Agentic Research
Agent Learning Roadmap · Stage A3

Connect a CLI Agent to a Safe Team Workflow

How do you safely connect external tools, CI, and team workflows?

Integrate with least privilege, human checks, and records.

5–8 hours6 mapped lessonsUpstream edition

📌 Learning goals

  • Hand an MCP server exactly one safe scope.
  • Let CI produce a reviewable suggestion automatically on PRs.
  • Read the usage, timing, and results of one run with observability.
  • Hand A2's skill to a teammate and let them rerun it safely.

Entry conditions

Finish A2's rule card and review skill, plus the Stage 5 Track-A core 5.1–5.4. This stop does exactly one thing: a CLI agent runs a read-only check on a test PR — it may comment, but never merge, deploy, or gain extra permissions.

🧭 Lessons on this site

Read in the suggested order; checkboxes share the same browser progress as the /learn track pages.
Progress here
0/6
Saved in your browser only
  1. 01
    Is My Data Safe? What Actually Leaves Your Computer When You Use AI

    'Is it safe?' is too blunt a question to ever get a useful answer. This article breaks it apart: the four kinds of things that actually leave your machine when you use cloud tools, why local tools are different, what the sentence 'we don't train on your data' does and does not promise, and three rules you can actually enforce. No legal advice included.

    11 min
  2. 02
    Enterprise Data Security Basics: What Data Should Never Be Fed to AI

    Employees pasting customer personal data into free AI tools is one of the most common and hardest-to-prevent data leakage paths in enterprises. This article provides a four-tier data classification standard, a 'never upload' red-line checklist, a comparison of enterprise vs. consumer terms, local deployment options, and a question list for IT and legal teams.

    8 min
  3. 03
    AI Compliance and Risk Boundaries: The Legal Checklist for Enterprise Adoption

    The legal homework before AI adoption is not 'find one regulation to comply with' but inventorying the risk dimensions clearly, asking the right questions, and demanding the right documents. This article gives you an inventory framework for five risk dimensions, a question list you can take straight into the legal meeting, a vendor-document request table, and the items to add to internal policies plus per-scenario management methods.

    18 min
  4. 04
    API Documentation Sync System: From Manual Maintenance to Code-Driven Docs Automation

    The API changed but the docs did not, so frontend colleagues guess parameters and the test environment becomes trial and error. This article wires Apidog, Fern, Mintlify, and an LLM node into a documentation-sync pipeline: extract interface definitions from code, generate examples automatically, detect inconsistencies and alert — keeping the docs permanently aligned with the implementation.

    17 min
  5. 05
    Automated Code Review Assistant: From Manual Line-by-Line Checks to an AI-Assisted Quality Gatekeeper

    Code review is time-consuming, edge cases slip through, and newcomers struggle to learn the team's conventions. This article wires GitHub Copilot, CodeRabbit, SonarQube, and an LLM node into an automated review pipeline: static analysis, security scanning, style checks, semantic understanding, and risk grading, so senior engineers handle only high-risk changes and the machine takes the repetitive work.

    17 min
  6. 06
    Building Organizational AI Capability: From Individual Heroes to Repeatable Processes

    A few people in the company being great at using AI does not mean the organization has AI capability. This article is about turning personal experience into organizational assets: capability inventory, seed users and a three-stage rollout path, consolidating personal prompts into a skill library and a template library, tiered training and documentation, and the dimensions and common failure modes for measuring whether it really landed.

    20 min

⚠️ Five guardrails before your first agent

  1. 1.MCP gets only a demo folder or a minimal read-only toolset.
  2. 2.The PR workflow only comments: no auto-merge, push, or deploy.
  3. 3.Secrets stay out of repos, prompts, and logs; workflows use least privilege.
  4. 4.Directories only help you find candidates, never vouch for them — before installing any MCP, Action, skill, or plugin, re-check the source, permissions, recent maintenance, and how to remove it.

🎯 Curated resources

ResourceWho it's forPriorityWhy
CI integration
anthropics/claude-code-action
Automated GitHub PR review⭐⭐⭐⭐⭐The official GitHub Action; read the security setup before granting permissions.
CI integration
openai/codex-action
CI review on the Codex path⭐⭐⭐⭐Compare against claude-code-action; confirm the approval boundary.
CI integration
GitHub Actions — Security hardening
Before writing any workflow⭐⭐⭐⭐⭐The official guide on least privilege, secrets, and unpinned inputs.
MCP
modelcontextprotocol/servers
Picking a first MCP server⭐⭐⭐⭐⭐Official reference servers; audit permissions before connecting.
MCP
MCP — Security best practices
Exposing or connecting MCP⭐⭐⭐⭐⭐Protocol-level security advice and local-server connection.
MCP
github/github-mcp-server
Letting an agent read GitHub⭐⭐⭐⭐GitHub's official MCP server; enable the read-only toolset first.
Observability
langfuse/langfuse
Usage and traces⭐⭐⭐⭐Self-hosted observability; mind data governance.
Observability
Helicone/helicone
Lightweight usage logging⭐⭐⭐⭐A proxy layer logging usage and cost in a few lines.
Observability
Arize-ai/phoenix
Local trace analysis⭐⭐⭐⭐OpenTelemetry-compatible; design sensitive-data masking first.
Sharing
obra/superpowers-marketplace
Sharing skills with teammates⭐⭐⭐⭐Learn the minimal marketplace that curates while plugins live elsewhere.

🛠 Hands-on practice (upstream)

Full exercises & starter code

Summaries from the upstream curriculum; full code, cost, and latency estimates live upstream.

  1. Exercise 1: connect one MCP server — hand it only a demo folder or read-only tools; write your own only when nothing official fits.
  2. Exercise 2: read-only CI review — on a test PR, let a GitHub Action run one read-only check and leave a comment.
  3. Exercise 3: observability records — log provider, model, usage, timing, and results; never guess at data you could not get.
  4. Exercise 4: hand off the skill — a teammate runs your skill in a clean demo repo and git status stays clean afterwards.

✅ Self-check

  • MCP received only a demo folder or a minimal read-only toolset.
  • The PR workflow only comments — no auto-merge, push, or deploy.
  • Secrets are absent from repos, prompts, and logs; workflows use least privilege.
  • I can point to one run's results and usage; nothing missing was guessed.
  • A teammate ran the skill in a clean demo repo and git status stayed clean.

Adapted from awesome-agentic-ai-zh (MIT, by Wenyu Chiou) v2026.09.23; links checked 2026-08-27. Stars mark learning priority (⭐⭐⭐⭐⭐ = you will get stuck without it), not popularity. MIT License · Curriculum structure last updated 2026-10-03. Content is still being filled in; lessons marked “in progress” are not live yet.