Skip to content

Add an opt-in shell-free native repository profile for Copilot SDK workflows #61629

Description

@jpmicrosoft

Problem

Copilot SDK workflows can disable general shell and task access, but upstream
does not currently provide a closed native repository profile for the remaining
Git and validation lifecycle. A downstream workflow therefore has to retain a
fork to inspect and edit a checkout, run fixed Go validation, and publish only a
validated projection without exposing arbitrary commands.

The scoped permission and denial-guard fixes from #60364 are now upstream. This
request covers the separate opt-in repository runtime that remains fork-only.

Proposed implementation

  1. Add a versioned go-repository tool profile for Copilot SDK workflows.
    Keep Bash, write_bash, generic task tools, and CLI proxy disabled. Expose
    native read/edit tools, approved MCP tools, safe outputs, and one
    go_repository tool.
  2. Give go_repository only these fixed operations:
    status, diff, prepare_branch, format, readiness, validate, and
    commit. Do not accept an arbitrary executable, argument list, working
    directory, or environment override.
  3. Bind publication to a clean GITHUB_SHA, validate the projected checkout,
    reject tracked or untracked validation mutations, and require successful
    revalidation before commit. Keep Git and Go operations credential-free and
    bounded.
  4. Package every transitive runtime helper, including
    branch_pattern_helpers.cjs, and return bounded, redacted native failure
    objects with useful mutation details and labeled stdout/stderr excerpts.
  5. Add promptless integration coverage that exercises the compiled native
    catalog, fixed repository operations, and approved MCP tools with zero model
    or provider requests.

Reference implementation

The working implementation is split across three focused fork PRs:

Fork Linux CI
passed the JavaScript/typecheck/lint/build/native gates containing the complete
implementation. The consuming workflow also completed a
live native-profile review;
that is downstream behavior evidence, not a substitute for upstream tests.

Acceptance criteria

  • The profile is opt-in and does not change default workflow tools.
  • No general shell, arbitrary process, or generic task interface is exposed.
  • Only the seven fixed repository operations are accepted.
  • Validation-created or ignored files cannot enter the publication tree.
  • Commit requires a current successful validation of the eligible bytes.
  • Native errors are sanitized, actionable, and at most 8192 serialized bytes.
  • The setup bundle contains all required helpers.
  • Direct and gateway-backed promptless integration passes with zero provider
    requests.
  • Existing safe-output authorization, protected-file policy, recovery, and
    publication behavior remain unchanged.

Out of scope

This does not request broader shell grants, a default profile change,
sessionless MCP transport, or FAM-specific policy in upstream.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions