Borrowing it
Nothing to install: this file belongs to akaghef/M3E. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/akaghef/M3E/main/.claude/skills/nightly-autopilot/SKILL.mdgit clone --depth 1 https://github.com/akaghef/M3EWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/akaghef/m3e/nightly-autopilot)<a href="https://agentmods.dev/skills/akaghef/m3e/nightly-autopilot"><img src="https://agentmods.dev/badge/skills/akaghef/m3e/nightly-autopilot/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/akaghef/m3e/nightly-autopilot"><img src="https://agentmods.dev/badge/skills/akaghef/m3e/nightly-autopilot.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00321 | $0.01779 |
| Opus 5.5 | $0.00128 | $0.00712 |
| Sonnet 5.5 | $0.00064 | $0.00356 |
| Haiku 4.5 | $0.00032 | $0.00178 |
Grade A, and why
nightly-autopilot scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 100 lines — stays where its author put it; the contents beside it link to each section on GitHub.
nightly-autopilot
dev-beta を「最新かつ green」に保ち、M3E データを版管理バックアップする保守ジョブ。 ハイブリッド構成:決定論パートは shell スクリプト、判断が要る PR/CI はエージェントが担う。 production(final/・main)と Syncthing には一切触れない。
2つのモード
| モード | 起動 | 用途 |
|---|---|---|
| 1-shot(朝・手動) | エージェントにこのスキルを実行させる(/nightly-autopilot 等) |
夜間が失敗した時の取り戻し/日中の手動同期 |
| scheduled(夜・自動) | Codex automation(~/.codex/automations/.../automation.toml、rrule 定期、prompt がこのスキルを起動) |
寝ている間の無人実行 |
どちらも実行内容は同じ。launchd LaunchAgent は使わない(撤去済み)。
実行手順(ハイブリッド)
Step 1 — 決定論パート(スクリプト)
scripts/ops/nightly-autopilot.sh --no-pr --no-ci-fix
これが Stage A: データ SQL ダンプ・バックアップ(3 ws を lock-safe に .backup→.dump →
akaghef/m3e-data の snapshots ブランチへ日付 commit/push)と Stage 0: dev-beta 最新化
(pull --ff-only→git add -u→chore: nightly auto-commit (日付)→push)を実行し、
logs/nightly-autopilot-YYYY-MM-DD.md に途中経過を残す。ガードレール(単一ロック・90分予算・
force-push 禁止・非ff abort)はスクリプト側で効く。まず --dry-run を付けて副作用ゼロを確認してから本番を。
Step 2 — green PR マージ(エージェント判断)
gh pr list --base dev-beta --state open --json number,title,mergeable,statusCheckRollup,headRefName
各 PR について:CI(statusCheckRollup)が全 success で、mergeable == MERGEABLE のものだけ
gh pr merge <n> --squash --delete-branch。
重要:GitHub は mergeability を非同期算出し初回は UNKNOWN を返す(既知の落とし穴)。
UNKNOWN の時は数秒待って再照会し、MERGEABLE/CONFLICTING が確定してから判断する。
赤・競合・保留は触らず理由を記録。マージ後は git pull --ff-only origin dev-beta。
Step 3 — CI green 化(エージェント判断・最小修正)
push 後、gh run list --branch dev-beta で現 HEAD の run が登録されるのを少し待ってから完了までポーリング
(直後は run 未登録のことがある/対象ワークフローが無いコミットは neutral 扱い)。
赤い run があれば gh run view <id> --log-failed でログを取り、最小修正を dev-beta に commit→push→再確認。
最大3回で打ち切り、それでも赤なら停止して報告。final/・main は触らない/force-push しない。
Step 4 — 報告
実施内容(データ snapshot / auto-commit / マージ&skip した PR+理由 / CI 結末 / 中断理由 / 総合判定)を簡潔に報告。
触らないもの(安全境界)
- final/ と main には一切触れない。 本番昇格は別途
majorupdateで人間が行う。 - Syncthing 設定は変更しない。 データの定常同期(DP2)は Syncthing が担い、本ジョブは版管理バックアップ(Stage A)のみ。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 100 lines · 321 tokens per session scan A 2243a7b66934
nightly-autopilot is a skill published in the GitHub repository akaghef/M3E (11 stars, last pushed 5d ago), licensed MIT. It adds 321 tokens to every session and 1,779 once invoked, about $0.0013 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-10-02.
Other skills, from other repositories
factory-ship
Experimental workflow for publishing and completing configured software delivery work. Use when the user or an enabled factory policy asks to ship.
gitlab-devops
GitLab DevOps operations — issues, merge requests, CI/CD pipelines, repository browsing, labels, milestones, releases, and wiki management. Use when querying GitLab project status, monitoring pipeline executions, browsing repository files, creating issues for network findings, opening merge requests for config…
seed-snapshot-release
An automated workflow for creating and tracking a snapshot release of the pull request on the current branch. A snapshot release is a temporary package build used for testing a branch before a normal release.
push-ci
Push to remote and monitor CI. Validates branch safety, executes git push WITH explicit user approval, then monitors CI run status via gh CLI. Use when: user says 'push', 'push and watch CI', 'ship it', 'push-ci'. Not for: committing (use /smart-commit), creating PRs (use /create-pr), merging (use /merge-prep).
release-engineering
Plan and verify software releases with versioning, changelogs, release branches, feature flags, canaries, migration gates, rollback, deployment checks, and release readiness. Use when preparing a release, shipping a risky PR, coordinating app/backend/database rollout, recovering from a bad deploy, or defining release…
ct-release-orchestrator
Orchestrates the canonical 4-verb release pipeline introduced by SPEC-T9345: cleo release plan, then cleo release open, then PR + GHA tag workflow, then cleo release reconcile. The deprecated cleo release ship monolith was deleted in T10103 — do not invoke it. Use ship-e2e-smoke to validate the full pipeline…