## Summary
The `workflow_run` auto-fix job has write permissions and checks out the triggering PR branch. It now runs only when all three conditions hold:
- the tracked CI workflow failed on a pull request;
- the pull request branch belongs to this repository, not a fork;
- the triggering actor is not a bot account.
The same-repository check closes the privileged fork boundary. The generic `[bot]` suffix check covers Polylane, Graphite, Dependabot, and other GitHub App bot users without maintaining a name list.
## Validation
- `go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 .github/workflows/claude-auto-fix-ci.yml`
- YAML parse with the repository's installed parser
- Final diff audit: one workflow, +3/-1, no added comments
Human-triggered same-repository pull requests keep the existing auto-fix behavior.
Add CI and upgrade Claude workflows
No CI existed — type errors and lint issues only caught by Cloudflare builds. Added type check + biome lint CI on PRs, auto-fix workflow when CI fails, and
upgraded code review with supermemory MCP + inline comments.