NOIR
Guides

Blog pull-request agent

Read a repository's voice, use an attached image, write on a review branch, and open a draft pull request safely.

A repository-writing agent needs two separate controls: editorial instructions for quality and executable authorization for access. Repository text and conversation claims are never authorization.

Connector

const githubConnector = github({
  repository: requiredEnv('GITHUB_REPOSITORY'),
  token: requiredEnv('GITHUB_TOKEN'),
  branch: 'main',
  branchPrefix: 'noir/',
  verifyRepositoryAuthorization(request) {
    const authorized = request.installationId === allowedInstallation
      && request.actorId === allowedActor
      && request.repository === allowedRepository
      && request.branch.startsWith('noir/')
      && request.branch !== 'main'
      && routineOperations.has(request.operation)

    return authorized
      ? { authorized: true, authorizationId: grantId }
      : { authorized: false }
  },
})

The authorization callback receives the exact repository, installation, actor, operation, and branch. repositoryAccess: 'user-owned' is deprecated because a declaration cannot prove ownership.

Editorial workflow

Teach the agent a deterministic sequence:

  1. List Markdown files under the configured posts directory.
  2. Read three to five representative posts.
  3. Infer voice, structure, frontmatter, linking, and image conventions without copying sentences.
  4. Create one review branch from the configured base branch.
  5. Write the complete post on that branch.
  6. Resolve any image only through the signed current Slack attachment.
  7. Write the image under the configured asset directory.
  8. Open a draft pull request after every requested file exists.
  9. Return repository, base SHA, branch, changed paths, commit SHAs, and PR URL.

Attached images

Use noir.resolveFile(id) or the GitHub connector's image artifact integration. Do not let the model provide an arbitrary URL for the server to fetch. The current message's opaque attachment ID is tied to the verified channel event and is the safer authority boundary.

Review, not deployment

Grant routine operations such as branch creation, file writes, and draft PR creation. Do not grant merge, release, access-control, billing, deletion, or default-branch operations. The human review step remains the publication control.

Voice memory

Repository posts are source material for the current task, not permanent instructions. Keep durable memory for stable preferences explicitly provided by the user. Re-read current posts on each editorial run so the agent does not freeze an outdated house style.

On this page