Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Scheduled Peer Review

ASecurity

Set up and validate the opt-in GitHub Actions scheduler for deterministic Canvas group peer-review pairing.

5 stars
0 votes
0 copies
0 views
Added 9/24/2026
educationpythongitapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/24/2026

$npx -y skills add chaz-clark/canvas-toolbox --skill scheduled-peer-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Scheduled Peer Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Scheduled Peer Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chaz-clark-scheduled-peer-review-dc2441fb/badge)](https://www.skillsdirectory.com/skills/chaz-clark-scheduled-peer-review-dc2441fb)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: scheduled-peer-review
description: Set up and validate the opt-in GitHub Actions scheduler for deterministic Canvas group peer-review pairing.
---

# Scheduled peer-review pairing

This is an advanced-user deployment. It installs a course-owned GitHub Actions
workflow that periodically runs `peer_review_schedule.py`, which gates the
configured local-time window and delegates Canvas work to the existing,
idempotent `peer_review_assign.py` tool.

## Ownership boundary

- Canonical tools, examples, and this skill live in `canvas-toolbox`.
- The concrete workflow belongs in the course repository at
  `.github/workflows/peer-review-sync.yml`.
- The course schedule belongs at `.canvas/peer-review-schedule.yml`.
- Do not install either automatically through `cb_flatten` or `cb_update`.
- Canvas credentials belong in GitHub Actions secrets. The course ID may be a
  repository variable; never commit a token.

## Setup

1. Confirm the course repository is a flattened toolkit install and that
   `lib/tools/peer_review_assign.py` is present.
2. Copy `scaffold/peer-review-schedule.yml.example` to
   `.canvas/peer-review-schedule.yml` and set the assignment/group set, term
   window, lock time, and `America/Denver` (or the course's actual IANA zone).
3. Copy `scaffold/peer-review-sync.yml.example` to
   `.github/workflows/peer-review-sync.yml`.
4. Authenticate the GitHub CLI for the course repository, then use the
   secret-safe helper from the course repo:

   ```text
   uv run python lib/tools/github_actions_setup.py --repo OWNER/COURSE
   uv run python lib/tools/github_actions_setup.py --repo OWNER/COURSE --apply --yes
   ```

   The helper reads only `CANVAS_API_TOKEN`, `CANVAS_BASE_URL`, and
   `CANVAS_COURSE_ID` from `.env`; it writes the first two as repository
   secrets and the course ID as a repository variable. It never prints secret
   values. Without `--apply --yes`, it is a dry run.
5. Run the workflow manually with `apply` unchecked and verify the counts.
6. Validate against a real Canvas sandbox. Only then set `allow_enrolled: true`
   for an enrolled production course and enable the schedule.

## Safety properties

- The schedule is dry-run by default.
- The local lock time is evaluated with `zoneinfo`; the GitHub cron is only a
  polling cadence, so DST changes do not require editing the workflow.
- Runs outside the configured window or before the lock time are no-ops.
- Pairing writes remain idempotent and read-back verified through
  `peer_review_assign.py`.
- The scheduler prints counts/status only; it does not print student names or
  submission contents.
- A non-zero tool result fails the GitHub job and surfaces through GitHub's
  normal notification/history mechanisms.
- The setup helper never uses `gh secret set --env-file .env`; it allowlists
  the three expected keys so unrelated `.env` values cannot be uploaded.

Attribution

chaz-clarkchaz-clark
View sourceSee grades on GitHubMore from chaz-clark →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Math Olympiad

1. **Strip thinking before verifying** — a verifier that sees the reasoning is biased toward agreement. Fresh context, cleaned proof only. 2. **"Does this prove RH?"** — if your theorem's specialization to ζ is a famous open problem, you have a gap. Most reliable red flag. 3. **Short proof → extract the general lemma** — try 2×2 counterexamples. If general form is false, find what's special about THIS instance. 4. **Same gap twice → step back** — the case split may be obscuring a unifie

374330 votes

Manim

Comprehensive guide for Manim Community - Python framework for creating mathematical animations and educational videos with programmatic control

304950 votes

Mcore Onboard Gb200 1node Tests

Onboard 1-node GitHub MR functional tests for GB200 from existing mr-scoped 2-node tests.

180410 votes

Mcore Split Pr

Split a PR into multiple PRs to reduce the number of required CODEOWNERS reviewer groups.

180410 votes

Read Sensor

Listens to a CARLA sensor and either saves its data to files, shows it live in a window, prints a one-shot summary, or (ros-info) reports the native ROS 2 topics, QoS and enabled-for-ROS state so you can echo it from ROS instead. Cameras save as PNG (depth/semantic auto-colourised) and display in a pygame window; lidar saves as .ply and shows as a top-down scatter; IMU/GNSS/radar/collision stream to JSONL or the console. Use when the user asks to "show/view the camera", "display the lidar", "...

144610 votes
View all in education →