Skip to content

[Repo Assist] refactor(rust-guard): add tool_names constants for GPG/SSH key and workflow-toggle tools - #14633

Merged
lpcox merged 2 commits into
mainfrom
repo-assist/improve-key-workflow-tool-names-a2903d9231cca8ad
Oct 9, 2026
Merged

lpcox merged 2 commits into
mainfrom
repo-assist/improve-key-workflow-tool-names-a2903d9231cca8ad

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🤖 This is an automated PR from Repo Assist.

Closes #14626

Adds tool_names constants (ADD_GPG_KEY, ADD_SSH_KEY, DELETE_GPG_KEY, DELETE_SSH_KEY, DISABLE_WORKFLOW, ENABLE_WORKFLOW, SYNC_FORK, CREATE_AGENT_TASK) and replaces the duplicated raw literals in tools.rs, labels/tool_rules.rs and labels/mod.rs. Constant-value assertions added to the constants test module. Pure refactor, no behaviour change; sorted-bucket tests still pass.

Test Status

  • cargo fmt clean
  • cargo test (rust-guard): 675 passed, 0 failed
  • Go build/tests not run (no Go files changed)

Generated by Repo Assist · copilot · auto · 51.1 AIC · ⊞ 18.8K · ◷
Comment /repo-assist to run again

Add this agentic workflow to your repo

To install this agentic workflow, run

gh aw add githubnext/agentics/workflows/repo-assist.md@851905c06e905bf362a9f6cc54f912e3df747d55

…rkflow-toggle tools

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@lpcox
lpcox marked this pull request as ready for review October 9, 2026 19:58
Copilot AI balanced review requested due to automatic review settings October 9, 2026 19:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The refactor consistently replaces targeted literals while preserving sorted operation buckets and existing behavior.

0 open findings

What changed in this PR

Centralizes additional Rust guard tool names to prevent literal drift without changing behavior.

Changes:

  • Adds eight canonical tool-name constants and assertions.
  • Reuses constants across operation buckets, label rules, and tests.
  • Applies Rust formatting updates.
File Description
labels/​constants.rs Defines and verifies new constants.
tools.rs Uses constants in classifications and tests.
labels/​tool_rules.rs Uses constants in labeling rules and tests.
labels/​mod.rs Uses the agent-task constant and applies formatting.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

🔒 mcpg Read-Only Stress — default AWF (normal container isolation)

Surface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Isolation runtime: default AWF (normal container isolation)

Part Surface Op Result Expected Status
A MCP reads (list_issues, list_pull_requests, get_file_contents, list_commits) data returned ALLOWED ✅
B MCP writes (add_issue_comment, star_repository, issue_write, create_branch, create_or_update_file, create_pull_request) all 6 targets absent from the 23-tool catalog; each call returned Error [-32602]: unknown tool "..." (not a gateway-specific refusal) BLOCKED ⚠️
C CLI reads (same as A, via github proxied CLI on PATH) data returned ALLOWED ✅
D CLI REST writes (reaction/star/issue/comment) not attempted — gh auth status reports unauthenticated BLOCKED ⚠️
E CLI GraphQL mutations (addReaction/addStar/createIssue) not attempted — gh unauthenticated BLOCKED ⚠️

Overall: INCONCLUSIVE

No write leaked through any surface. Part B is ⚠️ because the gateway's own
backend (launched via gh-aw's tools.github: with GITHUB_READ_ONLY=1) never
registers write tools at all — so refusals are "tool not found" rather than a
gateway-level DIFC denial, which cannot be independently exercised through this
wrapper (per the architectural note in the test plan; tracked as follow-up
work). Parts D/E are ⚠️ because gh is unauthenticated in this environment, so
the token-scope boundary could not be probed. No destructive or risky calls
were attempted; all targeted writes were benign-if-leaked and none leaked.

🔒 mcpg read-only stress (default AWF runtime) by Read-Only Stress: default runtime

@lpcox

lpcox commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@copilot merge main and resolve conflicts

…ey-workflow-tool-names-a2903d9231cca8ad

# Conflicts:
#	guards/github-guard/rust-guard/src/tools.rs

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@copilot merge main and resolve conflicts

Merged main and resolved the tools.rs conflict, keeping both branches’ tool-name constants. Merge commit: 4191187.

Copilot AI requested a review from lpcox October 9, 2026 20:17
@lpcox
lpcox merged commit 2993925 into main Oct 9, 2026
31 checks passed
@lpcox
lpcox deleted the repo-assist/improve-key-workflow-tool-names-a2903d9231cca8ad branch October 9, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[rust-guard] Add tool_names constants for GPG/SSH key and workflow-toggle tools

3 participants