Build a least-privilege adapter for documented REST API operations without inventing endpoints or treating PR comments as an SDK. Use when this operator task needs a current, evidence-backed CodeRabbit workflow. Trigger with "integrate with the CodeRabbit API".
CodeRabbit documents REST APIs for organizations, metrics, learnings, users, roles, logs, and security. Implement only referenced operations.
references/official-docs.md and re-check any time-sensitive contract before execution.x-coderabbitai-api-key header.Treat Git-provider sessions, CodeRabbit web sessions, CLI credentials, and CodeRabbit API keys as separate credentials. Use only an already-approved session or secret-manager reference, never print a secret, and do not place credentials in .coderabbit.yaml, source files, logs, or deliverables.
Select one operation and record plan, permission, key type, request, pagination, and response.
Build a thin typed adapter with injected URL and secret reference.
Implement only documented errors and preserve partial success.
Test fixtures, then one approved read-only request.
Require Admin and security approval for keys; require separate approval for writes, roles, seats, or exports. Keep analysis and drafts local until approval is explicit, and record who approved the action and its scope.
A contract record, adapter, redacted fixtures, pagination handling, live-read receipt, and rotation owner. Include source dates, unknowns, and the exact boundary between observed fact and recommendation.
| Condition | Response |
|---|---|
| Current contract is unclear or docs disagree | Stop mutation, cite both sources, and request owner resolution. |
| Required access or approval is missing | Produce a draft and evidence plan only. |
| Validation or pilot behavior differs from expectation | Restore the prior state and retain the failed evidence. |
| Output contains secrets or private code | Stop, quarantine the artifact, redact it, and notify the data owner. |
Fetch paginated metrics with cursor provenance.
Reconcile partial success before bulk role changes.
references/official-docs.md.88dcf65
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.