Engineering manager 1-on-1 meeting brief generator

Generate a 1-on-1 brief from GitHub activity. Fully deterministic pipeline — 5 tool calls, zero sub-agent spawns.

jacksync

@jacksync

Install

$ openclaw skills install @jacksync/pullstar-1on1

Overview

PullStar fetches GitHub activity for one engineer (PRs authored, reviews given), runs a deterministic local scoring engine across five dimensions, and prepares an LLM input payload. The agent then performs LLM inference and finalizes the brief.

Quickstart:

run_brief.py --login steipete --pr-insights --days 7
Read llm_input_steipete.json, do the LLM inference, present the brief

Data Flow Summary:

StepWhat runsExternal calls
Ingestrun_brief.pyingest.pyGitHub API
Scorerun_brief.pyscore.pyNone
Preparerun_brief.pyagent_prepare_1on1.pyNone
Agent inferenceAgent calls LLMLLM provider
FinalizeAgent runs agent_finalize_1on1.pyNone

⚠️ Important: Steps 1–3 run locally. Only the LLM inference step (step 4) sends data to your AI provider.


Requirements

  • Python 3.11+
  • Install dependencies: pip install PyGithub python-dotenv requests
  • A GitHub personal access token (see Security section below)

Security & Privacy

Token Scope

OptionWhere to createBest for
Classic PAT (repo scope)https://github.com/settings/tokensCross-user search, org-wide ingestion
Fine-grained PAThttps://github.com/settings/personal-access-tokensYour own repos only

Fine-grained PATs cannot search across arbitrary users. Use a classic PAT for org-wide briefs.

Set GITHUB_ORG to narrow search to one organization.

Token Resolution Order

Secrets are resolved using layered lookup — first match wins:

  1. --github-token CLI flag (override/debug only — never logged)
  2. GITHUB_TOKEN environment variable
  3. ~/.pullstar/credentials (key=value format)
  4. .env in the skill directory

Data Privacy by Mode

Default (no --pr-insights):

  • Only aggregated statistics and scores sent to LLM
  • No raw PR text, comments, or review bodies included

PR Insights (--pr-insights):

  • Bounded raw PR discussion text packaged into the LLM prompt
  • Bounded to 5 PRs, 3 reviews/comments each, 600 char limit per item
  • Review llm_input_{login}.json before inference if you have privacy concerns

Configuration

.env

VariableRequiredDescription
GITHUB_TOKENRecommendedClassic PAT with repo scope. Omit for unauthenticated access (60 req/hr).
GITHUB_ORGNoScope ingestion to one org.

Usage

Standard run

python run_brief.py --login jsmith

With PR insights

python run_brief.py --login jsmith --pr-insights

Common options

python run_brief.py --login jsmith --days 14          # wider lookback (default: 5)
python run_brief.py --login jsmith --max-results 10   # faster on high-activity users (default: 20)
python run_brief.py --login jsmith --api-mode rest    # force REST API (default: graphql)

All options

FlagDefaultDescription
--loginrequiredEngineer GitHub login
--days5Lookback window in days
--pr-insightsoffInclude PR review/comment context in LLM prompt
--max-results20Max search results to iterate (lower = faster)
--api-modegraphqlgraphql or rest
--output-dir.pullstarDirectory for all artifacts
--github-tokenOverride/debug only. Prefer .env.

Agent Flow (Deterministic — No Sub-Agents)

The entire pipeline runs in the agent's main session. Use exec for Python scripts and do the LLM inference inline — the agent itself is the LLM. Never spawn sub-agents.

1. exec:    python run_brief.py --login <login> [flags]
2. read:    .pullstar/llm_input_<login>.json
3. write:   .pullstar/llm_output_<login>.json  (produce the brief inline as the LLM)
4. exec:    python scripts/agent_finalize_1on1.py --login <login>
5. read:    .pullstar/output_<login>.json       (quality gate: verify meaningful data)
6. (done — present the brief)

Why Inline

  • Zero sub-agent overhead. No spawn latency, no polling, no completion-event complexity.
  • Deterministic tool count. Exactly 5 tool calls: exec → read → write → exec → read.
  • Faster end-to-end. All steps run sequentially in one session with no context-fork tax.
  • The agent IS the LLM. Creating a sub-agent to call the same model for inference adds nothing.

Quality Gate

After step 4, read output_<login>.json and verify the brief has meaningful data. If total_score is 0 or the brief contains phrases like "no activity" / "no contributions" / "no PRs merged" / "insufficient data", respond with a graceful fallback message instead of presenting an empty brief.


Agent JSON Contract

Input (from run_brief.py)

File: .pullstar/llm_input_{login}.json

FieldTypeDescription
systemstringSystem prompt with instructions
userstringUser message with engineer data and scores
metadataobjectVersion, timestamps, total score, confidence

Output (from agent)

File: .pullstar/llm_output_{login}.json

{
  "version":        "1.0",
  "engineer_login": "jsmith",
  "brief":          "## Quick Summary\n..."
}

Requirements:

  • Valid JSON
  • brief must be a non-empty markdown string
  • Plain text is also accepted — the full file content will be used as the brief

Brief Output Format

The final brief (output_{login}.json) contains a markdown document with six sections:

SectionContent
Quick Summary2–3 sentences, lead with concrete numbers
Highlights2–4 bullets, one data point each
Areas to Explore2–3 open-ended questions for the 1-on-1
Patterns Worth Noting1–3 factual behavioral observations
Score SummaryMarkdown table — Dimension / Score / Confidence / Signal. Emoji encouraged in Confidence column.
Suggested FocusOne paragraph on the most useful 1-on-1 theme

Example Score Summary table:

DimensionScoreConfidenceSignal
Velocity16/20✅ High10 PRs merged, 3 active weeks
PR Quality14/20✅ HighAvg 320 lines, 2 large PRs flagged
Review Participation8/20⚠️ Medium3 reviews given in window
Collaboration12/20✅ High4 repos, 3 reviewers per PR avg
Consistency10/20🔴 Low1 of 3 weeks inactive

Artifacts

All artifacts are written to .pullstar/ (gitignored, never committed).

FileWritten bySent to AI?
ingest_{login}.jsoningest.py❌ No
score_{login}.jsonscore.py❌ No
llm_input_{login}.jsonagent_prepare_1on1.py✅ Yes
llm_output_{login}.jsonAgent❌ No
output_{login}.jsonagent_finalize_1on1.py❌ No

Troubleshooting

"GitHub rejected the PR search query (422)" Use a classic PAT — fine-grained PATs cannot search across arbitrary users.

"GitHub rate limit hit" Authenticated: 5000 req/hr. Unauthenticated: 60 req/hr. Set GITHUB_TOKEN.

Slow ingestion on high-activity users Use --max-results 10 to cap iteration. Default is 20.

GraphQL errors Use --api-mode rest to fall back to the legacy REST API.


For Agent Developers

Deterministic Pattern (Mandatory)

The brief pipeline is fully deterministic. There is exactly one correct execution path:

exec(run_brief.py) → read(llm_input) → write(llm_output) → exec(agent_finalize) → read(output/quality gate)

❌ Never spawn sub-agents for this pipeline. The agent itself performs the LLM inference step — delegating to a sub-agent is redundant, adds latency, and creates thrash. The pipeline completes in 5 tool calls. If you're tempted to spawn a sub-agent, ask yourself: "Am I running a Python script or doing LLM inference?" If the answer is "Python script," use exec. If the answer is "LLM inference," do it inline.

Recovery: If run_brief.py exits non-zero, the GitHub user likely doesn't exist or the token is invalid. Respond with the graceful fallback message; do not retry or spawn alternative paths.


License

MIT — See source repository for full license text.

Top skills in this category

Humanizer

@biostartechnology

Remove signs of AI-generated writing from text. Use when editing or reviewing text to make it sound more natural and human-written. Based on Wikipedia's comprehensive "Signs of AI writing" guide. Detects and fixes patterns including: inflated symbolism, promotional language, superficial -ing analyses, vague attributions, em dash overuse, rule of three, AI vocabulary words, negative parallelisms, and excessive conjunctive phrases.

712130k

Answer Overflow

@rhyssullivan

Search indexed Discord community discussions via Answer Overflow. Find solutions to coding problems, library issues, and community Q&A that only exist in Discord conversations.

18122k

Video Subtitles

@ngutman

Generate SRT subtitles from video/audio with translation support. Transcribes Hebrew (ivrit.ai) and English (whisper), translates between languages, burns subtitles into video. Use for creating captions, transcripts, or hardcoded subtitles for WhatsApp/social media.

179.9k

Moltbot Best Practices

@nextfrontierbuilds

Best practices for AI agents - Cursor, Claude, ChatGPT, Copilot. Avoid common mistakes. Confirms before executing, drafts before publishing. Vibe-coding essential.

205.4k

Zero Trust

@doonot

Security-first behavioral guidelines for cautious agent operation. Use this skill for ALL operations involving external resources, installations, credentials, or actions with external effects. Triggers on - any URL/link interaction, package installations, API key handling, sending emails/messages, social media posts, financial transactions, or any action that could expose data or have irreversible effects.

136.7k