GitHub App autofeat-axc
Open a pull request with a spec and the label autofeat:go, and autofeat runs coding agents in a sandbox, then reviews and gates inside the budget you set.
01
01
The label starts the entry action. The GitHub App receives the webhook and reads repo policy from the default branch.
02
claude, codex, kimi, grok-build, or opencode runs inside the sandbox. A dry run does not push.
03
Each stage writes a check run named autofeat/<action> and a state comment on the PR.
04
autofeat:ready means you merge. Auto-merge runs only when your policy allows it.
02
Three layers. Policy sets the ceiling. Labels start and stop a PR. Signed comments advance the loop.
.autofeat/config.yml on the default branch is the hard ceiling. Extra keys are errors. The file is read only from that branch.
autofeat:go starts work. autofeat:stop is the kill switch. autofeat:pause uses the same path. autofeat:ready is the output label. Removing a label does not resume a run.
With dry_run off, a turn ends with a push and an HMAC-signed directive comment. That comment is the next webhook. A third party cannot forge it.
version: 1identity: appentry_action: reviewautonomy: merge_target: main merge_mode: stop_before_merge auto_approve: false dry_run: true require_green_checks: truepolicy: mode: review_onlyagents: default: claude allowed: [claude, codex, kimi, grok-build] billing: {claude: subscription, codex: subscription, kimi: subscription, grok-build: subscription} models: {claude: {model: sonnet}}budget: turns: 12 usd: 25.0 alert_usd: 10.0 minutes: 240security: require_signature: true trusted_actors: [OWNER]
Example policy from the schema. Omitted keys use their defaults, including budget.tokens at 2,000,000.
03
usd, tokens, minutes, and turns are hard ceilings per pull request. alert_usd warns before the usd ceiling.
04
Billing is subscription or api_key. An agent with no billing entry uses api_key. Subscription agents settle at usd 0.
05
The executor runs in a sandbox as a separate user id. Same-uid mode stays off unless dry_run is also on.
Sandbox egress goes through an allowlist, and that allowlist is enforced.
Repo policy is read only from .autofeat/config.yml on the default branch.
Run state is HMAC-signed. Directive comments are HMAC-signed, so the next turn cannot be forged.
Each PR keeps a durable journal ref at refs/heads/autofeat-state/pr-N.
The label autofeat:stop is refused before every other action and revokes in-flight runs.
Hosted receiver: ok
Install the GitHub App on the repositories you choose. Commit the policy file, add autofeat:go, and read the check run.