Conformance Check Failure
Check ID: REQ-002
Severity: MEDIUM
Category: Specification
Problem Description
The add_comment safe output type documentation in the specification is missing its Security Requirements subsection. REQ-002 requires every #### Type: section to contain all 5 standard subsections: MCP Tool Schema, Operational Semantics, Configuration Parameters, Security Requirements, and Required Permissions. add_comment currently has 4 of 5 (missing **Security Requirements**).
Note: this specific finding was logged as [MEDIUM] by the checker but — due to a separate subshell bug in the script (see companion issue) — was not reflected in the run's summary counts or exit code. The underlying documentation gap is still real and worth fixing independently of that script bug.
Affected Components
- Files:
docs/src/content/docs/specs/safe-outputs-specification.md (#### Type: add_comment section, around line 2321)
🔍 Current vs Expected Behavior
Current Behavior
The add_comment type section goes directly from **Controlled Comment Reuse Extensions** / **Enforced Constraints** content to **Required Permissions**, with no **Security Requirements** subsection, unlike other types such as create_issue which has:
**Security Requirements**:
- Title and body undergo full sanitization
- Label validation before creation
- Cross-repo validation against allowed-repos
- Expires implemented via scheduled workflow (not client-side)
Expected Behavior
add_comment should have an explicit **Security Requirements** subsection enumerating its actual security properties, e.g. body sanitization, the 65536-char/10-mention/50-link enforcement described in "Enforced Constraints", cross-repo validation via allowed-repos/target-repo, and the comment_id allowlist checks described in the "Controlled Comment Reuse Extensions" section (Section 7.1 / TYPE-005).
Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
- Open
docs/src/content/docs/specs/safe-outputs-specification.md and locate #### Type: add_comment.
- Add a
**Security Requirements** subsection (positioned consistently with other types, e.g. before **Required Permissions**) summarizing: body/content sanitization, the enforced length/mention/link constraints, target-repo cross-repo allowlist validation, and the comment_id reuse allowlist validation (allows-comment-ids) already described elsewhere in the type's section.
- Re-run the conformance checker to confirm the section count reaches 5/5 for
add_comment.
Verification
After remediation, verify the fix by running:
bash scripts/check-safe-outputs-conformance.sh
REQ-002 should report no per-type "has only N/5 required sections" messages for add_comment.
References
- Safe Outputs Specification: docs/src/content/docs/specs/safe-outputs-specification.md
- Conformance Checker: scripts/check-safe-outputs-conformance.sh
- Run: §36221596011
- Date: 2026-09-26
Generated by ✅ Daily Safe Outputs Conformance Checker · claude · agent · 106.4 AIC · ⌖ 7.66 AIC · ⊞ 7.6K · ◷
Conformance Check Failure
Check ID: REQ-002
Severity: MEDIUM
Category: Specification
Problem Description
The
add_commentsafe output type documentation in the specification is missing its Security Requirements subsection. REQ-002 requires every#### Type:section to contain all 5 standard subsections:MCP Tool Schema,Operational Semantics,Configuration Parameters,Security Requirements, andRequired Permissions.add_commentcurrently has 4 of 5 (missing**Security Requirements**).Note: this specific finding was logged as
[MEDIUM]by the checker but — due to a separate subshell bug in the script (see companion issue) — was not reflected in the run's summary counts or exit code. The underlying documentation gap is still real and worth fixing independently of that script bug.Affected Components
docs/src/content/docs/specs/safe-outputs-specification.md(#### Type: add_commentsection, around line 2321)🔍 Current vs Expected Behavior
Current Behavior
The
add_commenttype section goes directly from**Controlled Comment Reuse Extensions**/**Enforced Constraints**content to**Required Permissions**, with no**Security Requirements**subsection, unlike other types such ascreate_issuewhich has:Expected Behavior
add_commentshould have an explicit**Security Requirements**subsection enumerating its actual security properties, e.g. body sanitization, the 65536-char/10-mention/50-link enforcement described in "Enforced Constraints", cross-repo validation viaallowed-repos/target-repo, and thecomment_idallowlist checks described in the "Controlled Comment Reuse Extensions" section (Section 7.1 / TYPE-005).Remediation Steps
This task can be assigned to a Copilot coding agent with the following steps:
docs/src/content/docs/specs/safe-outputs-specification.mdand locate#### Type: add_comment.**Security Requirements**subsection (positioned consistently with other types, e.g. before**Required Permissions**) summarizing: body/content sanitization, the enforced length/mention/link constraints,target-repocross-repo allowlist validation, and thecomment_idreuse allowlist validation (allows-comment-ids) already described elsewhere in the type's section.add_comment.Verification
After remediation, verify the fix by running:
REQ-002 should report no per-type "has only N/5 required sections" messages for
add_comment.References