Problem
Copilot SDK workflows can disable general shell and task access, but upstream
does not currently provide a closed native repository profile for the remaining
Git and validation lifecycle. A downstream workflow therefore has to retain a
fork to inspect and edit a checkout, run fixed Go validation, and publish only a
validated projection without exposing arbitrary commands.
The scoped permission and denial-guard fixes from #60364 are now upstream. This
request covers the separate opt-in repository runtime that remains fork-only.
Proposed implementation
- Add a versioned
go-repository tool profile for Copilot SDK workflows.
Keep Bash, write_bash, generic task tools, and CLI proxy disabled. Expose
native read/edit tools, approved MCP tools, safe outputs, and one
go_repository tool.
- Give
go_repository only these fixed operations:
status, diff, prepare_branch, format, readiness, validate, and
commit. Do not accept an arbitrary executable, argument list, working
directory, or environment override.
- Bind publication to a clean
GITHUB_SHA, validate the projected checkout,
reject tracked or untracked validation mutations, and require successful
revalidation before commit. Keep Git and Go operations credential-free and
bounded.
- Package every transitive runtime helper, including
branch_pattern_helpers.cjs, and return bounded, redacted native failure
objects with useful mutation details and labeled stdout/stderr excerpts.
- Add promptless integration coverage that exercises the compiled native
catalog, fixed repository operations, and approved MCP tools with zero model
or provider requests.
Reference implementation
The working implementation is split across three focused fork PRs:
Fork Linux CI
passed the JavaScript/typecheck/lint/build/native gates containing the complete
implementation. The consuming workflow also completed a
live native-profile review;
that is downstream behavior evidence, not a substitute for upstream tests.
Acceptance criteria
- The profile is opt-in and does not change default workflow tools.
- No general shell, arbitrary process, or generic task interface is exposed.
- Only the seven fixed repository operations are accepted.
- Validation-created or ignored files cannot enter the publication tree.
- Commit requires a current successful validation of the eligible bytes.
- Native errors are sanitized, actionable, and at most 8192 serialized bytes.
- The setup bundle contains all required helpers.
- Direct and gateway-backed promptless integration passes with zero provider
requests.
- Existing safe-output authorization, protected-file policy, recovery, and
publication behavior remain unchanged.
Out of scope
This does not request broader shell grants, a default profile change,
sessionless MCP transport, or FAM-specific policy in upstream.
Problem
Copilot SDK workflows can disable general shell and task access, but upstream
does not currently provide a closed native repository profile for the remaining
Git and validation lifecycle. A downstream workflow therefore has to retain a
fork to inspect and edit a checkout, run fixed Go validation, and publish only a
validated projection without exposing arbitrary commands.
The scoped permission and denial-guard fixes from #60364 are now upstream. This
request covers the separate opt-in repository runtime that remains fork-only.
Proposed implementation
go-repositorytool profile for Copilot SDK workflows.Keep Bash,
write_bash, generic task tools, and CLI proxy disabled. Exposenative read/edit tools, approved MCP tools, safe outputs, and one
go_repositorytool.go_repositoryonly these fixed operations:status,diff,prepare_branch,format,readiness,validate, andcommit. Do not accept an arbitrary executable, argument list, workingdirectory, or environment override.
GITHUB_SHA, validate the projected checkout,reject tracked or untracked validation mutations, and require successful
revalidation before commit. Keep Git and Go operations credential-free and
bounded.
branch_pattern_helpers.cjs, and return bounded, redacted native failureobjects with useful mutation details and labeled stdout/stderr excerpts.
catalog, fixed repository operations, and approved MCP tools with zero model
or provider requests.
Reference implementation
The working implementation is split across three focused fork PRs:
commit
4f2fae65fc5d23c0e398231f3424f0af24b1bf65:profile, compiler/runtime wiring, fixed operations, projection safeguards,
catalog enforcement, and integration tests.
commit
111624be1e4135a0adc61eb92adec8cd36757a6e:complete safe-output helper packaging.
commit
9ba2c3bf771630b1ba840dbf0be6c22ccd4e23ea:bounded actionable diagnostics and validation-state handling.
Fork Linux CI
passed the JavaScript/typecheck/lint/build/native gates containing the complete
implementation. The consuming workflow also completed a
live native-profile review;
that is downstream behavior evidence, not a substitute for upstream tests.
Acceptance criteria
requests.
publication behavior remain unchanged.
Out of scope
This does not request broader shell grants, a default profile change,
sessionless MCP transport, or FAM-specific policy in upstream.