diff --git a/lib/llm/index.js b/lib/llm/index.js index dfdba59..7755ca5 100644 --- a/lib/llm/index.js +++ b/lib/llm/index.js @@ -61,9 +61,9 @@ sqlcmd -i ./scripts/query.sql ### Safety Rules -**CRITICAL**: Before executing any write operation (INSERT, UPDATE, DELETE, MERGE, TRUNCATE, DROP): -1. Check current context: \`sqlcmd config current-context\` -2. Show the context name and query to the user +**Safety**: Before executing any write operation (INSERT, UPDATE, DELETE, MERGE, TRUNCATE, DROP): +1. Resolve the target: the \`-S\` server if the command passes one, otherwise the chained or current context (\`sqlcmd config current-context\`) +2. Show that target, the database and the full query to the user 3. Ask for explicit confirmation before executing ### Gotchas @@ -85,7 +85,7 @@ Use the \`gh\` command for interacting with github.com ### PR Line Comments via Reviews Endpoint -Use the **reviews endpoint** (\`POST /pulls/{id}/reviews\`) with a \`comments\` array — NOT the individual comments endpoint. Pass the body as raw JSON via \`--input -\`; \`--field\` serializes arrays as strings. +Use the **reviews endpoint** (\`POST /pulls/{id}/reviews\`) with a \`comments\` array, not the individual comments endpoint. Pass the body as raw JSON via \`--input -\`; \`--field\` serializes arrays as strings. \`\`\`bash cat <<'JSONEOF' | gh api repos/{owner}/{repo}/pulls/{pr}/reviews -X POST --input - @@ -144,11 +144,11 @@ gh api repos/{owner}/{repo}/pulls/comments/{comment_id} -X DELETE ### Local Repo May Be Behind -When reviewing a PR against the current default branch, the local checkout may not include recently merged PRs. Always pull from origin first: +When reviewing a PR against the current default branch, the local checkout may not include recently merged PRs. Fetch the default branch (\`master\` or \`main\`) from origin first: \`\`\`bash -git fetch origin main -git show origin/main:path/to/file +git fetch origin +git show origin/:path/to/file \`\`\` `, }, @@ -165,6 +165,8 @@ The context and Assets commands below require atl-cli v1.13.0 or newer. \`\`\`bash atl auth status # Check every configured site +atl auth refresh --hostname mycompany.atlassian.net # Force a token refresh +atl doctor # Diagnose config, OAuth credentials, and token state atl auth setup # First-time OAuth setup (required once) atl auth login --hostname mycompany.atlassian.net \`\`\` @@ -210,7 +212,7 @@ atl --context sandbox confluence space list Inline \`ATLASSIAN_CONTEXT=prod atl ...\` is equivalent, but the flag is preferred. -Jira commands are under \`atl jira\` (\`atl jira issue\`, \`atl jira board\`, \`atl jira sm\`, \`atl jira sprint\`). The bare \`atl issue\`/\`atl board\`/\`atl sm\` forms still work as deprecated aliases (they warn) and may be removed. +Jira commands are under \`atl jira\` (\`atl jira issue\`, \`atl jira board\`, \`atl jira sm\`, \`atl jira sprint\`). ### Jira Assets @@ -244,6 +246,7 @@ atl --context prod jira issue create --project PROJ --type Bug --summary "Title" # Edit atl --context prod jira issue edit PROJ-1234 --summary "New summary" atl --context prod jira issue edit PROJ-1234 --assignee @me +atl --context prod jira issue assign PROJ-1234 --assignee @me # or a user; "-" unassigns atl --context prod jira issue edit PROJ-1234 --description "New description" atl --context prod jira issue edit PROJ-1234 --description "Appended text" --append atl --context prod jira issue edit PROJ-1234 --add-label bug --remove-label wontfix @@ -259,6 +262,8 @@ atl --context prod jira issue edit PROJ-1234 --security "" # atl --context prod jira issue transition PROJ-1234 "In Progress" atl --context prod jira issue transition PROJ-1234 --list # List available transitions atl --context prod jira issue transition PROJ-1234 "Done" --field "Resolution=Fixed" # Transition with required fields +atl --context prod jira issue transition PROJ-1234 "Done" --comment "Text" # Transition and comment +atl --context prod jira issue changelog PROJ-1234 --field status # Field change history # Impediment flag (board highlight, no status change) atl --context prod jira issue flag PROJ-1234 # Flag the issue as impeded @@ -298,7 +303,9 @@ atl --context prod jira issue comment delete PROJ-1234 --id COMMENT_ID # Attachments atl --context prod jira issue attachment PROJ-1234 --list # List attachments -atl --context prod jira issue attachment PROJ-1234 --download # Download attachment +atl --context prod jira issue attachment PROJ-1234 --download --id # Download one attachment +atl --context prod jira issue attachment PROJ-1234 --download-all # Download all (--output ) +atl --context prod jira issue attachment PROJ-1234 --upload ./file.png # Upload (repeat --upload for more) # Metadata discovery atl --context prod jira issue types --project PROJ # List issue types @@ -309,7 +316,7 @@ atl --context prod jira issue field-options --project PROJ --type Bug # atl --context prod jira issue field-options --project PROJ --type Bug --field "Repo" # Specific field options atl --context prod jira issue field-options --project PROJ --type Bug --field security # Security levels (for --security) -# Read-only REST passthrough (atl v1.12.0+; GET only, path relative to /rest/api/3) +# Read-only REST passthrough (GET only, path relative to /rest/api/3) atl --context prod jira api GET issue/PROJ-1234/editmeta # Endpoints atl doesn't model atl --context prod jira api project/PROJ/securitylevel # Method arg optional; defaults to GET @@ -356,6 +363,7 @@ atl --context prod confluence page create -s DOCS -t "Title" --parent # Ch atl --context prod confluence page create -s DOCS -t "Title" --draft # Create as draft atl --context prod confluence page edit --title "New Title" atl --context prod confluence page edit --body "

New content

" +atl --context prod confluence page edit --body "

More

" --append # Append instead of replace # Hierarchy navigation atl --context prod confluence page children # List immediate children @@ -493,7 +501,7 @@ Plain \`--field "Name=value"\` is string-only. Complex Jira field types need \`- | Multi-select | \`"Name": [{"value": "A"}, {"value": "B"}]\` | No | | Issue security level | use \`--security ""\` instead | No — \`--field\` can't set it | -**Issue security level** has a dedicated flag (atl v1.12.0+) — don't reach for \`--field-file\`. Set it on create/edit with \`--security "Developer only"\` (name or numeric id); \`--security ""\` on edit clears it. Discover a project's levels with \`atl --context prod jira issue field-options --project PROJ --type Bug --field security\`. +**Issue security level** has a dedicated flag — don't reach for \`--field-file\`. Set it on create/edit with \`--security "Developer only"\` (name or numeric id); \`--security ""\` on edit clears it. Discover a project's levels with \`atl --context prod jira issue field-options --project PROJ --type Bug --field security\`. Example combining labels + select + radio (placeholder field names — the actual fields and allowed values depend on your project's schema, not on this example): @@ -524,7 +532,7 @@ Workaround: flatten nested code into inline single-backtick fragments; replace \ - \`@[Display Name]\` or \`@[id:accountId]\` — generates a real Jira mention with notification - Plain \`@Name\` — renders as text, no notification -- \`[~accountid:...]\` / \`[~username]\` — raw ADF syntax. The Markdown→ADF pipeline ships it as literal text. Do NOT use. +- \`[~accountid:...]\` / \`[~username]\` — raw ADF syntax. The Markdown→ADF pipeline ships it as literal text, so don't use it. ### Replying to Jira Issue Comments @@ -574,7 +582,7 @@ For code blocks, use Confluence macro: \`\`\` -**Important**: The \`--body\` flag replaces the ENTIRE page content. +The \`--body\` flag replaces the whole page content; pass \`--append\` to add to the end instead. `, }, n8nctl: { @@ -627,6 +635,16 @@ n8nctl workflow run --webhook --method POST # Trigger via POST # Activate/deactivate n8nctl workflow activate n8nctl workflow deactivate + +# Move to another project. Credentials move too unless --skip-credentials, which +# changes who can use them: confirm the target project with the user first. +n8nctl workflow transfer +\`\`\` + +### Projects + +\`\`\`bash +n8nctl project list # List projects (IDs for workflow transfer) \`\`\` ### Variables @@ -680,7 +698,7 @@ gcx login --server # Log in and create/use a context ### Authentication — two separate credential planes -A working stack login does NOT imply cloud access, or vice versa: +A working stack login does not imply cloud access, or vice versa: | Plane | Serves | Broken looks like | Fix | |-------|--------|-------------------|-----| @@ -696,7 +714,7 @@ Re-running the stack login never fixes a "context has no cloud auth" error. (\`open\` on macOS, \`xdg-open\` on Linux, \`start\` on Windows), tell the user the verification code so they can match it - before approving, and wait on the process. NEVER restart the flow while a tab + before approving, and wait on the process. Never restart the flow while a tab is pending: each run mints a one-time \`state\`, a restart orphans the open tab, and an approval on an orphaned tab is silently ignored — the user logs in "successfully" while the CLI waits forever. @@ -705,7 +723,7 @@ Re-running the stack login never fixes a "context has no cloud auth" error. \`gcx config set cloud.grafana-com.token glc_...\` then \`gcx config set contexts..cloud grafana-com\`. The user creates the token in the stack UI under Administration → Users and access → Cloud - access policies. Do NOT use \`gcx login --cloud-token\` in an agent + access policies. Don't use \`gcx login --cloud-token\` in an agent session: it re-runs the stack browser-OAuth leg first and blocks on a browser approval even with \`--yes\`; gcx's help also marks interactive cloud OAuth EXPERIMENTAL, with a token that cannot be refreshed. For a @@ -759,10 +777,10 @@ PnP CLI for Microsoft 365 - manage SharePoint, Teams, OneDrive, Planner, and mor ### Safety Rules -**CRITICAL**: Before executing any write or delete operation (add, set, remove, copy, move): +**Safety**: Before executing any write or delete operation (add, set, remove, copy, move): 1. Show the full command and target URL to the user 2. Ask for explicit confirmation before executing -3. DO NOT use the \`--confirm\` flag unless specifically requested by the user +3. Do not pass \`-f/--force\` (it skips the confirmation prompt) unless the user asks ### Authentication @@ -857,7 +875,7 @@ m365 spo site list --output json --query "[].{Title:Title,Url:Url}" # JMESPath - Use \`--output json\` with \`--query\` for filtering results with JMESPath syntax - Use \`m365 --help\` for detailed command documentation - SharePoint URLs are case-sensitive in many operations -- NEVER use \`--confirm\` flag autonomously - it skips safety prompts +- Never pass \`-f/--force\` autonomously: it skips the confirmation prompt `, }, esq: { @@ -1062,7 +1080,7 @@ await browser.close(); ### Tips -- CLI \`screenshot\` command does NOT support HTTP Basic Auth via URL (Chromium deprecated this) — use the programmatic API with \`httpCredentials\` instead +- CLI \`screenshot\` command does not support HTTP Basic Auth via URL (Chromium deprecated this) — use the programmatic API with \`httpCredentials\` instead - Use \`--save-har\` to capture all network requests for debugging - Use \`--load-storage\` / \`--save-storage\` to persist and reuse authentication sessions - HAR files can be parsed as JSON: \`python3 -c "import json; ..."\` or \`jq\` @@ -1130,7 +1148,7 @@ hcloud server list -o columns=name,status,ipv4 # Pick columns ### Safety Rules -**CRITICAL**: Before executing any destructive operation (\`delete\`, \`reset\`, \`poweroff\`): +**Safety**: Before executing any destructive operation (\`delete\`, \`reset\`, \`poweroff\`): 1. Check active context: \`hcloud context active\` 2. Show the resource and target context to the user 3. Ask for explicit confirmation before executing @@ -1175,7 +1193,7 @@ Every command supports \`--help\` for its subcommands and flags. Use \`--format ### Safety Rules -**CRITICAL**: Before executing any destructive operation (\`delete\`, \`terminate\`, \`reinstall\`, \`reboot\`): +**Safety**: Before executing any destructive operation (\`delete\`, \`terminate\`, \`reinstall\`, \`reboot\`): 1. Show the resource and target account/endpoint to the user 2. Ask for explicit confirmation before executing 3. Never pass a \`--yes\`/confirmation-skipping flag autonomously @@ -1219,8 +1237,8 @@ Reference docs for each tool are in \`${docsPath}/\`. Read the relevant file whe ${rows} **Safety**: Before executing any SQL write operation (INSERT, UPDATE, DELETE, MERGE, TRUNCATE, DROP): -1. Check current context: \`sqlcmd config current-context\` -2. Show the context name and query to the user +1. Resolve the target: the \`-S\` server if the command passes one, otherwise the chained or current context (\`sqlcmd config current-context\`) +2. Show that target, the database and the full query to the user 3. Ask for explicit confirmation before executing **Safety**: Every Jira, Confluence, or Assets operation must pass an explicit @@ -1230,7 +1248,7 @@ persistent context from an agent session. **Safety**: Before executing any M365 write or delete operation (add, set, remove, copy, move): 1. Show the full command and target URL to the user 2. Ask for explicit confirmation before executing -3. Do NOT use the \`--confirm\` flag unless specifically requested by the user +3. Do not pass \`-f/--force\` (it skips the confirmation prompt) unless the user asks **Safety**: Before executing any hcloud destructive operation (\`delete\`, \`reset\`, \`poweroff\`): 1. Check active context: \`hcloud context active\`