Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 44 additions & 27 deletions lib/llm/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -61,9 +61,9 @@ sqlcmd -i ./scripts/query.sql

### Safety Rules

**CRITICAL**: Before executing any write operation (INSERT, UPDATE, DELETE, MERGE, TRUNCATE, DROP):
1. Check current context: \`sqlcmd config current-context\`
2. Show the context name and query to the user
**Safety**: Before executing any write operation (INSERT, UPDATE, DELETE, MERGE, TRUNCATE, DROP):
1. Resolve the target: the \`-S\` server if the command passes one, otherwise the chained or current context (\`sqlcmd config current-context\`)
2. Show that target, the database and the full query to the user
3. Ask for explicit confirmation before executing

### Gotchas
Expand All @@ -85,7 +85,7 @@ Use the \`gh\` command for interacting with github.com

### PR Line Comments via Reviews Endpoint

Use the **reviews endpoint** (\`POST /pulls/{id}/reviews\`) with a \`comments\` array — NOT the individual comments endpoint. Pass the body as raw JSON via \`--input -\`; \`--field\` serializes arrays as strings.
Use the **reviews endpoint** (\`POST /pulls/{id}/reviews\`) with a \`comments\` array, not the individual comments endpoint. Pass the body as raw JSON via \`--input -\`; \`--field\` serializes arrays as strings.

\`\`\`bash
cat <<'JSONEOF' | gh api repos/{owner}/{repo}/pulls/{pr}/reviews -X POST --input -
Expand Down Expand Up @@ -144,11 +144,11 @@ gh api repos/{owner}/{repo}/pulls/comments/{comment_id} -X DELETE

### Local Repo May Be Behind

When reviewing a PR against the current default branch, the local checkout may not include recently merged PRs. Always pull from origin first:
When reviewing a PR against the current default branch, the local checkout may not include recently merged PRs. Fetch the default branch (\`master\` or \`main\`) from origin first:

\`\`\`bash
git fetch origin main
git show origin/main:path/to/file
git fetch origin <default-branch>
git show origin/<default-branch>:path/to/file
\`\`\`
`,
},
Expand All @@ -165,6 +165,8 @@ The context and Assets commands below require atl-cli v1.13.0 or newer.

\`\`\`bash
atl auth status # Check every configured site
atl auth refresh --hostname mycompany.atlassian.net # Force a token refresh
atl doctor # Diagnose config, OAuth credentials, and token state
atl auth setup # First-time OAuth setup (required once)
atl auth login --hostname mycompany.atlassian.net
\`\`\`
Expand Down Expand Up @@ -210,7 +212,7 @@ atl --context sandbox confluence space list

Inline \`ATLASSIAN_CONTEXT=prod atl ...\` is equivalent, but the flag is preferred.

Jira commands are under \`atl jira\` (\`atl jira issue\`, \`atl jira board\`, \`atl jira sm\`, \`atl jira sprint\`). The bare \`atl issue\`/\`atl board\`/\`atl sm\` forms still work as deprecated aliases (they warn) and may be removed.
Jira commands are under \`atl jira\` (\`atl jira issue\`, \`atl jira board\`, \`atl jira sm\`, \`atl jira sprint\`).

### Jira Assets

Expand Down Expand Up @@ -244,6 +246,7 @@ atl --context prod jira issue create --project PROJ --type Bug --summary "Title"
# Edit
atl --context prod jira issue edit PROJ-1234 --summary "New summary"
atl --context prod jira issue edit PROJ-1234 --assignee @me
atl --context prod jira issue assign PROJ-1234 --assignee @me # or a user; "-" unassigns
atl --context prod jira issue edit PROJ-1234 --description "New description"
atl --context prod jira issue edit PROJ-1234 --description "Appended text" --append
atl --context prod jira issue edit PROJ-1234 --add-label bug --remove-label wontfix
Expand All @@ -259,6 +262,8 @@ atl --context prod jira issue edit PROJ-1234 --security "" #
atl --context prod jira issue transition PROJ-1234 "In Progress"
atl --context prod jira issue transition PROJ-1234 --list # List available transitions
atl --context prod jira issue transition PROJ-1234 "Done" --field "Resolution=Fixed" # Transition with required fields
atl --context prod jira issue transition PROJ-1234 "Done" --comment "Text" # Transition and comment
atl --context prod jira issue changelog PROJ-1234 --field status # Field change history

# Impediment flag (board highlight, no status change)
atl --context prod jira issue flag PROJ-1234 # Flag the issue as impeded
Expand Down Expand Up @@ -298,7 +303,9 @@ atl --context prod jira issue comment delete PROJ-1234 --id COMMENT_ID

# Attachments
atl --context prod jira issue attachment PROJ-1234 --list # List attachments
atl --context prod jira issue attachment PROJ-1234 --download <id> # Download attachment
atl --context prod jira issue attachment PROJ-1234 --download --id <id> # Download one attachment
atl --context prod jira issue attachment PROJ-1234 --download-all # Download all (--output <dir>)
atl --context prod jira issue attachment PROJ-1234 --upload ./file.png # Upload (repeat --upload for more)

# Metadata discovery
atl --context prod jira issue types --project PROJ # List issue types
Expand All @@ -309,7 +316,7 @@ atl --context prod jira issue field-options --project PROJ --type Bug #
atl --context prod jira issue field-options --project PROJ --type Bug --field "Repo" # Specific field options
atl --context prod jira issue field-options --project PROJ --type Bug --field security # Security levels (for --security)

# Read-only REST passthrough (atl v1.12.0+; GET only, path relative to /rest/api/3)
# Read-only REST passthrough (GET only, path relative to /rest/api/3)
atl --context prod jira api GET issue/PROJ-1234/editmeta # Endpoints atl doesn't model
atl --context prod jira api project/PROJ/securitylevel # Method arg optional; defaults to GET

Expand Down Expand Up @@ -356,6 +363,7 @@ atl --context prod confluence page create -s DOCS -t "Title" --parent <id> # Ch
atl --context prod confluence page create -s DOCS -t "Title" --draft # Create as draft
atl --context prod confluence page edit <id> --title "New Title"
atl --context prod confluence page edit <id> --body "<p>New content</p>"
atl --context prod confluence page edit <id> --body "<p>More</p>" --append # Append instead of replace

# Hierarchy navigation
atl --context prod confluence page children <id> # List immediate children
Expand All @@ -371,6 +379,7 @@ atl --context prod confluence page move <id> --space NEWSPACE # Move to differe

# Archive and delete
atl --context prod confluence page archive <id> # Archive page
atl --context prod confluence page archive <id> --unarchive # Restore archived page

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This always fails. In atl-cli v1.13.0, v1.14.0 and current main, UnarchivePage (internal/api/confluence.go) returns unarchive is not supported via API ... Please use the Confluence web UI without making any request. The flag exists in --help, but nothing behind it calls an API. Please drop this line and restore the removed use web UI API note.

atl --context prod confluence page delete <id> --force # Delete (skip confirmation)
atl --context prod confluence page publish <id> # Publish draft

Expand All @@ -385,14 +394,13 @@ atl --context prod confluence template update <id> --name "New Name" --body "<p>
**API version notes**:
- Most operations use v2 API (cursor pagination, max 250/page)
- Search, archive, move, and templates use v1 API (offset pagination, different OAuth scopes)
- Some v1 endpoints return 410 Gone (unarchive removed - use web UI)
- \`--all\` flag handles pagination automatically for list commands

**Tips**:
- Prefer page IDs over title search - titles require exact match and \`--space\`
- Use \`--raw\` to get storage format (XHTML with macros) for backup/migration
- Use \`children --descendants\` to map full page tree with depth levels
- Archive is reversible (via web UI only - no restore API), delete is not
- Archive is reversible (\`archive --unarchive\`), delete is not

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Archive is only reversible by a human in the Confluence web UI. With this wording, an agent may think it can undo an archive itself and archive more readily. Please restore the previous wording: Archive is reversible (via web UI only - no restore API), delete is not.

- Delete returning 404? Could be permission denied - Confluence returns 404 for both "not found" and "no permission". Verify page exists with search first.

### Folder Operations
Expand Down Expand Up @@ -493,7 +501,7 @@ Plain \`--field "Name=value"\` is string-only. Complex Jira field types need \`-
| Multi-select | \`"Name": [{"value": "A"}, {"value": "B"}]\` | No |
| Issue security level | use \`--security "<name|id>"\` instead | No — \`--field\` can't set it |

**Issue security level** has a dedicated flag (atl v1.12.0+) — don't reach for \`--field-file\`. Set it on create/edit with \`--security "Developer only"\` (name or numeric id); \`--security ""\` on edit clears it. Discover a project's levels with \`atl --context prod jira issue field-options --project PROJ --type Bug --field security\`.
**Issue security level** has a dedicated flag — don't reach for \`--field-file\`. Set it on create/edit with \`--security "Developer only"\` (name or numeric id); \`--security ""\` on edit clears it. Discover a project's levels with \`atl --context prod jira issue field-options --project PROJ --type Bug --field security\`.

Example combining labels + select + radio (placeholder field names — the actual fields and allowed values depend on your project's schema, not on this example):

Expand Down Expand Up @@ -524,7 +532,7 @@ Workaround: flatten nested code into inline single-backtick fragments; replace \

- \`@[Display Name]\` or \`@[id:accountId]\` — generates a real Jira mention with notification
- Plain \`@Name\` — renders as text, no notification
- \`[~accountid:...]\` / \`[~username]\` — raw ADF syntax. The Markdown→ADF pipeline ships it as literal text. Do NOT use.
- \`[~accountid:...]\` / \`[~username]\` — raw ADF syntax. The Markdown→ADF pipeline ships it as literal text, so don't use it.

### Replying to Jira Issue Comments

Expand Down Expand Up @@ -574,7 +582,7 @@ For code blocks, use Confluence macro:
</ac:structured-macro>
\`\`\`

**Important**: The \`--body\` flag replaces the ENTIRE page content.
The \`--body\` flag replaces the whole page content; pass \`--append\` to add to the end instead.
`,
},
n8nctl: {
Expand Down Expand Up @@ -627,6 +635,15 @@ n8nctl workflow run <id> --webhook <path> --method POST # Trigger via POST
# Activate/deactivate
n8nctl workflow activate <id>
n8nctl workflow deactivate <id>

# Move to another project (credentials move too unless --skip-credentials)
n8nctl workflow transfer <id> <project-id>
\`\`\`

### Projects

\`\`\`bash
n8nctl project list # List projects (IDs for workflow transfer)
\`\`\`

### Variables
Expand Down Expand Up @@ -680,7 +697,7 @@ gcx login <ctx> --server <url> # Log in and create/use a context

### Authentication — two separate credential planes

A working stack login does NOT imply cloud access, or vice versa:
A working stack login does not imply cloud access, or vice versa:

| Plane | Serves | Broken looks like | Fix |
|-------|--------|-------------------|-----|
Expand All @@ -696,7 +713,7 @@ Re-running the stack login never fixes a "context has no cloud auth" error.
(\`open\` on macOS, \`xdg-open\` on Linux, \`start\` on Windows), tell the
user the verification
code so they can match it
before approving, and wait on the process. NEVER restart the flow while a tab
before approving, and wait on the process. Never restart the flow while a tab
is pending: each run mints a one-time \`state\`, a restart orphans the open
tab, and an approval on an orphaned tab is silently ignored — the user logs
in "successfully" while the CLI waits forever.
Expand All @@ -705,7 +722,7 @@ Re-running the stack login never fixes a "context has no cloud auth" error.
\`gcx config set cloud.grafana-com.token glc_...\` then
\`gcx config set contexts.<ctx>.cloud grafana-com\`. The user creates the
token in the stack UI under Administration → Users and access → Cloud
access policies. Do NOT use \`gcx login --cloud-token\` in an agent
access policies. Don't use \`gcx login --cloud-token\` in an agent
session: it re-runs the stack browser-OAuth leg first and blocks on a
browser approval even with \`--yes\`; gcx's help also marks interactive
cloud OAuth EXPERIMENTAL, with a token that cannot be refreshed. For a
Expand Down Expand Up @@ -759,10 +776,10 @@ PnP CLI for Microsoft 365 - manage SharePoint, Teams, OneDrive, Planner, and mor

### Safety Rules

**CRITICAL**: Before executing any write or delete operation (add, set, remove, copy, move):
**Safety**: Before executing any write or delete operation (add, set, remove, copy, move):
1. Show the full command and target URL to the user
2. Ask for explicit confirmation before executing
3. DO NOT use the \`--confirm\` flag unless specifically requested by the user
3. Do not pass \`-f/--force\` (it skips the confirmation prompt) unless the user asks

### Authentication

Expand Down Expand Up @@ -857,7 +874,7 @@ m365 spo site list --output json --query "[].{Title:Title,Url:Url}" # JMESPath
- Use \`--output json\` with \`--query\` for filtering results with JMESPath syntax
- Use \`m365 <command> --help\` for detailed command documentation
- SharePoint URLs are case-sensitive in many operations
- NEVER use \`--confirm\` flag autonomously - it skips safety prompts
- Never pass \`-f/--force\` autonomously: it skips the confirmation prompt
`,
},
esq: {
Expand Down Expand Up @@ -1062,7 +1079,7 @@ await browser.close();

### Tips

- CLI \`screenshot\` command does NOT support HTTP Basic Auth via URL (Chromium deprecated this) — use the programmatic API with \`httpCredentials\` instead
- CLI \`screenshot\` command does not support HTTP Basic Auth via URL (Chromium deprecated this) — use the programmatic API with \`httpCredentials\` instead
- Use \`--save-har\` to capture all network requests for debugging
- Use \`--load-storage\` / \`--save-storage\` to persist and reuse authentication sessions
- HAR files can be parsed as JSON: \`python3 -c "import json; ..."\` or \`jq\`
Expand Down Expand Up @@ -1130,7 +1147,7 @@ hcloud server list -o columns=name,status,ipv4 # Pick columns

### Safety Rules

**CRITICAL**: Before executing any destructive operation (\`delete\`, \`reset\`, \`poweroff\`):
**Safety**: Before executing any destructive operation (\`delete\`, \`reset\`, \`poweroff\`):
1. Check active context: \`hcloud context active\`
2. Show the resource and target context to the user
3. Ask for explicit confirmation before executing
Expand Down Expand Up @@ -1175,7 +1192,7 @@ Every command supports \`--help\` for its subcommands and flags. Use \`--format

### Safety Rules

**CRITICAL**: Before executing any destructive operation (\`delete\`, \`terminate\`, \`reinstall\`, \`reboot\`):
**Safety**: Before executing any destructive operation (\`delete\`, \`terminate\`, \`reinstall\`, \`reboot\`):
1. Show the resource and target account/endpoint to the user
2. Ask for explicit confirmation before executing
3. Never pass a \`--yes\`/confirmation-skipping flag autonomously
Expand Down Expand Up @@ -1219,8 +1236,8 @@ Reference docs for each tool are in \`${docsPath}/\`. Read the relevant file whe
${rows}

**Safety**: Before executing any SQL write operation (INSERT, UPDATE, DELETE, MERGE, TRUNCATE, DROP):
1. Check current context: \`sqlcmd config current-context\`
2. Show the context name and query to the user
1. Resolve the target: the \`-S\` server if the command passes one, otherwise the chained or current context (\`sqlcmd config current-context\`)
2. Show that target, the database and the full query to the user
3. Ask for explicit confirmation before executing

**Safety**: Every Jira, Confluence, or Assets operation must pass an explicit
Expand All @@ -1230,7 +1247,7 @@ persistent context from an agent session.
**Safety**: Before executing any M365 write or delete operation (add, set, remove, copy, move):
1. Show the full command and target URL to the user
2. Ask for explicit confirmation before executing
3. Do NOT use the \`--confirm\` flag unless specifically requested by the user
3. Do not pass \`-f/--force\` (it skips the confirmation prompt) unless the user asks

**Safety**: Before executing any hcloud destructive operation (\`delete\`, \`reset\`, \`poweroff\`):
1. Check active context: \`hcloud context active\`
Expand Down
Loading