Skip to content

Blog Auditor: add agentic-workflows MCP tool for snippet validation - #66560

Merged
pelikhan merged 2 commits into
mainfrom
copilot/aw-fix-missing-tools-report
Oct 7, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/aw-fix-missing-tools-report

Conversation

Copilot AI commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

The Blog Auditor reported a missing tool. Its sandbox blocked gh aw compile, so it could not validate the workflow snippets extracted from the blog and fell back to reviewing them by hand.

The fix gives the workflow the agentic-workflows MCP tool, which provides compile, so validation no longer depends on the gh aw CLI being callable from bash. I recompiled the workflow, but I haven't run it, so it's unconfirmed that the MCP compile tool validates the snippets in a real run.

  • Frontmatter (blog-auditor.md)
    • Added tools.agentic-workflows.
    • Added permissions.actions: read. The compiler rejects the tool without it.
    permissions:
      actions: read
      contents: read
    tools:
      agentic-workflows:
  • Prompt
    • The snippet-validation step now names the MCP compile tool as the preferred route.
    • It keeps gh aw compile --no-emit --validate --dir as a fallback in case the CLI is available.
  • Lock file: regenerated blog-auditor.lock.yml.

Copilot AI linked an issue Oct 7, 2026 that may be closed by this pull request
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix missing tools reported in Blog Auditor Blog Auditor: add agentic-workflows MCP tool for snippet validation Oct 7, 2026
Copilot AI requested a review from pelikhan October 7, 2026 12:31
@pelikhan
pelikhan marked this pull request as ready for review October 7, 2026 13:58
Copilot AI balanced review requested due to automatic review settings October 7, 2026 13:58
@pelikhan
pelikhan merged commit ec6348b into main Oct 7, 2026
2 checks passed
@pelikhan
pelikhan deleted the copilot/aw-fix-missing-tools-report branch October 7, 2026 13:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The concise prompt still requests the blocked CLI, and the MCP container cannot access snippets created by the documented temporary-directory command.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds the agentic-workflows MCP server so Blog Auditor can compile extracted workflow snippets without sandboxed CLI access.

Changes:

  • Grants required Actions read permission and enables the MCP tool.
  • Directs detailed audits toward MCP compilation.
  • Regenerates the compiled workflow.
File Description
.github/​workflows/​blog-auditor.md Configures and prompts MCP-based validation.
.github/​workflows/​blog-auditor.lock.yml Adds generated MCP setup and permissions.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

tools:
cli-proxy: true
playwright:
agentic-workflows:
Copilot AI added a commit that referenced this pull request Oct 7, 2026
…66560)

* Initial plan

* Apply remaining changes

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@github-actions github-actions Bot mentioned this pull request Oct 7, 2026
pelikhan added a commit that referenced this pull request Oct 7, 2026
…66554)

* Initial plan

* Align nine workflow tool permissions and warn on denied prompt tools

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

* docs(adr): add draft ADR-66554 for advisory prompt tool validation

* Classify stalled Codex MCP calls as transport wedges (#66303)
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Stop Codex resume retries after invalid request-body rejection (#66553)

* Initial plan

* Stop Codex resume retries on deterministic request-body rejection

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

* Export Codex request error code helper

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Blog Auditor: add agentic-workflows MCP tool for snippet validation (#66560)

* Initial plan

* Apply remaining changes

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Fix prompt tool validation review findings

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Address follow-up prompt validation findings

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.5

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[aw] Blog Auditor is missing required tool

3 participants