Miro CI Contract Tests
SkillMediaDesign and implement repository-side Miro CI gates with schema-faithful fixtures, protected live-test handoffs, test-board isolation, and cleanup proof. Use when adding Miro checks to CI. Trigger with \"test Miro in CI\".
Use Miro CI Contract Tests in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Miro CI Contract Tests and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Miro CI Contract Tests skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by jeremylongshore/tons-of-skills-marketplace in skills/.curated/miro-ci-integration/SKILL.md and read by ahel’s review.
Overview
Keep pull-request checks credential-free and reserve live Miro calls for protected, explicitly scoped lanes. A test must never mutate a collaboration board by accident; use the evidence produced here to make the next decision explicit and reviewable.
Prerequisites
- CI trust-boundary and fork policy
- Pinned schemas/fixtures and test command
- Dedicated app, team, board, identity, and cleanup owner for live tests
Tool Discipline
Use Read, Glob, and Grep to inspect the repository, configuration names, adapters, tests, and evidence. Use WebFetch only for current official Miro documentation. Use Write or Edit after confirming the requested mode, target environment, tenant, board, and approval boundary. These declared tools do not call authenticated Miro APIs or deployment CLIs; implement client, configuration, and test changes, then return exact operator commands or an approval-gated handoff for live execution.
Current Contract
- Untrusted fork workflows must not receive Miro credentials.
- Live traffic consumes production-like per-user/application credits even on test resources.
- Bulk create is transactional but cleanup still needs an explicit inventory and board guard.
- OAuth refresh rotation can invalidate concurrent jobs sharing one installation.
Authentication
For REST work, use OAuth 2.0 Authorization Code with the narrowest Miro scopes. Bind each encrypted token record to its user, application, authorized team, and granted scopes. Never print access tokens, refresh tokens, client secrets, authorization codes, or board content.
Instructions
- Split formatting, unit, schema, security, and fixture tests from the protected live lane.
- Assert that PR/fork lanes have no credential context and cannot invoke live helpers.
- Pin dependencies and validate captured fixtures against current official response contracts.
- Serialize protected live jobs per installation, assert app/team/board guards, and use bounded read-first tests.
- Mark any created item with the run identity, reconcile it, then clean only confirmed run-owned IDs.
- Fail the gate on leaked data, ambiguous writes, cleanup residue, unexpected schema, or quota-policy breach.
Approval Boundaries
Do not expose credentials to forks, share one rotating token across parallel jobs, or enable destructive live tests without repository and board-owner approval. Pause when the responsible owner or exact target is uncertain.
Output
Return lane/trust map, fixture provenance, protected-resource guards, test results, credits used, cleanup receipt, and gate conclusion. State what was not inspected or changed so the receipt cannot overclaim coverage.
Error Handling
| Condition | Response |
|---|---|
| Fork lane can read secrets | Disable the live path and repair workflow permissions before merging. |
| Refresh collision occurs | Serialize jobs or isolate installations. |
| Cleanup cannot prove ownership | Leave content intact and fail the lane. |
| Rate headroom is low | Skip live mutations and report capacity pressure. |
Examples
The example is a redacted operator receipt; identifiers are hashes or bounded labels, not board content or credentials.
unit=46/46; schemas=12/12; fork-secrets=0; live-read=passed; live-writes=0; cleanup-residue=0
Resources
Signals
- GitHub stars
- 3k
- Forks
- 415
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
miro-ci-integration- Source
- github.com/jeremylongshore/tons-of-skills-marketplace
github.com/jeremylongshore/tons-of-skills-marketplace
Related picks
Skill · tddworks
The pick for GitHub Actionsgithub-actions-docs
Skill · devantler-tech
The pick for GitHub Actionsassemblyai-webhooks-events
Skill · jeremylongshore
The pick for Webhookswebhooks
Skill · nahid-sparktales
The pick for Webhooksprototype
Skill · mattpocock
More in Mediabrand-guidelines
Skill · anthropics
More in Media