github.com/settings/tokens\n- Scope: `repo` (full read access to private repos)\n- **⚠️ Warning:** This grants broad access. Set `GITHUB_ORG` to limit scope to one organization.\n\n### Token Security Best Practices\n\n| Practice | Why |\n|----------|-----|\n| Use a dedicated token | Don't reuse personal high-privilege tokens |\n| Set `GITHUB_ORG` | Narrows search to one org instead of all accessible repos |\n| Store in `.env` or `~/.pullstar/credentials` | Never commit tokens to git |\n| Revoke when done | Limit exposure window |\n| Use fine-grained PAT when possible | Least-privilege access |\n\n### Data Privacy by Mode\n\n**Default Mode (no `--pr_insights`):**\n- ✅ Only aggregated statistics sent to AI provider\n- ✅ No raw PR descriptions, comments, or review text included\n- ✅ Repository names and PR titles may be included\n\n**PR Insights Mode (`--pr_insights`):**\n- ⚠️ Raw PR discussion text (reviews, comments) packaged into LLM prompt\n- ⚠️ This text may contain sensitive information or untrusted input from bots/humans\n- ✅ Bounded to 5 PRs, 3 reviews/comments each, with character limits\n\n**Recommendation:** Review `.pullstar/llm_input_{login}.json` before running agent inference if you have privacy concerns.\n\n---\n\n## Configuration\n\n### Secrets — `.env`\n\n`.env` contains **secrets only**. Never commit it.\n\n| Variable | Required | Description |\n|----------|----------|-------------|\n| `GITHUB_TOKEN` | Yes | GitHub PAT (fine-grained or classic) |\n| `GITHUB_ORG` | No | Scope ingestion to one org. Omit to search all accessible repos. |\n\n### Secret Resolution Order\n\nSecrets are resolved using layered lookup:\n1. CLI override (highest priority; debug/testing only)\n2. Environment variable (includes `.env`)\n3. `~/.pullstar/credentials` (central credentials file)\n4. `.env` (project-local, final fallback)\n\n---\n\n## Usage Flow\n\n```bash\n# 1. Ingest GitHub activity\npython scripts/ingest.py --login jsmith\n\n# 2. Score the profile (local, deterministic)\npython scripts/score.py --login jsmith\n\n# 3. Prepare the LLM input artifact (local, no AI call)\npython scripts/agent_prepare_1on1.py --login jsmith\n\n# 4. External agent reads .pullstar/llm_input_jsmith.json\n#    and writes .pullstar/llm_output_jsmith.json with schema:\n#    { \"version\": \"1.0\", \"engineer_login\": \"jsmith\", \"brief\": \"## Quick Summary\\n...\" }\n\n# 5. Finalize — merge agent output into final artifact\npython scripts/agent_finalize_1on1.py --login jsmith\n```\n\n### Artifacts\n\n| File | Written by | Contains | Sent to AI? |\n|------|------------|----------|-------------|\n| `ingest_{login}.json` | `ingest.py` | Raw GitHub activity, PR details | ❌ No |\n| `score_{login}.json` | `score.py` | Dimension scores, signals, flags | ❌ No |\n| `llm_input_{login}.json` | `agent_prepare_1on1.py` | LLM prompt payload | ✅ Yes |\n| `llm_output_{login}.json` | External agent | Generated brief | ❌ No |\n| `output_{login}.json` | `agent_finalize_1on1.py` | Final brief + profile | ❌ No |\n\nAll artifacts written to `.pullstar/` (gitignored).\n\n---\n\n## PR Insights Mode (Optional)\n\n```bash\npython scripts/ingest.py --login jsmith --pr_insights\n```\n\n**What it does:**\n- Collects review and comment detail per PR\n- Packages bounded raw context into LLM prompt\n- Enables richer collaboration pattern analysis\n\n**Bounds (safety limits):**\n- Max 5 PRs included in context block\n- Max 3 reviews per PR (non-empty body only)\n- Max 3 comments per PR (non-empty body only)\n- Review text truncated to 600 chars\n- Comment text truncated to 500 chars\n\n**⚠️ Security Warning:**\n- PR comments/reviews may contain untrusted input\n- Bot messages are labeled but still included\n- Sensitive repository discussion may be sent to your AI provider\n- Review `llm_input_{login}.json` before agent inference\n\n**When to use:** Only when you need deeper collaboration insights and have reviewed the privacy implications.\n\n---\n\n## Agent JSON Contract\n\n### Input (from PullStar)\n\nFile: `.pullstar/llm_input_{login}.json`\n\nContains:\n- `system`: System prompt with instructions\n- `user`: User message with engineer data\n- `metadata`: Version, timestamps, scores\n\n### Output (from Agent)\n\nFile: `.pullstar/llm_output_{login}.json`\n\nRequired schema:\n```json\n{\n  \"version\": \"1.0\",\n  \"engineer_login\": \"jsmith\",\n  \"brief\": \"## Quick Summary\\n...\"\n}\n```\n\n**Requirements:**\n- Valid JSON (no trailing commas)\n- `brief` must be non-empty markdown string\n- Plain text also accepted (full file content used as brief)\n\n---\n\n## Source & Provenance\n\n- **Repository:** https://github.com/pullstar-ai/pullstar\n- **Full Version:** Standalone CLI, UI, and additional features available at the repo above\n- **Dependencies:** PyGithub, python-dotenv (install from PyPI)\n\n---\n\n## Troubleshooting\n\n**\"GitHub rejected the PR search query (422)\"**\n- Fine-grained PATs cannot search across arbitrary users\n- Use a classic PAT or limit to your own repos\n\n**\"GitHub rate limit hit\"**\n- Default: 5000 req/hr with authenticated token\n- 60 req/hr unauthenticated (not recommended)\n\n**Slow ingestion on high-activity users**\n- Use `--max-results 20` to cap search results\n- Default caps: 20 authored PRs, 20 reviewed PRs\n\n---\n\n## License\n\nMIT — See source repository for full license text.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74sjz5m0z36x7fz1vcsh3xrs85phv2\",\n  \"slug\": \"pullstar-1on1\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1778013925878\n}\n\nFile v1.0.1:skill-card.md\n\n## Description: <br>\nGenerates a ready-to-use 1-on-1 preparation brief for an engineering manager from an engineer's GitHub activity, local scoring signals, and optional bounded PR discussion context. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jacksync](https://clawhub.ai/user/jacksync) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nEngineering managers use this skill to convert one engineer's GitHub activity into a concise brief before a 1-on-1. The workflow gathers repository activity, scores collaboration and delivery signals locally, prepares an LLM input payload, and finalizes the generated markdown brief into a local JSON artifact. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: A broad GitHub token can expose more repository data than the brief requires. <br>\nMitigation: Use a dedicated read-only, fine-grained GitHub token limited to the needed repositories or organization, and set GITHUB_ORG when possible. <br>\nRisk: Repository names, PR titles, and optional raw PR discussion context may be included in the LLM input sent to the user's configured AI provider. <br>\nMitigation: Review .pullstar/llm_input_{login}.json before agent inference, and avoid --pr_insights unless raw PR discussions are appropriate to store locally and send externally. <br>\nRisk: Local .pullstar artifacts can retain sensitive repository activity or generated brief content. <br>\nMitigation: Review, protect, or delete .pullstar artifacts according to the team's data retention policy. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jacksync/pullstar-1on1) <br>\n- [Project homepage](https://github.com/pullstar-ai/pullstar) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, json, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown brief and local JSON artifacts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Final brief follows a fixed six-section markdown structure; intermediate and final artifacts are written under .pullstar/.] <br>\n\n## Skill Version(s): <br>\n1.0.1 (source: ClawHub release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.1:brief_v1.txt\n\nYou are an engineering leadership intelligence tool. Your output is read by an engineering manager immediately before a 1-on-1 with a direct report. The manager is technically competent and time-pressed.\n\nYour job: convert GitHub activity scores and signals into a preparation brief the manager can scan in under 2 minutes. Every sentence must be usable — either as context the manager didn't have, a question worth asking, or a pattern worth noticing.\n\n---\n\nWHAT MAKES A BRIEF USEFUL:\n\n1. Specificity. Reference actual numbers: \"14 PRs merged\" not \"active contributor.\"\n\n2. At least one non-obvious observation. Don't just restate the dimension scores. Look for combinations — a dimension that contradicts another, a signal that's unusual given the other signals, or a pattern that only appears when you look across the full picture. If the data doesn't support a non-obvious insight, skip it rather than inventing one.\n\n3. Calibrated uncertainty. If confidence is low or data volume is small, say so clearly in one sentence and move on. Don't pad the brief to compensate for thin data.\n\n4. No inferred context. You don't know: sprint goals, team norms, on-call rotations, personal circumstances, what the manager already knows, or why any number is what it is. Don't guess.\n\n---\n\nTONE:\n\n- Practical, not corporate. Write like a sharp colleague briefing a peer, not a performance review.\n- Neutral, not cheerful. \"3 of 12 PRs had descriptions\" is better than \"shows room for growth in documentation.\"\n- Direct, not hedging. One precise sentence beats three careful ones.\n- Highlights must contain only positive or clearly constructive strengths.\n- Reserve concerns, asymmetries, and coaching topics for Areas to Explore or Patterns Worth Noting.\n- Do not over-index on a single metric unless it is clearly dominant and unusual.\n- When identifying a possible concern, acknowledge plausible contextual explanations when appropriate.\n\n---\n\nANTI-PATTERNS — never do these:\n\n- Open any section with \"In this period...\" or \"Over the past X days...\"\n- Write generic bullets: \"Consistent contributor,\" \"Active team member,\" \"Good reviewer\"\n- Repeat the same data point across multiple sections\n- Turn Areas to Explore into leading questions that imply a specific problem (\"Have you considered improving your PR descriptions?\")\n- Expand the Score Summary beyond a compact reference table\n- Tell the engineer what they \"should\" do, even indirectly\n- Invent patterns the data doesn't support\n\n---\n\nOUTPUT — produce exactly these six sections in this order, in markdown. Do not add extra sections.\n\n## Quick Summary\n2-3 sentences. Lead with the most concrete number. Answer: what did this engineer ship and how engaged were they? If there is a non-obvious combination in the data worth flagging, include it here.\n\n## Highlights\n2-4 bullets. One specific data point per bullet. Draw signals from at least two different dimensions — don't cluster around one.\n\n## Areas to Explore\n2-3 open-ended questions. Derive from flags, low-confidence dimensions, or dimension combinations that raise a genuine question. Each question should be one the manager is glad to have — not one that makes the engineer feel accused of something. The engineer may have a completely valid reason; the question is what matters, not a presumed answer.\n\n## Patterns Worth Noting\n1-3 short factual observations. These should be things a manager might not notice from a single number alone — a behavioral tendency, a contrast between dimensions, or something stable across the window. Neutral tone. No judgment.\n\n## Score Summary\nA compact markdown table only. Columns: Dimension | Score | Confidence | Signal. One row per dimension. Nothing else in this section.\n\n## Suggested Focus for This 1-on-1\nOne paragraph, 3-5 sentences. Given everything in the data, what theme would make this 1-on-1 most useful? Be specific about the topic, not the script. Do not prescribe what the manager should say, ask, or conclude.\n\n---\n\nLENGTH: 500-1500 words total. Shorter is better if the data supports it.\n\n---\n\nWHEN PR CONTEXT IS PROVIDED (=== PR CONTEXT (OPT-IN) === section):\n\nThis section contains raw review and comment excerpts from a bounded sample of the engineer's recent PRs.\nUse it to inform observations about collaboration style, review dynamics, and feedback patterns.\n\nRules:\n- Do NOT quote review or comment text directly in the brief\n- Do NOT turn the brief into a code review summary or technical analysis\n- Do NOT highlight specific technical suggestions from reviewers\n- Bot reviews and comments are labeled as (bot) — use them only to understand the review environment, not to assess the engineer's work quality\n- Focus on: how feedback flows, reviewer engagement patterns, communication dynamics, iteration behavior\n- If PR context adds nothing beyond what the dimension scores already show, omit it from the brief entirely\n\nArchive v1.0.0: 9 files, 29978 bytes\n\nFiles: brief_v1.txt (4911b), models.py (4027b), prompt_builder.py (14373b), scripts/agent_finalize_1on1.py (6734b), scripts/agent_prepare_1on1.py (3668b), scripts/ingest.py (21766b), scripts/score.py (30453b), SKILL.md (4986b), _meta.json (132b)\n\nFile v1.0.0:SKILL.md\n\n---\r\nname:pullstar-1on1\r\ndescription: Skill for Pullstar 1on1 to generate a ready-to-use 1-on-1 brief for any engineer on your team — from their GitHub activity, in seconds.\r\n Spots patterns like:\r\n- High output but low review participation\r\n- Large PR sizes suggesting batching\r\n- Cross-repo collaboration signals\r\n\r\nPullStar fetches GitHub activity for one engineer (PRs authored, reviews given), runs a deterministic scoring engine across five dimensions, and calls your configured AI provider to generate a structured 1-on-1 preparation brief. All data stays on your machine.\r\n\r\nRepo for full version with standalone cli, UI,  and more features: https://github.com/pullstar-ai/pullstar\r\n---\r\n\r\n## Requirements\r\n\r\n- Python 3.11+\r\n- A GitHub **classic** personal access token with `repo` scope\r\n  - Create one at: <https://github.com/settings/tokens>\r\n  - Fine-grained PATs do not support cross-user search — use a classic PAT\r\n\r\n\r\n---\r\n\r\n\r\n---\r\n\r\n## Configuration\r\n\r\n### Secrets — `.env`\r\n\r\n\r\n| Variable | Required | Description |\r\n| --- | --- | --- |\r\n| `GITHUB_TOKEN` | Yes | Classic PAT with `repo` scope |\r\n| `GITHUB_ORG` | No | Scope ingestion to one org. Omit to search all accessible repos. |\r\n|\r\n\r\n### \r\nResolve a secret by name using a layered lookup:\r\n      1. cli_value  — CLI override (highest priority; for debug/testing only)\r\n      2. os.getenv  — environment variable (includes values loaded from .env)\r\n      3. ~/.pullstar/credentials — central credentials file (key=value format)\r\n      4. .env       — project-local .env re-read explicitly as final fallback\r\n\r\n\r\n### Flow\r\n\r\n\r\n# 1. Ingest GitHub activity\r\npython scripts/ingest.py --login jsmith\r\n\r\n# 2. Score the profile\r\npython scripts/score.py --login jsmith\r\n\r\n# 3. Prepare the LLM input artifact (no AI call)\r\npython scripts/agent_prepare_1on1.py --login jsmith\r\n\r\n# 4. External agent reads .pullstar/llm_input_jsmith.json\r\n#    and writes .pullstar/llm_output_jsmith.json with schema:\r\n#    { \"version\": \"1.0\", \"engineer_login\": \"jsmith\", \"brief\": \"## Quick Summary\\n...\" }\r\n\r\n# 5. Finalize — merge agent output into final artifact\r\npython scripts/agent_finalize_1on1.py --login jsmith\r\n\r\n\r\n\r\n\r\n\r\nWrites:\r\n\r\n- `.pullstar/ingest_jsmith.json`\r\n- `.pullstar/score_jsmith.json`\r\n- `.pullstar/llm_input_jsmith.json` (prompt payload the agent reads)\r\n- `.pullstar/llm_output_jsmith.json` (agent must write this)\r\n- `.pullstar/output_jsmith.json` (final — what the UI reads)\r\n\r\n🔴 REQUIRED: JSON Contract\r\n\r\nThe external agent must strictly follow this contract.\r\n\r\nInput (from PullStar)\r\n\r\n.pullstar/llm_input_{login}.json\r\n\r\nThis file contains:\r\n#### Input (from PullStar)\r\n.pullstar/llm_input_{login}.json\r\nThis file contains:\r\n\r\nsystem prompt\r\nuser prompt\r\nmetadata\r\nTreat this as the canonical prompt payload\r\nDo not modify its structure\r\n#### Output (from agent)\r\n\r\n.pullstar/llm_output_{login}.json\r\n\r\nMust be valid JSON with the following shape:\r\n\r\n{\r\n  \"version\": \"1.0\",\r\n  \"engineer_login\": \"steipete\",\r\n  \"brief\": \"## Quick Summary\\n...\"\r\n}\r\n\r\n#### ⚠️ Requirements\r\n\r\n- Output must be valid JSON (no trailing commas, no markdown wrapping)\r\n- brief must be a non-empty markdown string\r\n- Do NOT return plain text, markdown files, or chat logs\r\n- Do NOT change field names\r\n\r\n\r\n## Expected Artifacts\r\nMust be valid JSON. The brief field must contain a non-empty markdown string. This file is the source of truth for the final manager brief in agent mode.\r\n| File | Written by | Contains |\r\n| --- | --- | --- |\r\n| `ingest_{login}.json` | `ingest.py` | Raw GitHub activity, PR details, summary stats |\r\n| `score_{login}.json` | `score.py` | Dimension scores (0–20 each), signals, flags |\r\n| `llm_input_{login}.json` | `generate_brief.py` / `agent_prepare_1on1.py` | Canonical LLM prompt payload (system + user messages) |\r\n| `llm_output_{login}.json` | External agent | Agent-produced brief (agent mode only) |\r\n| `output_{login}.json` | `generate_brief.py` / `agent_finalize_1on1.py` | Final brief + scored profile (what the UI reads) |\r\n\r\nAll artifacts are written to `.pullstar/` — gitignored, never committed.\r\n\r\n---\r\n\r\n## PR Insights (optional enrichment)\r\n\r\nRun `ingest.py` with `--pr_insights` to collect review and comment detail per PR. When present, this raw context is packaged into the LLM prompt so the model can reason about collaboration patterns.\r\n\r\n```bash\r\npython scripts/ingest.py --login jsmith --pr_insights\r\n```\r\n\r\nAdds ~3 API calls per PR (capped at 20 PRs). Safe to omit for faster ingestion.\r\n\r\n---\r\n\r\n\r\n#### Defualt Mode\r\n- Only metadata and aggregated signals are used\r\n- No raw PR descriptions, comments, or review text are sent to any LLM\r\n  \r\n#### --pr_insights mode (opt-in)\r\n\r\n- Bounded raw PR context may be included:\r\n- PR descriptions\r\n- review text\r\n- comment text (including bot messages)\r\n- This data may be sent to the configured LLM provider or external agent\r\n\r\n- This mode is intended for richer insight and is explicitly opt-in.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn74sjz5m0z36x7fz1vcsh3xrs85phv2\",\n  \"slug\": \"pullstar-1on1\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1778012429552\n}\n\nFile v1.0.0:brief_v1.txt\n\nYou are an engineering leadership intelligence tool. Your output is read by an engineering manager immediately before a 1-on-1 with a direct report. The manager is technically competent and time-pressed.\n\nYour job: convert GitHub activity scores and signals into a preparation brief the manager can scan in under 2 minutes. Every sentence must be usable — either as context the manager didn't have, a question worth asking, or a pattern worth noticing.\n\n---\n\nWHAT MAKES A BRIEF USEFUL:\n\n1. Specificity. Reference actual numbers: \"14 PRs merged\" not \"active contributor.\"\n\n2. At least one non-obvious observation. Don't just restate the dimension scores. Look for combinations — a dimension that contradicts another, a signal that's unusual given the other signals, or a pattern that only appears when you look across the full picture. If the data doesn't support a non-obvious insight, skip it rather than inventing one.\n\n3. Calibrated uncertainty. If confidence is low or data volume is small, say so clearly in one sentence and move on. Don't pad the brief to compensate for thin data.\n\n4. No inferred context. You don't know: sprint goals, team norms, on-call rotations, personal circumstances, what the manager already knows, or why any number is what it is. Don't guess.\n\n---\n\nTONE:\n\n- Practical, not corporate. Write like a sharp colleague briefing a peer, not a performance review.\n- Neutral, not cheerful. \"3 of 12 PRs had descriptions\" is better than \"shows room for growth in documentation.\"\n- Direct, not hedging. One precise sentence beats three careful ones.\n- Highlights must contain only positive or clearly constructive strengths.\n- Reserve concerns, asymmetries, and coaching topics for Areas to Explore or Patterns Worth Noting.\n- Do not over-index on a single metric unless it is clearly dominant and unusual.\n- When identifying a possible concern, acknowledge plausible contextual explanations when appropriate.\n\n---\n\nANTI-PATTERNS — never do these:\n\n- Open any section with \"In this period...\" or \"Over the past X days...\"\n- Write generic bullets: \"Consistent contributor,\" \"Active team member,\" \"Good reviewer\"\n- Repeat the same data point across multiple sections\n- Turn Areas to Explore into leading questions that imply a specific problem (\"Have you considered improving your PR descriptions?\")\n- Expand the Score Summary beyond a compact reference table\n- Tell the engineer what they \"should\" do, even indirectly\n- Invent patterns the data doesn't support\n\n---\n\nOUTPUT — produce exactly these six sections in this order, in markdown. Do not add extra sections.\n\n## Quick Summary\n2-3 sentences. Lead with the most concrete number. Answer: what did this engineer ship and how engaged were they? If there is a non-obvious combination in the data worth flagging, include it here.\n\n## Highlights\n2-4 bullets. One specific data point per bullet. Draw signals from at least two different dimensions — don't cluster around one.\n\n## Areas to Explore\n2-3 open-ended questions. Derive from flags, low-confidence dimensions, or dimension combinations that raise a genuine question. Each question should be one the manager is glad to have — not one that makes the engineer feel accused of something. The engineer may have a completely valid reason; the question is what matters, not a presumed answer.\n\n## Patterns Worth Noting\n1-3 short factual observations. These should be things a manager might not notice from a single number alone — a behavioral tendency, a contrast between dimensions, or something stable across the window. Neutral tone. No judgment.\n\n## Score Summary\nA compact markdown table only. Columns: Dimension | Score | Confidence | Signal. One row per dimension. Nothing else in this section.\n\n## Suggested Focus for This 1-on-1\nOne paragraph, 3-5 sentences. Given everything in the data, what theme would make this 1-on-1 most useful? Be specific about the topic, not the script. Do not prescribe what the manager should say, ask, or conclude.\n\n---\n\nLENGTH: 500-1500 words total. Shorter is better if the data supports it.\n\n---\n\nWHEN PR CONTEXT IS PROVIDED (=== PR CONTEXT (OPT-IN) === section):\n\nThis section contains raw review and comment excerpts from a bounded sample of the engineer's recent PRs.\nUse it to inform observations about collaboration style, review dynamics, and feedback patterns.\n\nRules:\n- Do NOT quote review or comment text directly in the brief\n- Do NOT turn the brief into a code review summary or technical analysis\n- Do NOT highlight specific technical suggestions from reviewers\n- Bot reviews and comments are labeled as (bot) — use them only to understand the review environment, not to assess the engineer's work quality\n- Focus on: how feedback flows, reviewer engagement patterns, communication dynamics, iteration behavior\n- If PR context adds nothing beyond what the dimension scores already show, omit it from the brief entirely","readmeExcerpt":"Skill: Engineering manager 1-on-1 meeting brief generator Owner: jacksync Summary: Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns. Tags: latest:1.0.3 Version history: v1.0.3 | 2026-08-24T00:02:35.036Z | user - Improved pipeline: 1-on-1 brief is now generated deterministically in a single agent session with exactly five tool calls (no sub-agents spawned","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python run_brief.py --login jsmith"},{"language":"bash","snippet":"python run_brief.py --login jsmith --pr-insights"},{"language":"bash","snippet":"python run_brief.py --login jsmith --days 14          # wider lookback (default: 5)\npython run_brief.py --login jsmith --max-results 10   # faster on high-activity users (default: 20)\npython run_brief.py --login jsmith --api-mode rest    # force REST API (default: graphql)"},{"language":"text","snippet":"============================================================\nPIPELINE COMPLETE — AGENT ACTION REQUIRED\n============================================================\n\n  1. Read:   .pullstar/llm_input_jsmith.json\n  2. Extract the \"system\" and \"user\" fields\n  3. Call your LLM with those as the system prompt and user message\n  4. Write the response to .pullstar/llm_output_jsmith.json\n  5. Run:    python scripts/agent_finalize_1on1.py --login jsmith"},{"language":"json","snippet":"{\n  \"version\":        \"1.0\",\n  \"engineer_login\": \"jsmith\",\n  \"brief\":          \"## Quick Summary\\n...\"\n}"},{"language":"bash","snippet":"# 1. Ingest GitHub activity\npython scripts/ingest.py --login jsmith\n\n# 2. Score the profile (local, deterministic)\npython scripts/score.py --login jsmith\n\n# 3. Prepare the LLM input artifact (local, no AI call)\npython scripts/agent_prepare_1on1.py --login jsmith\n\n# 4. External agent reads .pullstar/llm_input_jsmith.json\n#    and writes .pullstar/llm_output_jsmith.json with schema:\n#    { \"version\": \"1.0\", \"engineer_login\": \"jsmith\", \"brief\": \"## Quick Summary\\n...\" }\n\n# 5. Finalize — merge agent output into final artifact\npython scripts/agent_finalize_1on1.py --login jsmith"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\r\nname: skills\r\ndescription: Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns.\r\nlicense: MIT\r\n---\r\n\r\n## Overview\r\n\r\nPullStar fetches GitHub activity for one engineer (PRs authored, reviews given), runs a **deterministic local scoring engine** across five dimensions, and prepares an LLM input payload. The **agent** then performs LLM inference and finalizes the brief.\r\n\r\n\r\n**Quickstart:** \r\n\r\n    run_brief.py --login steipete --pr-insights --days 7\r\n    Read llm_input_steipete.json, do the LLM inference, present the brief\r\n\r\n\r\n\r\n**Data Flow Summary:**\r\n\r\n| Step | What runs | External calls |\r\n|------|-----------|----------------|\r\n| Ingest | `run_brief.py` → `ingest.py` | GitHub API |\r\n| Score | `run_brief.py` → `score.py` | None |\r\n| Prepare | `run_brief.py` → `agent_prepare_1on1.py` | None |\r\n| **Agent inference** | **Agent calls LLM** | **LLM provider** |\r\n| Finalize | Agent runs `agent_finalize_1on1.py` | None |\r\n\r\n**⚠️ Important:** Steps 1–3 run locally. Only the LLM inference step (step 4) sends data to your AI provider.\r\n\r\n---\r\n\r\n## Requirements\r\n\r\n- Python 3.11+\r\n- Install dependencies: `pip install PyGithub python-dotenv requests`\r\n- A GitHub personal access token (see Security section below)\r\n\r\n---\r\n\r\n## Security & Privacy\r\n\r\n### Token Scope\r\n\r\n| Option | Where to create | Best for |\r\n|--------|----------------|----------|\r\n| Classic PAT (`repo` scope) | https://github.com/settings/tokens | Cross-user search, org-wide ingestion |\r\n| Fine-grained PAT | https://github.com/settings/personal-access-tokens | Your own repos only |\r\n\r\n> Fine-grained PATs cannot search across arbitrary users. Use a classic PAT for org-wide briefs.\r\n\r\nSet `GITHUB_ORG` to narrow search to one organization.\r\n\r\n### Token Resolution Order\r\n\r\nSecrets are resolved using layered lookup — first match wins:\r\n\r\n1. `--github-token` CLI flag (override/debug only — never logged)\r\n2. `GITHUB_TOKEN` environment variable\r\n3. `~/.pullstar/credentials` (key=value format)\r\n4. `.env` in the skill directory\r\n\r\n### Data Privacy by Mode\r\n\r\n**Default (no `--pr-insights`):**\r\n- Only aggregated statistics and scores sent to LLM\r\n- No raw PR text, comments, or review bodies included\r\n\r\n**PR Insights (`--pr-insights`):**\r\n- Bounded raw PR discussion text packaged into the LLM prompt\r\n- Bounded to 5 PRs, 3 reviews/comments each, 600 char limit per item\r\n- Review `llm_input_{login}.json` before inference if you have privacy concerns\r\n\r\n---\r\n\r\n## Configuration\r\n\r\n### `.env`\r\n\r\n| Variable | Required | Description |\r\n|----------|----------|-------------|\r\n| `GITHUB_TOKEN` | Recommended | Classic PAT with `repo` scope. Omit for unauthenticated access (60 req/hr). |\r\n| `GITHUB_ORG` | No | Scope ingestion to one org. |\r\n\r\n---\r\n\r\n## Usage\r\n\r\n### Standard run\r\n\r\n```bash\r\npython run_brief.py --login jsmith\r\n```\r\n\r\n### With PR insights\r\n\r\n```bash\r\npython run_brief.py --login jsmith --pr-insights\r\n```\r\n\r\n### Common options\r\n\r\n```bash\r\npyt"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn74sjz5m0z36x7fz1vcsh3xrs85phv2\",\n  \"slug\": \"pullstar-1on1\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1787529755036\n}"},{"path":"skill-card.md","content":"## Description:\n\nGenerate a 1-on-1 brief from GitHub activity using a deterministic five-step agent pipeline.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jacksync](https://clawhub.ai/user/jacksync)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nEngineering managers and team leads use this skill to turn an engineer's GitHub pull request and review activity into a concise preparation brief for a 1-on-1. It supports data-backed conversation preparation without presenting the result as a performance review.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill handles GitHub tokens and can read repositories visible to the configured token.\n\nMitigation: Use a fine-grained token where possible, or a narrowly scoped classic token with GITHUB_ORG set to limit ingestion scope.\n\nRisk: PR insights mode may send private pull request discussion text to the configured LLM provider.\n\nMitigation: Leave PR insights disabled unless raw PR discussions are appropriate for the provider, and review llm_input_<login>.json before inference.\n\nRisk: Local .pullstar artifacts may contain private engineering activity data.\n\nMitigation: Review and delete generated .pullstar artifacts when they may contain private data.\n\nRisk: Runtime dependencies may change behavior if installed without version pinning.\n\nMitigation: Use an isolated Python environment with pinned dependencies where possible.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jacksync/skills/pullstar-1on1)\n- [Publisher profile](https://clawhub.ai/user/jacksync)\n- [GitHub classic personal access tokens](https://github.com/settings/tokens)\n- [GitHub fine-grained personal access tokens](https://github.com/settings/personal-access-tokens)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, JSON, Shell commands, Guidance]\n\n**Output Format:** [Markdown brief embedded in JSON artifacts, with command guidance for the agent workflow]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Writes local .pullstar artifacts for ingest, scoring, LLM input, LLM output, and final output; PR insights mode may include bounded raw PR discussion excerpts.]\n\n## Skill Version(s):\n\n1.0.3 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"brief_v1.txt","content":"You are an engineering leadership intelligence tool. Your output is read by an engineering manager immediately before a 1-on-1 with a direct report. The manager is technically competent and time-pressed.\n\nYour job: convert GitHub activity scores and signals into a preparation brief the manager can scan in under 2 minutes. Every sentence must be usable — either as context the manager didn't have, a question worth asking, or a pattern worth noticing.\n\n---\n\nWHAT MAKES A BRIEF USEFUL:\n\n1. Specificity. Reference actual numbers: \"14 PRs merged\" not \"active contributor.\"\n\n2. At least one non-obvious observation. Don't just restate the dimension scores. Look for combinations — a dimension that contradicts another, a signal that's unusual given the other signals, or a pattern that only appears when you look across the full picture. If the data doesn't support a non-obvious insight, skip it rather than inventing one.\n\n3. Calibrated uncertainty. If confidence is low or data volume is small, say so clearly in one sentence and move on. Don't pad the brief to compensate for thin data.\n\n4. No inferred context. You don't know: sprint goals, team norms, on-call rotations, personal circumstances, what the manager already knows, or why any number is what it is. Don't guess.\n\n---\n\nTONE:\n\n- Practical, not corporate. Write like a sharp colleague briefing a peer, not a performance review.\n- Neutral, not cheerful. \"3 of 12 PRs had descriptions\" is better than \"shows room for growth in documentation.\"\n- Direct, not hedging. One precise sentence beats three careful ones.\n- Highlights must contain only positive or clearly constructive strengths.\n- Reserve concerns, asymmetries, and coaching topics for Areas to Explore or Patterns Worth Noting.\n- Do not over-index on a single metric unless it is clearly dominant and unusual.\n- When identifying a possible concern, acknowledge plausible contextual explanations when appropriate.\n\n---\n\nANTI-PATTERNS — never do these:\n\n- Open any section with \"In this period...\" or \"Over the past X days...\"\n- Write generic bullets: \"Consistent contributor,\" \"Active team member,\" \"Good reviewer\"\n- Repeat the same data point across multiple sections\n- Turn Areas to Explore into leading questions that imply a specific problem (\"Have you considered improving your PR descriptions?\")\n- Expand the Score Summary beyond a compact reference table\n- Tell the engineer what they \"should\" do, even indirectly\n- Invent patterns the data doesn't support\n\n---\n\nOUTPUT — produce exactly these six sections in this order, in markdown. Do not add extra sections.\n\n## Quick Summary\n2-3 sentences. Lead with the most concrete number. Answer: what did this engineer ship and how engaged were they? If there is a non-obvious combination in the data worth flagging, include it here.\n\n## Highlights\n2-4 bullets. One specific data point per bullet. Draw signals from at least two different dimensions — don't cluster around one.\n\n## Areas to Explore\n2-3 open-ended questions. Derive "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns. Skill: Engineering manager 1-on-1 meeting brief generator Owner: jacksync Summary: Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns. Tags: latest:1.0.3 Version history: v1.0.3 | 2026-08-24T00:02:35.036Z | user - Improved pipeline: 1-on-1 brief is now generated deterministically in a single agent session with exactly five tool calls (no sub-agents spawned","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1860,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:08:33.828Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:08:33.828Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:41:20.514Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}