Adoption at a glance
Loading NuGet download figures…
Automation & AI
SkiaSharp is a large native binding that tracks Google's Skia engine along Chrome's release train. A small team keeps it current because agentic workflows handle the repetitive work and deterministic scripts handle the mechanics. Humans spend their time on API design and correctness.
AI does not write the graphics engine. It does the toil: syncing upstream, diffing APIs, scaffolding docs, triaging issues, and auditing for CVEs. The mechanical steps run as plain scripts, the agent does the judgement work, and every code or documentation change is proposed through a normal, reviewable pull request.
Moving faster with AI
A few signals the automation moves, cached when the site rebuilds and refreshed from public data. Every number below links back to its source, and each panel notes the date it was last refreshed so a stale figure is obvious rather than hidden.
Loading NuGet download figures…
AI opens, tests, and lands the sync PR; humans review the API.
Loading milestone cadence…
Loading weekly cost…
How it fits together
The Skia update lifecycle runs in two phases. First the upstream sync lands in the library. Then the website release notes are prepared in this repository while API reference publication proceeds independently in mono/SkiaSharp-API-docs. Automation does the mechanical work, the AI agent does the parts that need judgement, and a maintainer reviews before anything ships.
Phase 1 · Sync to merge
Engine & bindings → nuget.org
Merge new commits from Google's Skia, resolve conflicts, and regenerate the bindings.
AI agentBuild the native and managed libraries and run the full test suite on the pull requests.
AutomationA maintainer reviews the two pull requests and merges them into main.
Human reviewPhase 2 · Documentation
Release notes & API diffs → website
Compute the public API diff across every published NuGet of both families.
AutomationTurn the raw diffs and data into readable, human release notes.
AI agentA maintainer merges the docs PR and the website rebuilds.
Human reviewAPI reference publication → Microsoft Learn
mono/SkiaSharp-API-docs independently owns generated API-reference output, validation, and publication.
AutomationMaintainers review API reference changes in the external documentation repository.
Human reviewThe independent pipeline publishes the reviewed API reference to Microsoft Learn.
AutomationWhere we use AI
Six workflows run an AI agent. Each one is wired so the agent can only emit a small set of constrained outputs, listed as "allowed outputs" below. Everything else is read-only.
Merges new commits from Google's upstream Skia, resolves the conflicts, regenerates the bindings, and opens the two paired pull requests: one in mono/skia for the submodule and one in mono/SkiaSharp. The hardest reasoning in the whole pipeline, which is why it runs on the strongest model.
Reads new and untriaged issues, classifies them by type, area, platform, and backend, applies the right labels, and fills the triage fields on the project board. It writes a triage report as an artifact rather than posting noise on the issue.
A deterministic prepare job computes the public API diff over every NuGet and generates the raw release-note data. The agent then turns that data into readable notes and opens one pull request, only when the prepare step actually found changes.
Rotates through native-ownership and disposal risk areas in the managed bindings. A candidate must be proven with a red-to-green regression test before the workflow can file the finding and propose a fix; a quiet run is an explicit success.
Searches the managed layer for measurable hot-path overhead. It must prove both a BenchmarkDotNet improvement and behavior parity before it can file the finding and propose a focused optimization.
Reads a pull request's issue links, code changes, commits, reviews, and validation evidence, then drafts a durable merge message that preserves the why for git history. It never edits the branch or submits the review.
How we automate the rest
A lot of the pipeline is plain GitHub Actions with no AI at all. These run before the agent to prepare its inputs, or after it to publish the result. The agent handles one part, the deterministic step handles the other, so we need both.
Before the release-notes agent runs, scripts do the mechanical work: a Cake task computes the API diff across NuGets and generators produce the raw release-note data. The agent starts from a clean, factual baseline rather than gathering it by hand.
When an agentic run finishes, this workflow downloads its uploaded artifacts and
commits them to the aw-data branch under a key derived from the workflow
name, for example triage reports under ai-triage. It keeps a durable,
inspectable record of what the agents did.
The final, deliberate publish step, triggered manually by a maintainer. It opens (or
reuses) a pull request from main into the live branch;
merging that PR ships the latest API reference to Microsoft Learn.
More plain automation keeps the project moving: the website deploy and staging cleanup, the samples build, API reference publication in its independent repository, PR backport and rebase commands, and a build artifacts comment for fork PRs. None of these use AI; they are the connective tissue the agents plug into.
Reusable instructions
A skill is a folder under .agents/skills/ with a SKILL.md file
that captures how to do one job well: the steps, the rules, and the checks. The agentic
workflows load a skill and let it drive, and maintainers invoke the same skills by hand
as slash commands. One source of truth, used by both the automation and the humans.
Repository-owned workflows and PowerShell scripts perform release mutations; these skills remain thin guidance and observation layers.
Want the full text? Each skill is a plain Markdown file you can read in the repository. Browse the skills folder →
How we keep it safe
The trust story is deliberate. The agents are boxed in by design, and nothing reaches the public API or documentation site without a human-controlled gate.
The mechanical work runs as plain scripts before the agent starts. The agent only does the part that needs judgement, so its surface area is small.
Each workflow declares an allow-list of safe outputs: open a pull request, add labels, set project fields. The agent cannot make arbitrary writes to the repository.
Code and documentation edits arrive as ordinary pull requests. Library changes require maintainer review, and API reference publishing remains independently controlled by its documentation repository.
mono/SkiaSharp-API-docs owns generated API-reference output, validation, and publishing independently of this repository.
Transparency. Everything here runs as public GitHub Actions you can
open and inspect, and SkiaSharp's agentic report artifacts are also copied to the
aw-data
branch. The machinery is not a black box; it is in the open, in the same repositories as
the code.
Go deeper
All of it is open. Read the workflows and skills, or open a pull request to make them better.