The Code Review workflow can fail to persist review state during PR reviews, especially when resuming a review or updating an existing report. Enable native editing for review artifacts while defining a shared behavioral boundary that keeps source files read-only.
Finding
The reported configuration grants the Code Review parent and its eight subagents file-creation capabilities but omits edit/editFiles, although the workflow requires updating existing state and reports. This mismatch can lead the agent to try a shell command named apply_patch, which may not exist in the container, leaving persistence incomplete. A native patch tool and a shell executable with the same name are separate capabilities.
Removing edit tools does not establish a path-based write restriction: creation tools and the parent's terminal capability can also write files. Tool availability and the intended write boundary need to be addressed separately.
Proposed Fix
- Add
edit/editFiles to the Code Review parent and all eight review subagents, retaining their existing creation capabilities and other configuration.
- Define one shared write contract in the Code Review skill, loaded by the parent and subagents. Permit local writes only to review-owned artifacts in the reviewed repository's gitignored tracking directory, subject to narrower task output paths. Use native creation tools for new artifacts and native editing tools for existing state and reports. Apply the same boundary to delegated research, commands, generators, and validation. Keep source files read-only and report suggested code changes as findings.
- Preserve existing human-review and external-publication approval gates. Permission to write local review artifacts must not authorize Git mutations or posting reviews, comments, or issues.
Acceptance Criteria
Affected Components
.github/agents/coding-standards/code-review.agent.md
- Code Review workers under
.github/agents/coding-standards/subagents/
.github/skills/coding-standards/code-review/SKILL.md
The Code Review workflow can fail to persist review state during PR reviews, especially when resuming a review or updating an existing report. Enable native editing for review artifacts while defining a shared behavioral boundary that keeps source files read-only.
Finding
The reported configuration grants the Code Review parent and its eight subagents file-creation capabilities but omits
edit/editFiles, although the workflow requires updating existing state and reports. This mismatch can lead the agent to try a shell command namedapply_patch, which may not exist in the container, leaving persistence incomplete. A native patch tool and a shell executable with the same name are separate capabilities.Removing edit tools does not establish a path-based write restriction: creation tools and the parent's terminal capability can also write files. Tool availability and the intended write boundary need to be addressed separately.
Proposed Fix
edit/editFilesto the Code Review parent and all eight review subagents, retaining their existing creation capabilities and other configuration.Acceptance Criteria
edit/editFileswhile retaining their existing creation capabilities.apply_patchexecutable.Affected Components
.github/agents/coding-standards/code-review.agent.md.github/agents/coding-standards/subagents/.github/skills/coding-standards/code-review/SKILL.md