Skip to content

[Safe Outputs Conformance] REQ-002: add_comment type documentation missing Security Requirements section #63571

Description

@github-actions

Conformance Check Failure

Check ID: REQ-002
Severity: MEDIUM
Category: Specification

Problem Description

The add_comment safe output type documentation in the specification is missing its Security Requirements subsection. REQ-002 requires every #### Type: section to contain all 5 standard subsections: MCP Tool Schema, Operational Semantics, Configuration Parameters, Security Requirements, and Required Permissions. add_comment currently has 4 of 5 (missing **Security Requirements**).

Note: this specific finding was logged as [MEDIUM] by the checker but — due to a separate subshell bug in the script (see companion issue) — was not reflected in the run's summary counts or exit code. The underlying documentation gap is still real and worth fixing independently of that script bug.

Affected Components

  • Files: docs/src/content/docs/specs/safe-outputs-specification.md (#### Type: add_comment section, around line 2321)
🔍 Current vs Expected Behavior

Current Behavior

The add_comment type section goes directly from **Controlled Comment Reuse Extensions** / **Enforced Constraints** content to **Required Permissions**, with no **Security Requirements** subsection, unlike other types such as create_issue which has:

**Security Requirements**:

- Title and body undergo full sanitization
- Label validation before creation
- Cross-repo validation against allowed-repos
- Expires implemented via scheduled workflow (not client-side)

Expected Behavior

add_comment should have an explicit **Security Requirements** subsection enumerating its actual security properties, e.g. body sanitization, the 65536-char/10-mention/50-link enforcement described in "Enforced Constraints", cross-repo validation via allowed-repos/target-repo, and the comment_id allowlist checks described in the "Controlled Comment Reuse Extensions" section (Section 7.1 / TYPE-005).

Remediation Steps

This task can be assigned to a Copilot coding agent with the following steps:

  1. Open docs/src/content/docs/specs/safe-outputs-specification.md and locate #### Type: add_comment.
  2. Add a **Security Requirements** subsection (positioned consistently with other types, e.g. before **Required Permissions**) summarizing: body/content sanitization, the enforced length/mention/link constraints, target-repo cross-repo allowlist validation, and the comment_id reuse allowlist validation (allows-comment-ids) already described elsewhere in the type's section.
  3. Re-run the conformance checker to confirm the section count reaches 5/5 for add_comment.

Verification

After remediation, verify the fix by running:

bash scripts/check-safe-outputs-conformance.sh

REQ-002 should report no per-type "has only N/5 required sections" messages for add_comment.

References

  • Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
  • Conformance Checker: scripts/check-safe-outputs-conformance.sh
  • Run: §36221596011
  • Date: 2026-09-26

Generated by ✅ Daily Safe Outputs Conformance Checker · claude · agent · 106.4 AIC · ⌖ 7.66 AIC · ⊞ 7.6K · ◷

  • expires on Sep 26, 2026, 9:50 PM UTC-08:00

Activity

  1. github-actions commented on Sep 27, 2026

    @github-actions
    ContributorAuthor

    This issue is being closed as outdated. A newer issue has been created: #63790

    View newer issue


    This action was performed automatically by the Daily Safe Outputs Conformance Checker workflow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions