The generateOpenApiSpec Gradle task fetches pinned Kilo CLI release
metadata from the GitHub REST API to generate the backend OpenAPI
client. The test-jetbrains workflow did not expose a token to this
step, so the calls were unauthenticated and subject to the 60/hour
per-IP limit. On shared Blacksmith runners that budget is exhausted
across concurrent jobs, intermittently failing the build with
'API rate limit exceeded'.
Pass GITHUB_TOKEN to the test step so the task uses the authenticated
(1000/hour repo-scoped) limit.