ONCUE / GUIDE
Repositories
A repository that explains how to install, test, and build gives both the agent and the reviewer a clearer starting point.
Make the task reproducible
Commit the relevant package-manager lockfile and keep repository instructions current. Explain the purpose of the project, important conventions, and how to run meaningful checks.
OnCue detects supported scripts from package.json and uses lockfiles to identify the package manager. Repository configuration can override detected commands.
Declare commands explicitly
The source supports a .oncue/project.yaml file. This illustrative configuration assumes the named scripts actually exist in your repository:
version: 1
commands:
test: pnpm run test
lint: pnpm run lint
typecheck: pnpm run typecheck
build: pnpm run buildUse commands that validate your project. A command returning success is only useful when it checks the behavior the task changed.
Declare secret names, never values
Where a task needs development secrets, configuration declares names under secrets.required or secrets.optional. Values belong in the intended secret configuration flow, not YAML committed to Git.
Only provide secrets required for the task. Read the disclosure and permission context before granting access.
Know the current boundaries
Do not plan around a finished live-preview experience: previews are a placeholder in the inspected source. Likewise, base-branch selection and other workflow changes should be checked against the actual deployed revision.
Use the file diff and check evidence as the core review surface.