All skills
simota avatar

/harvest

@51065a1
by shingo imotasimota/agent-skills85 stars
15

Collecting GitHub PR data and generating work reports. Retrieves PR info via gh commands to auto-generate weekly/monthly reports and release notes. Use when work reporting or PR analysis is needed.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/harvest

This session only. Nothing lands on disk.

referencereporting-anti-patterns.md

≈720 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Reporting Anti-Patterns

Purpose: Use this reference when Harvest must ensure reports stay actionable, contextual, and resistant to metric gaming.

Contents

  • Report-design anti-patterns
  • Goodhart and gaming
  • Reporting cadence
  • Audience layers
  • Quality checklist

Report-Design Anti-Patterns

ID Anti-pattern Guardrail
RA-01 Too many metrics Keep 3-5 core metrics for the audience
RA-02 No context Include previous period, target, or trend
RA-03 Cherry-picking Show negative and positive signal together
RA-04 Individual ranking Prefer team aggregates; keep personal detail private
RA-05 Over-reporting Match frequency to decision cadence
RA-06 Snapshot bias Add trend lines or period comparisons
RA-07 No next action Attach actions to important findings
RA-08 Blind trust in automation Review anomalies before publishing

Goodhart And Gaming

Typical patterns to watch:

Signal Possible gaming
PR sizes suddenly become uniform Artificial PR splitting
Review times collapse with no comments Rubber-stamp approvals
Friday evening merges spike Weekly metric chasing
Coverage jumps without assertion growth Hollow test additions

Reporting Cadence

Cadence Best for
Daily Build status, open PR count, urgent operations
Weekly Cycle time, merge volume, review responsiveness
Monthly Quality trends, DORA-style patterns, effort summaries
Quarterly Tech debt, long-term architecture or process health

Audience Layers

Layer Focus
L1 Executive Business impact and delivery status
L2 Manager Team performance and bottlenecks
L3 Engineer Detailed PR-level technical feedback

Quality Checklist

  • Is the audience explicit?
  • Are the core metrics limited and contextualized?
  • Does the report include both signal and caveats?
  • Does it avoid personal ranking?
  • Does it end with next actions?

2026 Caveat Additions

  • AI period flagging: When the report covers any window in which the team's AI-assistant adoption rate changed materially, flag the change inline. DORA 2025 reports AI now positively correlates with throughput but negatively with delivery stability — so a "throughput up" headline without the stability counter-context is misleading.
  • DORA 2025 vocabulary: Use percentile language ("Top 15%", "Top 15-30%") and 7 team archetypes instead of Elite/High/Medium/Low when sourcing DORA-style commentary.
  • Copilot Code Review split: When review-time metrics include the Copilot reviewer, separate human and AI review timestamps; otherwise rubber-stamping detection and pickup-time benchmarks misclassify automated comments as human review activity.

Source: SKILL.md on GitHub

3 warnings5mo5 checks · Risk MEDIUM
  • Gen Agent Trust Hub5mo

    The skill provides comprehensive tools for PR analysis and reporting but contains several helper scripts vulnerable to command injection. Specifically, generate-report.js and html-to-pdf.sh construct shell commands using string concatenation of input arguments (like repository names or file paths) without sanitization, which could allow arbitrary command execution if an attacker influences these parameters through a malicious prompt or repository metadata.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    5/24 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 51065a1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 months ago

README badge

README badge for simota/agent-skills/harvest