All skills
simota avatar

/harvest

@51065a1
by shingo imotasimota/agent-skills85 stars
15

Collecting GitHub PR data and generating work reports. Retrieves PR info via gh commands to auto-generate weekly/monthly reports and release notes. Use when work reporting or PR analysis is needed.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/harvest

This session only. Nothing lands on disk.

referenceestimation-anti-patterns.md

≈552 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Estimation Anti-Patterns

Purpose: Use this reference when Harvest includes estimated effort and you need to explain limitations or avoid misleading productivity claims.

Contents

  • LOC pitfalls
  • Estimation anti-patterns
  • Fatigue warnings
  • Harvest-specific guardrails

LOC Pitfalls

ID Problem Why it matters
EA-01 Solution complexity != problem complexity Hard work can produce little code
EA-02 Language dependence LOC varies by stack
EA-03 Refactoring penalty Code reduction looks falsely "unproductive"
EA-04 Non-coding work ignored Design, review, debugging are invisible
EA-05 No quality correlation More code can mean more defects
EA-06 Copy-paste incentive Volume can displace maintainability
EA-07 Generated code pollution Boilerplate distorts effort
EA-08 Team contribution invisibility Mentoring and review disappear

Estimation Anti-Patterns

ID Anti-pattern Guardrail
EA-09 Optimism bias Prefer historical data and buffers
EA-10 Anchoring Re-estimate when new information arrives
EA-11 Parkinson's law Separate buffer from expected effort
EA-12 Ignoring scope creep Version estimates when scope changes
EA-13 Using the fastest person as baseline Report team-safe ranges
EA-14 Assuming linear effort Apply complexity multipliers in larger or riskier work

Fatigue Warning

Long-hours metrics need explicit caution:

  • Sustainable work beats raw hours.
  • Night/weekend work > 10% should trigger a health warning.
  • Do not reward long hours as productivity.

Harvest Guardrails

  • Mark hours as estimated.
  • Prefer min / expected / max when reporting to managers or clients.
  • Exclude auto-generated files when they materially skew effort.
  • If estimate accuracy falls below 60%, recommend reviewing the estimation process.
  • AI-assisted coding (Copilot, Claude Code, Cursor, etc.) decouples LOC from human effort. When AI usage is high, prefer review-cycle and pickup-time signals over LOC-derived hours and document the AI posture in the report.

Source: SKILL.md on GitHub

3 warnings5mo5 checks · Risk MEDIUM
  • Gen Agent Trust Hub5mo

    The skill provides comprehensive tools for PR analysis and reporting but contains several helper scripts vulnerable to command injection. Specifically, generate-report.js and html-to-pdf.sh construct shell commands using string concatenation of input arguments (like repository names or file paths) without sanitization, which could allow arbitrary command execution if an attacker influences these parameters through a malicious prompt or repository metadata.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    5/24 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 51065a1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 months ago

README badge

README badge for simota/agent-skills/harvest