From aa5b334aacd9891385675c55d249cc2e3236df38 Mon Sep 17 00:00:00 2001 From: Aaron Powell Date: Mon, 7 Sep 2026 12:20:26 +1000 Subject: [PATCH 1/8] Fixing readme (#2969) * Had a bad readme merge recently, fixing * Excluding the bin and obj of .NET output from skills file list --- docs/README.agents.md | 2 +- eng/yaml-parser.mjs | 15 ++++++++++++--- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/docs/README.agents.md b/docs/README.agents.md index eac43b3e..60883491 100644 --- a/docs/README.agents.md +++ b/docs/README.agents.md @@ -90,7 +90,7 @@ See [CONTRIBUTING.md](../CONTRIBUTING.md#adding-agents) for guidelines on how to | [Doublecheck](../agents/doublecheck.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdoublecheck.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdoublecheck.agent.md) | Interactive verification agent for AI-generated output. Runs a three-layer pipeline (self-audit, source verification, adversarial review) and produces structured reports with source links for human review. | | | [Droid](../agents/droid.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdroid.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdroid.agent.md) | Provides installation guidance, usage examples, and automation patterns for the Droid CLI, with emphasis on droid exec for CI/CD and non-interactive automation | | | [Drupal Expert](../agents/drupal-expert.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdrupal-expert.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdrupal-expert.agent.md) | Expert assistant for Drupal development, architecture, and best practices using PHP 8.3+ and modern Drupal patterns | | -| [Dynatrace Expert](../agents/dynatrace-expert.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdynatrace-expert.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdynatrace-expert.agent.md) | The Dynatrace Expert Agent integrates observability and security capabilities directly into GitHub workflows, enabling development teams to investigate incidents, validate deployments, triage errors, detect performance regressions, validate releases, and manage security vulnerabilities by autonomously analysing traces, logs, and Dynatrace findings. This enables targeted and precise remediation of identified issues directly within the repository. | [dynatrace](https://github.com/mcp/io.github.dynatrace-oss/Dynatrace-mcp)
[![Install MCP](https://img.shields.io/badge/Install-VS_Code-0098FF?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-vscode?name=dynatrace&config=%7B%22url%22%3A%22https%3A%2F%2Fpia1134d.dev.apps.dynatracelabs.com%2Fplatform-reserved%2Fmcp-gateway%2Fv0.1%2Fservers%2Fdynatrace-mcp%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24COPILOT_MCP_DT_API_TOKEN%22%7D%7D)
[![Install MCP](https://img.shields.io/badge/Install-VS_Code_Insiders-24bfa5?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-vscodeinsiders?name=dynatrace&config=%7B%22url%22%3A%22https%3A%2F%2Fpia1134d.dev.apps.dynatracelabs.com%2Fplatform-reserved%2Fmcp-gateway%2Fv0.1%2Fservers%2Fdynatrace-mcp%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24COPILOT_MCP_DT_API_TOKEN%22%7D%7D)
[![Install MCP](https://img.shields.io/badge/Install-Visual_Studio-C16FDE?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-visualstudio/mcp-install?%7B%22url%22%3A%22https%3A%2F%2Fpia1134d.dev.apps.dynatracelabs.com%2Fplatform-reserved%2Fmcp-gateway%2Fv0.1%2Fservers%2Fdynatrace-mcp%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24COPILOT_MCP_DT_API_TOKEN%22%7D%7D) | +| [Dynatrace Expert](../agents/dynatrace-expert.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdynatrace-expert.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fdynatrace-expert.agent.md) | The Dynatrace Expert Agent integrates observability and security capabilities directly into GitHub workflows, enabling development teams to investigate incidents, validate deployments, triage errors, detect performance regressions, validate releases, and manage security vulnerabilities by autonomously analysing traces, logs, and Dynatrace findings. This enables targeted and precise remediation of identified issues directly within the repository. | [dynatrace](https://github.com/mcp/io.github.Dynatrace/dynatrace-for-ai)
[![Install MCP](https://img.shields.io/badge/Install-VS_Code-0098FF?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-vscode?name=dynatrace&config=%7B%22url%22%3A%22https%3A%2F%2Fpia1134d.dev.apps.dynatracelabs.com%2Fplatform-reserved%2Fmcp-gateway%2Fv0.1%2Fservers%2Fdynatrace-mcp%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24COPILOT_MCP_DT_API_TOKEN%22%7D%7D)
[![Install MCP](https://img.shields.io/badge/Install-VS_Code_Insiders-24bfa5?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-vscodeinsiders?name=dynatrace&config=%7B%22url%22%3A%22https%3A%2F%2Fpia1134d.dev.apps.dynatracelabs.com%2Fplatform-reserved%2Fmcp-gateway%2Fv0.1%2Fservers%2Fdynatrace-mcp%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24COPILOT_MCP_DT_API_TOKEN%22%7D%7D)
[![Install MCP](https://img.shields.io/badge/Install-Visual_Studio-C16FDE?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-visualstudio/mcp-install?%7B%22url%22%3A%22https%3A%2F%2Fpia1134d.dev.apps.dynatracelabs.com%2Fplatform-reserved%2Fmcp-gateway%2Fv0.1%2Fservers%2Fdynatrace-mcp%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24COPILOT_MCP_DT_API_TOKEN%22%7D%7D) | | [Elasticsearch Agent](../agents/elasticsearch-observability.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Felasticsearch-observability.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Felasticsearch-observability.agent.md) | Our expert AI assistant for debugging code (O11y), optimizing vector search (RAG), and remediating security threats using live Elastic data. | elastic-mcp
[![Install MCP](https://img.shields.io/badge/Install-VS_Code-0098FF?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-vscode?name=elastic-mcp&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22mcp-remote%22%2C%22https%253A%252F%252F%257BKIBANA_URL%257D%252Fapi%252Fagent_builder%252Fmcp%22%2C%22--header%22%2C%22Authorization%253A%2524%257BAUTH_HEADER%257D%22%5D%2C%22env%22%3A%7B%7D%7D)
[![Install MCP](https://img.shields.io/badge/Install-VS_Code_Insiders-24bfa5?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-vscodeinsiders?name=elastic-mcp&config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22mcp-remote%22%2C%22https%253A%252F%252F%257BKIBANA_URL%257D%252Fapi%252Fagent_builder%252Fmcp%22%2C%22--header%22%2C%22Authorization%253A%2524%257BAUTH_HEADER%257D%22%5D%2C%22env%22%3A%7B%7D%7D)
[![Install MCP](https://img.shields.io/badge/Install-Visual_Studio-C16FDE?style=flat-square)](https://aka.ms/awesome-copilot/install/mcp-visualstudio/mcp-install?%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22mcp-remote%22%2C%22https%253A%252F%252F%257BKIBANA_URL%257D%252Fapi%252Fagent_builder%252Fmcp%22%2C%22--header%22%2C%22Authorization%253A%2524%257BAUTH_HEADER%257D%22%5D%2C%22env%22%3A%7B%7D%7D) | | [Electron Code Review Mode Instructions](../agents/electron-angular-native.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Felectron-angular-native.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Felectron-angular-native.agent.md) | Code Review Mode tailored for Electron app with Node.js backend (main), Angular frontend (render), and native integration layer (e.g., AppleScript, shell, or native tooling). Services in other repos are not reviewed here. | | | [Ember](../agents/ember.agent.md)
[![Install in VS Code](https://img.shields.io/badge/VS_Code-Install-0098FF?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fember.agent.md)
[![Install in VS Code Insiders](https://img.shields.io/badge/VS_Code_Insiders-Install-24bfa5?style=flat-square&logo=visualstudiocode&logoColor=white)](https://aka.ms/awesome-copilot/install/agent?url=vscode-insiders%3Achat-agent%2Finstall%3Furl%3Dhttps%3A%2F%2Fraw.githubusercontent.com%2Fgithub%2Fawesome-copilot%2Fmain%2Fagents%2Fember.agent.md) | An AI partner, not an assistant. Ember carries fire from person to person — helping humans discover that AI partnership isn't something you learn, it's something you find. | | diff --git a/eng/yaml-parser.mjs b/eng/yaml-parser.mjs index a0cf8db6..d3850766 100644 --- a/eng/yaml-parser.mjs +++ b/eng/yaml-parser.mjs @@ -168,8 +168,14 @@ function parseSkillMetadata(skillPath) { entries.forEach((entry) => { const filePath = path.join(dirPath, entry.name); if (entry.isDirectory()) { + if (entry.name === "bin" || entry.name === "obj") { + return; // Skip bin and obj directories as they are .NET project output folders and not part of the skill assets + } arrayOfFiles = getAllFiles(filePath, arrayOfFiles); - } else if (!entry.isSymbolicLink() || !skipsAsBundledAsset(filePath)) { + } else if ( + !entry.isSymbolicLink() || + !skipsAsBundledAsset(filePath) + ) { const relativePath = path.relative(skillPath, filePath); if (relativePath !== "SKILL.md") { // Normalize path separators to forward slashes for cross-platform consistency @@ -245,7 +251,10 @@ function parseHookMetadata(hookPath) { const filePath = path.join(dirPath, entry.name); if (entry.isDirectory()) { arrayOfFiles = getAllFiles(filePath, arrayOfFiles); - } else if (!entry.isSymbolicLink() || !skipsAsBundledAsset(filePath)) { + } else if ( + !entry.isSymbolicLink() || + !skipsAsBundledAsset(filePath) + ) { const relativePath = path.relative(hookPath, filePath); if (relativePath !== "README.md") { // Normalize path separators to forward slashes for cross-platform consistency @@ -337,8 +346,8 @@ export { extractMcpServerConfigs, extractMcpServers, parseFrontmatter, - parseSkillMetadata, parseHookMetadata, + parseSkillMetadata, parseWorkflowMetadata, parseYamlFile, safeFileOperation, From c8c95796e09fd17fc42a3b01b1968658efc114ec Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 7 Sep 2026 12:22:19 +1000 Subject: [PATCH 2/8] chore(deps): bump fast-uri in the npm_and_yarn group across 1 directory (#2927) Bumps the npm_and_yarn group with 1 update in the / directory: [fast-uri](https://github.com/fastify/fast-uri). Updates `fast-uri` from 3.1.5 to 3.1.7 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.7 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- package-lock.json | 14 +++++++------- package.json | 2 +- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/package-lock.json b/package-lock.json index af3f7ad5..6246e551 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,7 +9,7 @@ "version": "1.0.0", "license": "MIT", "dependencies": { - "js-yaml": "^5.2.3", + "js-yaml": "^5.4.1", "vfile": "^6.0.3", "vfile-matter": "^5.0.1" }, @@ -885,9 +885,9 @@ "license": "MIT" }, "node_modules/fast-uri": { - "version": "3.1.5", - "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.5.tgz", - "integrity": "sha512-gHwA1O9LDIcKunMKhObS/HimwtehO1nPUECKAu5TpKgaO19fcWEl4bliWe1jWxVFvIXztJjjQ4L8XQ1EU9f7Jw==", + "version": "3.1.7", + "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.7.tgz", + "integrity": "sha512-dOvZVzjdZdz7phd9v6jCbwxrBW3fK6n8Rc0CtdmM4bumzMnxywBYhuph6J819RRw/ku+rLbelwfMunktuzVVHg==", "dev": true, "funding": [ { @@ -1010,9 +1010,9 @@ } }, "node_modules/js-yaml": { - "version": "5.2.3", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.2.3.tgz", - "integrity": "sha512-n+mUVyUX5bVv7G/G2zyIHOhdxfuU1dY2NOFzTQUWiMUbFss8b57NFlgCCaggU78wSw5KVS9cllzeLyzyR+n5nw==", + "version": "5.4.1", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.4.1.tgz", + "integrity": "sha512-28R/k+NAjeuf7+CKlTxWZVExJGwVVLwY06DgEnOMz2gEpfNkDcD7QvyiVPT0xy0XXhU8vHsd4Ot42OOPdJG7dQ==", "funding": [ { "type": "github", diff --git a/package.json b/package.json index b50e8346..a7928fd2 100644 --- a/package.json +++ b/package.json @@ -45,7 +45,7 @@ "all-contributors-cli": "^6.26.1" }, "dependencies": { - "js-yaml": "^5.2.3", + "js-yaml": "^5.4.1", "vfile": "^6.0.3", "vfile-matter": "^5.0.1" }, From 536f6b049da3cd555b93fb8a17b1b47d28e3ec8f Mon Sep 17 00:00:00 2001 From: Oliver Zehentleitner AIgent Date: Mon, 7 Sep 2026 04:24:08 +0200 Subject: [PATCH 3/8] chore: bump keep-the-why to 0.12.0 (#2933) --- .github/plugin/marketplace.json | 4 ++-- plugins/external.json | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/plugin/marketplace.json b/.github/plugin/marketplace.json index cd19cc91..e43c1e7f 100644 --- a/.github/plugin/marketplace.json +++ b/.github/plugin/marketplace.json @@ -979,7 +979,7 @@ { "name": "keep-the-why", "description": "Preserves or recovers the reasoning behind a codebase — architectural decisions, rejected alternatives, workarounds, incident learnings, operational constraints, and historical context the code itself cannot explain.", - "version": "0.10.1", + "version": "0.12.0", "author": { "name": "Oliver Zehentleitner", "url": "https://github.com/oliver-zehentleitner" @@ -998,7 +998,7 @@ "source": { "source": "github", "repo": "oliver-zehentleitner/keep-the-why", - "ref": "v0.10.1" + "ref": "v0.12.0" } }, { diff --git a/plugins/external.json b/plugins/external.json index 9aea727f..34acdbaa 100644 --- a/plugins/external.json +++ b/plugins/external.json @@ -687,7 +687,7 @@ { "name": "keep-the-why", "description": "Preserves or recovers the reasoning behind a codebase — architectural decisions, rejected alternatives, workarounds, incident learnings, operational constraints, and historical context the code itself cannot explain.", - "version": "0.10.1", + "version": "0.12.0", "author": { "name": "Oliver Zehentleitner", "url": "https://github.com/oliver-zehentleitner" @@ -706,7 +706,7 @@ "source": { "source": "github", "repo": "oliver-zehentleitner/keep-the-why", - "ref": "v0.10.1" + "ref": "v0.12.0" } }, { From 44aa844a855b518bc023d66ef1f875053c6282ba Mon Sep 17 00:00:00 2001 From: Guo Cheng Date: Mon, 7 Sep 2026 10:24:47 +0800 Subject: [PATCH 4/8] Contributors table: keep every row at seven cells (#2938) The last row carries eight elements while all fifty-three others carry seven. Each cell is fixed at width="14.28%" (one seventh), so eight of them overflow the table: the final avatar renders narrower than the rest and sits past the edge, reachable only by scrolling horizontally. Moving that one cell onto its own row restores the invariant. Verified by counting cells per row before and after: the distribution goes from {7, 8} to {7, 1}, the 1 being the new trailing row that the next contributor fills. --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index 31d139d2..32414747 100644 --- a/README.md +++ b/README.md @@ -547,6 +547,8 @@ Thanks goes to these wonderful people ([emoji key](./CONTRIBUTING.md#contributor
Konstantinos Passadis | Azure MVP | MCT

Alex Sokol

Jiro Matsuzawa
+ +
Guo Cheng
From d28f79cbe8f188e707fcf9891b77d8f009192108 Mon Sep 17 00:00:00 2001 From: Tim Mulholland Date: Sun, 6 Sep 2026 19:26:26 -0700 Subject: [PATCH 5/8] Update upgrade-agent plugin to 1.1.485 (#2940) --- .github/plugin/marketplace.json | 6 +++--- plugins/external.json | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/plugin/marketplace.json b/.github/plugin/marketplace.json index e43c1e7f..75e3e627 100644 --- a/.github/plugin/marketplace.json +++ b/.github/plugin/marketplace.json @@ -1809,7 +1809,7 @@ { "name": "upgrade-agent", "description": "AI-powered upgrade assistant for upgrading and migrating applications. Helps modernize legacy code and upgrade .NET applications to current frameworks.", - "version": "1.1.441", + "version": "1.1.485", "author": { "name": "Microsoft", "url": "https://www.microsoft.com" @@ -1828,8 +1828,8 @@ "source": "github", "repo": "microsoft/upgrade-agent-plugins", "path": "plugins/upgrade-agent", - "ref": "v1.1.441", - "sha": "f8abab778cfb5b57a3c745d540631b7aab15d5b3" + "ref": "v1.1.485", + "sha": "de2dd654a288726652de81998fbaff7a849891dc" } }, { diff --git a/plugins/external.json b/plugins/external.json index 34acdbaa..85626aac 100644 --- a/plugins/external.json +++ b/plugins/external.json @@ -1229,7 +1229,7 @@ { "name": "upgrade-agent", "description": "AI-powered upgrade assistant for upgrading and migrating applications. Helps modernize legacy code and upgrade .NET applications to current frameworks.", - "version": "1.1.441", + "version": "1.1.485", "author": { "name": "Microsoft", "url": "https://www.microsoft.com" @@ -1248,8 +1248,8 @@ "source": "github", "repo": "microsoft/upgrade-agent-plugins", "path": "plugins/upgrade-agent", - "ref": "v1.1.441", - "sha": "f8abab778cfb5b57a3c745d540631b7aab15d5b3" + "ref": "v1.1.485", + "sha": "de2dd654a288726652de81998fbaff7a849891dc" } }, { From 0ccadfda8a80f9068ad536481d8c2a8276484039 Mon Sep 17 00:00:00 2001 From: Catherine Han <123369259+ninihen1@users.noreply.github.com> Date: Mon, 7 Sep 2026 12:40:51 +1000 Subject: [PATCH 6/8] Update FlowStudio Power Automate skills for server 1.2.77 (#2943) trigger_live_flow now runs scheduled (Recurrence) flows on demand; list_live_connections requires environmentName and applies top after search; the ChatGPT/claude.ai connector path is documented in the mcp skill; the brand reads FlowStudio (one word) across the skills and plugin README; the build skill is back under the 500-line lint limit. Co-authored-by: Aaron Powell --- plugins/flowstudio-power-automate/README.md | 4 +- .../flowstudio-power-automate-build/SKILL.md | 37 ++++++++----------- .../flowstudio-power-automate-debug/SKILL.md | 10 +++-- .../SKILL.md | 14 +++---- skills/flowstudio-power-automate-mcp/SKILL.md | 3 ++ .../references/tool-reference.md | 27 +++++++------- .../SKILL.md | 4 +- 7 files changed, 49 insertions(+), 50 deletions(-) diff --git a/plugins/flowstudio-power-automate/README.md b/plugins/flowstudio-power-automate/README.md index 7178f7fd..387c49e4 100644 --- a/plugins/flowstudio-power-automate/README.md +++ b/plugins/flowstudio-power-automate/README.md @@ -1,6 +1,6 @@ # FlowStudio Power Automate Plugin -Give your AI agent the same visibility you have in the Power Automate portal. The Graph API only returns top-level run status — agents can't see action inputs, loop iterations, nested failures, or who owns a flow. Flow Studio MCP exposes all of it. +Give your AI agent the same visibility you have in the Power Automate portal. The Graph API only returns top-level run status — agents can't see action inputs, loop iterations, nested failures, or who owns a flow. FlowStudio MCP exposes all of it. This plugin includes five skills covering the full lifecycle: connect, debug, build, monitor, and govern Power Automate cloud flows. @@ -16,7 +16,7 @@ Requires a [FlowStudio MCP](https://mcp.flowstudio.app) subscription. | Flow health and failure rates | Nothing | | Who built a flow, what connectors it uses | Nothing | -Flow Studio MCP fills these gaps. +FlowStudio MCP fills these gaps. ## Installation diff --git a/skills/flowstudio-power-automate-build/SKILL.md b/skills/flowstudio-power-automate-build/SKILL.md index 87237229..25c05dca 100644 --- a/skills/flowstudio-power-automate-build/SKILL.md +++ b/skills/flowstudio-power-automate-build/SKILL.md @@ -411,50 +411,43 @@ print(f"Status: {result['responseStatus']}, via: {result['invocation']}") print(result.get("warning")) # set when a required input was missing: the run still ran, with null ``` -### Brand-new non-HTTP flows (Recurrence, connector triggers, etc.) +### Brand-new non-HTTP flows -A brand-new Recurrence or connector-triggered flow has **no prior runs** to -resubmit and no HTTP endpoint to call. This is the ONLY scenario where you -need the temporary HTTP trigger approach below. **Deploy with a temporary -HTTP trigger first, test the actions, then swap to the production trigger.** +A brand-new **Recurrence** flow needs no workaround: deploy it, then run it +immediately with `trigger_live_flow` and no `body` — same as the portal's +"Run flow" button. A body is refused; scheduled triggers take no inputs. -Compact recipe: +A brand-new **connector-triggered** flow (SharePoint, webhooks) has no prior +runs and cannot fire without a real source event. Deploy with a temporary +HTTP trigger, test the actions, then swap to the production trigger: ```python production_trigger = definition["triggers"] definition["triggers"] = { "manual": {"type": "Request", "kind": "Http", "inputs": {"schema": {}}} } - -result = mcp("update_live_flow", - environmentName=ENV, +result = mcp("update_live_flow", environmentName=ENV, flowName=FLOW_ID, # omit if creating new - definition=definition, - connectionReferences=connection_references, + definition=definition, connectionReferences=connection_references, displayName="Overdue Invoice Notifications") -FLOW_ID = FLOW_ID or result["created"] +FLOW_ID = FLOW_ID or result["flowName"] -test = mcp("trigger_live_flow", environmentName=ENV, flowName=FLOW_ID, - body={"sample": "payload"}) +mcp("trigger_live_flow", environmentName=ENV, flowName=FLOW_ID, + body={"sample": "payload"}) runs = mcp("get_live_flow_runs", environmentName=ENV, flowName=FLOW_ID, top=1) - if runs[0]["status"] == "Failed": err = mcp("get_live_flow_run_error", environmentName=ENV, flowName=FLOW_ID, runName=runs[0]["name"]) raise Exception(err["failedActions"][-1]) definition["triggers"] = production_trigger -mcp("update_live_flow", - environmentName=ENV, - flowName=FLOW_ID, - definition=definition, - connectionReferences=connection_references) +mcp("update_live_flow", environmentName=ENV, flowName=FLOW_ID, + definition=definition, connectionReferences=connection_references) ``` The trigger is only the entry point; testing through HTTP still exercises the same actions. If actions use `triggerBody()` or `triggerOutputs()`, pass a -representative `trigger_live_flow.body` shaped like the production trigger -payload. +representative `body` shaped like the production trigger payload. --- diff --git a/skills/flowstudio-power-automate-debug/SKILL.md b/skills/flowstudio-power-automate-debug/SKILL.md index c4d1ddd9..50622de9 100644 --- a/skills/flowstudio-power-automate-debug/SKILL.md +++ b/skills/flowstudio-power-automate-debug/SKILL.md @@ -409,10 +409,10 @@ print(new_runs[0]["status"]) # Succeeded = done | Scenario | Use | Why | |---|---|---| | **Testing a fix** on any flow | `resubmit_live_flow_run` | Replays the exact trigger payload that caused the failure — best way to verify | -| Recurrence / scheduled flow | `resubmit_live_flow_run` | Cannot be triggered on demand any other way | +| Recurrence / scheduled flow | `trigger_live_flow` (no `body`) | Runs it now, like the portal's "Run flow" button; resubmit replays a past run's data | | SharePoint / connector trigger | `resubmit_live_flow_run` | Cannot be triggered without creating a real SP item | | HTTP, Button, or PowerApps trigger with **custom** test payload | `trigger_live_flow` | When you need to send different data than the original run | -| Brand-new flow, never run | `trigger_live_flow` (HTTP, Button, PowerApps) | No prior run exists to resubmit | +| Brand-new flow, never run | `trigger_live_flow` | No prior run exists to resubmit | ### Testing HTTP, Button, and PowerApps flows with custom payloads @@ -445,8 +445,10 @@ if result.get("warning"): ``` > `trigger_live_flow` handles AAD-authenticated triggers automatically. -> Works for `Request` triggers only: HTTP request, Button, and PowerApps. -> Scheduled and connector triggers cannot be run this way. +> Works for `Request` triggers (HTTP request, Button, PowerApps) and for +> scheduled (Recurrence) flows, which it runs immediately — with no `body`, +> since a scheduled trigger takes no inputs (a body is refused). Automated +> connector triggers only fire from their source event. > > Power Automate does not enforce a trigger's `required` inputs. If you leave > one out the run still starts, with that input null, and the result carries a diff --git a/skills/flowstudio-power-automate-governance/SKILL.md b/skills/flowstudio-power-automate-governance/SKILL.md index 58092bcc..b4413ea6 100644 --- a/skills/flowstudio-power-automate-governance/SKILL.md +++ b/skills/flowstudio-power-automate-governance/SKILL.md @@ -64,18 +64,18 @@ If a deleted flow has `monitor=true`, suggest disabling monitoring ## The Write Tool: `update_store_flow` -`update_store_flow` writes governance metadata to the **Flow Studio cache +`update_store_flow` writes governance metadata to the **FlowStudio cache only** — it does NOT modify the flow in Power Automate. These fields are not visible via `get_live_flow` or the PA portal. They exist only in the -Flow Studio store and are used by Flow Studio's scanning pipeline and +FlowStudio store and are used by FlowStudio's scanning pipeline and notification rules. This means: -- `ownerTeam` / `supportEmail` — sets who Flow Studio considers the +- `ownerTeam` / `supportEmail` — sets who FlowStudio considers the governance contact. Does NOT change the actual PA flow owner. -- `rule_notify_email` — sets who receives Flow Studio failure/missing-run +- `rule_notify_email` — sets who receives FlowStudio failure/missing-run notifications. Does NOT change Microsoft's built-in flow failure alerts. -- `monitor` / `critical` / `businessImpact` — Flow Studio classification +- `monitor` / `critical` / `businessImpact` — FlowStudio classification only. Power Automate has no equivalent fields. Merge semantics — only fields you provide are updated. Returns the full @@ -218,7 +218,7 @@ store tags, so read/append/write. Avoid overriding computed `tier` unless asked. ### 7. Maker Offboarding When an employee leaves, identify their flows and apps, and reassign -Flow Studio governance contacts and notification recipients. +FlowStudio governance contacts and notification recipients. ``` 1. get_store_maker(makerKey="") @@ -234,7 +234,7 @@ Flow Studio governance contacts and notification recipients. apps needing manual reassignment ``` -This changes Flow Studio governance contacts, not actual PA ownership. Power +This changes FlowStudio governance contacts, not actual PA ownership. Power Apps ownership changes are manual/admin-center work. ### 8. Security Review diff --git a/skills/flowstudio-power-automate-mcp/SKILL.md b/skills/flowstudio-power-automate-mcp/SKILL.md index de1d9bd4..517390c7 100644 --- a/skills/flowstudio-power-automate-mcp/SKILL.md +++ b/skills/flowstudio-power-automate-mcp/SKILL.md @@ -26,6 +26,9 @@ skills that all build on this one. > compatible Power Automate MCP server). You will need: > - MCP endpoint: `https://mcp.flowstudio.app/mcp` (same for all subscribers) > - API key / JWT token (`x-api-key` header — NOT Bearer) +> - In ChatGPT or claude.ai there is no key: add `https://mcp.flowstudio.app/mcp/oauth` +> as a connector and sign in with Microsoft — see the +> [ChatGPT walkthrough](https://learn.flowstudio.app/chatgpt-power-automate) > - Power Platform environment name (e.g. `Default-`) --- diff --git a/skills/flowstudio-power-automate-mcp/references/tool-reference.md b/skills/flowstudio-power-automate-mcp/references/tool-reference.md index 060eea61..efd4f7f4 100644 --- a/skills/flowstudio-power-automate-mcp/references/tool-reference.md +++ b/skills/flowstudio-power-automate-mcp/references/tool-reference.md @@ -93,9 +93,9 @@ Response: wrapper object with `connections` array. > Filter by status: prefer `overallStatus == "Connected"` when present; otherwise > check `statuses[0].status == "Connected"`. > -> For build workflows, pass `environmentName` to avoid using a connection from -> the wrong environment. Omit it only when intentionally inventorying connections -> across all environments. +> `environmentName` is required — the platform cannot list connections across +> environments (omitting it answers 400 MissingEnvironmentFilter). Get one from +> `list_live_environments`. > > Pass `search=` to narrow output and receive > `connectionReferenceTemplate` plus `hostTemplate` values that can be copied @@ -448,9 +448,10 @@ Response keys: `flowKey`, `triggerName`, `triggerKind`, `invocation`, `triggerUr `requiresAadAuth`, `authType`, `responseStatus`, `responseBody`, `runName`, and `warning` when a required trigger input was not supplied. -> **Works for `Request` triggers: HTTP request, Button, and PowerApps.** Returns an -> error for Recurrence and connector triggers: -> `"only HTTP Request triggers can be invoked via this tool"`. +> **Works for `Request` triggers (HTTP request, Button, PowerApps) and for +> scheduled (Recurrence) flows.** A scheduled flow runs immediately, like the +> portal's "Run flow" button, and takes no `body` — one is refused. Automated +> connector triggers only fire from their source event and return an error. > > HTTP triggers go through the signed callback URL (`invocation: callbackUrl`). > Button and PowerApps triggers have no callback URL; with a `body` they run @@ -483,8 +484,7 @@ Response keys: `flowKey`, `triggerName`, `triggerKind`, `invocation`, `triggerUr ### `set_live_flow_state` -Start or stop a Power Automate flow via the live PA API. Does **not** require -a Power Clarity workspace — works for any flow the impersonated account can access. +Start or stop a Power Automate flow in any environment you have access to. Reads the current state first and only issues the start/stop call if a change is actually needed. @@ -594,11 +594,11 @@ tool schemas cannot tell you. connectionReferences. Use `set_live_flow_state` to start/stop a flow. ### `trigger_live_flow` -- **Works for HTTP, Button, and PowerApps triggers.** Returns error for Recurrence, - connector, and other trigger types. +- **Works for HTTP, Button, PowerApps, and scheduled (Recurrence) triggers.** + A scheduled flow runs with no `body`. Automated connector triggers error. - Pass trigger inputs as `body`. A `warning` in the result means a required input was missing and the run started with it null. -- AAD-authenticated triggers are handled automatically (impersonated Bearer token). +- AAD-authenticated triggers are handled automatically (Bearer token attached). ### `get_live_flow_runs` - `top` defaults to **30** with automatic pagination for higher values. @@ -611,8 +611,9 @@ tool schemas cannot tell you. - `poster`: `"Flow bot"` for Workflows bot identity, `"User"` for user identity. ### `list_live_connections` -- For build workflows, pass `environmentName`; omitting it inventories - connections across environments. +- `environmentName` is required; the platform cannot list connections across + environments. `top` is applied after `search` and the result carries + `truncated` + `matchedCount` when the cap drops matches. - Use `search=` to get smaller output and paste-ready `connectionReferenceTemplate` / `hostTemplate` values. - `id` is the value you need for `connectionName` in `connectionReferences`. diff --git a/skills/flowstudio-power-automate-monitoring/SKILL.md b/skills/flowstudio-power-automate-monitoring/SKILL.md index bbd1a248..cdf7457d 100644 --- a/skills/flowstudio-power-automate-monitoring/SKILL.md +++ b/skills/flowstudio-power-automate-monitoring/SKILL.md @@ -39,7 +39,7 @@ enriched with governance metadata and remediation hints. ## How Monitoring Works -Flow Studio scans the Power Automate API daily for each subscriber and caches +FlowStudio scans the Power Automate API daily for each subscriber and caches the results. There are two levels: - **All flows** get metadata scanned: definition, connections, owners, trigger @@ -54,7 +54,7 @@ the results. There are two levels: a flow was last scanned. If stale, the scanning pipeline may not be running. **Enabling monitoring:** Set `monitor: true` via `update_store_flow` or the -Flow Studio for Teams app +FlowStudio for Teams app ([how to select flows](https://learn.flowstudio.app/teams-monitoring)). **Designating critical flows:** Use `update_store_flow` with `critical=true` From 877b3f064047b6d9c4f6d01e767c59fe0e77116e Mon Sep 17 00:00:00 2001 From: John Papa Date: Sun, 6 Sep 2026 22:42:17 -0400 Subject: [PATCH 7/8] Update ai-ready to v1.3.0 (#2952) Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Aaron Powell Copilot-Session: 9ffae6e6-6810-4c61-982f-a295ac49f669 --- .github/plugin/marketplace.json | 4 ++-- plugins/external.json | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/plugin/marketplace.json b/.github/plugin/marketplace.json index 75e3e627..8677354b 100644 --- a/.github/plugin/marketplace.json +++ b/.github/plugin/marketplace.json @@ -51,7 +51,7 @@ { "name": "ai-ready", "description": "Analyze any repository and generate AI-ready configuration — AGENTS.md, copilot-instructions.md, CI workflows, issue templates, and more. Mines your PR review patterns and creates files customized to your stack.", - "version": "1.1.0", + "version": "1.3.0", "author": { "name": "John Papa", "url": "https://github.com/johnpapa" @@ -72,7 +72,7 @@ "source": "github", "repo": "johnpapa/ai-ready", "path": ".github/plugin", - "ref": "v1.1.0" + "ref": "v1.3.0" } }, { diff --git a/plugins/external.json b/plugins/external.json index 85626aac..7eaf44e5 100644 --- a/plugins/external.json +++ b/plugins/external.json @@ -29,7 +29,7 @@ { "name": "ai-ready", "description": "Analyze any repository and generate AI-ready configuration — AGENTS.md, copilot-instructions.md, CI workflows, issue templates, and more. Mines your PR review patterns and creates files customized to your stack.", - "version": "1.1.0", + "version": "1.3.0", "author": { "name": "John Papa", "url": "https://github.com/johnpapa" @@ -50,7 +50,7 @@ "source": "github", "repo": "johnpapa/ai-ready", "path": ".github/plugin", - "ref": "v1.1.0" + "ref": "v1.3.0" } }, { From 87ba8b1780d0e2655fc19fa3f8d4fc7879881744 Mon Sep 17 00:00:00 2001 From: sina morida <112853012+sinamorida@users.noreply.github.com> Date: Sun, 6 Sep 2026 22:45:16 -0400 Subject: [PATCH 8/8] docs(ai-team-orchestration): add role guidance, PR checklist, QA risk matrix, and sample prompts (#2946) Improve the ai-team-orchestration skill references: - anti-patterns.md: Do/Don't role responsibilities (Producer/Dev/QA) and decision-log guidance - brainstorm-format.md: minimal sample prompts for Producer, Dev, and QA agents - sprint-plan-template.md: concrete acceptance-criteria examples, PR checklist, and a QA risk matrix - project-brief-template.md: onboarding checklist and where to record decisions Co-authored-by: sinamorida Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Aaron Powell --- .../references/anti-patterns.md | 19 +++++++++++++++ .../references/brainstorm-format.md | 17 ++++++++++++++ .../references/project-brief-template.md | 11 +++++++++ .../references/sprint-plan-template.md | 23 ++++++++++++++++++- 4 files changed, 69 insertions(+), 1 deletion(-) diff --git a/skills/ai-team-orchestration/references/anti-patterns.md b/skills/ai-team-orchestration/references/anti-patterns.md index ac3cbcf4..c2d1ec32 100644 --- a/skills/ai-team-orchestration/references/anti-patterns.md +++ b/skills/ai-team-orchestration/references/anti-patterns.md @@ -11,3 +11,22 @@ | Bugs and decisions kept only in chat | Use the repository's issue tracker and durable context | Future sessions can discover them. | | QA fixes application source | QA reports behavior; Dev implements fixes | Separation preserves independent verification. | | Treating every automated suggestion as a requirement | Assess relevance, confidence, scope, and practical risk | Review should improve the product, not expand scope without limit. | + +## Role responsibilities (Do / Don't) + +- Producer + - Do: Clarify outcome, constraints, acceptance criteria, and explicit exclusions; coordinate reviewers and merge policy. + - Don't: Implement or ship code changes that should be reviewed by Dev. + +- Dev + - Do: Implement the smallest complete solution, run listed verification, include tests, and prepare the PR with verification steps. + - Don't: Merge without required checks, failing tests, or without documenting risks and decisions. + +- QA (optional) + - Do: Independently verify behavior, file reproducible issues, and confirm fixes after Dev applies them. + - Don't: Modify application source as a shortcut for failing verification — report and hand back to Dev. + +## Decision logging guidance + +- Record material decisions in a DECISIONS.md or the repository issue tracker with: title, date, owner, decision summary (1 line), rationale, and link to related PR/issue. +- Keep entries short and searchable; record the next action when a decision defers work. diff --git a/skills/ai-team-orchestration/references/brainstorm-format.md b/skills/ai-team-orchestration/references/brainstorm-format.md index b10c199b..6d13feac 100644 --- a/skills/ai-team-orchestration/references/brainstorm-format.md +++ b/skills/ai-team-orchestration/references/brainstorm-format.md @@ -87,3 +87,20 @@ Each agent reviews from their perspective: Flag issues and suggest fixes. ``` + +## Sample agent prompts (minimal) + +- Producer (short): +``` +You are Remy, the Producer. Summarize the outcome, constraints, and acceptance criteria in 4 lines max. List required reviewers and whether QA is needed. End with the single next action. +``` + +- Dev (short): +``` +You are Nova+Sage (Dev). Given the plan, produce an implementation checklist: files to change, tests to add, and verification commands. Keep it actionable. +``` + +- QA (short): +``` +You are Ivy (QA). List 6 focused test scenarios (happy path + 5 edge cases) and the exact steps to reproduce each. Include expected results. +``` diff --git a/skills/ai-team-orchestration/references/project-brief-template.md b/skills/ai-team-orchestration/references/project-brief-template.md index acc1d733..8a0953eb 100644 --- a/skills/ai-team-orchestration/references/project-brief-template.md +++ b/skills/ai-team-orchestration/references/project-brief-template.md @@ -66,5 +66,16 @@ Use this only when the project benefits from durable context across sessions. Ke - Dev: implementation and verification - QA: optional independent behavioral verification +## Onboarding checklist (add to brief) + +- Setup verified: `npm ci` / `pip -r requirements.txt` +- Tests run: `npm test` / `pytest -q` +- Lint pass: `npm run lint` +- Where to find CI logs and deploy dashboards + +## Where to record decisions + +- Add short entries to DECISIONS.md or create an issue with the decision tag. Each entry should include: title, date, owner, 1-line summary, rationale, and link to PR/issue. + Record material decisions, blockers, and the next action here or in the active plan. Use GitHub Issues or the repository's tracker for bugs and follow-up work. ``` diff --git a/skills/ai-team-orchestration/references/sprint-plan-template.md b/skills/ai-team-orchestration/references/sprint-plan-template.md index 95c50cee..ccaeb8a9 100644 --- a/skills/ai-team-orchestration/references/sprint-plan-template.md +++ b/skills/ai-team-orchestration/references/sprint-plan-template.md @@ -32,20 +32,41 @@ Use this for substantial work. Small, clear changes can proceed directly from th ## Acceptance Criteria - [ ] [observable behavior] -- [ ] Relevant repository checks pass +- [ ] Relevant repository checks pass (example: `npm run lint`, `npm test`) +- [ ] Tests covering the change are added or validated - [ ] Documentation/context is updated when behavior or operation changed ## Verification - Automated: [commands or checks] + - Example: `npm ci && npm run test` or `pytest -q` + - Example: `npm run lint && npm run build` - Manual: [focused scenarios, if useful] - Independent review: required / optional / not needed - [reason] - QA: required / optional / not needed - [reason] +## PR Checklist (add to PR body) + +- Branch name follows repo policy (e.g., `feat/`, `fix/`, or `chore/`) +- Description: short summary, why, and acceptance criteria +- Verification steps included (commands & manual checks) +- Tests added or existing tests updated +- Relevant docs/PROJECT_BRIEF updated if behavior changed +- Reviewers: @team or specific owners +- Required checks: list CI jobs that must pass +- Release notes / changelog entry: yes/no + ## Risks and Decisions - [risk or material decision] +## QA risk matrix (when to require QA) + +- High impact × High uncertainty = QA required +- High impact × Low uncertainty = QA recommended +- Low impact × High uncertainty = QA recommended +- Low impact × Low uncertainty = QA optional + ## Next Action [owner and immediate next step]