Skip to content

TL-M0-25 · Agent fork (withdrawn)

Why: Run this only if GitHub Team is not approved (row 14b, OQ23); with Team, agents get the repository through the Claude app instead. D27 hands writing docs, tests and code to agents, while D26 keeps write access to the repository with zuki until the organization is on GitHub Team. So agents work in a private fork under your personal account: they push branches there and see CI run there, and you open each pull request from the fork into the repository, where CI runs again with no secrets, and merge it. In M0 only the Docs Engineer uses the fork; from the data phase on, every pack arrives through it.

ID TL-M0-25 · Level L0

<GITHUB_USER>/opleet-agents is a private fork of the repository; Claude can write to it and to no other repository; CI runs in it; and the repository runs CI on pull requests from it with a read-only token and no secrets.

  • TL-M0-14 is Done.
  • <GITHUB_USER> below is your personal GitHub username, and <GITHUB_OWNER> the organization, as in TL-M0-12.

1 · Allow private forks, first for the organization, then for the repository

Section titled “1 · Allow private forks, first for the organization, then for the repository”
Terminal window
open "https://github.com/organizations/<GITHUB_OWNER>/settings/member_privileges"

In the browser: under Repository forking, tick Allow forking of private repositories and save. Then open the repository's Settings › General and, under Features, tick Allow forking.

Terminal window
gh repo view <GITHUB_OWNER>/opleet --web

2 · Fork it to your account as opleet-agents, main only, without touching your local remotes

Section titled “2 · Fork it to your account as opleet-agents, main only, without touching your local remotes”
Terminal window
gh repo fork <GITHUB_OWNER>/opleet --fork-name opleet-agents --default-branch-only --clone=false --remote=false

3 · Turn on Actions in the fork; a fork starts with its workflows off

Section titled “3 · Turn on Actions in the fork; a fork starts with its workflows off”
Terminal window
open "https://github.com/<GITHUB_USER>/opleet-agents/actions"

In the browser: choose I understand my workflows, go ahead and enable them.

4 · Run CI on pull requests from forks, with a read-only token and no secrets: for the organization, then for the repository

Section titled “4 · Run CI on pull requests from forks, with a read-only token and no secrets: for the organization, then for the repository”
Terminal window
open "https://github.com/organizations/<GITHUB_OWNER>/settings/actions"
open "https://github.com/<GITHUB_OWNER>/opleet/settings/actions"

In each: under Fork pull request workflows in private repositories, tick Run workflows from fork pull requests, leave Send write tokens and Send secrets unticked, and save.

5 · Give Claude the fork and nothing else

Section titled “5 · Give Claude the fork and nothing else”
Terminal window
open "https://github.com/settings/installations"

In the browser: Claude › Configure › Repository access › Only select repositories › opleet-agents › Save. If Claude isn't listed, attach <GITHUB_USER>/opleet-agents from a claude.ai session first; GitHub asks you to install it, and you choose the same.

Terminal window
open "https://github.com/organizations/<GITHUB_OWNER>/settings/installations"

In the browser: if Claude is listed for the organization, open Configure and make sure opleet is not among its repositories.

6 · Try the loop once with an empty commit: a pull request inside the fork, then one from the fork into the repository

Section titled “6 · Try the loop once with an empty commit: a pull request inside the fork, then one from the fork into the repository”
Terminal window
git remote add agents https://github.com/<GITHUB_USER>/opleet-agents.git
git switch -c try/agent-fork
git commit --allow-empty -m "chore: try the agent fork"
git push agents try/agent-fork
fork_pr=$(gh pr create --repo <GITHUB_USER>/opleet-agents --base main --head try/agent-fork --title "chore: try the agent fork" --body "Throwaway.")
sleep 15 && gh pr checks "$fork_pr" --watch
pr=$(gh pr create --repo <GITHUB_OWNER>/opleet --base main --head <GITHUB_USER>:try/agent-fork --title "chore: try the agent fork" --body "Throwaway.")
sleep 15 && gh pr checks "$pr" --watch

7 · Close both without merging, and clean up

Section titled “7 · Close both without merging, and clean up”
Terminal window
gh pr close "$pr"
gh pr close "$fork_pr"
git switch main
git push agents --delete try/agent-fork
git branch -D try/agent-fork
  • Block 2: “✓ Created fork <GITHUB_USER>/opleet-agents”.
  • Block 6: checks and pr-title pass twice, first on the pull request inside the fork, then on the one in the repository.
  • Block 7: both pull requests close, and the branch is deleted in the fork and here.
Terminal window
gh repo view <GITHUB_USER>/opleet-agents --json isPrivate,parent --jq '"\(.isPrivate) \(.parent.owner.login)/\(.parent.name)"'

Prints “true <GITHUB_OWNER>/opleet”. On the installations page from block 5, Claude lists only opleet-agents.

  • Block 2 says the repository can't be forked: one of the two boxes in block 1 isn't saved.
  • The pull request inside the fork shows no checks: Actions are still off in the fork (block 3).
  • The pull request in the repository shows no checks: the setting in block 4 is off at the organization or the repository.
  • A job fails asking for a secret or a write permission: paste the output of gh run view --log-failed into a CTO session. No M0 job needs either.
Terminal window
gh repo delete <GITHUB_USER>/opleet-agents
git remote remove agents

Then untick the boxes from blocks 1 and 4.

Withdrawn 2026-10-07 (D28): GitHub Team replaced the fork. Never run.