Running Robota in GitHub Actions
To use Robota in a GitHub Actions workflow today, install the reference CLI in a step and run it in
print mode (robota -p): it answers one prompt, writes the answer to stdout, and exits. The repository
also contains a packaged GitHub Action, but it is not released yet — see
The Robota GitHub Action below.
Run the CLI in a workflow
This workflow reviews a pull request and posts the review as a comment:
name: AI review
on:
pull_request:
permissions:
contents: read
pull-requests: write
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: actions/setup-node@v4
with:
node-version: 22
- name: Install the Robota CLI
run: npm install -g @robota-sdk/agent-cli
- name: Review the pull request
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
BASE_REF: ${{ github.base_ref }}
run: |
robota --safe-mode -p "Review the changes between origin/$BASE_REF and HEAD (use git diff). List correctness problems and missing tests." > review.md
- name: Post the review
env:
GH_TOKEN: ${{ github.token }}
run: gh pr comment ${{ github.event.pull_request.number }} --body-file review.mdWhat the steps rely on:
- Node.js 22.12 or later. The CLI requires it, so set it up with
actions/setup-node. - An API key as a secret. With
ANTHROPIC_API_KEYset, the CLI needs no settings file and uses Anthropic's default model;GEMINI_API_KEY,DEEPSEEK_API_KEYandDASHSCOPE_API_KEY(Qwen) work the same way. Add--model <model>to choose another model. - Workspace trust. Print mode refuses to start in a Git repository that is not trusted, and a fresh
checkout is not.
--safe-modestarts with every customization off — instruction files, skills, commands, plugins, hooks and MCP servers — and runs Restricted, so it needs no trust. To load the repository'sAGENTS.md, settings, skills and hooks instead, runrobota trust --yesbefore the prompt; do that only for code you trust, because it runs the repository's hooks. - Permissions. Print mode uses the
defaultpermission mode: reads, searches and read-only commands such asgit diffrun, and anything that would ask for approval (an edit, another shell command) is denied, since no one can answer. Pass--permission-mode acceptEditsto allow edits, orbypassPermissionsto allow everything except a few protected operations, such as writes into.git. - Output. The answer goes to stdout.
--output-format jsonorstream-jsongives machine-readable output, and--max-turns <n>caps the number of agent turns.
The CLI reference lists every flag.
Use the SDK in a Node.js step
A script step can call the SDK directly with createQuery from @robota-sdk/agent-framework:
import { createQuery } from '@robota-sdk/agent-framework';
import { AnthropicProvider } from '@robota-sdk/agent-provider-anthropic';
const query = createQuery({
provider: new AnthropicProvider({ apiKey: process.env.ANTHROPIC_API_KEY }),
});
const result = await query('Review the changed files in this branch for potential issues');
console.log(result);createQuery also runs in the default permission mode, and without a projectAccess decision it
does not load the repository's instruction files or settings. See Using the SDK.
The Robota GitHub Action (not released)
The GitHub Action lives in apps/action. It is not released: its
action.yml runs dist/index.js, which is not committed, and no workflow builds or publishes it, so
there is no uses: reference a workflow can point at yet. Until it is released, use the CLI as shown
above.
The action runs npx --yes @robota-sdk/agent-cli -p <task> --output-format <output>, adding --model
and --max-turns when they are set, with api-key passed to the CLI as ANTHROPIC_API_KEY. It sets
the result output to what the CLI printed, and fails the step if the CLI exits with an error. Each
input reaches the CLI as a separate argument, never through a shell, so a task built from issue or pull
request text cannot inject shell commands.
Inputs
| Input | Required | Default | Description |
|---|---|---|---|
task | yes | — | The task or prompt to send to the agent |
model | no | — | AI model to use (e.g. claude-sonnet-4-6) |
api-key | no | — | Anthropic API key (pass it from secrets) |
output | no | text | Output format: text | json | stream-json |
max-turns | no | — | Maximum agent turns before stopping |
Outputs
| Output | Description |
|---|---|
result | The agent response text |
Security
- Pass API keys through
secrets(for example${{ secrets.ANTHROPIC_API_KEY }}), never in the workflow file. - Pass untrusted text such as pull request titles or issue bodies to a step through
env, not by writing${{ … }}into arun:script.