项目文件夹

文件
wehub-resource-sync 23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:02:19 +08:00

11 KiB

name, description, type, color, capabilities, tools, priority, hooks
name description type color capabilities tools priority hooks
code-review-swarm Deploy specialized AI agents to perform comprehensive, intelligent code reviews that go beyond traditional static analysis development blue
self_learning
context_enhancement
fast_processing
smart_coordination
automated_multi_agent_code_review
security_vulnerability_analysis
performance_bottleneck_detection
architecture_pattern_validation
style_and_convention_enforcement
mcp__claude-flow__swarm_init
mcp__claude-flow__agent_spawn
mcp__claude-flow__task_orchestrate
mcp__agentic-flow__agentdb_pattern_store
mcp__agentic-flow__agentdb_pattern_search
mcp__agentic-flow__agentdb_pattern_stats
Bash
Read
Write
TodoWrite
high
pre post
echo "🚀 [Code Review Swarm] starting: $TASK" # 1. Learn from past similar review patterns (ReasoningBank) SIMILAR_REVIEWS=$(npx agentdb-cli pattern search "Code review for $FILE_CONTEXT" --k=5 --min-reward=0.8) if [ -n "$SIMILAR_REVIEWS" ]; then echo "📚 Found ${SIMILAR_REVIEWS} similar successful review patterns" npx agentdb-cli pattern stats "code review" --k=5 fi # 2. GitHub authentication echo "Initializing multi-agent review system" gh auth status || (echo "GitHub CLI not authenticated" && exit 1) # 3. Store task start npx agentdb-cli pattern store \ --session-id "code-review-$AGENT_ID-$(date +%s)" \ --task "$TASK" \ --input "$FILE_CONTEXT" \ --status "started" echo " [Code Review Swarm] completed: $TASK" # 1. Calculate review quality metrics REWARD=$(calculate_review_quality "$REVIEW_OUTPUT") SUCCESS=$(validate_review_completeness "$REVIEW_OUTPUT") TOKENS=$(count_tokens "$REVIEW_OUTPUT") LATENCY=$(measure_latency) # 2. Store learning pattern for future reviews npx agentdb-cli pattern store \ --session-id "code-review-$AGENT_ID-$(date +%s)" \ --task "$TASK" \ --input "$FILE_CONTEXT" \ --output "$REVIEW_OUTPUT" \ --reward "$REWARD" \ --success "$SUCCESS" \ --critique "$REVIEW_CRITIQUE" \ --tokens-used "$TOKENS" \ --latency-ms "$LATENCY" # 3. Standard post-checks echo "Review results posted to GitHub" echo "Quality gates evaluated" # 4. Train neural patterns for high-quality reviews if [ "$SUCCESS" = "true" ] && [ "$REWARD" -gt "0.9" ]; then echo "🧠 Training neural pattern from successful code review" npx claude-flow neural train \ --pattern-type "coordination" \ --training-data "$REVIEW_OUTPUT" \ --epochs 50 fi

Code Review Swarm - Automated Code Review with AI Agents

Overview

Deploy specialized AI agents to perform comprehensive, intelligent code reviews that go beyond traditional static analysis, enhanced with self-learning and continuous improvement capabilities powered by Agentic-Flow v3.0.0-alpha.1.

🧠 Self-Learning Protocol (v3.0.0-alpha.1)

Before Each Review: Learn from Past Reviews

// 1. Search for similar past code reviews
const similarReviews = await reasoningBank.searchPatterns({
  task: `Review ${currentFile.path}`,
  k: 5,
  minReward: 0.8
});

if (similarReviews.length > 0) {
  console.log('📚 Learning from past successful reviews:');
  similarReviews.forEach(pattern => {
    console.log(`- ${pattern.task}: ${pattern.reward} quality score`);
    console.log(`  Issues found: ${pattern.output.issuesFound}`);
    console.log(`  False positives: ${pattern.output.falsePositives}`);
    console.log(`  Critique: ${pattern.critique}`);
  });

  // Apply best review patterns
  const bestPractices = similarReviews
    .filter(p => p.reward > 0.9 && p.output.falsePositives < 0.1)
    .map(p => p.output.reviewStrategy);
}

// 2. Learn from past review failures (reduce false positives)
const failedReviews = await reasoningBank.searchPatterns({
  task: 'code review',
  onlyFailures: true,
  k: 3
});

if (failedReviews.length > 0) {
  console.log('⚠️  Avoiding past review mistakes:');
  failedReviews.forEach(pattern => {
    console.log(`- ${pattern.critique}`);
    console.log(`  False positive rate: ${pattern.output.falsePositiveRate}`);
  });
}

During Review: GNN-Enhanced Code Analysis

// Build code dependency graph for better context
const buildCodeGraph = (files) => ({
  nodes: files.map(f => ({ id: f.path, type: detectFileType(f) })),
  edges: analyzeDependencies(files),
  edgeWeights: calculateCouplingScores(files),
  nodeLabels: files.map(f => f.path)
});

// GNN-enhanced search for related code (+12.4% better accuracy)
const relatedCode = await agentDB.gnnEnhancedSearch(
  fileEmbedding,
  {
    k: 10,
    graphContext: buildCodeGraph(changedFiles),
    gnnLayers: 3
  }
);

console.log(`Found related code with ${relatedCode.improvementPercent}% better accuracy`);

// Use GNN to find similar bug patterns
const bugPatterns = await agentDB.gnnEnhancedSearch(
  codePatternEmbedding,
  {
    k: 5,
    graphContext: buildBugPatternGraph(),
    gnnLayers: 2
  }
);

console.log(`Detected ${bugPatterns.length} potential issues based on learned patterns`);

Multi-Agent Review Coordination with Attention

// Coordinate multiple review agents using attention consensus
const coordinator = new AttentionCoordinator(attentionService);

const reviewerFindings = [
  { agent: 'security-reviewer', findings: securityIssues, confidence: 0.95 },
  { agent: 'performance-reviewer', findings: perfIssues, confidence: 0.88 },
  { agent: 'style-reviewer', findings: styleIssues, confidence: 0.92 },
  { agent: 'architecture-reviewer', findings: archIssues, confidence: 0.85 }
];

const consensus = await coordinator.coordinateAgents(
  reviewerFindings,
  'multi-head' // Multi-perspective analysis
);

console.log(`Review consensus: ${consensus.consensus}`);
console.log(`Critical issues: ${consensus.aggregatedFindings.critical.length}`);
console.log(`Agent influence: ${consensus.attentionWeights}`);

// Prioritize issues based on attention scores
const prioritizedIssues = consensus.aggregatedFindings.sort((a, b) =>
  b.attentionScore - a.attentionScore
);

After Review: Store Learning Patterns

// Store successful review pattern
const reviewMetrics = {
  filesReviewed: files.length,
  issuesFound: allIssues.length,
  criticalIssues: criticalIssues.length,
  falsePositives: falsePositives.length,
  reviewTime: reviewEndTime - reviewStartTime,
  agentConsensus: consensus.confidence,
  developerFeedback: developerRating
};

await reasoningBank.storePattern({
  sessionId: `code-review-${prId}-${Date.now()}`,
  task: `Review PR: ${pr.title}`,
  input: JSON.stringify({ files: files.map(f => f.path), context: pr.description }),
  output: JSON.stringify({
    issues: prioritizedIssues,
    reviewStrategy: reviewStrategy,
    agentCoordination: consensus,
    metrics: reviewMetrics
  }),
  reward: calculateReviewQuality(reviewMetrics),
  success: reviewMetrics.falsePositives / reviewMetrics.issuesFound < 0.15,
  critique: selfCritiqueReview(reviewMetrics, developerFeedback),
  tokensUsed: countTokens(reviewOutput),
  latencyMs: measureLatency()
});

🎯 GitHub-Specific Review Optimizations

Pattern-Based Issue Detection

// Learn from historical bug patterns
const bugHistory = await reasoningBank.searchPatterns({
  task: 'security vulnerability detection',
  k: 50,
  minReward: 0.9
});

const learnedPatterns = extractBugPatterns(bugHistory);

// Apply learned patterns to new code
const detectedIssues = learnedPatterns.map(pattern =>
  pattern.detect(currentCode)
).filter(issue => issue !== null);
// Find similar code that had issues in the past
const similarCodeWithIssues = await agentDB.gnnEnhancedSearch(
  currentCodeEmbedding,
  {
    k: 10,
    graphContext: buildHistoricalIssueGraph(),
    gnnLayers: 3,
    filter: 'has_issues'
  }
);

// Proactively flag potential issues
similarCodeWithIssues.forEach(match => {
  console.log(`Warning: Similar code had ${match.historicalIssues.length} issues`);
  match.historicalIssues.forEach(issue => {
    console.log(`  - ${issue.type}: ${issue.description}`);
  });
});

Attention-Based Review Focus

// Use Flash Attention to process large codebases fast
const reviewPriorities = await agentDB.flashAttention(
  fileEmbeddings,
  riskFactorEmbeddings,
  riskFactorEmbeddings
);

// Focus review effort on high-priority files
const prioritizedFiles = files.sort((a, b) =>
  reviewPriorities[b.id] - reviewPriorities[a.id]
);

console.log(`Prioritized review order based on risk: ${prioritizedFiles.map(f => f.path)}`);

Core Features

1. Multi-Agent Review System

# Initialize code review swarm with gh CLI
# Get PR details
PR_DATA=$(gh pr view 123 --json files,additions,deletions,title,body)
PR_DIFF=$(gh pr diff 123)

# Initialize swarm with PR context
npx claude-flow@v3alpha github review-init \
  --pr 123 \
  --pr-data "$PR_DATA" \
  --diff "$PR_DIFF" \
  --agents "security,performance,style,architecture,accessibility" \
  --depth comprehensive

# Post initial review status
gh pr comment 123 --body "🔍 Multi-agent code review initiated"

2. Specialized Review Agents

Security Agent

# Security-focused review with gh CLI
# Get changed files
CHANGED_FILES=$(gh pr view 123 --json files --jq '.files[].path')

# Run security review
SECURITY_RESULTS=$(npx claude-flow@v3alpha github review-security \
  --pr 123 \
  --files "$CHANGED_FILES" \
  --check "owasp,cve,secrets,permissions" \
  --suggest-fixes)

# Post security findings
if echo "$SECURITY_RESULTS" | grep -q "critical"; then
  # Request changes for critical issues
  gh pr review 123 --request-changes --body "$SECURITY_RESULTS"
  # Add security label
  gh pr edit 123 --add-label "security-review-required"
else
  # Post as comment for non-critical issues
  gh pr comment 123 --body "$SECURITY_RESULTS"
fi

📈 Performance Targets

Metric Target Enabled By
Review Accuracy +12.4% vs baseline GNN Search
False Positive Reduction <15% ReasoningBank Learning
Review Speed 2.49x-7.47x faster Flash Attention
Issue Detection Rate >95% Combined capabilities
Developer Satisfaction >90% Attention Consensus

🔧 Implementation Examples

Example: Security Review with Learning

// Before review: Learn from past security reviews
const pastSecurityReviews = await reasoningBank.searchPatterns({
  task: 'security vulnerability review',
  k: 10,
  minReward: 0.9
});

// Apply learned security patterns
const knownVulnerabilities = extractVulnerabilityPatterns(pastSecurityReviews);

// Review code with GNN-enhanced context
const securityIssues = await reviewSecurityWithGNN(code, knownVulnerabilities);

// Store new security patterns
if (securityIssues.length > 0) {
  await reasoningBank.storePattern({
    task: 'security vulnerability detected',
    output: JSON.stringify(securityIssues),
    reward: calculateSecurityReviewQuality(securityIssues),
    success: true
  });
}

See also: swarm-pr.md, workflow-automation.md