TL-M0-25 · Agent fork (withdrawn)
Why: Run this only if GitHub Team is not approved (row 14b, OQ23); with Team, agents get the repository through the Claude app instead. D27 hands writing docs, tests and code to agents, while D26 keeps write access to the repository with zuki until the organization is on GitHub Team. So agents work in a private fork under your personal account: they push branches there and see CI run there, and you open each pull request from the fork into the repository, where CI runs again with no secrets, and merge it. In M0 only the Docs Engineer uses the fork; from the data phase on, every pack arrives through it.
ID TL-M0-25 · Level L0
<GITHUB_USER>/opleet-agents is a private fork of the repository; Claude can write to it and to no other repository; CI runs in it; and the repository runs CI on pull requests from it with a read-only token and no secrets.
Before
Section titled “Before”- TL-M0-14 is Done.
- <GITHUB_USER> below is your personal GitHub username, and <GITHUB_OWNER> the organization, as in TL-M0-12.
1 · Allow private forks, first for the organization, then for the repository
Section titled “1 · Allow private forks, first for the organization, then for the repository”open "https://github.com/organizations/<GITHUB_OWNER>/settings/member_privileges"In the browser: under Repository forking, tick Allow forking of private repositories and save. Then open the repository's Settings › General and, under Features, tick Allow forking.
gh repo view <GITHUB_OWNER>/opleet --web2 · Fork it to your account as opleet-agents, main only, without touching your local remotes
Section titled “2 · Fork it to your account as opleet-agents, main only, without touching your local remotes”gh repo fork <GITHUB_OWNER>/opleet --fork-name opleet-agents --default-branch-only --clone=false --remote=false3 · Turn on Actions in the fork; a fork starts with its workflows off
Section titled “3 · Turn on Actions in the fork; a fork starts with its workflows off”open "https://github.com/<GITHUB_USER>/opleet-agents/actions"In the browser: choose I understand my workflows, go ahead and enable them.
4 · Run CI on pull requests from forks, with a read-only token and no secrets: for the organization, then for the repository
Section titled “4 · Run CI on pull requests from forks, with a read-only token and no secrets: for the organization, then for the repository”open "https://github.com/organizations/<GITHUB_OWNER>/settings/actions"open "https://github.com/<GITHUB_OWNER>/opleet/settings/actions"In each: under Fork pull request workflows in private repositories, tick Run workflows from fork pull requests, leave Send write tokens and Send secrets unticked, and save.
5 · Give Claude the fork and nothing else
Section titled “5 · Give Claude the fork and nothing else”open "https://github.com/settings/installations"In the browser: Claude › Configure › Repository access › Only select repositories › opleet-agents › Save. If Claude isn't listed, attach <GITHUB_USER>/opleet-agents from a claude.ai session first; GitHub asks you to install it, and you choose the same.
open "https://github.com/organizations/<GITHUB_OWNER>/settings/installations"In the browser: if Claude is listed for the organization, open Configure and make sure opleet is not among its repositories.
6 · Try the loop once with an empty commit: a pull request inside the fork, then one from the fork into the repository
Section titled “6 · Try the loop once with an empty commit: a pull request inside the fork, then one from the fork into the repository”git remote add agents https://github.com/<GITHUB_USER>/opleet-agents.gitgit switch -c try/agent-forkgit commit --allow-empty -m "chore: try the agent fork"git push agents try/agent-forkfork_pr=$(gh pr create --repo <GITHUB_USER>/opleet-agents --base main --head try/agent-fork --title "chore: try the agent fork" --body "Throwaway.")sleep 15 && gh pr checks "$fork_pr" --watchpr=$(gh pr create --repo <GITHUB_OWNER>/opleet --base main --head <GITHUB_USER>:try/agent-fork --title "chore: try the agent fork" --body "Throwaway.")sleep 15 && gh pr checks "$pr" --watch7 · Close both without merging, and clean up
Section titled “7 · Close both without merging, and clean up”gh pr close "$pr"gh pr close "$fork_pr"git switch maingit push agents --delete try/agent-forkgit branch -D try/agent-forkExpect
Section titled “Expect”- Block 2: “✓ Created fork <GITHUB_USER>/opleet-agents”.
- Block 6: checks and pr-title pass twice, first on the pull request inside the fork, then on the one in the repository.
- Block 7: both pull requests close, and the branch is deleted in the fork and here.
gh repo view <GITHUB_USER>/opleet-agents --json isPrivate,parent --jq '"\(.isPrivate) \(.parent.owner.login)/\(.parent.name)"'Prints “true <GITHUB_OWNER>/opleet”. On the installations page from block 5, Claude lists only opleet-agents.
If it fails
Section titled “If it fails”- Block 2 says the repository can't be forked: one of the two boxes in block 1 isn't saved.
- The pull request inside the fork shows no checks: Actions are still off in the fork (block 3).
- The pull request in the repository shows no checks: the setting in block 4 is off at the organization or the repository.
- A job fails asking for a secret or a write permission: paste the output of gh run view --log-failed into a CTO session. No M0 job needs either.
gh repo delete <GITHUB_USER>/opleet-agentsgit remote remove agentsThen untick the boxes from blocks 1 and 4.
Withdrawn 2026-10-07 (D28): GitHub Team replaced the fork. Never run.