Skip to content

fix(triage): make gh api mandatory for review comments, closing /code-review's print fallback - #5292

Merged
springfall2008 merged 1 commit into
mainfrom
fix/triage-review-print-fallback
Sep 28, 2026
Merged

springfall2008 merged 1 commit into
mainfrom
fix/triage-review-print-fallback

Conversation

@springfall2008

Copy link
Copy Markdown
Owner

Problem

The triage bot's review of #5283 found four issues and then printed them instead of posting them. claude -p exited 0, and the daemon's before/after activity count correctly marked the PR BOT_FAILED.

No permission rule was involved. The built-in /code-review skill's --comment instruction (Claude Code 2.1.283) reads:

post each finding … via mcp__github_inline_comment__create_inline_comment … If that tool is not available in this session, fall back to gh api (…/pulls/{pr}/comments) or print the findings instead.

The bot never loads that MCP tool (--strict-mcp-config loads only gitnexus), so every review reaches the fallback sentence, and "or print" is an exit that needs no denial. The #5283 run never attempted gh api. The same model posted via gh api without trouble on #5218, #5231, #5271, #5281 and #5284, so which branch a run takes is chance. GH_API_ENDPOINT_FIRST_PROMPT only forbade printing after a denied call, which didn't cover a run that never tried.

This is a third way for a bot review to be silently lost, separate from the prefix-glob denials (#4758) and the command substitution in inline bodies (#5229).

Change

  • GH_API_ENDPOINT_FIRST_PROMPT now opens by saying the MCP tool is never available here and gh api is the required path. Printing is allowed only after a gh api call has actually been denied. The prompt is appended to the review and cleanup flows only.
  • A new GhApiFormPromptTests.test_closes_the_skills_print_instead_fallback pins that wording.

Testing

  • python3 -m unittest test_triage_daemon: 308 tests pass. The new test failed before the change.
  • pre-commit is clean on both files.

After merging

The running daemon keeps the module it imported at startup, so it must be restarted to pick this up.

🤖 Generated with Claude Code

…-review's print fallback

/code-review --comment prefers mcp__github_inline_comment__create_inline_comment and,
when that tool is missing, says "fall back to gh api ... or print the findings instead".
The bot never loads that tool (--strict-mcp-config), so every review lands on that
sentence. PR #5283's run took the print branch without attempting gh api at all, so
nothing was denied and the existing "report a denial, don't print" rule never applied.
The review was lost and the PR was marked BOT_FAILED.

GH_API_ENDPOINT_FIRST_PROMPT now names the tool as absent and makes gh api the required
path, allowing printing only after a gh api call has actually been denied.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@springfall2008
springfall2008 merged commit d951201 into main Sep 28, 2026
2 checks passed
@springfall2008
springfall2008 deleted the fix/triage-review-print-fallback branch September 28, 2026 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant