Skip to content

fix(agents): enable native Code Review edits with a tracking-only write contract #3165

Description

The Code Review workflow can fail to persist review state during PR reviews, especially when resuming a review or updating an existing report. Enable native editing for review artifacts while defining a shared behavioral boundary that keeps source files read-only.

Finding

The reported configuration grants the Code Review parent and its eight subagents file-creation capabilities but omits edit/editFiles, although the workflow requires updating existing state and reports. This mismatch can lead the agent to try a shell command named apply_patch, which may not exist in the container, leaving persistence incomplete. A native patch tool and a shell executable with the same name are separate capabilities.

Removing edit tools does not establish a path-based write restriction: creation tools and the parent's terminal capability can also write files. Tool availability and the intended write boundary need to be addressed separately.

Proposed Fix

  1. Add edit/editFiles to the Code Review parent and all eight review subagents, retaining their existing creation capabilities and other configuration.
  2. Define one shared write contract in the Code Review skill, loaded by the parent and subagents. Permit local writes only to review-owned artifacts in the reviewed repository's gitignored tracking directory, subject to narrower task output paths. Use native creation tools for new artifacts and native editing tools for existing state and reports. Apply the same boundary to delegated research, commands, generators, and validation. Keep source files read-only and report suggested code changes as findings.
  3. Preserve existing human-review and external-publication approval gates. Permission to write local review artifacts must not authorize Git mutations or posting reviews, comments, or issues.

Acceptance Criteria

  • The Code Review parent and all eight review subagents declare edit/editFiles while retaining their existing creation capabilities.
  • All nine agents load the same tracking-only write contract from the Code Review skill.
  • Fresh, resumed, and rerun reviews can create and update review state and reports using native tools without requiring a shell apply_patch executable.
  • The shared contract keeps source files read-only and limits commands, generators, validation, and delegated work to the same review-owned tracking outputs.
  • Existing human approval and external-publication gates remain unchanged.
  • Relevant artifact validation passes, and required plugin, documentation, and extension projections remain synchronized.
  • The contract explicitly states that it is behavioral guidance, not filesystem enforcement.

Affected Components

  • .github/agents/coding-standards/code-review.agent.md
  • Code Review workers under .github/agents/coding-standards/subagents/
  • .github/skills/coding-standards/code-review/SKILL.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

agentsCustom chat agents (.agent.md)

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions