Repository navigation
fix(triage): make gh api mandatory for review comments, closing /code-review's print fallback - #5292
Merged
Merged
Conversation
…-review's print fallback /code-review --comment prefers mcp__github_inline_comment__create_inline_comment and, when that tool is missing, says "fall back to gh api ... or print the findings instead". The bot never loads that tool (--strict-mcp-config), so every review lands on that sentence. PR #5283's run took the print branch without attempting gh api at all, so nothing was denied and the existing "report a denial, don't print" rule never applied. The review was lost and the PR was marked BOT_FAILED. GH_API_ENDPOINT_FIRST_PROMPT now names the tool as absent and makes gh api the required path, allowing printing only after a gh api call has actually been denied. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The triage bot's review of #5283 found four issues and then printed them instead of posting them.
claude -pexited 0, and the daemon's before/after activity count correctly marked the PRBOT_FAILED.No permission rule was involved. The built-in
/code-reviewskill's--commentinstruction (Claude Code 2.1.283) reads:The bot never loads that MCP tool (
--strict-mcp-configloads only gitnexus), so every review reaches the fallback sentence, and "or print" is an exit that needs no denial. The #5283 run never attemptedgh api. The same model posted viagh apiwithout trouble on #5218, #5231, #5271, #5281 and #5284, so which branch a run takes is chance.GH_API_ENDPOINT_FIRST_PROMPTonly forbade printing after a denied call, which didn't cover a run that never tried.This is a third way for a bot review to be silently lost, separate from the prefix-glob denials (#4758) and the command substitution in inline bodies (#5229).
Change
GH_API_ENDPOINT_FIRST_PROMPTnow opens by saying the MCP tool is never available here andgh apiis the required path. Printing is allowed only after agh apicall has actually been denied. The prompt is appended to the review and cleanup flows only.GhApiFormPromptTests.test_closes_the_skills_print_instead_fallbackpins that wording.Testing
python3 -m unittest test_triage_daemon: 308 tests pass. The new test failed before the change.After merging
The running daemon keeps the module it imported at startup, so it must be restarted to pick this up.
🤖 Generated with Claude Code