ONCUE / GUIDE

Repositories

A repository that explains how to install, test, and build gives both the agent and the reviewer a clearer starting point.

Make the task reproducible

Commit the relevant package-manager lockfile and keep repository instructions current. Explain the purpose of the project, important conventions, and how to run meaningful checks.

OnCue detects supported scripts from package.json and uses lockfiles to identify the package manager. Repository configuration can override detected commands.

Declare commands explicitly

The source supports a .oncue/project.yaml file. This illustrative configuration assumes the named scripts actually exist in your repository:

version: 1
commands:
  test: pnpm run test
  lint: pnpm run lint
  typecheck: pnpm run typecheck
  build: pnpm run build

Use commands that validate your project. A command returning success is only useful when it checks the behavior the task changed.

Declare secret names, never values

Where a task needs development secrets, configuration declares names under secrets.required or secrets.optional. Values belong in the intended secret configuration flow, not YAML committed to Git.

Only provide secrets required for the task. Read the disclosure and permission context before granting access.

Know the current boundaries

Do not plan around a finished live-preview experience: previews are a placeholder in the inspected source. Likewise, base-branch selection and other workflow changes should be checked against the actual deployed revision.

Use the file diff and check evidence as the core review surface.