mindtickle-ci-integration
Installation
SKILL.md
Fail-Closed Mindtickle Integration CI
Overview
Gate adapter changes on contract integrity and sanitized behavior while keeping external tenant access isolated, read-only, and manually authorized.
Prerequisites
- Deterministic local tests and sanitized fixtures from
mindtickle-local-dev-loop - Protected branches, pinned CI permissions, a secret scanner, and artifact retention policy
- A separately owned non-production tenant principal if a live smoke lane is justified
Tool Discipline
Use Read, Glob, and Grep to inspect workflows and dependency locks, WebFetch for current CI and tenant contracts, and Write or Edit for workflow files, tests, and redacted evidence.
Current Contract
The always-on lane must not depend on a live Mindtickle tenant. A live lane is optional and must use the customer's documented read-only operation, protected environment approval, bounded execution, and redacted logs.