Skip to content
Merged
Show file tree
Hide file tree
Changes from 14 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions .github/ISSUE_TEMPLATE/bug-report.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
name: Bug report
description: Report a bug in a skill, tool, or the agent
description: Report a bug in a skill, plugin, or agent guidance
title: "[Bug]: "
labels: ["bug"]
body:
Expand All @@ -8,6 +8,8 @@ body:
value: |
Thanks for taking the time to file a bug report!

**WinApp CLI or WinUI analyzer bug?** Please [open an issue in microsoft/winappCli](https://github.com/microsoft/winappCli/issues/new/choose) for analyzer diagnostics/package issues or tool behavior in `find-api`, `run`, packaging, and Windows Sandbox. Use this form for incorrect skill/agent guidance or plugin integration.

💡 **The single most useful thing you can attach** is a `session-report.md` from the **`winui-session-report`** skill — it captures the agent's tool calls, build output, and timing in a structured way.
- type: textarea
id: description
Expand All @@ -31,7 +33,6 @@ body:
- "skill: winui-packaging"
- "skill: winui-session-report"
- "skill: winui-wpf-migration"
- "tool: winui-analyzer (Roslyn)"
- "area: plugin / install"
- "area: docs"
validations:
Expand Down
3 changes: 3 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
blank_issues_enabled: false
contact_links:
- name: WinApp CLI or WinUI analyzer bug
url: https://github.com/microsoft/winappCli/issues/new/choose
about: Report analyzer diagnostics/package issues and find-api, run, packaging, or Windows Sandbox tool bugs in the WinApp repository.
- name: Question / discussion
url: https://github.com/microsoft/win-dev-skills/discussions
about: Have a question about how to use a skill, or want to discuss an idea? Start a Discussion.
Expand Down
3 changes: 1 addition & 2 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ The `pr-target-policy` CI check enforces this.

- [ ] Agent (`plugins/winui/agents/`, `plugins/winui/agent-plugin/com.github.copilot/agents/`)
- [ ] Skill: <!-- name(s) -->
- [ ] Tool: <!-- winui-analyzer -->
- [ ] Script: <!-- Analyze-Session.ps1 / workflow regressions / release helper -->
- [ ] Plugin metadata (`plugin.json`, `plugins/winui/`)
- [ ] Repo-level docs / governance

Expand All @@ -41,7 +41,6 @@ The `pr-target-policy` CI check enforces this.

- [ ] Tested locally on Windows (build + agent invocation if applicable)
- [ ] If a skill changed: `SKILL.md` frontmatter still valid; cross-references to other skills still resolve
- [ ] If `Microsoft.WindowsAppSDK.Analyzers` source changed: rebuilt the DLL and committed it (`plugins/winui/agent-plugin/skills/winui-dev-workflow/analyzer/Microsoft.WindowsAppSDK.Analyzers.dll`) — provenance check in CI will fail otherwise
- [ ] If a `.ps1` script changed: tested under default `RemoteSigned` execution policy
- [ ] If a CLI command or agent invocation changed: `README.md` updated
- [ ] New tests added for new functionality (if applicable)
Expand Down
6 changes: 0 additions & 6 deletions .github/codeql/codeql-config.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,2 @@
paths:
- src
- .github/workflows
- plugins/winui
paths-ignore:
- '**/*Tests/*.cs'
- '**/bin/**'
- '**/obj/**'
27 changes: 0 additions & 27 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,32 +15,5 @@ updates:
prefix: "ci"
include: "scope"

# Microsoft.WindowsAppSDK.Analyzers (Roslyn analyzer)
cooldown:
default-days: 7
- package-ecosystem: "nuget"
directory: "/src/tools/winui-analyzer/Microsoft.WindowsAppSDK.Analyzers"
schedule:
interval: "weekly"
day: "monday"
open-pull-requests-limit: 5
labels:
- "dependencies"
- "tool: winui-analyzer"
commit-message:
prefix: "deps"
include: "scope"

# Microsoft.WindowsAppSDK.Analyzers tests (xUnit + Roslyn test deps)
- package-ecosystem: "nuget"
directory: "/src/tools/winui-analyzer/Microsoft.WindowsAppSDK.Analyzers.Tests"
schedule:
interval: "weekly"
day: "monday"
open-pull-requests-limit: 5
labels:
- "dependencies"
- "tool: winui-analyzer"
commit-message:
prefix: "deps"
include: "scope"
51 changes: 23 additions & 28 deletions .github/skills/pr-review/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: pr-review
description: Multi-dimensional review of a PR or feature branch in microsoft/win-dev-skills. Activate on "review my PR / changes / branch", "vet before pushing", "PR review", "is this ready to merge". Fans out parallel sub-agents over skill content, the skill-vs-tool boundary (solution hierarchy), tool correctness, payload/provenance/tests, docs & manifest sync, plus a multi-model cross-check. Reports findings to stdout. Does NOT apply fixes.
description: Multi-dimensional review of a PR or feature branch in microsoft/win-dev-skills. Activate on "review my PR / changes / branch", "vet before pushing", "PR review", "is this ready to merge". Fans out parallel sub-agents over skill content, the skill-vs-tool boundary (solution hierarchy), tool correctness, dependency integration/tests, docs & manifest sync, plus a multi-model cross-check. Reports findings to stdout. Does NOT apply fixes.
infer: true
---

Expand All @@ -9,23 +9,22 @@ Your job is to give a contributor a thorough, high-signal review of their
in-progress branch before they push, by fanning out parallel sub-agents and
consolidating their findings.

This repo is **not a regular C# product**. It ships:
This repo is a **content plugin, not a C# product**. Its review surfaces are:

- A portable **Agent Plugins package** under `plugins/winui/agent-plugin/`
plus the containing Claude/Codex/OpenClaw compatibility package — agent
prompt + skill prompts (`SKILL.md` files). These are **Tier 3 instructions**
that agents frequently ignore (see `dimensions/skill-tool-boundary.md`).
Adding prose here is the *last resort*, not the first response to any problem.
- One **in-repo C# tool** under `src/tools/` — the WinUI 3 Roslyn analyzer.
This is **Tier 1 enforcement** and the preferred place
to land behavior changes that belong in this repository.
- **Committed analyzer payloads** (DLL and
`Microsoft.WindowsAppSDK.Analyzers.targets`) inside
`plugins/winui/agent-plugin/skills/`
that must stay in sync with their sources. CI provenance jobs will fail
the PR if they drift, but it's better to flag the drift in review.

The reviewer's job is to keep these three layers honest, lean, and in sync —
- **PowerShell helpers and regression checks** for session reporting and
repository workflows. There is no local analyzer or metadata CLI source.
- **External Tier 1 enforcement:** WinApp CLI 0.7+ owns build/run, packaging,
API discovery, and Sandbox automation. Projects consume
`Microsoft.Windows.SDK.BuildTools.WinUIAnalyzer` from NuGet. Its active
source and publication live in `microsoft/winappCli`; do not request
committed DLL refreshes or recreate a local build/run wrapper.

The reviewer's job is to keep these surfaces honest, lean, and in sync —
and to push back on changes that bloat the skills with content that should
have been a tool change.

Expand Down Expand Up @@ -113,16 +112,13 @@ focus. Common buckets in this repo:
|-------------|--------------|
| `plugins/winui/agent-plugin/skills/<name>/SKILL.md` | skill-content, skill-tool-boundary |
| `plugins/winui/agent-plugin/skills/<name>/references/` | skill-content (references discipline) |
| `plugins/winui/agent-plugin/skills/<name>/*.ps1` (e.g. `BuildAndRun.ps1`, `Analyze-Session.ps1`) | tool-correctness, payloads-and-tests |
| `plugins/winui/agent-plugin/skills/winui-dev-workflow/analyzer/` | payloads-and-tests (committed analyzer payload) |
| `plugins/winui/agent-plugin/skills/<name>/*.ps1` (e.g. `Analyze-Session.ps1`) | tool-correctness, payloads-and-tests |
| `plugins/winui/{agents,agent-plugin/com.github.copilot/agents}/winui-dev.agent.md` | skill-content, docs-and-manifests |
| `plugins/winui/agent-plugin/plugin.json` | docs-and-manifests |
| `.github/plugin/marketplace.json` | docs-and-manifests |
| `src/tools/winui-analyzer/Microsoft.WindowsAppSDK.Analyzers/` | tool-correctness, payloads-and-tests |
| `src/tools/winui-analyzer/Microsoft.WindowsAppSDK.Analyzers.Tests/` | payloads-and-tests |
| `src/tools/winui-analyzer/RULES.md` / `CHANGELOG.md` | docs-and-manifests |
| `scripts/build-tools.ps1` | payloads-and-tests |
| `.github/workflows/` | docs-and-manifests (CI), payloads-and-tests (provenance) |
| `scripts/tests/` | tool-correctness, payloads-and-tests |
| `scripts/open-release-pr.ps1` | tool-correctness, docs-and-manifests |
| `.github/workflows/` | docs-and-manifests (CI), payloads-and-tests (regressions) |
| `README.md`, `SECURITY.md`, `SUPPORT.md` | docs-and-manifests |

### 3. Fan out parallel sub-agents
Expand All @@ -131,8 +127,8 @@ Launch all 5 specialist sub-agents in **the same response** using the `task`
tool, mode `"sync"`. Pick the agent type per the table below — `code-review`
is the right default for `tool-correctness` because that built-in agent
already specializes in bug/security review of C# and PowerShell, which lets
the dimension fragment focus on the *repo-specific* deltas (analyzer ID
immutability, AOT constraints, payload-script behavior). Each prompt must
the dimension fragment focus on the *repo-specific* deltas (external command
contracts, target scoping, shipped-script behavior). Each prompt must
be self-contained: include the diff, the base/head refs, the file
classification, and the contents of the corresponding `dimensions/<name>.md`
plus the shared contract.
Expand All @@ -143,8 +139,8 @@ The 6 dimensions and their fragment files:
|---|-----------|----------|---------------|
| 1 | skill content quality | `dimensions/skill-content.md` | general-purpose |
| 2 | skill ↔ tool boundary (solution hierarchy) | `dimensions/skill-tool-boundary.md` | general-purpose |
| 3 | tool correctness (C# / PowerShell in `src/tools/` and shipped scripts) | `dimensions/tool-correctness.md` | code-review |
| 4 | payloads, provenance, analyzer tests | `dimensions/payloads-and-tests.md` | general-purpose |
| 3 | PowerShell correctness and external command contracts | `dimensions/tool-correctness.md` | code-review |
| 4 | dependency integration and script regressions | `dimensions/payloads-and-tests.md` | general-purpose |
| 5 | docs & manifests sync | `dimensions/docs-and-manifests.md` | explore |
| 6 | multi-model cross-check | `dimensions/multi-model.md` | general-purpose, with `model` override |

Expand Down Expand Up @@ -232,10 +228,9 @@ verdict.
- **No fix application.** Even if findings are obvious, do not edit code.
- **No file output.** Stdout only, unless the user explicitly asked for a
file.
- **No build/test execution.** Flag staleness (analyzer DLL not refreshed,
`RULES.md` not updated) but do not run
`scripts/build-tools.ps1` or `dotnet test` yourself — they are slow and
the contributor will run them.
- **No test execution.** Flag specific missing regression cases or unsupported
external contracts, but do not run workflow tests yourself; the contributor
and CI run the checks.
- **Signal-to-noise.** Reject sub-agent findings that are pure style nits,
formatting, things the compiler / analyzer already catches, context
inflation without evidence, or scenario-specific patches that don't
Expand Down Expand Up @@ -270,7 +265,7 @@ parameter on the `task` call to a different model family than yourself.

```
1. collect-diff.ps1 -Scope auto → JSON: 7 files, +220/-40, status=ok
2. Map files to areas → 1 SKILL.md + analyzer rule + RULES.md + tests + payload
2. Map files to areas → 1 SKILL.md + helper script + regression tests
3. Fan out 5 task() calls in parallel → wait for all
4. Fan out task() #6 with model override → wait
5. Dedupe, sort, ID, mark multi-model status
Expand Down
30 changes: 15 additions & 15 deletions .github/skills/pr-review/dimensions/_shared-contract.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ After the findings (or in place of them when there are zero), include:
## What I checked
- <one bullet per area inspected, e.g., "All new lines in winui-design SKILL.md">
- <e.g., "Analyzer rule WUI2099 implementation + tests">
- <e.g., "plugins/winui/agent-plugin/skills/winui-dev-workflow/analyzer/ payload">
- <e.g., "winui-dev-workflow analyzer package integration">
```

This appears in the orchestrator's `Coverage notes` section so the
Expand Down Expand Up @@ -81,36 +81,35 @@ high. The bar for adding tooling enforcement is lower.
three other situations where this change would help, it is too
narrow.
- **Redundant enforcement.** Suggesting skill text for something the
C# compiler, the WinUI analyzer, the `winapp` CLI, `BuildAndRun.ps1`,
or the CI provenance jobs already catch. Name the existing
C# compiler, the WinUI analyzer NuGet package, the `winapp` CLI,
or existing CI checks already catch. Name the existing
enforcement instead of duplicating it.
- **Action bias.** Feeling obliged to flag every diff hunk. "No
finding" is a valid verdict for a clean change.
- **Speculative hypotheticals not grounded in the diff.**

### Keep these

- Bugs, logic errors, races, missed edge cases (in tool C# code or in
shipped PowerShell scripts).
- Bugs, logic errors, races, missed edge cases in PowerShell helpers or
documented executable examples.
- Security issues — never suppressed, even at low confidence.
- Skill content that is **measurably bloated** with content that
duplicates other skills, would have been better as a tool change, or
is too scenario-specific.
- Trigger-phrasing problems in `description:` frontmatter that would
cause the wrong agent activation.
- Stale committed analyzer payloads (DLL or
`Microsoft.WindowsAppSDK.Analyzers.targets`) that will fail CI
provenance.
- External command/package contracts that the required released version
does not support, or analyzer installation guidance that omits XAML inputs.
- Manifest / version / agent-file drift that ships broken artifacts to
end users.
- Missing analyzer xUnit tests for new or changed rules.
- Missing PowerShell regression cases for changed helper behavior.

## Severity guide

| Severity | Meaning |
|----------|---------|
| critical | Will ship broken behavior to end users (plugin install fails, manifest invalid, analyzer crashes on real code) or block release. Must fix before merge. |
| high | Real bug in tool code, real provenance drift CI will reject, real skill bloat that meaningfully harms agent quality, or missing tests for a new analyzer rule. Should fix before merge. |
| critical | Will ship broken behavior to end users (plugin install fails, manifest invalid, helper unusable) or block release. Must fix before merge. |
| high | Real bug in helper code, broken external dependency integration, real skill bloat that meaningfully harms agent quality, or missing regression coverage. Should fix before merge. |
| medium | Worth fixing but not a blocker; may be deferred with a note. |
| low | Minor improvement; only emit if the recommendation is concrete and actionable AND the finding survives the Team Lead Test. |

Expand All @@ -125,7 +124,7 @@ high. The bar for adding tooling enforcement is lower.
verifiable.

Security findings (in the `tool-correctness` dimension when reviewing
shipped PowerShell or analyzer code) are **never** suppressed by low
PowerShell helpers or executable examples) are **never** suppressed by low
confidence — emit them anyway.

## The Solution Hierarchy (cross-cutting)
Expand All @@ -136,14 +135,14 @@ change should land. Cite the tier on every `skill-content` and

| Tier | Type | Reliability | Examples in this repo |
|------|------|-------------|------------------------|
| **0** | Environment / harness defaults | Highest — agent never sees it | `winapp new` template choice, `BuildAndRun.ps1` defaults, prerequisite checks in `winui-setup` |
| **1** | Tooling enforcement | High — produces errors/warnings the agent must address | `Microsoft.WindowsAppSDK.Analyzers` rules, `winapp find-ui` query results, `winapp find-api` API verification, `winapp` CLI exit codes |
| **0** | Environment / harness defaults | Highest — agent never sees it | `winapp new` template choice, project analyzer references, prerequisite checks in `winui-setup` |
| **1** | Tooling enforcement | High — produces errors/warnings the agent must address | WinUI analyzer NuGet rules, `winapp find-ui` / `find-api`, `winapp` CLI exit codes |
| **2** | Templates / scaffolding | Medium — structural, applied at creation time | `Microsoft.WindowsAppSDK.WinUI.CSharp.Templates`, starter project files |
| **3** | Instructions / skills | Lowest — advisory, frequently ignored | `SKILL.md` content, `winui-dev.agent.md` rules, `references/*.md` |

### Upstream alternatives (when this repo isn't the right place at all)

Two of the most leveraged Tier 0/1/2 surfaces this plugin depends on
The most leveraged Tier 0/1/2 surfaces this plugin depends on
live in **other repositories**. When a finding's recommendation lands
naturally on one of them, name the upstream surface explicitly so the
contributor can decide whether to file an issue there instead of
Expand All @@ -152,6 +151,7 @@ working around it locally:
| Upstream | Lives in | Right for |
|----------|----------|-----------|
| **`winapp` CLI** ([`microsoft/winappcli`](https://github.com/microsoft/winappcli)) | external repo, installed via `winget install Microsoft.WinAppCLI` | New install/run/sign/package/automate behavior; better error messages from `winapp run`, `winapp ui`, `winapp manifest`, `winapp pack`; new subcommands the skill currently scripts around. The skills are co-developed with this CLI in lockstep, so "land it in `winapp`" is often the highest-leverage option. |
| **WinUI analyzer NuGet** (`Microsoft.Windows.SDK.BuildTools.WinUIAnalyzer`) | `microsoft/winappCli/src/winapp-Analyzer` | Analyzer rules, tests, and package targets. All implementation changes belong upstream; this repo documents package consumption only. |
| **WinUI 3 .NET templates** (`Microsoft.WindowsAppSDK.WinUI.CSharp.Templates`) | shipped on [NuGet](https://www.nuget.org/packages/Microsoft.WindowsAppSDK.WinUI.CSharp.Templates) by the WinAppSDK team | New "every WinUI 3 app should start with X" defaults — pre-wired dependencies, default `app.manifest` settings, baseline MVVM scaffolding, default analyzer references. Anything the agent re-types into `dotnet new` output every time is a template request. |

**Rule:** When a finding recommends *adding* something to a `SKILL.md`
Expand Down
Loading
Loading