Repository navigation
Align nine workflow tool allowlists and warn on denied prompt tools - #66554
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Tool detection gaps and contradictory CLI/MCP instructions can still permit missed warnings and denied calls.
Review effort: Balanced
Findings: 4
Open (4)
What changed in this PR
Aligns nine workflow tool permissions with prompt requirements and adds compile-time warnings for unavailable tools.
Changes:
- Adds prompt/tool validation with import and transport awareness.
- Corrects workflow allowlists, MCP/CLI usage, and Codex file access.
- Adds tests, documentation, and regenerated locks.
| File | Description |
|---|---|
pkg/workflow/reported_tool_permissions_test.go |
Tests permissions for nine workflows. |
pkg/workflow/prompt_tool_validation.go |
Implements prompt tool diagnostics. |
pkg/workflow/prompt_tool_validation_test.go |
Covers parsing and availability checks. |
pkg/workflow/compiler.go |
Invokes the new validator. |
docs/src/content/docs/reference/compilation-process.md |
Documents advisory warnings. |
.github/workflows/smoke-workflow-call.md |
Corrects Claude command prefixes. |
.github/workflows/smoke-workflow-call.lock.yml |
Regenerates the workflow. |
.github/workflows/smoke-copilot-aoai-apikey.md |
Clarifies CLI-based smoke tests. |
.github/workflows/smoke-copilot-aoai-apikey.lock.yml |
Regenerates the workflow. |
.github/workflows/sighthound-security-scan.md |
Adds fixed-path MCP readers. |
.github/workflows/sighthound-security-scan.lock.yml |
Regenerates the workflow. |
.github/workflows/outcome-collector.md |
Adds MCP readers and zero-outcome handling. |
.github/workflows/outcome-collector.lock.yml |
Regenerates the workflow. |
.github/workflows/daily-schema-audit-cursor.md |
Allows required shell commands. |
.github/workflows/daily-schema-audit-cursor.lock.yml |
Regenerates the workflow. |
.github/workflows/daily-regression-audit-kiro.md |
Expands shell access and guidance. |
.github/workflows/daily-regression-audit-kiro.lock.yml |
Regenerates the workflow. |
.github/workflows/daily-graft-intelligence.md |
Moves Graft usage to CLI transport. |
.github/workflows/daily-graft-intelligence.lock.yml |
Regenerates the workflow. |
.github/workflows/daily-compiler-quality.md |
Aligns tools and native MCP transport. |
.github/workflows/daily-compiler-quality.lock.yml |
Regenerates the workflow. |
.github/workflows/code-scanning-fixer.md |
Moves mounted tools to CLI usage. |
.github/workflows/code-scanning-fixer.lock.yml |
Regenerates the workflow. |
|
|
||
| ## Workflow Steps | ||
|
|
||
| Use native edit tools for writing cache records and report bodies rather than shell heredocs. Safe outputs are CLI-mounted: invoke `safeoutputs <tool>` through bash (use `--help` for parameters), not an invented native safe-output tool. |
There was a problem hiding this comment.
All safe-output actions now use the CLI-mounted safeoutputs command through bash, including create-pull-request, create-issue, and noop. Fixed in c20f9b3.
| ### 2. List All Open Alerts | ||
|
|
||
| Use `list_code_scanning_alerts` to list all open code scanning alerts. | ||
| Run `github list_code_scanning_alerts` through bash to list all open code scanning alerts. The GitHub CLI wrapper is available; do not invent a `github-list_code_scanning_alerts` tool name. |
There was a problem hiding this comment.
All GitHub reads now use the CLI-mounted github wrapper, and checked-out files are read through allowed shell readers; native GitHub MCP and get_file_contents guidance was removed. Fixed in c20f9b3.
| if requirements, qualified := promptQualifiedRequirements(target); qualified { | ||
| return requirements |
There was a problem hiding this comment.
Qualified invocations are now collected across the full instruction, with a regression that denies only the second custom MCP tool. Fixed in c20f9b3.
| case "safeoutputs": | ||
| return HasSafeOutputsEnabled(data.SafeOutputs) |
There was a problem hiding this comment.
Safe-output availability now checks the exact enabled manifest tool set, including dynamic tools; regressions cover noop-only configuration and custom scripts. Fixed in c20f9b3.
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 6974129
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.
|
|
🧠 Matt Pocock Skills Reviewer is reviewing this pull request using Matt Pocock's engineering skills... |
|
✅ Ponytail Reviewer completed successfully!
|
|
✅ PR Code Quality Reviewer completed the code quality review.
|
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff
|
🏗️ Design Decision Gate: ADR RequiredThis PR triggers ADR enforcement and no Architecture Decision Record was found. Why this PR requires an ADR
Evidence: 23 changed files, including ADR search results
Action takenA draft ADR has been generated from the diff and committed to this branch:
It records the decision as: add an advisory, compile-time validator that extracts explicit tool requirements from prompt text (including imports) and emits warnings — never errors, never permission widening — when the merged permissions, engine capabilities, or transport cannot satisfy them. Alternatives captured: hard compile error, and runtime-only detection via log mining. Next step for you
Merging with the ADR still in
|
There was a problem hiding this comment.
pkg/workflow/prompt_tool_validation.go:L39-41: yagni: second recursive runtime-import collector. Reuse c.collectRuntimeImportMarkdownForCompilerAnalysis(data), adding comment stripping there if needed.
net: -25 lines possible.
Generated by ✂️ Ponytail Reviewer for #66554 · codex · gpt56 · 23.9 AIC · ⌖ 6.49 AIC · ⊞ 13.4K
Comment /ponytail to run again
| for _, entry := range data.PromptImports { | ||
| contents = append(contents, entry.Markdown) | ||
| } | ||
| seed := runtimeImportValidationMarkdown(data) + "\n" + strings.Join(contents, "\n") |
There was a problem hiding this comment.
L39-41: yagni: second recursive runtime-import collector. Reuse c.collectRuntimeImportMarkdownForCompilerAnalysis(data), adding comment stripping there if needed.
There was a problem hiding this comment.
Prompt validation now reuses collectRuntimeImportMarkdownForCompilerAnalysis; the shared collector strips XML comments and includes inline imported prompt markdown. Nested, commented, and confined import coverage was added. Fixed in c20f9b3.
Comment MemoryPeek at saved memory (pr-code-quality-reviewer)Note This comment is managed by comment memory.Expand the saved memory block to view or edit the persistent context for this thread.
|
There was a problem hiding this comment.
Request changes
The new prompt-permission checks still miss explicit tool requirements, and code-scanning-fixer now gives conflicting instructions about native tools versus CLI wrappers.
Blocking themes
code-scanning-fixertells the agent to use CLI-mountedgithub/safeoutputscommands in the workflow steps, but its earlier Tool Usage section still mandates native MCP reads and direct safe-output emission.prompt_tool_validation.goonly validates the first qualified tool reference on a line, so combined instructions can still hide a denied MCP tool.- The validator also ignores bare safe-output aliases such as
create_issueandadd_labels, so the main prompt style used in these workflows still bypasses the new warning entirely.
🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 52.3 AIC · ⌖ 5.51 AIC · ⊞ 19.7K
Comment /review to run again
| if strings.EqualFold(verb, "run") && promptLiteralShellCommand(target) { | ||
| return promptShellRequirements(strings.TrimSuffix(target, ".")) | ||
| } | ||
| if strings.EqualFold(verb, "use") || strings.EqualFold(verb, "call") { |
There was a problem hiding this comment.
This validator still ignores the normal bare safe-output aliases, so prompts like Call create_issue or Use add_labels can require tools that were never configured and compile without any warning.
💡 Why this matters
promptInvocationRequirements only resolves bare names through knownGitHubTools, so the new availability checks never run for the safe-output spellings these workflows actually use. A missing or denied safe output can still slip through unchanged. Please map configured safe-output aliases into the safeoutputs server and add a regression that fails when Call create_issue is present but safe-outputs.create-issue is absent.
There was a problem hiding this comment.
Bare safe-output names and aliases now resolve to safeoutputs requirements and use the same exact availability check; a regression verifies create_issue warns when only add-labels is enabled. Fixed in c20f9b3.
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
* Initial plan * Stop Codex resume retries on deterministic request-body rejection Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> * Export Codex request error code helper Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
…66560) * Initial plan * Apply remaining changes Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot run pr-finisher skill |
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
🎉 This pull request is included in a new release. Release: |

Nine workflows required tools their effective configurations denied, blocking analysis. This change aligns those prompts and permissions and adds compiler warnings for explicit tool requirements that cannot be satisfied.
Workflow access
Compiler diagnostics
Coverage and documentation
For example, this prompt now warns because
jqis denied: