Implement comprehensive error handling for Python code paths to keep services resilient and user-friendly. Use when failures are currently silent or exceptions leak through.
日本語の概要は準備中です。原文の説明を表示しています。
Triage and fix Dependabot alerts and CodeQL findings in the ai repository. Use when the user asks to address security vulnerabilities, fix Dependabot alerts, resolve CodeQL issues, or do security maintenance.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
I drive the security maintenance workflow for the ai repository to keep both dashboards at zero:
Versions and changelogs are fully owned by release-please (config: release-please-config.json, manifest: .release-please-manifest.json). CI enforces this via .github/scripts/check-no-manual-release.sh, which fails any PR that modifies:
CHANGELOG.md.release-please-manifest.jsonversion = "..." line in any pyproject.tomlBecause of that:
CHANGELOG.md or bump version by hand. Do not use the release-process skill to justify manual edits in security PRs — that skill documents automation, not hand bumps.git-conventional-commits). For Dependabot/CodeQL fixes use fix(<scope>): ... so release-please groups them under "Bug Fixes". Use chore(deps): ... only for risk-free dep bumps you don't want to surface in user-facing notes (it's hidden in the changelog).Never merge Dependabot auto-PRs. Use constraint-dependencies in the root pyproject.toml instead.
gh api --paginate); the Dependabot endpoint is cursor-paged and a single per_page=100 call silently caps at 100.constraint-dependencies in root pyproject.toml with "<package>>=<fixed-version>".exclude-newer conflicts — if the fix version is within the 2-week rolling window, add an exclude-newer-package timestamp (day after latest PyPI upload). See exclude-newer reference.exclude-newer-package entries — remove any timestamp older than 2 weeks (redundant, global window already covers it). Keep = false entries.uv lock --refresh. If resolution fails, bump the timestamp and retry.fix/dependabot-<pkg>-<ver> (single CVE) or fix/security-<date> (batch). Subject: fix(deps): bump <pkg> to >=<ver> (GHSA-xxxx) or fix(security): batch dependabot fixes <date>. Do not touch CHANGELOG.md or any version = ... field — release-please will pick the commit up on the next standing Release PR.fix(<package-or-area>): <what was hardened> (CodeQL <rule-id>). Again: no manual changelog/version edits.exclude-newer-package entries.fix(...) subjects so release-please attributes bumps to the right workspace package(s) on the next Release PR.check-no-manual-release.sh, then close any resolved Dependabot auto-PRs after merge.constraint-dependencies persists across relocks; auto-PRs only edit uv.lock.CHANGELOG.md, .release-please-manifest.json, or version = ... — check-no-manual-release.sh will block the PR.fix(...) not chore(deps): ... when you want the fix to appear in user-facing release notes; chore is hidden by the changelog config.uv uses strict < on individual wheel upload times).まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Implement comprehensive error handling for Python code paths to keep services resilient and user-friendly. Use when failures are currently silent or exceptions leak through.
日本語の概要は準備中です。原文の説明を表示しています。
Tabular and numerical data analysis with descriptive statistics and insights. Use when the user provides data, tables, CSVs, or numbers and wants analysis.
日本語の概要は準備中です。原文の説明を表示しています。
Financial factsheet analysis with key metrics extraction and investment rationale
日本語の概要は準備中です。原文の説明を表示しています。
Diagnose and fix CI failures without leaving your editor.
日本語の概要は準備中です。原文の説明を表示しています。
Reproduce ai-repo PR checks locally with Poe and CI scripts, including per-package typecheck and coverage behavior. Use when validating changes before push or when user asks which local commands match CI.
日本語の概要は準備中です。原文の説明を表示しています。
Ask clarifying questions before implementing to ensure Python requirements are understood. Use when a task lacks detail, dependencies are unclear, or multiple interpretations are possible.
日本語の概要は準備中です。原文の説明を表示しています。